Move webhook pages to /hook/ID and inbound URLs to /h/UUID (closes #367)
check / check (push) Successful in 4m23s

The webhook page and everything under it move from /source/ID to
/hook/ID, the list and new-webhook form to /hooks and /hooks/new, and
the event log from .../logs to /hook/ID/events, body download
included. Entrypoint URLs move from /webhook/UUID to /h/UUID, and the
webhook page shows only that form. The old paths are gone.

Links, redirects, form actions, tests, comments and the README follow.
Go identifiers and template file names are unchanged. A new route test
posts to the entrypoint URL the webhook page shows and checks that the
receiver rate limit applies to it.

Model: opus-5-5
This commit is contained in:
2026-10-01 19:13:32 +00:00
parent b79e4649a1
commit cf795ff5df
46 changed files with 266 additions and 218 deletions
+5 -5
View File
@@ -182,7 +182,7 @@ func (s *Server) setupUserRoutes() {
}
func (s *Server) setupSourceRoutes() {
s.router.Route("/sources", func(r chi.Router) {
s.router.Route("/hooks", func(r chi.Router) {
// MaxBodySize precedes CSRF and RequireAuth deliberately;
// see maxFormBodySize for why, and for what it costs.
r.Use(s.mw.MaxBodySize(maxFormBodySize))
@@ -194,7 +194,7 @@ func (s *Server) setupSourceRoutes() {
r.Post("/new", s.h.HandleSourceCreateSubmit())
})
s.router.Route("/source/{sourceID}", func(r chi.Router) {
s.router.Route("/hook/{sourceID}", func(r chi.Router) {
// MaxBodySize precedes CSRF and RequireAuth deliberately;
// see maxFormBodySize for why, and for what it costs.
r.Use(s.mw.MaxBodySize(maxFormBodySize))
@@ -205,14 +205,14 @@ func (s *Server) setupSourceRoutes() {
r.Get("/edit", s.h.HandleSourceEdit())
r.Post("/edit", s.h.HandleSourceEditSubmit())
r.Post("/delete", s.h.HandleSourceDelete())
r.Get("/logs", s.h.HandleSourceLogs())
r.Get("/events", s.h.HandleSourceLogs())
// The log page renders each body only up to its cap, so
// this is the only route that serves a whole one. It
// belongs to this group for its RequireAuth and
// NoCache; see HandleEventBodyDownload for the headers
// that keep the bytes it returns inert.
r.Get(
"/logs/{eventID}/body",
"/events/{eventID}/body",
s.h.HandleEventBodyDownload(),
)
// Replay is the one page action that queues outbound work:
@@ -279,7 +279,7 @@ func (s *Server) setupSourceRoutes() {
func (s *Server) setupWebhookRoutes() {
s.router.With(s.mw.ReceiverRateLimit()).HandleFunc(
"/webhook/{uuid}",
"/h/{uuid}",
s.h.HandleWebhook(),
)
}