- delivery_id is now generated once per firing and used for both the X-Hermes-Delivery header and the signed body's delivery_id field — previously they were two different uuid4s, breaking receiver-side dedupe as documented. - 3xx responses are no longer followed: urllib's default redirect handler converts a redirected POST into a body-less GET, silently dropping the signed payload. Redirects now log a misconfiguration warning and count as delivery failure (no retry). - Docs: receiver-side replay-protection guidance (dedupe on delivery_id, timestamp freshness window) + redirect semantics. - Tests: 5xx retry count, redirect-not-followed (sabotage-verified), header/body delivery_id equality. |
||
|---|---|---|
| .. | ||
| docs | ||
| i18n/zh-Hans/docusaurus-plugin-content-docs/current | ||
| scripts | ||
| src | ||
| static | ||
| .gitignore | ||
| .npmrc | ||
| README.md | ||
| docusaurus.config.ts | ||
| package-lock.json | ||
| package.json | ||
| sidebars.ts | ||
| tsconfig.json | ||
README.md
Website
This website is built using Docusaurus, a modern static website generator.
Installation
yarn
Local Development
yarn start
This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.
Build
yarn build
This command generates static content into the build directory and can be served using any static contents hosting service.
Deployment
Using SSH:
USE_SSH=true yarn deploy
Not using SSH:
GIT_USER=<Your GitHub username> yarn deploy
If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.
Diagram Linting
CI runs ascii-guard to lint docs for ASCII box diagrams. Use Mermaid (````mermaid`) or plain lists/tables instead of ASCII boxes to avoid CI failures.