Fixes #13862 Updates the webhook OpenAPI schema to match the current API behavior for webhook secrets and supported subscription events. ## Why Current source already creates per-webhook secrets, returns `secret` from the account webhook API, and uses that secret to sign outbound webhook requests with `X-Chatwoot-Signature`. The OpenAPI schema was behind that contract: - `components.schemas.webhook` did not include the returned `secret` field. - Webhook subscription enums did not include the typing events that are already available in the dashboard webhook form and handled by `WebhookListener`. ## What this change does - Documents `secret` on the webhook response schema. - Documents the outbound webhook signing headers associated with `secret`: `X-Chatwoot-Timestamp`, `X-Chatwoot-Signature`, and `X-Chatwoot-Delivery`. - Adds `conversation_typing_on` and `conversation_typing_off` to webhook subscription enums. - Regenerates the main and tag-group swagger JSON files. ## Validation - Ran `bundle exec rails swagger:build`. - Ran `bundle exec rspec spec/swagger/openapi_spec.rb`. - Verified generated swagger JSON includes `secret`, `conversation_typing_on`, and `conversation_typing_off` in the webhook schemas. --------- Co-authored-by: Syed Muhammad Bilal <sdmhbilal@users.noreply.github.com> Co-authored-by: Sojan Jose <sojan@pepalo.com>
36 lines
1.1 KiB
YAML
36 lines
1.1 KiB
YAML
type: object
|
|
properties:
|
|
id:
|
|
type: number
|
|
description: The ID of the webhook
|
|
url:
|
|
type: string
|
|
description: The url to which the events will be send
|
|
name:
|
|
type: string
|
|
description: The name of the webhook
|
|
subscriptions:
|
|
type: array
|
|
items:
|
|
type: string
|
|
enum: [
|
|
"conversation_created",
|
|
"conversation_status_changed",
|
|
"conversation_updated",
|
|
"contact_created",
|
|
"contact_updated",
|
|
"message_created",
|
|
"message_updated",
|
|
"webwidget_triggered",
|
|
"conversation_typing_on",
|
|
"conversation_typing_off"
|
|
]
|
|
description: The list of subscribed events
|
|
secret:
|
|
type: string
|
|
nullable: true
|
|
description: Secret used to sign webhook requests. Signed webhook deliveries include `X-Chatwoot-Timestamp` and `X-Chatwoot-Signature`; the signature is `sha256=` followed by the HMAC-SHA256 of `{timestamp}.{raw_request_body}` using this secret. Deliveries also include `X-Chatwoot-Delivery` when a delivery id is available.
|
|
account_id:
|
|
type: number
|
|
description: The id of the account which the webhook object belongs to
|