trypost/app/Actions/Webhook/CreateWebhook.php
Paulo Castellano a932c51bbb
Expose workspace webhooks through the API and MCP (#330)
* Expose workspace webhooks through the API and MCP.

The same create/update/test/rotate/replay/delete flow now lives in Actions so the web UI, REST API, and MCP tools stay in lockstep.

* Keep webhook validation local to each web, API, and MCP entry point.

* Extract MCP webhook rules into request classes and close remaining API/MCP review gaps.

* Tighten webhook updates to a field whitelist and reset failures only on re-enable.

* Treat a mismatched webhook replay as not found and mark secret rotation destructive.
2026-09-04 12:00:32 -03:00

31 lines
787 B
PHP

<?php
declare(strict_types=1);
namespace App\Actions\Webhook;
use App\Enums\Webhook\Status;
use App\Models\Webhook;
use App\Models\Workspace;
use App\Services\WebhookService;
class CreateWebhook
{
/**
* @param array<string, mixed> $data
*/
public static function execute(Workspace $workspace, array $data, WebhookService $webhooks): Webhook
{
$endpoint = (string) data_get($data, 'endpoint');
$webhooks->assertEndpointAllowed($endpoint);
return Webhook::query()->create([
'workspace_id' => $workspace->id,
'endpoint' => $endpoint,
'events' => data_get($data, 'events'),
'status' => Status::Enabled,
'signing_secret' => Webhook::generateSigningSecret(),
]);
}
}