WebhookHandler has no timeout: a webhook that never answers blocks every log call #38

Closed
opened 2026-10-06 08:03:43 +02:00 by clawbot · 0 comments
Collaborator

WebhookHandler.Handle sends each record with http.DefaultClient, which has no timeout. slog calls the handler on the logging goroutine, so a webhook server that accepts the connection and never answers stops that log call for good, and every later log call that reaches the handler too. The handler also closes the response without reading its body, so the connection is not reused.

Found in the review of #35, and older than it. Starts after that PR lands, since both change the handler's HTTP client.

Definition of done

  • Every webhook request is bounded by a timeout. A request that runs past it fails, and Handle returns an error that says so.
  • The response body is read to the end (or discarded) before it is closed.
  • A test against an httptest server that never answers shows Handle returning an error within the timeout, not hanging.
  • The README's handler description states the timeout.
  • The full check is green.

Implementation requirements

  • Judgement call left to the implementer, disclosed in the PR: the timeout value. A few seconds is enough for a webhook and keeps a dead server from holding up the program. It is a fixed value, not a new setting, unless the code already has a place for settings.
  • No path back into the stdlib log package.
  • Landing commit title must end with (closes #<this issue>).

Model: opus-5-5

`WebhookHandler.Handle` sends each record with `http.DefaultClient`, which has no timeout. `slog` calls the handler on the logging goroutine, so a webhook server that accepts the connection and never answers stops that log call for good, and every later log call that reaches the handler too. The handler also closes the response without reading its body, so the connection is not reused. Found in the review of https://git.eeqj.de/sneak/simplelog/pulls/35, and older than it. Starts after that PR lands, since both change the handler's HTTP client. ## Definition of done - Every webhook request is bounded by a timeout. A request that runs past it fails, and `Handle` returns an error that says so. - The response body is read to the end (or discarded) before it is closed. - A test against an `httptest` server that never answers shows `Handle` returning an error within the timeout, not hanging. - The README's handler description states the timeout. - The full check is green. ## Implementation requirements - Judgement call left to the implementer, disclosed in the PR: the timeout value. A few seconds is enough for a webhook and keeps a dead server from holding up the program. It is a fixed value, not a new setting, unless the code already has a place for settings. - No path back into the stdlib `log` package. - Landing commit title must end with ` (closes #<this issue>)`. Model: opus-5-5
clawbot self-assigned this 2026-10-06 08:03:43 +02:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/simplelog#38