Skip to content

feat(notifications): add W66 bounded webhook runtime - #255

Merged
akhiabanchian merged 1 commit into
mainfrom
w66-webhook-runtime-foundation
Oct 4, 2026
Merged

akhiabanchian merged 1 commit into
mainfrom
w66-webhook-runtime-foundation

Conversation

@ammarheidari

@ammarheidari ammarheidari commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Authority

W66 / #215 typed notification destination/security foundation is protected-main admitted via PRs #240/#242.

Runtime slice scope

  • concrete webhook-provider orchestration over preconfigured NotificationDestinationProfile;
  • fixed safe event projection only: event ID/class/type/subject/summary/time;
  • configured endpoint only — no caller-supplied URL, method, headers or redirect policy;
  • endpoint re-resolution through INotificationEndpointResolutionPort and pinned endpoint binding;
  • optional credentials resolved only through opaque preprovisioned NotificationCredentialBindingId;
  • payload size enforced before any resolution/network boundary;
  • destination event-class admission enforced before any external work;
  • transport receives only the pinned endpoint, fixed JSON payload, profile revision fingerprint and optional redacted credential value;
  • SHA-256 payload fingerprint returned for later durable dedup/evidence integration.

Safety

  • no generic HTTP proxy;
  • no arbitrary per-request endpoint;
  • no raw secret locator/value in event payload;
  • no caller-controlled headers;
  • no redirect surface in the adapter contract;
  • no retry loop, durable worker, subscription runtime or API/UI activation in this slice;
  • Email/Slack/Teams/Telegram/PagerDuty remain outside this slice.

Rebased exact head: c92ed6d3fcbc6fb622a535f4c3092cbe1f27ad6d.

Refs #215 #209.

  • corrected runtime-bound length validation so the W66 runtime compiles under the repository's .NET 10 quality gate.
  • rebased without semantic changes onto protected-main cb2519bc853ed21da5b3e310530c6d062324ca20 after W67 PR feat(cli): extend W67 bounded read-only parity #256 admission; fresh exact-head gates/review required.

Copy link
Copy Markdown
Contributor Author

@codex review

Please review exact head 18f5c1fa52b47f7cb1a08db6a30f7d1f7d2325e9 only. Focus on SSRF/pinning boundary preservation, endpoint substitution, credential scoping, secret exposure, payload/event bounds, cancellation, and ensuring this cannot become a caller-controlled generic HTTP proxy.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T21:42:36.246827Z c92ed6d Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@ammarheidari
ammarheidari force-pushed the w66-webhook-runtime-foundation branch from 3d976bc to 428eda7 Compare October 4, 2026 21:13

Copy link
Copy Markdown
Contributor Author

@codex review

Please review corrective exact head 428eda7cce2145abae7977d3b0b512f1db706af2 only. Verify the bounded webhook runtime remains non-proxying and preserves endpoint pinning, credential scoping, fixed event projection, payload bounds, cancellation and secret non-disclosure.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Bravo.

Reviewed commit: 428eda7cce

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
@ammarheidari
ammarheidari force-pushed the w66-webhook-runtime-foundation branch from 428eda7 to c92ed6d Compare October 4, 2026 21:39

Copy link
Copy Markdown
Contributor Author

@codex review

Please review rebased exact head c92ed6d3fcbc6fb622a535f4c3092cbe1f27ad6d only. Tree semantics are unchanged; verify the bounded webhook runtime remains non-proxying and preserves endpoint pinning, credential scoping, fixed projection, payload bounds and secret non-disclosure.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Can't wait for the next one!

Reviewed commit: c92ed6d3fc

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@akhiabanchian
akhiabanchian merged commit 67edb79 into main Oct 4, 2026
8 checks passed
@akhiabanchian
akhiabanchian deleted the w66-webhook-runtime-foundation branch October 4, 2026 21:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants