Skip to content

Follow a same-host https redirect in the notify action (GRYT-1304) - #28

Merged
sivert-io merged 1 commit into
mainfrom
claude/GRYT-1304-notify-https-redirect
Sep 23, 2026
Merged

sivert-io merged 1 commit into
mainfrom
claude/GRYT-1304-notify-https-redirect

Conversation

@sivert-io

Copy link
Copy Markdown
Member

Fixes GRYT-1304.

What

notify.sh's post() already upgrades an http:// webhook secret to https:// before sending. It didn't handle the target answering back with a redirect: any 301/302/307/308 was logged as a warning and dropped, even when the redirect just pointed at the correct https address on the same host.

Now a redirect is followed once, and only when the Location header stays on the same host and points at https://. A redirect to another host, or one that points back at http://, is still not followed — those log a warning instead. A second redirect after the first isn't chased either.

This came up because community.gryt.chat was handing out an http:// webhook URL.

Testing

Ran shellcheck actions/*/*.sh and actionlint locally — both clean.

Tested against a throwaway local HTTPS server with a self-signed cert, covering:

  • same-host redirect to https — followed, posts land on the target (HTTP 200)
  • redirect to a different host — not followed, warning logged
  • redirect down to http on the same host — not followed, warning logged
  • a second redirect after following the first — not chased, warning logged

Output:

=== same-host https redirect (followed) ===
::warning::Gryt: the webhook URL answered HTTP 302 and redirected to https on the same host. It was retried there once. Point the secret straight at https:// to skip the redirect.
Gryt: posted (HTTP 200).

=== redirect to a different host (not followed) ===
::warning::Gryt: the webhook URL answered HTTP 302, a redirect, and redirects aren't followed to a different host or back down to http. Point the secret at the address it should use.

=== redirect down to http on same host (not followed) ===
::warning::Gryt: the webhook URL answered HTTP 302, a redirect, and redirects aren't followed to a different host or back down to http. Point the secret at the address it should use.

=== double redirect (only the first is followed) ===
::warning::Gryt: the webhook URL answered HTTP 302 and redirected to https on the same host. It was retried there once. Point the secret straight at https:// to skip the redirect.
::warning::Gryt: the redirect target itself answered HTTP 302, another redirect, and only one is followed. Point the secret at the address it should use.

🤖 Generated with Claude Code

community.gryt.chat was handing out an http:// webhook URL. notify.sh
already upgraded that to https before sending, but if the target then
answered a redirect, the post was dropped instead of following it.
Retry once at the Location header, and only when it stays on the same
host and points at https — never to another host, never back down to
http.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
@sivert-io
sivert-io merged commit 3b52b1b into main Sep 23, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant