feat: enhance webhook settings UI and security: Mostly working, just final post not functioning

- Add CSS styles for token URL input and hints
- Implement safe data attribute parsing in settings.js
- Refactor room fetching logic to use promise chains and auto-fetch on load
- Display full webhook URLs in the settings UI instead of raw tokens
- Generate URL-safe base64 tokens to prevent encoding issues
- Add #[PublicPage] attribute to WebhookController for unauthenticated delivery
- Filter out internal Nextcloud Talk system rooms from the room picker
- Add OCS-ApiRequest header to bot API requests
- Sanitize data attributes in templates to prevent XSS
This commit is contained in:
kyle
2026-06-11 10:55:30 -07:00
parent 3f51a8ca48
commit aa06394aa9
5 changed files with 103 additions and 30 deletions
+2
View File
@@ -16,6 +16,7 @@ use OCP\IUserSession;
use OCP\AppFramework\Controller\Attribute\AdminRequired;
use Psr\Log\LoggerInterface;
use OCP\AppFramework\Http\Attribute\NoCSRFRequired;
use OCP\AppFramework\Http\Attribute\PublicPage;
use OCP\AppFramework\Http\Attribute\SubAdminRequired;
class WebhookController extends Controller {
@@ -35,6 +36,7 @@ class WebhookController extends Controller {
*
* URL: POST /apps/ncdiscordhook/webhook/{roomToken}/{authToken}
*/
#[PublicPage]
#[NoCSRFRequired]
public function receive(string $roomToken, string $authToken): DataResponse {
// Validate auth token