Repository navigation
feat: add polytomic-webhooks skill - #209
Merged
Merged
Conversation
The IP-allowlist caveat in SKILL.md and references/setup.md presented a paraphrase inside quotation marks. Replaced with the verbatim sentence from https://docs.polytomic.com/docs/whitelist-ips so the attribution matches the source. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds the
polytomic-webhooksskill: how to receive and authenticate the webhookbatches a Polytomic Webhook destination connection POSTs to your endpoint.
The scheme — Polytomic signs nothing
This is a no-signature provider, and the one thing a reviewer should check
first is that no HMAC was force-fitted. There is none in the verify path (a test
in each example asserts the absence):
Authorization: Bearer <secret>, compared constant-time against the SecretPolytomic shows you during connection setup. Verbatim from the docs: "For now,
this is the only request authorization and is a static value."
Polytomic-Signature-Timestampis not a signature despite the name — itcarries an RFC 3339 timestamp (
2021-06-01T22:55:36Z), not a digest, andnot epoch seconds. The examples use it for an optional, configurable freshness
window (default 300s) and say plainly that this proves nothing about
authenticity, because the timestamp is not covered by anything.
(
aud: webhook,jti,iss), but it is signed with a key Polytomic does notgive you and has no
exp. The skill treats it as an opaque secret and warnsagainst
jwt.verify/jwt.decode.bearer token is the whole security boundary.
Shape
One documented event,
sync.records, and the payload is a batch(
object.records[], default 100 records, user-configurable) — so every handlerloops.
records[].fieldskeys are user-defined by the sync configuration, sonothing is typed against the docs'
email/last_loginexample;object.metadatamay be an object,null, or absent. Unknowneventvaluesreturn 200, because a 4xx/5xx "will cause the sync to appear as a failure" and
the docs anticipate future event types.
Hedged facts a reviewer may otherwise re-flag
Accept-Encoding: gzipwhile the prosesays payloads arrive "as a gzipped response". Those are in tension, so the
skill states the operational consequence (the body may arrive compressed; most
frameworks decompress transparently) rather than asserting a header nobody has
observed. Marked unsettled pending a live capture.
docs.polytomic.com/docs/whitelist-ips, which the webhooks page links to — but
that page frames the list for database/warehouse connections, and it does not
apply to self-hosted Polytomic. Presented as a firewall convenience, not
authentication.
records[].hashis described as an idempotency key only; its algorithm andlength are not asserted.
Testing
scripts/validate-provider.sh polytomic-webhooks— passesAccuracy review: the generator approved with 4 suggestions (2 auto-fixed). My own
pass over the three verify paths confirmed no HMAC/hash primitive, no invented
signature header, and no invented event names — every such string in the skill is
a negative assertion. One genuine defect found and fixed in a follow-up commit: an
IP-allowlist caveat presented a paraphrase inside quotation marks, now quoted
verbatim from the source page. All other quoted claims were checked word-for-word
against https://docs.polytomic.com/docs/webhooks-connections.md.
No live Polytomic account was available, so the gzip question and the exact
Authorizationvalue remain doc-sourced rather than capture-confirmed.Left as a draft pending owner sign-off.
🤖 Generated with Claude Code