A route test now posts an oversized body with no session or CSRF
token to each page route group, /settings included, and requires 413
with no CSRF cookie. Before, only the login form pinned the cap ahead
of CSRF; reordering the /settings, /hooks or /hook groups failed
nothing.
The MaxBodySize doc comment says other methods pass uncapped on
purpose, and the middleware test comment names the helper it
describes. The three router helpers in the server tests build the
Server through New, on a lifecycle that is never started, instead of
setting its fields by hand. The README already described the cap's
position correctly.
Model: opus-5-5
Saving, deleting, activating or deactivating a webhook, entrypoint or target, and signing out, now land on their page with a one-line notice such as "Webhook deleted." or "Signed out.". The redirect carries a fixed code that maps to fixed text; an unknown code shows nothing, so nothing from the URL is ever echoed. One partial in the page layout shows the notice on every page, and replay and resubmit now use the same codes and partial. Error pages show no notice.
Model: opus-5-5
Every 400, 403, 404 and 500 on an admin page now answers with an error page in the normal layout: the status, one fixed line explaining it, and a link back to the webhook list, or to sign-in when nobody is signed in. Unknown paths reach it through the router's not-found handler, a refused form token through the CSRF middleware, and a panic through a recoverer each admin page route group installs first. Status codes are unchanged, and the page always sends Cache-Control: no-store.
If the error page fails to render, the answer is the same status in plain text; if it panics, the answer is a 500. The receiver, the healthcheck and /metrics keep their plain answers.
Model: opus-5-5