Notifications

Email (SMTP) and webhook (HTTP POST) notices about new reports and whistleblower messages. Both are off by default and independent of each other.

Channel Goes to Carries
Email your own admins the case number: only they can act on a specific case
Webhook third parties (Slack, Teams, a generic endpoint) counts only, never a case number or a deadline date

Neither ever carries the report description, category or submission time.

Why notifications are batched

A notice sent the second a report arrives tells the employer when it was written, and who was at their desk then. So notices go out as one digest every NOTIFICATION_BATCH_MINUTES (default 1440, once a day at 00:00 UTC). Report times are stored as the day only; the digest interval bounds how precisely a notice dates a report. An hourly digest would say which hour. The trade-off: case managers learn of a report up to a day late, well inside the 7-day acknowledgement deadline. 0 sends each notice at once, only if you accept the timing risk.

Variable Description
NOTIFICATION_BATCH_MINUTES Optional Minutes between digests of new reports and whistleblower messages. All replicas fire at the same wall-clock moments; exactly one sends. 0 sends each event at once. Default: 1440

Email (SMTP)

Variable Description
NOTIFY_EMAIL_ENABLED Optional Set to true to send an email notification when a new report arrives. Default: false
NOTIFY_EMAIL_TO Optional Comma-separated list of recipient addresses (e.g. admin@example.com,compliance@example.com).
NOTIFY_EMAIL_FROM Optional Sender (From) address for notification emails. Default: openwhistle@localhost
NOTIFY_SMTP_HOST Optional Hostname of the SMTP server. Default: localhost
NOTIFY_SMTP_PORT Optional SMTP port. Use 587 for STARTTLS or 465 for SMTPS. Default: 587
NOTIFY_SMTP_USER Optional SMTP authentication username. Leave blank for unauthenticated relay.
NOTIFY_SMTP_PASSWORD Optional SMTP authentication password.
NOTIFY_SMTP_TLS Optional Use STARTTLS on the SMTP connection. Set to false when using SMTPS (port 465). Default: true
NOTIFY_SMTP_SSL Optional Use direct TLS (SMTPS, port 465). When true, also set NOTIFY_SMTP_TLS=false. Default: false

Webhook

A POST with a JSON body. With NOTIFY_WEBHOOK_SECRET set, an X-OpenWhistle-Signature: sha256=<hex> header lets the receiver verify it (HMAC-SHA256).

json
{
  "event": "new_activity",
  "new_reports": 2,
  "new_messages": 1,
  "message": "2 new reports, 1 case with new messages"
}

new_messages counts cases with new whistleblower messages, not the messages.

Variable Description
NOTIFY_WEBHOOK_ENABLED Optional Set to true to POST a JSON notification to a webhook URL on new reports. Default: false
NOTIFY_WEBHOOK_URL Optional Target URL for webhook POST requests (e.g. a Slack incoming webhook or a custom endpoint).
NOTIFY_WEBHOOK_SECRET Optional HMAC-SHA256 signing secret. When set, each request carries an X-OpenWhistle-Signature header for verification.
NOTIFY_WEBHOOK_TYPE Optional Payload format for webhook notifications. generic sends {"event": "new_activity", "new_reports": 2, "new_messages": 1, "message": "..."} (new_messages: cases with new messages) (counts, never case numbers); slack sends a Slack Block Kit message; teams sends a Microsoft Teams Adaptive Card (v1.4). The SLA reminder webhook uses the same three formats with {"event": "sla_reminder", "ack_due": ..., "feedback_due": ..., "message": "..."} for generic. Default: generic

SLA Reminders

Reminders before a HinSchG deadline runs out. The scheduler checks every open report every 30 minutes; Redis dedup keys send each warning once per window.

  • Email (your own admins): one per case, with its case number.
  • Webhook: one per run, with only the number of cases due. Never a case number or a deadline date.
Variable Description
REMINDER_ENABLED Optional Set to true to enable automatic SLA reminder notifications. Default: false
REMINDER_ACK_WARN_DAYS Optional Send an acknowledgement reminder this many days before the 7-day deadline expires. Default: 2
REMINDER_FEEDBACK_WARN_DAYS Optional Send a feedback reminder when this many days or fewer remain before the 3-month feedback deadline. Default: 30

Edit this page on GitHub