HTTP API: register, list and remove webhooks, kept across restarts (closes #6)
check / check (push) Successful in 1m19s

An external app can register webhooks on a chat (`POST /api/v1/chats/{id}/webhooks` with a URL), list them, and remove one. Registering the same URL again returns the existing registration. Registrations are kept in `$DATA_DIR/webhooks.json`, rewritten whole on each change through a file created 0600, synced and renamed, so a crash leaves the old file or the new one; a file present but unreadable stops startup. Delivery of incoming messages is the next unit.

Disclosures: the JSON body reading is now one helper shared with the send endpoint; gosec G304 is suppressed on reading the webhooks file; the 0600-from-creation claim rests on `os.CreateTemp`'s source, not a system-call trace.

Model: opus-5-5
This commit was merged in pull request #17.
This commit is contained in:
2026-09-29 08:38:13 +02:00
parent f53b666119
commit 397fc95149
11 changed files with 1018 additions and 47 deletions
+7
View File
@@ -23,6 +23,7 @@ const (
chatsPath = "/api/v1/chats"
messagesPath = "/api/v1/chats/3/messages"
webhooksPath = "/api/v1/chats/3/webhooks"
unauthorized = `{"error":"unauthorized"}` + "\n"
)
@@ -197,6 +198,12 @@ func TestNoPathIsExempt(t *testing.T) {
http.MethodPost, messagesPath, "",
http.StatusUnauthorized, unauthorized,
},
{http.MethodGet, webhooksPath, "", http.StatusUnauthorized, unauthorized},
{http.MethodPost, webhooksPath, "", http.StatusUnauthorized, unauthorized},
{
http.MethodDelete, webhooksPath + "/" + unknownID, "",
http.StatusUnauthorized, unauthorized,
},
} {
rec := request(t, srv, tc.method, tc.path, tc.auth)
if rec.Code != tc.want || rec.Body.String() != tc.body {