Use case
Change requests in your own tools
Every request for changes arrives signed on your route, with the client’s comment, ready to become a ticket.
import { verifyWebhook } from '@colis/protocol'
export async function POST(request: Request) {
const body = await request.text()
const result = await verifyWebhook(process.env.DROP_WEBHOOK_SECRET!, request.headers, body)
if (!result.valid) return new Response(null, { status: 401 })
const event = JSON.parse(body)
if (event.type === 'parcel.changes_requested') {
await createIssue({ // your tracker
title: `Corrections : ${event.data.filename}`,
body: event.data.comment,
reference: event.data.code,
})
}
return new Response(null, { status: 204 })
}The situation
What is actually going on.
The problem
Client feedback gets lost between email, chat and calls. The one that matters, “the logo as SVG, and a lighter background”, has to end up in your tracker.
What colis does about it
Point DROP_WEBHOOK_URL at a route of yours. verifyWebhook from @colis/protocol checks the Standard Webhooks signature (HMAC-SHA256) with the same code the deployment signs with. On parcel.changes_requested, data.comment carries what the client wrote: open the ticket, and link the parcel by its code.
Worth watching
The things that are easy to get wrong.
Read the raw body
The signature covers the bytes received: request.text() before any JSON.parse.
Five minutes of tolerance
A timestamp more than five minutes off is refused, so an old delivery cannot be replayed.
No secret in the event
data never holds the password, its hash, or the sender’s token.
Related
Other ways to deliver.
Send it. They sign off. You know.
Your storage, a delivery page under your name, a webhook at every step. Nothing hosted by someone else.