trypost/app/Actions/Webhook/RotateWebhookSecret.php
Paulo Castellano a932c51bbb
Expose workspace webhooks through the API and MCP (#330)
* Expose workspace webhooks through the API and MCP.

The same create/update/test/rotate/replay/delete flow now lives in Actions so the web UI, REST API, and MCP tools stay in lockstep.

* Keep webhook validation local to each web, API, and MCP entry point.

* Extract MCP webhook rules into request classes and close remaining API/MCP review gaps.

* Tighten webhook updates to a field whitelist and reset failures only on re-enable.

* Treat a mismatched webhook replay as not found and mark secret rotation destructive.
2026-09-04 12:00:32 -03:00

19 lines
336 B
PHP

<?php
declare(strict_types=1);
namespace App\Actions\Webhook;
use App\Models\Webhook;
class RotateWebhookSecret
{
public static function execute(Webhook $webhook): Webhook
{
$webhook->update([
'signing_secret' => Webhook::generateSigningSecret(),
]);
return $webhook->refresh();
}
}