basalt / webhooks/src / WebhookDelivererOptions
Interface: WebhookDelivererOptions
Defined in: webhooks/src/deliver.ts:142
Extended by
Properties
allowSharedSecret?
> optional allowSharedSecret?: boolean
Defined in: webhooks/src/deliver.ts:155
Opt-out: sign tenant-bound endpoints that have no own secret with the shared default secret. Off by default — such deliveries are refused.
allowUnsigned?
> optional allowUnsigned?: boolean
Defined in: webhooks/src/deliver.ts:161
Opt-out: send deliveries unsigned when neither the endpoint nor the deliverer has a secret. Off by default — unsigned deliveries are refused, since receivers could not tell them from forgeries.
backoffMs?
> optional backoffMs?: number
Defined in: webhooks/src/deliver.ts:165
Base backoff in ms, doubled per attempt. Default 500.
fetchImpl?
> optional fetchImpl?: (input, init?) => Promise<Response>
Defined in: webhooks/src/deliver.ts:182
(Advanced) custom HTTP client. The default is NOT global fetch but a built-in transport that pins the socket to the SSRF-validated IP (defeats DNS rebinding). A custom fetchImpl receives that IP on its init object under PINNED_ADDRESS but plain fetch ignores it and re-resolves the hostname, re-opening the rebind window. To keep pinning, delegate to pinnedFetch (or pin via your own dispatcher) and set fetchImplPinsAddress: true. Otherwise the deliverer warns once (BASALT_WEBHOOKS_UNPINNED_FETCH) and re-validates the host before every retry — which narrows, but cannot close, the window.
Parameters
input
string | URL | Request
init?
RequestInit
Returns
Promise<Response>
fetchImplPinsAddress?
> optional fetchImplPinsAddress?: boolean
Defined in: webhooks/src/deliver.ts:188
Declares that the custom fetchImpl honours init[PINNED_ADDRESS] (e.g. it delegates to pinnedFetch). Silences the unpinned-fetch warning and skips the per-retry re-validation.
maxRetries?
> optional maxRetries?: number
Defined in: webhooks/src/deliver.ts:163
Retries after the first attempt. Default 3.
now?
> optional now?: () => number
Defined in: webhooks/src/deliver.ts:191
Clock in seconds, for deterministic tests.
Returns
number
secret?
> optional secret?: string
Defined in: webhooks/src/deliver.ts:150
Default signing secret (an endpoint's own secret overrides it). At least MIN_WEBHOOK_SECRET_LENGTH characters. It is only used for tenant-agnostic endpoints: a tenant-bound endpoint must carry its own secret (see allowSharedSecret), since a secret shared by every tenant would let one tenant forge webhooks another tenant's receiver accepts.
sleep?
> optional sleep?: (ms) => Promise<void>
Defined in: webhooks/src/deliver.ts:189
Parameters
ms
number
Returns
Promise<void>
ssrf?
> optional ssrf?: false | SsrfGuardOptions
Defined in: webhooks/src/deliver.ts:198
SSRF guard for the delivery URL. By default every delivery is refused if the URL scheme isn't http(s) or the host is/resolves to a private, loopback, link-local, CGNAT, ULA or reserved address. Set ssrf.allowPrivateHosts: true only for a trusted self-hosted setup that delivers to internal hosts.
timeoutMs?
> optional timeoutMs?: number
Defined in: webhooks/src/deliver.ts:170
Per-attempt deadline in ms, covering DNS resolution AND the request: a resolver that hangs fails the attempt like a slow receiver does. Default 10s.