e40192118e
GitLab (lib/gitlab/web_hooks.rb, app/services/web_hook_service.rb) sends webhook-id and webhook-timestamp on EVERY delivery and adds webhook-signature only when a signing token is configured. Selecting the HMAC path on any webhook-* header would 401 every legacy X-Gitlab-Token install the moment it upgrades to GitLab 19, so only the signature header selects the path; id and timestamp then travel with it and the validator still fails closed when either is missing. svix-* keeps its existing any-header selection. Tests trimmed to the invariant bar: one parameterized contract (whsec_ and raw secrets accept; wrong secret, tampered body and stale timestamp reject) plus the GitLab legacy-token coexistence contract. evals/webhook_auth/standard_webhooks_ab.py drives a real aiohttp WebhookAdapter on a dedicated loopback port with real signed requests for before/after evidence. Related: #47849 (HwangJohn, cherry-picked here), #92024 (earlier salvage of #47849), #102080 and #103167 (same alias fix, same target).