feat: enhance webhook settings UI and security: Mostly working, just final post not functioning

- Add CSS styles for token URL input and hints
- Implement safe data attribute parsing in settings.js
- Refactor room fetching logic to use promise chains and auto-fetch on load
- Display full webhook URLs in the settings UI instead of raw tokens
- Generate URL-safe base64 tokens to prevent encoding issues
- Add #[PublicPage] attribute to WebhookController for unauthenticated delivery
- Filter out internal Nextcloud Talk system rooms from the room picker
- Add OCS-ApiRequest header to bot API requests
- Sanitize data attributes in templates to prevent XSS
This commit is contained in:
kyle
2026-06-11 10:55:30 -07:00
parent 3f51a8ca48
commit aa06394aa9
5 changed files with 103 additions and 30 deletions
+17
View File
@@ -22,6 +22,13 @@ class TalkService {
private const APP_ID = 'ncdiscordhook';
private const IMAGES_DIR = 'NCdiscordhook-images';
// Internal system rooms to hide from the room picker.
private const INTERNAL_ROOMS = [
'talk-bot',
'Note to self',
"Let's get started!",
];
private IClient $client;
private IConfig $config;
private IDBConnection $db;
@@ -238,6 +245,15 @@ class TalkService {
'rooms' => array_keys($rooms),
]);
// Filter out internal system rooms.
foreach (self::INTERNAL_ROOMS as $internal) {
foreach ($rooms as $token => $name) {
if (mb_strtolower($name) === mb_strtolower($internal)) {
unset($rooms[$token]);
}
}
}
return $rooms;
} catch (\Exception $e) {
$this->logger->error('NCdiscordhook: room listing exception', [
@@ -602,6 +618,7 @@ class TalkService {
'basic' => [$bot->getUID(), $botPassword],
'headers' => [
'OCS-Expect' => '100',
'OCS-ApiRequest' => 'true',
'Content-Type' => 'application/x-www-form-urlencoded',
'Content-Length' => (string) strlen($body),
],