diff --git a/README.md b/README.md index 49e1a3a..08a2d25 100644 --- a/README.md +++ b/README.md @@ -95,80 +95,8 @@ Both handler constructors take the following parameters: ## Generating lures Since `.lure` files follow a structured format, they are well-suited to be -generated by an LLM. Copy the prompt below into any LLM conversation, replace -the placeholder at the end with a description of your webhook, and the LLM will -produce a ready-to-use `.lure` file. - -```` -You are generating a .lure file for the Lure webhook library. A .lure file is -a Markdown file with YAML frontmatter. The filename without the .lure extension -determines the webhook path relative to the configured base path: `push.lure` -handles `/push`, and `github/push.lure` handles -`/github/push`. - -## Frontmatter - -### `verify` (optional) - -Specifies how to authenticate incoming webhook requests. Omit if the provider -does not sign requests. Only one strategy may be specified. - -HMAC (e.g. GitHub, GitLab — computes SHA-256 over the request body): - -```yaml -verify: - hmac: - header: X-Hub-Signature-256 # or query: param-name - prefix: "sha256=" # optional: stripped before comparing the digest - secret: $ENV_VAR_NAME # must be an environment variable reference -``` - -Literal (e.g. Forgejo, plain API key — compares value directly): - -```yaml -verify: - literal: - header: Authorization # or query: uid - secret: $ENV_VAR_NAME # must be an environment variable reference -``` - -### `payload` (optional) - -```yaml -payload: - contentType: json # currently the only supported value -``` - -### `config` (optional) - -An arbitrary object passed as-is to the application callback. Use this for any -application-specific values you want to associate with this lure. - -```yaml -config: - key: value -``` - -## Template body - -Below the frontmatter is a Liquid template (https://liquidjs.com). Write it as -a natural language prompt for the LLM that will process the webhook. The -following variables are available: - -- `payload` — the request body (parsed JSON for `contentType: json`) -- `headers` — request headers as a plain object with lowercase keys (e.g. `{{ headers["x-my-header"] }}`) -- `query` — query string as a plain object (e.g. `{{ query.foo }}`) - -Use `{{ expression }}` to interpolate values and `{% if %}...{% endif %}` for -conditionals. - -## Task - -Generate a .lure file for the following webhook: - -[DESCRIBE THE WEBHOOK SOURCE, EVENT TYPE, PAYLOAD SHAPE, VERIFICATION METHOD, -AND WHAT THE LLM RECEIVING THE PROMPT SHOULD DO IN RESPONSE] -```` +generated by an LLM. A `create-lure` skill is available in +[SKILL.md](./SKILL.md) at the root of this repository. ## Lifecycle diff --git a/.claude/skills/create-lure/SKILL.md b/SKILL.md similarity index 77% rename from .claude/skills/create-lure/SKILL.md rename to SKILL.md index 8492254..c9780a7 100644 --- a/.claude/skills/create-lure/SKILL.md +++ b/SKILL.md @@ -10,7 +10,11 @@ Generate a new `.lure` file for handling an incoming webhook. 1. **Gather requirements.** If not already provided, ask the user: - What webhook source and event is this for? - What path should it be mounted at? (e.g. `github/push` → `lures/github/push.lure`) - - Does the provider sign requests? If so, what method (HMAC?), which header or query parameter carries the signature, and what environment variable holds the secret? + - Does the provider sign requests? If so: + - HMAC or literal token comparison? + - Which header or query parameter carries the signature or token? + - What environment variable holds the secret? + - For HMAC: does the provider prefix the digest (e.g. `sha256=`)? - What should the LLM do when it receives this webhook? - Is there any application-specific config to include? @@ -28,13 +32,22 @@ handles `/github/push`. Specifies how to authenticate incoming webhook requests. Omit if the provider does not sign requests. Only one strategy may be specified. -HMAC: +HMAC (e.g. GitHub, GitLab — computes SHA-256 over the request body): ```yaml verify: hmac: - location: header # or "query" - name: X-Hub-Signature-256 # header or query parameter name + header: X-Hub-Signature-256 # or query: param-name + prefix: "sha256=" # optional: stripped before comparing the digest + secret: $ENV_VAR_NAME # must be an environment variable reference +``` + +Literal (e.g. Forgejo, Omi — compares value directly against the secret): + +```yaml +verify: + literal: + header: Authorization # or query: uid secret: $ENV_VAR_NAME # must be an environment variable reference ```