Fix two resubmit comments and test the resubmit route's middleware (closes #252)
check / check (push) Successful in 3m33s
check / check (push) Successful in 3m33s
loadResubmitSource credited GORM's soft-delete scope for refusing a reaped event; the reaper deletes the row outright. createAndFanOut claimed to be the only path that creates deliveries; per-delivery replay creates one too. New tests drive the resubmit route through the production router: CSRF refuses a missing, malformed or foreign token; another user's webhook and another webhook's event are 404; the rate limit refuses once spent; and signed-out requests never reach that rate limit. The handler refuses a signed-out request with the same redirect itself, so keeping such requests off the budget is what RequireAuth adds. Model: opus-5-5
This commit is contained in:
@@ -272,10 +272,12 @@ func requestEventSource(
|
||||
|
||||
// createAndFanOut writes the event and one pending delivery per target,
|
||||
// and adds them to the webhook's running totals, in a single
|
||||
// transaction, then hands the tasks to the delivery engine. It is the
|
||||
// only path by which an event and its deliveries are created, so a
|
||||
// resubmitted event is retried, SSRF-guarded and circuit-broken
|
||||
// exactly as a received one is.
|
||||
// transaction, then hands the tasks to the delivery engine. Every
|
||||
// event is created here, received or resubmitted, so a resubmitted
|
||||
// event is retried, SSRF-guarded and circuit-broken exactly as a
|
||||
// received one is. Per-delivery replay is the one other path that
|
||||
// creates a delivery: it adds one to an existing event without
|
||||
// coming through here.
|
||||
//
|
||||
// The tasks are returned as well as queued, so a caller can report how
|
||||
// many targets the event went to.
|
||||
|
||||
Reference in New Issue
Block a user