Notifications
Email (SMTP) and webhook (HTTP POST) notices about new reports and whistleblower messages. Both are off by default and independent of each other.
| Channel | Goes to | Carries |
|---|---|---|
| your own admins | the case number: only they can act on a specific case | |
| Webhook | third parties (Slack, Teams, a generic endpoint) | counts only, never a case number or a deadline date |
Neither ever carries the report description, category or submission time.
A notice sent the second a report arrives tells the employer when it was written, and who
was at their desk then. So notices go out as one digest every
NOTIFICATION_BATCH_MINUTES (default 1440, once a day at 00:00 UTC). Report
times are stored as the day only; the digest interval bounds how precisely a notice dates
a report. An hourly digest would say which hour. The trade-off: case managers learn of a
report up to a day late, well inside the 7-day acknowledgement deadline.
0 sends each notice at once, only if you accept the timing risk.
| Variable | Description |
|---|---|
NOTIFICATION_BATCH_MINUTES Optional |
Minutes between digests of new reports and whistleblower messages. All replicas fire at the same wall-clock moments; exactly one sends. 0 sends each event at once. Default: 1440 |
Email (SMTP)
| Variable | Description |
|---|---|
NOTIFY_EMAIL_ENABLED Optional |
Set to true to send an email notification when a new report arrives. Default: false |
NOTIFY_EMAIL_TO Optional |
Comma-separated list of recipient addresses (e.g. admin@example.com,compliance@example.com). |
NOTIFY_EMAIL_FROM Optional |
Sender (From) address for notification emails. Default: openwhistle@localhost |
NOTIFY_SMTP_HOST Optional |
Hostname of the SMTP server. Default: localhost |
NOTIFY_SMTP_PORT Optional |
SMTP port. Use 587 for STARTTLS or 465 for SMTPS. Default: 587 |
NOTIFY_SMTP_USER Optional |
SMTP authentication username. Leave blank for unauthenticated relay. |
NOTIFY_SMTP_PASSWORD Optional |
SMTP authentication password. |
NOTIFY_SMTP_TLS Optional |
Use STARTTLS on the SMTP connection. Set to false when using SMTPS (port 465). Default: true |
NOTIFY_SMTP_SSL Optional |
Use direct TLS (SMTPS, port 465). When true, also set NOTIFY_SMTP_TLS=false. Default: false |
Webhook
A POST with a JSON body. With NOTIFY_WEBHOOK_SECRET set, an
X-OpenWhistle-Signature: sha256=<hex> header lets the receiver verify it
(HMAC-SHA256).
{
"event": "new_activity",
"new_reports": 2,
"new_messages": 1,
"message": "2 new reports, 1 case with new messages"
}
new_messages counts cases with new whistleblower messages, not the messages.
| Variable | Description |
|---|---|
NOTIFY_WEBHOOK_ENABLED Optional |
Set to true to POST a JSON notification to a webhook URL on new reports. Default: false |
NOTIFY_WEBHOOK_URL Optional |
Target URL for webhook POST requests (e.g. a Slack incoming webhook or a custom endpoint). |
NOTIFY_WEBHOOK_SECRET Optional |
HMAC-SHA256 signing secret. When set, each request carries an X-OpenWhistle-Signature header for verification. |
NOTIFY_WEBHOOK_TYPE Optional |
Payload format for webhook notifications. generic sends {"event": "new_activity", "new_reports": 2, "new_messages": 1, "message": "..."} (new_messages: cases with new messages) (counts, never case numbers); slack sends a Slack Block Kit message; teams sends a Microsoft Teams Adaptive Card (v1.4). The SLA reminder webhook uses the same three formats with {"event": "sla_reminder", "ack_due": ..., "feedback_due": ..., "message": "..."} for generic. Default: generic |
SLA Reminders
Reminders before a HinSchG deadline runs out. The scheduler checks every open report every 30 minutes; Redis dedup keys send each warning once per window.
- Email (your own admins): one per case, with its case number.
- Webhook: one per run, with only the number of cases due. Never a case number or a deadline date.
| Variable | Description |
|---|---|
REMINDER_ENABLED Optional |
Set to true to enable automatic SLA reminder notifications. Default: false |
REMINDER_ACK_WARN_DAYS Optional |
Send an acknowledgement reminder this many days before the 7-day deadline expires. Default: 2 |
REMINDER_FEEDBACK_WARN_DAYS Optional |
Send a feedback reminder when this many days or fewer remain before the 3-month feedback deadline. Default: 30 |