Write a form-error page's status only after it renders (closes #128)
check / check (push) Waiting to run

The login form and the webhook create and edit forms set their 400 or
409 with WriteHeader before calling renderTemplate, so a template
failure there answered with that status instead of 500. A variant of
renderTemplate now takes the status and writes it only once the page
has rendered into the buffer; renderTemplate sends 200 through it.

Model: opus-5-5
This commit is contained in:
2026-10-02 12:09:39 +00:00
parent 8cf5acaf1d
commit b471323911
4 changed files with 91 additions and 22 deletions
+28 -10
View File
@@ -309,12 +309,26 @@ func (s *Handlers) getUserInfo(
}
// renderTemplate renders a pre-parsed template with common
// data
// data and answers 200.
func (s *Handlers) renderTemplate(
w http.ResponseWriter,
r *http.Request,
pageTemplate string,
data any,
) {
s.renderTemplateStatus(w, r, pageTemplate, data, http.StatusOK)
}
// renderTemplateStatus is renderTemplate answering with status, for a
// form shown again with an error. Call it instead of WriteHeader
// followed by renderTemplate: the status is written only once the page
// has rendered, so a failed render can still answer 500.
func (s *Handlers) renderTemplateStatus(
w http.ResponseWriter,
r *http.Request,
pageTemplate string,
data any,
status int,
) {
tmpl, ok := s.templates[pageTemplate]
if !ok {
@@ -327,7 +341,9 @@ func (s *Handlers) renderTemplate(
return
}
s.executeTemplate(w, r, tmpl, s.pageData(r, data, noticeFor(r)))
s.executeTemplate(
w, r, tmpl, s.pageData(r, data, noticeFor(r)), status,
)
}
// pageData adds the fields the shared layout renders to a page's own
@@ -363,19 +379,20 @@ func (s *Handlers) pageData(
}
}
// executeTemplate renders the template into a buffer and writes to
// the response only once rendering has fully succeeded. Executing
// straight into the ResponseWriter commits a partial body and a 200
// status before a mid-render error can be reported, leaving no way
// to serve a 500. Buffering makes a page's rendered size resident
// memory per concurrent viewer, so every page owes it a bound: the
// event log caps each stored body at maxRenderedBodyBytes for exactly
// this reason.
// executeTemplate renders the template into a buffer and writes status
// and the page to the response only once rendering has fully
// succeeded. Executing straight into the ResponseWriter commits a
// partial body and the status before a mid-render error can be
// reported, leaving no way to serve a 500. Buffering makes a page's
// rendered size resident memory per concurrent viewer, so every page
// owes it a bound: the event log caps each stored body at
// maxRenderedBodyBytes for exactly this reason.
func (s *Handlers) executeTemplate(
w http.ResponseWriter,
r *http.Request,
tmpl *template.Template,
data any,
status int,
) {
var buf bytes.Buffer
@@ -390,6 +407,7 @@ func (s *Handlers) executeTemplate(
}
w.Header().Set("Content-Type", "text/html; charset=utf-8")
w.WriteHeader(status)
_, err = buf.WriteTo(w)
if err != nil {