Ghost is lightweight headless server that enables Ghost self hosters to bridge to standard.site with ease..

ghost: list webhooks via raw HTTP since the lib special-cases the resource master

@tryghost/admin-api exposes webhooks.add/edit/delete but explicitly NOT browse (lines 234-241 of admin-api.js). That broke ensureWebhooks in production: 'client.webhooks.browse is not a function'. Bypass the lib for the list call: hand-roll the same Ghost-style JWT (kid + HMAC-SHA256 over header.payload, 5-min expiry, audience /admin/) and GET /admin/webhooks/ directly. The lib still handles add() since that DOES work. JWT logic is straightforward enough that pulling in jsonwebtoken would be overkill — node:crypto's createHmac is all we need.


+41 -4
1 changed file