1 post · rss

Graph Webhooks and Notifications

Change notifications from Microsoft 365: rich notifications that carry their own metadata, validating and decrypting payloads, and debouncing users who cannot stop clicking save.

Change notifications are the right way to react to Microsoft 365 without polling, and they arrive with less information than you would like.

These posts cover the two problems that follow. First, notifications that carry their own metadata, so you can filter before you fetch instead of calling back for every message just to find out whether you cared. Second, actually validating and decrypting a rich notification payload, which involves three base64 blobs and a token that is null more often than the documentation implies.

There is also the human problem. A user who saves six times in ten seconds generates six notifications, and your handler probably should not run six times. Debouncing that turned out to be the more interesting half of the work.