Skip to content

Commit f2427ba

Browse files
author
stlc-bot
committed
feat(api-keys): enforce scoped API key permissions (#1038)
Stainless-Generated-From: c4490679ad1c4036f4865d52b7b223b9daf73af8
1 parent 39ca377 commit f2427ba

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

‎pkg/cmd/monitor.go‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -93,7 +93,7 @@ var monitorsCreate = requestflag.WithInnerFlags(cli.Command{
9393
},
9494
&requestflag.InnerFlag[string]{
9595
Name: "webhook.secret",
96-
Usage: "Signing secret used to verify webhook authenticity. Each delivery includes an `X-Context-Signature: t=<unix>,v1=<hmac>` header, where the HMAC is SHA-256 over `\"{t}.{rawRequestBody}\"` keyed by this secret. Recompute it with a constant-time compare and reject stale timestamps to prevent replay. Generated by the API; cannot be set by clients.",
96+
Usage: "Signing secret used to verify webhook authenticity. Omitted unless the API key has monitors:write permission or full access. Each delivery includes an `X-Context-Signature: t=<unix>,v1=<hmac>` header, where the HMAC is SHA-256 over `\"{t}.{rawRequestBody}\"` keyed by this secret. Recompute it with a constant-time compare and reject stale timestamps to prevent replay. Generated by the API; cannot be set by clients.",
9797
InnerField: "secret",
9898
},
9999
},
@@ -197,7 +197,7 @@ var monitorsUpdate = requestflag.WithInnerFlags(cli.Command{
197197
},
198198
&requestflag.InnerFlag[string]{
199199
Name: "webhook.secret",
200-
Usage: "Signing secret used to verify webhook authenticity. Each delivery includes an `X-Context-Signature: t=<unix>,v1=<hmac>` header, where the HMAC is SHA-256 over `\"{t}.{rawRequestBody}\"` keyed by this secret. Recompute it with a constant-time compare and reject stale timestamps to prevent replay. Generated by the API; cannot be set by clients.",
200+
Usage: "Signing secret used to verify webhook authenticity. Omitted unless the API key has monitors:write permission or full access. Each delivery includes an `X-Context-Signature: t=<unix>,v1=<hmac>` header, where the HMAC is SHA-256 over `\"{t}.{rawRequestBody}\"` keyed by this secret. Recompute it with a constant-time compare and reject stale timestamps to prevent replay. Generated by the API; cannot be set by clients.",
201201
InnerField: "secret",
202202
},
203203
},

0 commit comments

Comments
 (0)