IN PROGRESS
Technical summary
NEXUS plugin integrating the Intigriti platform — submissions are ingested via HMAC-SHA256 → Base64 webhooks (x-intigriti-digest) while OAuth2 Authorization Code syncs NEXUS→Intigriti messages and enriches bounty; it creates/updates tasks with priority derived from severity (critical=4 → low=1) plus Intelligence Hub enrichment (accumulated bounty).
Executed scope
backend.phpbackend (879 lines):intigriti_get_config()/intigriti_save_config()inDB::getConfig('plugin.intigriti')withwebhook_secret,client_id,client_secret,access_token,refresh_token,token_expires_at,environment(prod/uat),public_base_url,default_project,sync_comments,message_visibility(internal/external),enrich_tasks,auto_close_on_closed.- HMAC webhook:
intigriti_verify_signature()validatesx-intigriti-digest=HMAC-SHA256(secret, raw_body)→ Base64 viahash_equals; eventsSubmissionCreated/SubmissionSeverityChanged/SubmissionStatusChanged/SubmissionMessagePlaced/TestEvent. - OAuth2 Authorization Code (
intigriti_oauth_callback) + auto-refresh (intigriti_ensure_token, 60s early) — scopescompany_external_api offline_access core_platform:read/write. - Severity → priority:
intigriti_severity_to_priority()— critical=4, high=3, medium=2, low/default=1. - NEXUS → Intigriti message sync:
intigriti_on_comment_created(filtercomment_created) POST/v2/submissions/{code}/comments/internal|external; ignores system/status/attachment and intigriti/system authors (anti-loop). - Bounty enrich:
intigriti_extract_bounty_meta()extractstotalPayout(value/currency) from submission detail → cached in link + Intelligence Hub. - API client (
intigriti_api_request, cURL):Bearer <token>,Accept: application/json, baseapi.intigriti.com/external/company(or.uat.), 25s timeout. - Refresh:
intigriti_refresh_submission(GET/v2/submissions/{code}→ upsert + updates priority/title). - API: 8 actions via
PluginManager::registerApiAction(intigriti_webhook, intigriti_oauth_callback, intigriti_settings/_save, intigriti_refresh, intigriti_post_message, intigriti_stats, intigriti_links) — session/Bearer + CSRF. - Alpine.js UI (
tab.php, 339 lines): Webhook/OAuth status badges, stat cards (Linked/Today/Webhook/OAuth), Submissions tab (7-col: code, program, severity, bounty, status, task) + Config (secret/redirect/authorize/OAuth/client_id/secret/environment/project picker/toggles/visibility/Save). - Intelligence Hub:
intigriti_intel_enrich(priority 37) —_task: signalcode · P{sev} · {state}+ bounty (if > 0), score severity_score or P1=85/P2=75/P3=55/Low=25. - Tables:
intigriti_submissions(code↔task link + cache severity/status/bounty) andintigriti_webhook_log(audit). No version-controlledinstall.sql(loaded via file_get_contents inintigriti_install()). - Fastr
/intigriti(fastr.json):arg_required=false,pass_task_id=false→intigriti_stats. cronjob.jsonjobs empty (on demand) — no periodic routine.
Stack and tooling
- PHP 8 (no framework)
- MySQL 8 (config in admin_configs; intigriti_submissions + intigriti_webhook_log)
- Alpine.js + Tailwind CSS (premium light, teal ring)
- NEXUS plugin system (PluginManager)
- cURL → Intigriti API (OAuth2 Authorization Code + HMAC webhooks)
Operational tags
- Intigriti
- Bug Bounty
- Security
- Webhooks
- OAuth2
- DevOps
Operational outcome
- Closed intigriti→NEXUS→intigriti loop: submissions ingested via webhook (HMAC-SHA256/Base64 verified) become backlog tasks with correct priority;
SubmissionStatusChanged(Closed) marks the task done; severity changes update priority + add a comment. - Bidirectional message sync: NEXUS comments become internal/external messages on the Intigriti submission (configurable visibility; OAuth required).
- Contextual enrichment: tasks with a linked submission show severity, score, status and accumulated bounty without leaving NEXUS.
- OAuth2 with auto-refresh (60s early) — message sync and bounty enrich run without manual intervention after the initial authorization.
- Full audit trail: every delivery is logged (
intigriti_webhook_log).
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin ingesting Intigriti submissions via HMAC-SHA256/Base64 webhooks, OAuth2 Authorization Code for message sync + bounty enrich, severity→priority and Intelligence Hub.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.