Webhook: Secret Token stored in plain text.

Everyone can contribute. Help move this issue forward while earning points, leveling up and collecting rewards.

  • Close this issue

When configuring a Webhook, a Secret Token can be specified to validate the payload. The issue is that this token is not very secret as it's stored in plain text.

The secret should be treated like a password.

Edited Aug 21, 2025 by 🤖 GitLab Bot 🤖
Assignee Loading
Time tracking Loading