Give each event its own page and show bodies the same everywhere (closes #369)
check / check (push) Successful in 3m17s

Each event now has its own page at /hook/ID/events/EVENTID, behind the login, showing its details, its whole body and every delivery; a resubmitted copy links to its original's page. The recent events on the webhook page link there and expand to show their bodies, only the newest expanded on load. One renderer and one template show a body the same way in the recent events, the event log and the event's page: whole up to 32 KiB, cut there in the two lists with links to the event's page and the download; JSON pretty-printed unless that would grow it past four times plus 1 KiB; over 200 lines in a scrolling box; a body holding NUL or control characters treated as binary and never dumped raw.

Model: opus-5-5
This commit was merged in pull request #465.
This commit is contained in:
2026-10-02 22:00:42 +02:00
parent faf7ca1a5e
commit 719d7013ee
23 changed files with 1056 additions and 181 deletions
+43
View File
@@ -365,6 +365,7 @@ func (e *testEnv) seedEvent(
WebhookID: webhookID,
Method: http.MethodPost,
Body: body,
BodyBytes: int64(len(body)),
ContentType: "application/octet-stream",
}
@@ -1416,6 +1417,48 @@ func TestHook_LinksBetweenPages(t *testing.T) {
}
}
// TestEventPage_OpenedFromRecentEvents follows the Open link of a
// row in the recent events on the webhook page through the
// production router to the event's own page, which shows the body
// and links back. Another user gets a 404 at the same URL, and a
// logged-out request is sent to log in.
func TestEventPage_OpenedFromRecentEvents(t *testing.T) {
t.Parallel()
env := newTestEnv(t)
ownerID, _ := env.seedUser(t, "owner", "somepassword")
cookies := env.authCookies(t, ownerID, "owner")
wh := env.seedWebhook(t, ownerID)
evt := env.seedEvent(t, wh.ID, "OWNERS-PAYLOAD-3e9d")
page := "/hook/" + wh.ID
path := env.urlFrom(t, page, `href="([^"]+)"[^>]*>Open<`, cookies)
require.Equal(t, page+"/events/"+evt.ID, path)
w := env.get(path, cookies)
require.Equal(t, http.StatusOK, w.Code)
assert.Contains(t, w.Body.String(), "OWNERS-PAYLOAD-3e9d")
assert.Equal(
t, page,
env.urlFrom(t, path, `href="([^"]+)"[^>]*>&larr; Back to `, cookies),
)
intruderID, _ := env.seedUser(t, "intruder", "somepassword")
w = env.get(path, env.authCookies(t, intruderID, "intruder"))
assert.Equal(t, http.StatusNotFound, w.Code)
assert.NotContains(t, w.Body.String(), "OWNERS-PAYLOAD-3e9d")
anon := env.get(path, nil)
assert.Equal(t, http.StatusSeeOther, anon.Code)
assert.Equal(
t, "/pages/login?next="+url.QueryEscape(path),
anon.Header().Get("Location"),
)
}
// TestSourceLogs_TruncationLinkDownloadsTheBody walks the whole
// feature the way a user does: render the event log page through
// the production router, take the download URL out of the markup