Skip to content
Français

createGitlabWebhook

import { createGitlabWebhook } from "@elie-laloum/outpost";

Create a GitLab trigger source. With signingToken it verifies the webhook-signature header of a whsec_ signing token (GitLab 19.0+) within a timestamp window and uses webhook-id; with token it compares X-Gitlab-Token and uses Idempotency-Key or X-Gitlab-Event-UUID. It reports object_kind, the object action and the user as gitlab:<username>.

Complete example and detailed rules.

The fields below cover all variants; the signature specifies their allowed combinations.

  • optionsRequired
    GitlabWebhookOptions
    Either signingToken (recommended, signs the body) or token (legacy plain-text header); signingToken is used when both are set.
  • options.signingTokenVariant-dependent
    TriggerSecret
    whsec_ signing token of the GitLab webhook (GitLab 19.0+) verifying webhook-signature, or a callback returning every currently accepted token (old and new during a rotation). An empty string throws at creation; a callback that fails or returns nothing, or a token without the whsec_ prefix, denies requests.
  • options.toleranceMsVariant-dependent
    number | undefined
    Accepted clock difference for the request timestamp, in milliseconds; defaults to 300000 (5 minutes). A value that is not a positive integer throws at creation.
  • options.tokenVariant-dependent
    TriggerSecret
    Secret token compared in constant time with X-Gitlab-Token, or a callback returning every currently accepted token; weaker because the body is not signed. An empty string throws at creation; a callback that fails or returns nothing denies requests.

TriggerSource

export declare function createGitlabWebhook(
  options: GitlabWebhookOptions,
): TriggerSource;