Render delivery attempt detail in the event log (closes #202) (#219)
All checks were successful
check / check (push) Successful in 2m55s
All checks were successful
check / check (push) Successful in 2m55s
delivery_results stored status_code, response_body, error, duration and attempt_num, and no template rendered any of it, so a failure read as "target: failed" and diagnosing it meant opening the per-webhook SQLite file by hand. An expanded delivery now lists its attempts with attempt number, status code, duration, error and response body. The body is bounded in the query rather than read whole and truncated in Go (#135), and a body the engine itself cut is no longer presented as complete. The response body and error are untrusted remote content, so target credentials are removed before rendering. Two cases needed care: a secret severed by the 4096-byte cut matches nothing as a whole string, and the engine's io.LimitReader cuts at the same constant the renderer uses, so the guard keys on the body reaching the cap rather than on the stored size exceeding it. Empty secrets are filtered where the secret list is built, because an empty string passed to strings.ReplaceAll inserts the marker at every byte boundary. loadTargetMap builds the redactor half unscoped, so a soft-deleted target's historical deliveries still render redacted. Also regenerates static/css/tailwind.css, which had drifted from the templates: hover:text-red-700, text-red-500, underline and w-28 were in use but absent from the served stylesheet (#236).
This commit was merged in pull request #219.
This commit is contained in:
@@ -1201,6 +1201,83 @@ func TestDeliverHTTP_TargetTimeout(t *testing.T) {
|
||||
iAssertResultFailed(t, db, del.ID)
|
||||
}
|
||||
|
||||
// TestDeliverHTTP_CutsStoredResponseAtMaxBodyLog pins the size
|
||||
// this engine stores for an oversized response, because the
|
||||
// event log's redaction is written against it: the row holds
|
||||
// exactly maxBodyLog bytes and records nothing about how much
|
||||
// more the remote sent, so a credential echoed across that
|
||||
// boundary reaches the database already severed and no reader
|
||||
// of the row can tell the cut happened.
|
||||
func TestDeliverHTTP_CutsStoredResponseAtMaxBodyLog(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
// Padded so the cut falls five bytes before the end of the
|
||||
// echoed webhook URL.
|
||||
const (
|
||||
severedTail = 5
|
||||
overshoot = 100000
|
||||
)
|
||||
|
||||
sent := strings.Repeat(
|
||||
"A",
|
||||
delivery.ExportMaxBodyLog-len(slackWebhookURL)+
|
||||
severedTail,
|
||||
) + slackWebhookURL + strings.Repeat("Z", overshoot)
|
||||
|
||||
s := newISetup(t)
|
||||
|
||||
ts := httptest.NewServer(http.HandlerFunc(
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.WriteHeader(http.StatusBadGateway)
|
||||
_, _ = io.WriteString(w, sent)
|
||||
},
|
||||
))
|
||||
defer ts.Close()
|
||||
|
||||
cfgJSON := iHTTPConfig(ts.URL)
|
||||
|
||||
event := iSeedEvent(
|
||||
t, s.WebhookDB, s.WebhookID, `{"cut":"test"}`,
|
||||
)
|
||||
targetID := uuid.New().String()
|
||||
|
||||
del := iSeedDelivery(
|
||||
t, s.WebhookDB, event.ID, targetID,
|
||||
database.DeliveryStatusPending,
|
||||
)
|
||||
|
||||
bodyStr := event.Body
|
||||
task := iTask(
|
||||
del, event, s.WebhookID, targetID,
|
||||
"cut-target", cfgJSON, 0, 1, &bodyStr,
|
||||
)
|
||||
|
||||
s.Engine.ExportProcessNewTask(context.TODO(), &task)
|
||||
|
||||
results := iResults(t, s.WebhookDB, del.ID)
|
||||
require.Len(t, results, 1)
|
||||
|
||||
stored := results[0].ResponseBody
|
||||
|
||||
assert.Len(
|
||||
t, stored, delivery.ExportMaxBodyLog,
|
||||
"an oversized response is stored at exactly the cap",
|
||||
)
|
||||
assert.Equal(
|
||||
t, sent[:delivery.ExportMaxBodyLog], stored,
|
||||
)
|
||||
assert.NotContains(
|
||||
t, stored, slackWebhookURL,
|
||||
"the echoed URL is severed by the cut",
|
||||
)
|
||||
assert.Contains(
|
||||
t, stored, "T00000000",
|
||||
"the severed prefix still carries the credential",
|
||||
)
|
||||
}
|
||||
|
||||
// iSeedEventAndDelivery creates event + delivery
|
||||
// for standalone tests.
|
||||
func iSeedEventAndDelivery(
|
||||
|
||||
Reference in New Issue
Block a user