-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathapp.js
64 lines (56 loc) · 1.62 KB
/
app.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
var http = require("http");
var crypto = require("crypto");
var exec = require("child_process").exec;
// 在Webhook中设定的secret
var secret = "123456";
// 在Webhook中设定的Payload URL
var url = "/app";
http
.createServer(function(request, response) {
response.writeHead(200, { "Content-Type": "application/json" });
response.end();
if (
request.headers["x-github-event"] &&
request.headers["x-github-event"] === "push"
) {
console.log("push");
request.on("data", function(chunk) {
var Signature = request.headers["x-hub-signature"];
//console.log(chunk.toString()); chunk中存储了payload的数据,如果需要可以拿出来做更精确的处理.比如部署触发该次push的commit的代码
if (
verifySecret(Signature, sign(secret, chunk.toString())) &&
verifyUrl(url, request.url)
) {
console.log("verify");
runCommand();
} else {
console.log("verify faild");
}
});
}
})
.listen(7777, "127.0.0.1"); // 对,服务监听的是内网地址.用Nginx反代一下就好.(当然直接丢到外网也没问题)
function sign(secret, data) {
return (
"sha1=" +
crypto
.createHmac("sha1", secret)
.update(data)
.digest("hex")
);
}
function verifySecret(data0, data1) {
return data0 == data1;
}
function verifyUrl(data0, data1) {
return data0 == data1;
}
function runCommand() {
exec("./deploy.sh", function(err, stdout, stderr) {
if (err) {
console.log("error:" + stderr);
} else {
console.log("stdout:" + stdout);
}
});
}