Repository navigation
Follow a same-host https redirect in the notify action (GRYT-1304) - #28
Merged
Merged
Conversation
community.gryt.chat was handing out an http:// webhook URL. notify.sh already upgraded that to https before sending, but if the target then answered a redirect, the post was dropped instead of following it. Retry once at the Location header, and only when it stays on the same host and points at https — never to another host, never back down to http. Co-Authored-By: Claude Sonnet 5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes GRYT-1304.
What
notify.sh'spost()already upgrades anhttp://webhook secret tohttps://before sending. It didn't handle the target answering back with a redirect: any 301/302/307/308 was logged as a warning and dropped, even when the redirect just pointed at the correct https address on the same host.Now a redirect is followed once, and only when the
Locationheader stays on the same host and points athttps://. A redirect to another host, or one that points back athttp://, is still not followed — those log a warning instead. A second redirect after the first isn't chased either.This came up because community.gryt.chat was handing out an
http://webhook URL.Testing
Ran
shellcheck actions/*/*.shandactionlintlocally — both clean.Tested against a throwaway local HTTPS server with a self-signed cert, covering:
Output:
🤖 Generated with Claude Code