Keep what was typed when a target or webhook edit is refused (closes #381)
check / check (push) Successful in 3m20s

A refused save on the target edit page now shows the edit form again,
with the reason above it and every value submitted, instead of a bare
text page; the status codes are unchanged. The webhook edit page keeps
the submitted name, description and retention the same way, while the
page still reports the stored retention.

Target edits are validated by setTargetFromForm, which newTarget now
uses too, so the add and edit forms accept and refuse the same things.
An empty max_retries keeps the target's own count.

The browser test also saves both edit pages with refused values. Its
seeding and its table of target types move into helpers, leaving the
test function a plain list of check calls.

Model: opus-5-5
This commit is contained in:
2026-10-02 22:41:28 +00:00
committed by sneak
parent 61371d388e
commit 2d2d5f6e20
11 changed files with 467 additions and 269 deletions
@@ -44,9 +44,9 @@ func TestTargetRefusal_PrivateDestinationSaysHowToAllowIt(
form.Set("type", string(targetType))
form.Set("url", editBlockedURL)
// A refused add shows the webhook page again, where
// the hint is HTML-escaped; a refused edit answers in
// plain text.
// A refused add shows the webhook page again, and a
// refused edit the edit page, where the hint is
// HTML-escaped.
added := serveTarget(
env, http.MethodPost, targetsPath, form,
)
@@ -76,7 +76,8 @@ func TestTargetRefusal_PrivateDestinationSaysHowToAllowIt(
)
assert.Equal(t, http.StatusBadRequest, edited.Code)
assert.Contains(
t, edited.Body.String(), privateRefusalHint,
t, edited.Body.String(),
html.EscapeString(privateRefusalHint),
)
})
}