Event log: only the newest event expanded, and only the 50 most recent (closes #349)
check / check (push) Successful in 3m35s

The event log now loads the 50 newest events in its query and opens
only the newest on load, as the recent events on a webhook's page
already do. With 50 at most there is never a second page, so paging is
gone: the page links, the `page` query parameter, the page number that
Replay and Resubmit carried back to the log, and `pageOrFirst` with its
test. The count beside the heading reads "50 most recent of N events"
when there are more. The comments and README lines that named `page` as
the query parameter the service reads now name `next` and `notice`.

Model: opus-5-5
This commit is contained in:
2026-10-03 00:53:21 +00:00
committed by sneak
parent bcdd4791ec
commit d7107f1f9e
17 changed files with 157 additions and 185 deletions
+7 -6
View File
@@ -278,12 +278,13 @@ func (lrw *loggingResponseWriter) Unwrap() http.ResponseWriter {
// after the '?'. Keeping the path and dropping the query is what makes
// this branch as bounded as the pattern branches below.
//
// Nothing debuggable is lost. One route in the service reads a query
// parameter at all — `page`, on the authenticated pagination links in
// internal/handlers/source_management.go — and the alternatives that
// would preserve more (a key count, a key allowlist) all require
// parsing an attacker-sized query on every request, which is work an
// unauthenticated client would then be choosing for us.
// Nothing debuggable is lost. The only query parameters the service
// reads are the login page's `next`, the page to return to, and
// `notice`, which names the line a page shows after an action. The
// alternatives that would preserve more (a key count, a key
// allowlist) all require parsing an attacker-sized query on every
// request, which is work an unauthenticated client would then be
// choosing for us.
func concreteLogURL(r *http.Request) string {
path := r.URL.EscapedPath()