Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've already opened up some issues[1]. What you point to is what I mean, in addition a reverse IP lookup is also useful to tighten security a bit [2], but it's not mandatory. Specifying a secret is IMO the easiest way to have some peace of mind when it comes to accepting hooks. Regarding the API, I mainly found the documentation more difficult to navigate. There doesn't seem a section specifically for gitlab.com, so I just have to assume that 'community edition' applies there. I haven't found a place where the API endpoint for a gitlab.com profile is described, just took a bit of trial and error - and whatever isn't documented for an API I don't like to rely on.

[1] https://gitlab.com/gitlab-org/gitlab-ce/issues?scope=all&sor...

[2] https://developer.github.com/v3/meta/



Thanks for opening those issues days ago! I already marked the documentation issue https://gitlab.com/gitlab-org/gitlab-ce/issues/13479 for the attention of our technical writer 5 days ago. I think having the ability to specify a secret from webhooks makes sense and have asked our CTO and VP of Product for comments in https://gitlab.com/gitlab-org/gitlab-ce/issues/13478. GitLab.com runs GitLab EE, this is displayed at the top of https://about.gitlab.com/gitlab-com/ but please let me know if there is another logical place. The API endpoint paths are the same for all GitLab servers so https://gitlab.example.com/api becomes https://gitlab.com/api. I've made an issue to discuss replacing the example.com url with gitlab.com https://gitlab.com/gitlab-org/gitlab-ce/issues/13643

Thanks for all your feedback and creating issues!


You're welcome, and I appreciate the response. I forgot something btw., which is actually the biggest issue I had so far: We were affected by some variant of [1].

Regarding documentation, how about referencing 'gitlab.com' on the following top level selection? [2] You could add a new box linking to the EE documentation. That was the first place where I was looking and made me stumble.

[1] https://gitlab.com/gitlab-org/gitlab-ce/issues/3150

[2] http://doc.gitlab.com


Thanks for your suggestions.

1. Can you reproduce the web hook push event failure in any way?

2. Thanks for the suggestion, I made https://gitlab.com/gitlab-com/doc-gitlab-com/issues/55




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: