Give each event its own page and show bodies the same everywhere (closes #369)
check / check (push) Waiting to run

Each event now has its own page at /hook/ID/events/EVENTID, behind the login, showing its details, its whole body and every delivery; a resubmitted copy links to its original's page. The recent events on the webhook page link there and expand to show their bodies, only the newest expanded on load. One renderer and one template show a body the same way in the recent events, the event log and the event's page: whole up to 32 KiB, cut there in the two lists with links to the event's page and the download; JSON pretty-printed unless that would grow it past four times plus 1 KiB; over 200 lines in a scrolling box; a body holding NUL or control characters treated as binary and never dumped raw.

Model: opus-5-5
This commit was merged in pull request #465.
This commit is contained in:
2026-10-02 22:00:42 +02:00
parent faf7ca1a5e
commit 719d7013ee
23 changed files with 1056 additions and 181 deletions
+4 -3
View File
@@ -24,9 +24,10 @@ import (
const eventBodyQuery = "SELECT cast(body as blob) " +
"FROM events WHERE id = ? AND webhook_id = ? AND deleted_at IS NULL"
// HandleEventBodyDownload serves one event's stored body in
// full, which the event log page cannot: it caps each rendered
// body at maxRenderedBodyBytes.
// HandleEventBodyDownload serves one event's stored body byte
// for byte, which the pages do not: they show it as escaped
// text, cut at maxRenderedBodyBytes in the lists of events, and
// leave a binary one out.
//
// The bytes are attacker-supplied — anyone who can reach the
// public receiver chooses them — and this route hands them back