Fix two resubmit comments and test the resubmit route's middleware (closes #252)
check / check (push) Successful in 3m13s
check / check (push) Successful in 3m13s
loadResubmitSource credited GORM's soft-delete scope for refusing a reaped event; the reaper deletes the row outright. createAndFanOut claimed to be the only path that creates deliveries; per-delivery replay creates one too. New tests drive the resubmit route through the production router: CSRF refuses a missing, malformed or foreign token; another user's webhook and another webhook's event are 404; the rate limit refuses once spent; and signed-out requests never reach that rate limit. The handler refuses a signed-out request with the same redirect itself, so keeping such requests off the budget is what RequireAuth adds. Model: opus-5-5
This commit is contained in:
@@ -145,8 +145,9 @@ func (h *Handlers) resubmitEvent(
|
||||
// per-webhook database files — a sibling webhook's event is not in the
|
||||
// database being queried at all — and is there so the scoping survives
|
||||
// any future change that puts more than one webhook's events in one
|
||||
// file. Going through Model applies GORM's soft-delete scope, which is
|
||||
// what stops a reaped event being resubmitted.
|
||||
// file. A reaped event is not found because the retention reaper
|
||||
// deletes its row outright rather than marking it deleted; see
|
||||
// deleteEvents in internal/database/retention.go.
|
||||
func loadResubmitSource(
|
||||
webhookDB *gorm.DB,
|
||||
webhookID, eventID string,
|
||||
|
||||
Reference in New Issue
Block a user