Commit Graph
2 Commits
Author SHA1 Message Date
clawbot 342ae4f04d Keep test helpers out of the shipped binary (closes #506)
check / check (push) Successful in 9m44s
The four testing.go files in config, database, middleware and session
are gone. ClearEnvForTest moves to internal/config/configtest as
ClearEnv; the webhook database manager helpers move to
internal/database/databasetest as NewWebhookDBManager and
NewWebhookDBManagerWithLogger, and the middleware's NewForTest to
internal/middleware/middlewaretest as New, both now built through the
production constructors. Tests that wrapped an open main database use
database.Open. The session helpers move into the session package's
export_test.go; the middleware tests build their session through
session.New and age its timestamps instead of using a fake clock.

The session, middleware and webhook database manager now take the
*slog.Logger they log through, so tests in other packages can give
them their own.

Model: opus-5-5
2026-10-06 10:02:49 +00:00
clawbot 1f22b30de3 Log the client address next to the peer address (closes #270)
check / check (push) Successful in 3m34s
Behind a trusted proxy every log line named only the proxy, so abuse could not be traced from webhooker's own logs although the rate limiters already knew the client. The access log, the rate-limit rejection lines, the CSRF warning and the receiver's request line now carry clientIP next to remoteIP. remoteIP still means the connecting peer; clientIP is the address the rate limiters key on, the forwarded client when the peer is inside TRUSTED_PROXIES, worked out once per request by the same code. The README says the field is only as trustworthy as TRUSTED_PROXIES. The access log's 2,560-byte line ceiling holds with the field charged, and a size case with an oversized X-Forwarded-For pins it.

Model: opus-5-5
2026-10-02 16:50:22 +02:00