feat:344 | ambient agents webhooks (#6283)
* feat(ambient-agents): Add webhook trigger UI on start node (#6068)
* feat(ambient-agents): Add webhook trigger UI on start node, handles in both canvas, agentflow is out of scope but shows temporary ui
* fix: resolve webhookURL copy button not appearing after first save
useParams() does not update when window.history.replaceState() is used
on first save (bypasses React Router). Fall back to Redux canvas.chatflow.id
so NodeInputHandler re-renders reactively when SET_CHATFLOW is dispatched.
* feat/365-366-Webhooks-Server-Route-And-Execution (#6164)
* feat(webhooks): add server route and validation for webhook trigger
- POST /api/v1/webhook/:id route (accepts all HTTP methods via router.all)
- Validates chatflow exists and is configured as webhookTrigger, returns 404 otherwise
- Wraps raw webhook payload as incomingInput.webhook for buildAgentflow
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* feat(agentflow): wire up webhook flow execution (FLOWISE-366)
- Resolve {{ $webhook.field }} template variables in agentflow nodes
- Add required body param validation in webhook service
- Whitelist /api/v1/webhook/ to bypass global auth middleware
- Set $input to JSON payload in custom function nodes for webhook flows
- Add $webhook. autocomplete suggestions in node editors
- Unit tests for body param validation and pre-mutation body pass-through
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* feat(webhooks): namespace webhook payload under $webhook.body.*
- Wrap webhook body as { webhook: { body } } in controller so $webhook.body.*,
$webhook.headers.*, and $webhook.query.* can coexist as distinct namespaces
- Update suggestion option IDs/labels in UI from $webhook.* to $webhook.body.*
- Restrict webhookTrigger start option to agentflowv2 client only
- Remove static webhookURL placeholder from NodeInputHandler (agentflow)
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* feat/389-Webhooks-Headers-Query-params-Methods-validation (#6217)
* feat(ambient-agents): Add webhook trigger UI on start node, handles in both canvas, agentflow is out of scope but shows temporary ui
* fix: resolve webhookURL copy button not appearing after first save
useParams() does not update when window.history.replaceState() is used
on first save (bypasses React Router). Fall back to Redux canvas.chatflow.id
so NodeInputHandler re-renders reactively when SET_CHATFLOW is dispatched.
* feat(webhooks): add headers, query params & body validation to webhook trigger
- Add webhookTrigger input type to Start node with HTTP method, content
type, and expected headers/query/body param configuration
- New /api/v1/webhook/:id route with method, content-type, header, body,
and query param validation (400/405/415 on mismatch)
- Namespace webhook payload as $webhook.body.*, $webhook.headers.*,
$webhook.query.* in the flow runtime
- Resolve $webhook.* variables in downstream nodes via buildAgentflow.ts
- Auto-unwrap form-encoded `payload` JSON strings (e.g. GitHub webhooks)
so $webhook.body.* paths work regardless of content type
- Expose webhook variable suggestions in the node variable picker
- Show copyable webhook URL in the Start node canvas UI
* fixed a bug where downstream nodes cant reference values via node id, and a lowercase headers issue
* feat:533 webhook secrets (#6227)
* feat: add webhook secret & HMAC signature verification to webhook trigger
Adds server-side webhook secret management (generate/clear/verify) and a
UI control in the Start node for configuring the secret, signature header,
and signature type (HMAC-SHA256 or plain token). Raw request body is now
captured before JSON parsing so HMAC signatures can be verified against the
original bytes. Migrations added for all four supported databases.
* fix: accept string-coerced numbers and booleans in webhook body type validation
application/x-www-form-urlencoded payloads deliver all values as strings,
so the strict typeof check was incorrectly rejecting valid numeric ("42")
and boolean ("true"/"false") values. Updated the filter to coerce and
validate instead, with tests covering both JSON and form-encoded cases.
* fix: prevent mass-assignment of webhookSecret fields in chatflow create/update
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat:367 | Webhooks - Human Input + Callback Support (#6263)
* Added HITL support for webhooks
* feat: add async callback URL to webhook trigger
Optional Callback URL / Secret on the Start node (or x-callback-url
header). Webhook now returns 202 immediately and POSTs SUCCESS,
STOPPED (HITL), or ERROR to the callback URL, signed with HMAC-SHA256
when a secret is set. Retries 3x with 0s/3s/6s backoff.
* used getErrorMessage for error messages
* feat: add object/array body param types and per-option show/hide on d… (#6273)
* feat: add webhook secret & HMAC signature verification to webhook trigger
Adds server-side webhook secret management (generate/clear/verify) and a
UI control in the Start node for configuring the secret, signature header,
and signature type (HMAC-SHA256 or plain token). Raw request body is now
captured before JSON parsing so HMAC signatures can be verified against the
original bytes. Migrations added for all four supported databases.
* fix: accept string-coerced numbers and booleans in webhook body type validation
application/x-www-form-urlencoded payloads deliver all values as strings,
so the strict typeof check was incorrectly rejecting valid numeric ("42")
and boolean ("true"/"false") values. Updated the filter to coerce and
validate instead, with tests covering both JSON and form-encoded cases.
* Added HITL support for webhooks
* feat: add async callback URL to webhook trigger
Optional Callback URL / Secret on the Start node (or x-callback-url
header). Webhook now returns 202 immediately and POSTs SUCCESS,
STOPPED (HITL), or ERROR to the callback URL, signed with HMAC-SHA256
when a secret is set. Retries 3x with 0s/3s/6s backoff.
* feat: add object/array body param types and per-option show/hide on dropdowns
- Add object, array[string/number/boolean/object] as webhook body param types, available when content type is application/json
- Extend options fields with show/hide conditions so individual dropdown choices can be hidden based on other param values
* fix: prevent SSRF in webhook callback URL
Remove the x-callback-url header override that allowed any external
caller to control where the server sends POST requests. Callback URL
now only comes from the Start node config (authenticated users).
Add checkDenyList validation to block callback URLs targeting private
networks, cloud metadata endpoints, and loopback addresses.
* fix: exclude HTTP method from webhook URL copy
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* feat: enhance webhook functionality in Start node
- Added new input options for webhook handling, including input modes (Custom Text, No Input, Full Webhook Payload) and response modes (Synchronous, Asynchronous, Streaming).
- Implemented request signature verification and callback URL handling for asynchronous responses.
- Updated validation logic for webhook requests, including content type and required headers.
- Enhanced tests to cover new webhook features and validation scenarios
* adds a generic SSE observer primitive and a webhook listener registry that lets the canvas watch incoming webhook executions live
* fix webhook tests by mocking webhook listener registry and updating expectations for chatId in createWebhook function
* fix: harden webhook trigger surface against SSRF, secret leakage, and listener data exposure
* fix: improve webhook listener reliability with initial heartbeat and logging
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Henry <hzj94@hotmail.com> J
jchui-wd committed
aee37e16b1798c238fc0cfb63250b1a120ea210d
Parent: 6f7d37b
Committed by GitHub <noreply@github.com>
on 5/6/2026, 1:57:11 PM