joe94 opened this issue 4 years ago · 0 comments
Currently the owner of a webhook comes from a SAT token. If the authentication method is not SAT, we should check for the header X-Xmidt-Client-id
X-Xmidt-Client-id