Skip to content

feat(webhooks)!: add Basic Auth and required read flags - #32

Open
bjarn wants to merge 3 commits into
mainfrom
codex/webhook-basic-auth
Open

bjarn wants to merge 3 commits into
mainfrom
codex/webhook-basic-auth

Conversation

@bjarn

@bjarn bjarn commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Change

Add typed webhook Basic Auth credentials and the safe has_basic_auth response flag. Preserve omitted, set and explicit-null request states. Keep empty passwords and credential whitespace. API requests still use Bearer authentication; Basic Auth applies to webhook delivery.

Source

Fresh strict export from monorepo main bfabb708ead47ee31922a7ae772e3d6376ac2ea4, after backend PR https://github.com/lettermint/lettermint/pull/2578. Splitter tests: 7 pass, none skipped. Both split documents match the checked-in docs. No OpenAPI document is included in this repository.

Sending SHA-256: c2aafb6d48a2572e688224629076748322f9c257394f18fe8879efb3f05059cb
Team SHA-256: e385c5f9b330633e943729ecb0e1b93fca96e84fecb2f111b3af8f0bafa0cc75

Verification

85 tests pass; Ruff lint/format and mypy source checks pass. Sync and async credential-state tests and a mocked Sandbox 403 test pass.

Existing scheduling, cursor, raw-pong and signed webhook tests remain in the suite. Existing public methods and compatibility helpers are retained.

No merge, deployment or package publication was performed.

Python 3.9 regression: the new nullable credential hint uses Optional, and the test resolves each new field without evaluating unrelated older union hints. All 85 tests pass on Python 3.9 and the current local interpreter. The installed mypy warns that its configured Python 3.9 target is no longer supported; source checking still passes.

Intentional typed-fixture migration

The API requires has_basic_auth in webhook detail, list and secret responses. Three old-caller mypy tests prove that fixtures without this field fail checking, and that adding has_basic_auth: False or True restores source compatibility. The wire read flag must stay required. Python has no JVM-style binary interface for these TypedDict additions.

@bjarn
bjarn requested a review from a team as a code owner October 2, 2026 19:57
@bjarn bjarn changed the title feat(webhooks): support Basic Auth credentials and read flags feat(webhooks)!: add Basic Auth and required read flags Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant