Skip to content

basalt / webhooks/src / WebhookDelivererOptions

Interface: WebhookDelivererOptions ​

Defined in: webhooks/src/deliver.ts:142

Extended by ​

Properties ​

allowSharedSecret? ​

> optional allowSharedSecret?: boolean

Defined in: webhooks/src/deliver.ts:155

Opt-out: sign tenant-bound endpoints that have no own secret with the shared default secret. Off by default — such deliveries are refused.


allowUnsigned? ​

> optional allowUnsigned?: boolean

Defined in: webhooks/src/deliver.ts:161

Opt-out: send deliveries unsigned when neither the endpoint nor the deliverer has a secret. Off by default — unsigned deliveries are refused, since receivers could not tell them from forgeries.


backoffMs? ​

> optional backoffMs?: number

Defined in: webhooks/src/deliver.ts:165

Base backoff in ms, doubled per attempt. Default 500.


fetchImpl? ​

> optional fetchImpl?: (input, init?) => Promise<Response>

Defined in: webhooks/src/deliver.ts:182

(Advanced) custom HTTP client. The default is NOT global fetch but a built-in transport that pins the socket to the SSRF-validated IP (defeats DNS rebinding). A custom fetchImpl receives that IP on its init object under PINNED_ADDRESS but plain fetch ignores it and re-resolves the hostname, re-opening the rebind window. To keep pinning, delegate to pinnedFetch (or pin via your own dispatcher) and set fetchImplPinsAddress: true. Otherwise the deliverer warns once (BASALT_WEBHOOKS_UNPINNED_FETCH) and re-validates the host before every retry — which narrows, but cannot close, the window.

Parameters ​

input ​

string | URL | Request

init? ​

RequestInit

Returns ​

Promise<Response>


fetchImplPinsAddress? ​

> optional fetchImplPinsAddress?: boolean

Defined in: webhooks/src/deliver.ts:188

Declares that the custom fetchImpl honours init[PINNED_ADDRESS] (e.g. it delegates to pinnedFetch). Silences the unpinned-fetch warning and skips the per-retry re-validation.


maxRetries? ​

> optional maxRetries?: number

Defined in: webhooks/src/deliver.ts:163

Retries after the first attempt. Default 3.


now? ​

> optional now?: () => number

Defined in: webhooks/src/deliver.ts:191

Clock in seconds, for deterministic tests.

Returns ​

number


secret? ​

> optional secret?: string

Defined in: webhooks/src/deliver.ts:150

Default signing secret (an endpoint's own secret overrides it). At least MIN_WEBHOOK_SECRET_LENGTH characters. It is only used for tenant-agnostic endpoints: a tenant-bound endpoint must carry its own secret (see allowSharedSecret), since a secret shared by every tenant would let one tenant forge webhooks another tenant's receiver accepts.


sleep? ​

> optional sleep?: (ms) => Promise<void>

Defined in: webhooks/src/deliver.ts:189

Parameters ​

ms ​

number

Returns ​

Promise<void>


ssrf? ​

> optional ssrf?: false | SsrfGuardOptions

Defined in: webhooks/src/deliver.ts:198

SSRF guard for the delivery URL. By default every delivery is refused if the URL scheme isn't http(s) or the host is/resolves to a private, loopback, link-local, CGNAT, ULA or reserved address. Set ssrf.allowPrivateHosts: true only for a trusted self-hosted setup that delivers to internal hosts.


timeoutMs? ​

> optional timeoutMs?: number

Defined in: webhooks/src/deliver.ts:170

Per-attempt deadline in ms, covering DNS resolution AND the request: a resolver that hangs fails the attempt like a slow receiver does. Default 10s.

Released under the MIT License.