Fix two resubmit comments and test the resubmit route's middleware (closes #252)
check / check (push) Successful in 3m13s
check / check (push) Successful in 3m13s
loadResubmitSource credited GORM's soft-delete scope for refusing a reaped event; the reaper deletes the row outright. createAndFanOut claimed to be the only path that creates deliveries; per-delivery replay creates one too. New tests drive the resubmit route through the production router: CSRF refuses a missing, malformed or foreign token; another user's webhook and another webhook's event are 404; the rate limit refuses once spent; and signed-out requests never reach that rate limit. The handler refuses a signed-out request with the same redirect itself, so keeping such requests off the budget is what RequireAuth adds. Model: opus-5-5
This commit is contained in:
@@ -444,6 +444,23 @@ func (e *testEnv) countDeliveries(
|
||||
return count
|
||||
}
|
||||
|
||||
// countEvents reports how many events a webhook's database holds.
|
||||
func (e *testEnv) countEvents(t *testing.T, webhookID string) int64 {
|
||||
t.Helper()
|
||||
|
||||
webhookDB, err := e.dbMgr.GetDB(webhookID)
|
||||
require.NoError(t, err)
|
||||
|
||||
var count int64
|
||||
|
||||
require.NoError(
|
||||
t,
|
||||
webhookDB.Model(&database.Event{}).Count(&count).Error,
|
||||
)
|
||||
|
||||
return count
|
||||
}
|
||||
|
||||
// storedHash reads the current password hash for a username.
|
||||
func (e *testEnv) storedHash(t *testing.T, username string) string {
|
||||
t.Helper()
|
||||
|
||||
Reference in New Issue
Block a user