HTTP API: register, list and remove webhooks, kept across restarts (closes #6)
check / check (push) Successful in 1m19s

An external app can register webhooks on a chat (`POST /api/v1/chats/{id}/webhooks` with a URL), list them, and remove one. Registering the same URL again returns the existing registration. Registrations are kept in `$DATA_DIR/webhooks.json`, rewritten whole on each change through a file created 0600, synced and renamed, so a crash leaves the old file or the new one; a file present but unreadable stops startup. Delivery of incoming messages is the next unit.

Disclosures: the JSON body reading is now one helper shared with the send endpoint; gosec G304 is suppressed on reading the webhooks file; the 0600-from-creation claim rests on `os.CreateTemp`'s source, not a system-call trace.

Model: opus-5-5
This commit was merged in pull request #17.
This commit is contained in:
2026-09-29 08:38:13 +02:00
parent f53b666119
commit 397fc95149
11 changed files with 1018 additions and 47 deletions
+1 -16
View File
@@ -1,9 +1,7 @@
package api
import (
"encoding/json"
"errors"
"io"
"net/http"
"net/url"
"strconv"
@@ -124,21 +122,8 @@ func (h *handlers) handleSend() http.HandlerFunc {
return
}
body, err := io.ReadAll(r.Body)
var tooLarge *http.MaxBytesError
if errors.As(err, &tooLarge) {
h.respondError(w, http.StatusRequestEntityTooLarge, "the body is too large")
return
}
var req request
if err != nil || json.Unmarshal(body, &req) != nil {
h.respondError(w, http.StatusBadRequest,
`the body must be JSON such as {"text":"hello"}`)
if !h.decodeBody(w, r, &req, `{"text":"hello"}`) {
return
}