IN PROGRESS
Technical summary
NEXUS plugin integrating Bugcrowd for bug bounty: submissions are ingested via HMAC-SHA256-digest webhooks (X-Bugcrowd-Digest) and become tasks with severity-derived priority (P1=4 → P4=1); a program → project map routes each submission, NEXUS comments sync back to the submission and the Intelligence Hub enriches tasks with severity, state and Bugcrowd link — with automatic migration from legacy identities (bugcrowdnd/bugcrowd-company) to the canonical bugcrowd slug.
Executed scope
- Identity: canonical slug
bugcrowd(folderplugins/bugcrowd/);legacy_slugs: [bugcrowdnd, bugcrowd-company]; canonicalbugcrowd_*actions withbugcrowdnd_*aliases kept for legacy integrations; fastr/bugcrowd(canonical) +/bugcrowdnd(legacy alias). - Backend
backend.php(1071 lines):bugcrowd_get_config()/bugcrowd_save_config()inDB::getConfig('plugin.bugcrowd')withwebhook_secret,access_key,secret_key,public_base_url,default_project('Geral'),program_map(program_code/UUID → NEXUS project),sync_comments,comment_visibility(everyone|bugcrowd_and_customer),enrich_tasks,auto_close_on_closed,api_version(2025-01-01). - Automatic migration (
bugcrowd_migrate_legacy()): idempotent — migrates config fromplugin.bugcrowd-company/plugin.bugcrowdintoplugin.bugcrowd; promotes tablesbugcrowd_company_submissions/bugcrowd_submissions/bugcrowdnd_submissions→bugcrowd_submissions(RENAME + INSERT IGNORE) and the matching webhook log; validates SQL identifiers and compatible columns before migrating. - Webhook:
bugcrowd_verify_signature()validatesX-Bugcrowd-Digest=HMAC-SHA256(secret, raw_body + timestamp)viahash_equals; eventssubmission.created,submission.updated, comments and ping/test; public URLpublic_base_url + /api.php?action=bugcrowd_webhook; full audit inbugcrowd_webhook_log. - Severity → priority:
bugcrowd_severity_to_priority()— P1/Critical=4, P2/High=3, P3/Medium=2, P4/others=1;auto_close_on_closedmarks the taskdone(closed/resolved/informational) and triaged/unresolved/new becomesin_progress. - Task create/update:
submission.createdcreates a task ([Bugcrowd] <id> — <title>, markdown description with ID/program/event/title/severity/state/VRT) + API enrich;submission.updatedupdates priority/status and comments thechangesdiff. - NEXUS → Bugcrowd comment sync:
bugcrowd_on_comment_created(filtercomment_created) POSTs/submissions/{id}/commentswithbody_markdown+visibility_scope; ignores system/status/status_change/attachment comments and bugcrowd/system authors (anti-loop). - Program → project map:
bugcrowd_resolve_project()(code|id|name → project;default_projectfallback). - API client:
bugcrowd_api_request()(cURL) withAccept: application/vnd.bugcrowd+json,Authorization: Token <access_key>:<secret_key>,Bugcrowd-Versionand 25s timeout (8s connect); baseapi.bugcrowd.com. - Intelligence Hub:
bugcrowdenricher (['url','domain','_task'], priority 38) —_task: signalsid · P{sev} · {state}with scores P1=90/P2=75/P3=55/P4=30;url/domainon*.bugcrowd.comhosts → linked/unlinked (extracts/submissions/{id}). - Lookup/refresh:
bugcrowd_lookup(submission_id or URL → local link + fresh API) andbugcrowd_refresh(GET/submissions/{id}→ create/update withmanual.refreshevent). - API: 9 actions via
PluginManager::registerApiAction(bugcrowd_webhook, bugcrowd_settings/_save, bugcrowd_stats, bugcrowd_links, bugcrowd_test, bugcrowd_lookup, bugcrowd_refresh, bugcrowd_post_comment) — public webhook + digest; others session + CSRF. - Own i18n:
lang.json(226 lines, pt_BR/en_US) vianexusRegisterPluginI18n+nx_load_dictionary(window.t / __()). - Alpine.js UI (
tab.php, 389 lines, orange-600 theme): Webhook OK/API OK badges, 4 KPI cards (Linked/Events today/Webhook/API Token), Submissions tab (ID, program, severity, state, task link) + Config tab (webhook URL with copy + secret, Public Base URL, NEXUS project picker, Access/Secret Key, Bugcrowd-Version, Test API, dynamic program→project map rows, sync/enrich/auto-close toggles, comment visibility, "How to get the API Key" guide). - Tables:
bugcrowd_submissions(PK submission_id, UNIQUE task_id, indexes program_code/updated_at) andbugcrowd_webhook_log(event_type, submission_id, ok, message; indexes created_at/submission_id). - No
cronjob.json— event-driven plugin (webhooks), no continuous polling (Bugcrowd API limits ~60 req/min).
Stack and tooling
- PHP 8 (no framework)
- MySQL 8 (config in admin_configs; bugcrowd_submissions + bugcrowd_webhook_log)
- Alpine.js + Tailwind CSS (premium light, orange ring)
- NEXUS plugin system (PluginManager)
- cURL → Bugcrowd API (Token auth + HMAC-SHA256 webhooks)
Operational tags
- Bugcrowd
- Bug Bounty
- Security
- Webhooks
- REST API
- Intelligence Hub
Operational outcome
- Closed bugcrowd → NEXUS loop: submissions ingested via webhook (HMAC-SHA256 digest verified) become backlog tasks with correct priority; closed/resolved state marks the task done.
- Bidirectional comment sync: NEXUS comments become comments on the Bugcrowd submission (configurable visibility) with no loop from Bugcrowd authors.
- Per-program routing: each submission lands in the mapped NEXUS project (program code/UUID), falling back to the default project.
- Contextual Intelligence Hub: linked tasks show severity, score, state and submission link;
app.bugcrowd.com/submissions/*URLs are detected as references. - Full audit trail: every delivery and event is logged (
bugcrowd_webhook_log). - Transparent migration: legacy installs (bugcrowdnd/bugcrowd-company) are idempotently migrated to the canonical
bugcrowdslug, with aliases kept.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin integrating Bugcrowd for bug bounty: submissions ingested via HMAC-SHA256 webhooks (X-Bugcrowd-Digest) become tasks with severity-based priority, with program→project mapping, bidirectional comment sync, Intelligence Hub enrichment and automatic legacy migration.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- cURL
- Bugcrowd API
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.