fix(security): encrypt GitLab webhook token and mask input

Webhook secret was stored and shown as plaintext. Use a password field,
encrypt at rest (with legacy plaintext read support), and look up tokens
via findByWebhookToken so encrypted values still authenticate webhooks.
This commit is contained in:
Andras Bacsai
2026-07-21 21:21:04 +02:00
parent 94c3129ad1
commit 43919ef4e0
5 changed files with 118 additions and 4 deletions
+1 -1
View File
@@ -103,7 +103,7 @@ class Gitlab extends Controller
], 401);
}
$gitlab_app = GitlabApp::where('webhook_token', $x_gitlab_token)->first();
$gitlab_app = GitlabApp::findByWebhookToken($x_gitlab_token);
if (! $gitlab_app) {
auditLogWebhookFailure('gitlab', 'invalid_token', [
'event' => $object_kind,