Compare commits
1 Commits
190cabe0f2
...
issue-66-s
| Author | SHA1 | Date | |
|---|---|---|---|
| b04bc2cc7b |
45
README.md
45
README.md
@@ -92,6 +92,27 @@ TTY detection, and security headers are always applied.
|
||||
| `METRICS_USERNAME` | Basic auth username for `/metrics` | `""` |
|
||||
| `METRICS_PASSWORD` | Basic auth password for `/metrics` | `""` |
|
||||
| `SENTRY_DSN` | Sentry error reporting DSN | `""` |
|
||||
| `SESSION_IDLE_TIMEOUT` | Idle session timeout (Go duration) | `24h` |
|
||||
|
||||
Sessions are bounded by two independent clocks, and end at whichever
|
||||
one runs out first:
|
||||
|
||||
- **Idle expiry** (`SESSION_IDLE_TIMEOUT`, default `24h`) is a sliding
|
||||
window. Every authenticated request pushes it forward, so a session
|
||||
in continuous use never hits it, while an abandoned one expires a day
|
||||
after its last use. Set it to `0` to disable idle expiry entirely;
|
||||
the absolute cap below still applies. A set-but-unparseable value
|
||||
aborts startup rather than silently falling back to the default.
|
||||
- **Absolute expiry** is a fixed 7 days from login. Activity does
|
||||
**not** extend it: after a week, every session ends and the user
|
||||
authenticates again.
|
||||
|
||||
Only requests that authenticate with the session count as activity, so
|
||||
an unauthenticated request carrying the cookie cannot keep a session
|
||||
alive. The idle timestamp is rewritten at most once per tenth of the
|
||||
idle window rather than on every request, which means a session may
|
||||
expire up to 10% early relative to the user's true last request, but
|
||||
never late.
|
||||
|
||||
On first startup, webhooker automatically generates a cryptographically
|
||||
secure session encryption key and stores it in the database. This key
|
||||
@@ -531,30 +552,6 @@ older than the expiry are pruned each time the archive is (re)opened. An
|
||||
archive write failure is never silent success: the delivery records a
|
||||
failed attempt with the error and is marked failed.
|
||||
|
||||
Because reopens only happen on writes, an archive belonging to a webhook
|
||||
that has stopped receiving events would never be pruned. A background
|
||||
**archive sweeper** closes that gap: on the same interval as the event
|
||||
retention reaper (`RETENTION_SWEEP_INTERVAL`) it prunes every archive
|
||||
whose database target declares a positive expiry, whether or not the
|
||||
webhook is still receiving traffic. The sweep never creates an archive —
|
||||
a webhook whose archive file does not yet exist is skipped, not
|
||||
initialised — it takes the same per-webhook lock the write path uses, so
|
||||
it can never interleave with a write, and it leaves the archive closed
|
||||
afterwards so the move-the-file-away workflow keeps working. Archives
|
||||
with no expiry, or the expiry `never`, are not touched by the sweep at
|
||||
all.
|
||||
|
||||
Deleting a webhook releases its archive: the delivery engine's cached
|
||||
archive writer is dropped and its file handle closed, so nothing lingers
|
||||
after the webhook is gone. The archive **file itself is deliberately
|
||||
left on disk**. Unlike the event database — per-webhook working storage
|
||||
that is hard-deleted with the webhook — an archive is long-term storage
|
||||
an operator may still want to keep or move away for offline retention,
|
||||
and destroying it as a side effect of deleting a webhook would be
|
||||
unrecoverable. Removing `archive-{webhookID}.db` is the operator's call.
|
||||
Deleting a webhook's last `database` target releases the writer the same
|
||||
way, and for the same reason leaves the file alone.
|
||||
|
||||
The **Slack target type** sends webhook events as formatted messages to
|
||||
any Slack-compatible incoming webhook URL (works with Slack, Mattermost,
|
||||
and other compatible services). Each message includes event metadata
|
||||
|
||||
11
TODO.md
11
TODO.md
@@ -28,11 +28,10 @@ databases currently grow without bound.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-08-09 Archive writer lifecycle (#89): deleting a webhook (or its
|
||||
last `database` target) evicts the cached archive writer and closes
|
||||
its handle while deliberately leaving `archive-{webhookID}.db` on
|
||||
disk, and a new `ArchiveSweeper` prunes idle archives on the existing
|
||||
`RETENTION_SWEEP_INTERVAL` without ever creating an archive file
|
||||
- 2026-08-09 Inactivity-based session timeout: sliding idle expiry
|
||||
(`SESSION_IDLE_TIMEOUT`, default `24h`) refreshed on authenticated
|
||||
requests, with the 7-day absolute cap kept as an independent
|
||||
backstop that activity never extends (#66)
|
||||
- 2026-08-07 Update golangci-lint to v2.12.2 (Docker image digest in
|
||||
`Dockerfile`, release-archive sha256 pins in `script/bootstrap`),
|
||||
adopt the canonical `.golangci.yml` (v2 `linters.settings` layout so
|
||||
@@ -76,7 +75,7 @@ databases currently grow without bound.
|
||||
- event redelivery endpoint
|
||||
- OpenAPI specification
|
||||
- Analytics dashboard: success rates, response times, volume
|
||||
- Session expiration tuning and a remember-me option
|
||||
- A remember-me option at login
|
||||
- Password change and reset flow
|
||||
- Later, nice to have
|
||||
- email delivery target type
|
||||
|
||||
@@ -40,15 +40,9 @@ func main() {
|
||||
handlers.New,
|
||||
middleware.New,
|
||||
delivery.New,
|
||||
delivery.NewArchiveSweeper,
|
||||
// Wire *delivery.Engine as delivery.Notifier so the
|
||||
// webhook handler can notify the engine of new deliveries.
|
||||
func(e *delivery.Engine) delivery.Notifier { return e },
|
||||
// Wire *delivery.Engine as delivery.WebhookEvictor so
|
||||
// deleting a webhook releases its archive writer.
|
||||
func(e *delivery.Engine) delivery.WebhookEvictor {
|
||||
return e
|
||||
},
|
||||
server.New,
|
||||
),
|
||||
fx.Invoke(
|
||||
@@ -56,7 +50,6 @@ func main() {
|
||||
*server.Server,
|
||||
*delivery.Engine,
|
||||
*database.RetentionReaper,
|
||||
*delivery.ArchiveSweeper,
|
||||
) {
|
||||
},
|
||||
),
|
||||
|
||||
@@ -31,6 +31,10 @@ const (
|
||||
// defaultRetentionSweepInterval is how often the retention
|
||||
// reaper deletes events older than each webhook's RetentionDays.
|
||||
defaultRetentionSweepInterval = time.Hour
|
||||
|
||||
// defaultSessionIdleTimeout is how long a session may go without
|
||||
// authenticated activity before it expires.
|
||||
defaultSessionIdleTimeout = 24 * time.Hour
|
||||
)
|
||||
|
||||
// ErrInvalidEnvironment is returned when WEBHOOKER_ENVIRONMENT
|
||||
@@ -60,6 +64,10 @@ type Config struct {
|
||||
// RetentionSweepInterval is how often the retention reaper runs.
|
||||
RetentionSweepInterval time.Duration
|
||||
|
||||
// SessionIdleTimeout is the sliding inactivity window after
|
||||
// which a session expires. Non-positive disables idle expiry.
|
||||
SessionIdleTimeout time.Duration
|
||||
|
||||
params *ConfigParams
|
||||
log *slog.Logger
|
||||
}
|
||||
@@ -162,6 +170,15 @@ func New(lc fx.Lifecycle, params ConfigParams) (*Config, error) {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
// Same fail-loud treatment for the session idle timeout.
|
||||
sessionIdleTimeout, err := envDuration(
|
||||
"SESSION_IDLE_TIMEOUT",
|
||||
defaultSessionIdleTimeout,
|
||||
)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
// Load configuration values from environment variables
|
||||
s := &Config{
|
||||
DataDir: envString("DATA_DIR"),
|
||||
@@ -173,6 +190,7 @@ func New(lc fx.Lifecycle, params ConfigParams) (*Config, error) {
|
||||
Port: envInt("PORT", defaultPort),
|
||||
SentryDSN: envString("SENTRY_DSN"),
|
||||
RetentionSweepInterval: retentionSweepInterval,
|
||||
SessionIdleTimeout: sessionIdleTimeout,
|
||||
log: log,
|
||||
params: ¶ms,
|
||||
}
|
||||
|
||||
@@ -163,7 +163,7 @@ func TestRetentionSweepInterval(t *testing.T) {
|
||||
}
|
||||
|
||||
if tt.expectError {
|
||||
testRetentionSweepIntervalError(t)
|
||||
expectStartupError(t)
|
||||
} else {
|
||||
testRetentionSweepIntervalSuccess(t, tt.expected)
|
||||
}
|
||||
@@ -171,7 +171,9 @@ func TestRetentionSweepInterval(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func testRetentionSweepIntervalError(t *testing.T) {
|
||||
// expectStartupError asserts that fx refuses to build the app,
|
||||
// which is what a set-but-unparseable duration must cause.
|
||||
func expectStartupError(t *testing.T) {
|
||||
t.Helper()
|
||||
|
||||
var cfg *config.Config
|
||||
@@ -215,6 +217,82 @@ func testRetentionSweepIntervalSuccess(
|
||||
assert.Equal(t, expected, cfg.RetentionSweepInterval)
|
||||
}
|
||||
|
||||
func TestSessionIdleTimeout(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
set bool
|
||||
value string
|
||||
expectError bool
|
||||
expected time.Duration
|
||||
}{
|
||||
{
|
||||
name: "unset uses default",
|
||||
set: false,
|
||||
expected: 24 * time.Hour,
|
||||
},
|
||||
{
|
||||
name: "valid value is parsed",
|
||||
set: true,
|
||||
value: "30m",
|
||||
expected: 30 * time.Minute,
|
||||
},
|
||||
{
|
||||
name: "unparseable value fails startup",
|
||||
set: true,
|
||||
value: "not-a-duration",
|
||||
expectError: true,
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
|
||||
|
||||
if tt.set {
|
||||
t.Setenv("SESSION_IDLE_TIMEOUT", tt.value)
|
||||
} else {
|
||||
require.NoError(t, os.Unsetenv(
|
||||
"SESSION_IDLE_TIMEOUT",
|
||||
))
|
||||
}
|
||||
|
||||
if tt.expectError {
|
||||
expectStartupError(t)
|
||||
} else {
|
||||
testSessionIdleTimeoutSuccess(t, tt.expected)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func testSessionIdleTimeoutSuccess(
|
||||
t *testing.T,
|
||||
expected time.Duration,
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
var cfg *config.Config
|
||||
|
||||
app := fxtest.New(
|
||||
t,
|
||||
fx.Provide(
|
||||
globals.New,
|
||||
logger.New,
|
||||
config.New,
|
||||
),
|
||||
fx.Populate(&cfg),
|
||||
)
|
||||
require.NoError(t, app.Err())
|
||||
|
||||
app.RequireStart()
|
||||
|
||||
defer app.RequireStop()
|
||||
|
||||
assert.Equal(t, expected, cfg.SessionIdleTimeout)
|
||||
}
|
||||
|
||||
func TestDefaultDataDir(t *testing.T) {
|
||||
for _, env := range []string{"", "dev", "prod"} {
|
||||
name := env
|
||||
|
||||
@@ -1,189 +0,0 @@
|
||||
package delivery
|
||||
|
||||
import (
|
||||
"context"
|
||||
"log/slog"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"go.uber.org/fx"
|
||||
"sneak.berlin/go/webhooker/internal/config"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/logger"
|
||||
)
|
||||
|
||||
// ArchiveSweeperParams holds the fx dependencies for the
|
||||
// ArchiveSweeper.
|
||||
type ArchiveSweeperParams struct {
|
||||
fx.In
|
||||
|
||||
Config *config.Config
|
||||
Database *database.Database
|
||||
Engine *Engine
|
||||
Logger *logger.Logger
|
||||
}
|
||||
|
||||
// ArchiveSweeper periodically prunes expired rows from
|
||||
// per-webhook archive databases whose database target carries a
|
||||
// positive expiry.
|
||||
//
|
||||
// Without it, pruning happens only when an archive is
|
||||
// (re)opened, and archives are only ever reopened by writes: an
|
||||
// archive belonging to a webhook that has stopped receiving
|
||||
// events would keep its expired rows forever. The sweep closes
|
||||
// that gap without changing anything for archives whose expiry
|
||||
// is unset or "never".
|
||||
//
|
||||
// It reuses Config.RetentionSweepInterval rather than
|
||||
// introducing a second interval: this is a retention sweep with
|
||||
// the same semantics as the event retention reaper.
|
||||
type ArchiveSweeper struct {
|
||||
db *database.Database
|
||||
eng *Engine
|
||||
log *slog.Logger
|
||||
interval time.Duration
|
||||
cancel context.CancelFunc
|
||||
wg sync.WaitGroup
|
||||
}
|
||||
|
||||
// NewArchiveSweeper creates the archive sweeper and registers
|
||||
// its fx lifecycle hooks. The background sweep loop starts on
|
||||
// OnStart and stops cleanly on OnStop via context cancellation.
|
||||
func NewArchiveSweeper(
|
||||
lc fx.Lifecycle,
|
||||
params ArchiveSweeperParams,
|
||||
) *ArchiveSweeper {
|
||||
s := &ArchiveSweeper{
|
||||
db: params.Database,
|
||||
eng: params.Engine,
|
||||
log: params.Logger.Get(),
|
||||
interval: params.Config.RetentionSweepInterval,
|
||||
}
|
||||
|
||||
lc.Append(fx.Hook{
|
||||
OnStart: func(ctx context.Context) error {
|
||||
s.start(ctx)
|
||||
|
||||
return nil
|
||||
},
|
||||
OnStop: func(_ context.Context) error {
|
||||
s.stop()
|
||||
|
||||
return nil
|
||||
},
|
||||
})
|
||||
|
||||
return s
|
||||
}
|
||||
|
||||
func (s *ArchiveSweeper) start(ctx context.Context) {
|
||||
ctx, cancel := context.WithCancel(ctx)
|
||||
s.cancel = cancel
|
||||
|
||||
s.wg.Add(1)
|
||||
|
||||
go s.run(ctx)
|
||||
|
||||
s.log.Info(
|
||||
"archive sweeper started",
|
||||
"interval", s.interval.String(),
|
||||
)
|
||||
}
|
||||
|
||||
func (s *ArchiveSweeper) stop() {
|
||||
s.log.Info("archive sweeper stopping")
|
||||
|
||||
if s.cancel != nil {
|
||||
s.cancel()
|
||||
}
|
||||
|
||||
s.wg.Wait()
|
||||
s.log.Info("archive sweeper stopped")
|
||||
}
|
||||
|
||||
func (s *ArchiveSweeper) run(ctx context.Context) {
|
||||
defer s.wg.Done()
|
||||
|
||||
ticker := time.NewTicker(s.interval)
|
||||
defer ticker.Stop()
|
||||
|
||||
for {
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
return
|
||||
case <-ticker.C:
|
||||
s.sweep(ctx)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// sweep prunes every archive whose database target declares a
|
||||
// positive expiry. Targets belonging to a deleted webhook are
|
||||
// soft-deleted along with it, so GORM's default scope already
|
||||
// excludes them.
|
||||
//
|
||||
// A failure for one webhook is logged and the sweep continues,
|
||||
// matching how the write path already treats a prune error as
|
||||
// non-fatal.
|
||||
func (s *ArchiveSweeper) sweep(ctx context.Context) {
|
||||
var targets []database.Target
|
||||
|
||||
err := s.db.DB().
|
||||
Model(&database.Target{}).
|
||||
Where("type = ?", database.TargetTypeDatabase).
|
||||
Find(&targets).Error
|
||||
if err != nil {
|
||||
s.log.Error(
|
||||
"archive sweep: failed to list database targets",
|
||||
"error", err,
|
||||
)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
for i := range targets {
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
return
|
||||
default:
|
||||
}
|
||||
|
||||
s.sweepTarget(&targets[i])
|
||||
}
|
||||
}
|
||||
|
||||
// sweepTarget prunes the archive of a single database target.
|
||||
// A missing, empty, or "never" expiry parses as a zero duration
|
||||
// and is skipped entirely, so those archives keep exactly the
|
||||
// behaviour they had before the sweep existed.
|
||||
func (s *ArchiveSweeper) sweepTarget(target *database.Target) {
|
||||
expiry, err := parseArchiveExpiry(target.Config)
|
||||
if err != nil {
|
||||
s.log.Error(
|
||||
"archive sweep: invalid database target config",
|
||||
"webhook_id", target.WebhookID,
|
||||
"target_id", target.ID,
|
||||
"error", err,
|
||||
)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
if expiry <= 0 {
|
||||
return
|
||||
}
|
||||
|
||||
if s.eng == nil || s.eng.dbTarget == nil {
|
||||
return
|
||||
}
|
||||
|
||||
err = s.eng.dbTarget.sweepWebhook(target.WebhookID, expiry)
|
||||
if err != nil {
|
||||
s.log.Error(
|
||||
"archive sweep: failed to prune archive",
|
||||
"webhook_id", target.WebhookID,
|
||||
"target_id", target.ID,
|
||||
"error", err,
|
||||
)
|
||||
}
|
||||
}
|
||||
@@ -1,425 +0,0 @@
|
||||
package delivery_test
|
||||
|
||||
import (
|
||||
"context"
|
||||
"database/sql"
|
||||
"fmt"
|
||||
"net/http"
|
||||
"path/filepath"
|
||||
"sync"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/google/uuid"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"gorm.io/driver/sqlite"
|
||||
"gorm.io/gorm"
|
||||
"gorm.io/gorm/clause"
|
||||
_ "modernc.org/sqlite" // Pure Go SQLite driver.
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/delivery"
|
||||
)
|
||||
|
||||
const (
|
||||
// sweepRowOld and sweepRowNew are the event ids
|
||||
// seedArchiveRows assigns to the first and second seeded
|
||||
// rows.
|
||||
sweepRowOld = "ev-0"
|
||||
sweepRowNew = "ev-1"
|
||||
|
||||
// sweepConcurrentWrites is how many deliveries the
|
||||
// concurrent write-plus-sweep test races against the sweep.
|
||||
sweepConcurrentWrites = 20
|
||||
)
|
||||
|
||||
// sweeperEnv bundles the pieces an archive sweep test drives:
|
||||
// a main configuration database holding webhooks and targets, a
|
||||
// delivery engine owning the archive writer registry, and the
|
||||
// data directory the archive files live in.
|
||||
type sweeperEnv struct {
|
||||
sweeper *delivery.ArchiveSweeper
|
||||
eng *delivery.Engine
|
||||
mainDB *database.Database
|
||||
dataDir string
|
||||
}
|
||||
|
||||
func setupSweeperTest(t *testing.T) *sweeperEnv {
|
||||
t.Helper()
|
||||
|
||||
dataDir := t.TempDir()
|
||||
log := archiveTestLogger()
|
||||
|
||||
sqlDB, err := sql.Open(
|
||||
"sqlite",
|
||||
fmt.Sprintf(
|
||||
"file:%s?mode=rwc",
|
||||
filepath.Join(dataDir, "main.db"),
|
||||
),
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
t.Cleanup(func() { _ = sqlDB.Close() })
|
||||
|
||||
gdb, err := gorm.Open(
|
||||
sqlite.Dialector{Conn: sqlDB}, &gorm.Config{},
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
mainDB := database.NewTestDatabase(gdb)
|
||||
require.NoError(t, mainDB.Migrate())
|
||||
|
||||
eng := delivery.NewTestEngineWithDB(
|
||||
mainDB,
|
||||
database.NewTestWebhookDBManager(dataDir),
|
||||
log,
|
||||
&http.Client{Timeout: 5 * time.Second},
|
||||
1,
|
||||
)
|
||||
|
||||
return &sweeperEnv{
|
||||
sweeper: delivery.NewTestArchiveSweeper(
|
||||
mainDB, eng, log,
|
||||
),
|
||||
eng: eng,
|
||||
mainDB: mainDB,
|
||||
dataDir: dataDir,
|
||||
}
|
||||
}
|
||||
|
||||
// archivePath returns where the engine keeps a webhook's
|
||||
// archive file.
|
||||
func (env *sweeperEnv) archivePath(webhookID string) string {
|
||||
return filepath.Join(
|
||||
env.dataDir, fmt.Sprintf("archive-%s.db", webhookID),
|
||||
)
|
||||
}
|
||||
|
||||
// seedDatabaseTarget creates a webhook with one database target
|
||||
// carrying the given target config JSON, and returns the
|
||||
// webhook id.
|
||||
func (env *sweeperEnv) seedDatabaseTarget(
|
||||
t *testing.T, configJSON string,
|
||||
) string {
|
||||
t.Helper()
|
||||
|
||||
wh := &database.Webhook{
|
||||
UserID: uuid.New().String(),
|
||||
Name: "sweep-test",
|
||||
}
|
||||
require.NoError(
|
||||
t,
|
||||
env.mainDB.DB().
|
||||
Omit(clause.Associations).
|
||||
Create(wh).Error,
|
||||
)
|
||||
|
||||
tgt := &database.Target{
|
||||
WebhookID: wh.ID,
|
||||
Name: "archive",
|
||||
Type: database.TargetTypeDatabase,
|
||||
Active: true,
|
||||
Config: configJSON,
|
||||
}
|
||||
require.NoError(
|
||||
t,
|
||||
env.mainDB.DB().
|
||||
Omit(clause.Associations).
|
||||
Create(tgt).Error,
|
||||
)
|
||||
|
||||
return wh.ID
|
||||
}
|
||||
|
||||
// seedArchiveRows creates the archive file for a webhook and
|
||||
// inserts one row per supplied archived-at timestamp, returning
|
||||
// the archive path. The handle is closed before returning, so
|
||||
// the archive is idle exactly as it would be with no traffic.
|
||||
func (env *sweeperEnv) seedArchiveRows(
|
||||
t *testing.T, webhookID string, archivedAt ...time.Time,
|
||||
) string {
|
||||
t.Helper()
|
||||
|
||||
path := env.archivePath(webhookID)
|
||||
|
||||
sqlDB, err := sql.Open(
|
||||
"sqlite", fmt.Sprintf("file:%s?mode=rwc", path),
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
gdb, err := gorm.Open(
|
||||
sqlite.Dialector{Conn: sqlDB}, &gorm.Config{},
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
require.NoError(
|
||||
t, gdb.AutoMigrate(&delivery.ExportArchivedEvent{}),
|
||||
)
|
||||
|
||||
for i, at := range archivedAt {
|
||||
row := delivery.ExportArchivedEvent{
|
||||
EventID: fmt.Sprintf("ev-%d", i),
|
||||
WebhookID: webhookID,
|
||||
Method: http.MethodPost,
|
||||
Body: `{"seeded":true}`,
|
||||
ArchivedAt: at,
|
||||
}
|
||||
require.NoError(t, gdb.Create(&row).Error)
|
||||
}
|
||||
|
||||
require.NoError(t, sqlDB.Close())
|
||||
|
||||
return path
|
||||
}
|
||||
|
||||
// archivedEventIDs returns the event ids currently stored in an
|
||||
// archive file, read through a separate read-only handle.
|
||||
func archivedEventIDs(
|
||||
t *testing.T, path string,
|
||||
) []string {
|
||||
t.Helper()
|
||||
|
||||
var rows []delivery.ExportArchivedEvent
|
||||
|
||||
rdb := openArchiveDBForRead(t, path)
|
||||
require.NoError(t, rdb.Order("event_id").Find(&rows).Error)
|
||||
|
||||
ids := make([]string, 0, len(rows))
|
||||
for i := range rows {
|
||||
ids = append(ids, rows[i].EventID)
|
||||
}
|
||||
|
||||
return ids
|
||||
}
|
||||
|
||||
// TestArchiveSweep_PrunesIdleArchive is the core regression
|
||||
// test for this issue: an archive that receives no further
|
||||
// writes must still lose its expired rows. Before the sweeper
|
||||
// existed, pruning only ever ran on a write-triggered reopen,
|
||||
// so an idle archive kept expired rows forever.
|
||||
func TestArchiveSweep_PrunesIdleArchive(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSweeperTest(t)
|
||||
|
||||
webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
|
||||
|
||||
now := time.Now()
|
||||
path := env.seedArchiveRows(
|
||||
t, webhookID,
|
||||
now.Add(-48*time.Hour),
|
||||
now.Add(-time.Minute),
|
||||
)
|
||||
|
||||
require.Equal(
|
||||
t, []string{sweepRowOld, sweepRowNew},
|
||||
archivedEventIDs(t, path),
|
||||
)
|
||||
|
||||
env.sweeper.ExportSweep(context.Background())
|
||||
|
||||
assert.Equal(
|
||||
t, []string{sweepRowNew}, archivedEventIDs(t, path),
|
||||
"the sweep should prune rows older than the expiry "+
|
||||
"from an idle archive and keep the rest",
|
||||
)
|
||||
}
|
||||
|
||||
// TestArchiveSweep_LeavesArchiveClosed proves the sweep does
|
||||
// not hold the archive open afterwards, so an operator can
|
||||
// still move the file away for offline retention.
|
||||
func TestArchiveSweep_LeavesArchiveClosed(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSweeperTest(t)
|
||||
|
||||
webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
|
||||
env.seedArchiveRows(
|
||||
t, webhookID, time.Now().Add(-48*time.Hour),
|
||||
)
|
||||
|
||||
env.sweeper.ExportSweep(context.Background())
|
||||
|
||||
assert.False(
|
||||
t, env.eng.ExportArchiveHandleOpen(webhookID),
|
||||
"an idle archive must end the sweep closed",
|
||||
)
|
||||
}
|
||||
|
||||
// TestArchiveSweep_NeverExpiryUntouched proves the sweep is a
|
||||
// no-op for the default retention policy, so archives with no
|
||||
// expiry (or the literal "never") behave exactly as before.
|
||||
func TestArchiveSweep_NeverExpiryUntouched(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
for _, configJSON := range []string{
|
||||
`{"expiry":"never"}`,
|
||||
`{"expiry":""}`,
|
||||
"",
|
||||
} {
|
||||
env := setupSweeperTest(t)
|
||||
|
||||
webhookID := env.seedDatabaseTarget(t, configJSON)
|
||||
path := env.seedArchiveRows(
|
||||
t, webhookID,
|
||||
time.Now().Add(-10000*time.Hour),
|
||||
)
|
||||
|
||||
env.sweeper.ExportSweep(context.Background())
|
||||
|
||||
assert.Equal(
|
||||
t, []string{sweepRowOld}, archivedEventIDs(t, path),
|
||||
"config %q must keep rows forever", configJSON,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// TestArchiveSweep_DoesNotCreateArchiveFile proves the sweep
|
||||
// never conjures an archive: a webhook with a database target
|
||||
// that has never received an event must still have no archive
|
||||
// file (nor SQLite sidecar) after a sweep.
|
||||
func TestArchiveSweep_DoesNotCreateArchiveFile(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSweeperTest(t)
|
||||
|
||||
webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
|
||||
path := env.archivePath(webhookID)
|
||||
|
||||
require.NoFileExists(t, path)
|
||||
|
||||
env.sweeper.ExportSweep(context.Background())
|
||||
|
||||
for _, suffix := range []string{"", "-wal", "-shm"} {
|
||||
assert.NoFileExists(
|
||||
t, path+suffix,
|
||||
"the sweep must not create an archive file",
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// TestArchiveSweep_DoesNotCreateAfterWriterExists covers the
|
||||
// same guarantee once a writer is cached in the registry but
|
||||
// the file itself is still absent (for instance because the
|
||||
// operator moved the archive away).
|
||||
func TestArchiveSweep_DoesNotCreateAfterWriterExists(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSweeperTest(t)
|
||||
|
||||
webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
|
||||
|
||||
path, err := env.eng.ExportEnsureArchiveWriter(webhookID)
|
||||
require.NoError(t, err)
|
||||
require.NoFileExists(t, path)
|
||||
|
||||
env.sweeper.ExportSweep(context.Background())
|
||||
|
||||
assert.NoFileExists(t, path)
|
||||
}
|
||||
|
||||
// TestArchiveSweep_SkipsDeletedWebhookTargets proves that the
|
||||
// sweep ignores targets soft-deleted along with their webhook,
|
||||
// so a deleted webhook's archive is never reopened.
|
||||
func TestArchiveSweep_SkipsDeletedWebhookTargets(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSweeperTest(t)
|
||||
|
||||
webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
|
||||
path := env.seedArchiveRows(
|
||||
t, webhookID, time.Now().Add(-48*time.Hour),
|
||||
)
|
||||
|
||||
require.NoError(
|
||||
t,
|
||||
env.mainDB.DB().
|
||||
Where("webhook_id = ?", webhookID).
|
||||
Delete(&database.Target{}).Error,
|
||||
)
|
||||
|
||||
env.sweeper.ExportSweep(context.Background())
|
||||
|
||||
assert.Equal(
|
||||
t, []string{sweepRowOld}, archivedEventIDs(t, path),
|
||||
"a deleted target's archive must be left alone",
|
||||
)
|
||||
}
|
||||
|
||||
// TestArchiveSweep_ConcurrentWrites proves the sweep serialises
|
||||
// against writes through the per-webhook writer mutex. Run
|
||||
// under -race, an unsynchronised sweep would be caught here.
|
||||
func TestArchiveSweep_ConcurrentWrites(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSweeperTest(t)
|
||||
|
||||
webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
|
||||
|
||||
webhookDB := testWebhookDB(t)
|
||||
|
||||
// The deliveries are seeded up front, on the test's own
|
||||
// goroutine: the seed helpers assert, and testify assertions
|
||||
// must not run off the test goroutine.
|
||||
deliveries := make(
|
||||
[]*database.Delivery, 0, sweepConcurrentWrites,
|
||||
)
|
||||
|
||||
for range sweepConcurrentWrites {
|
||||
event := seedEvent(t, webhookDB, `{"n":1}`)
|
||||
event.WebhookID = webhookID
|
||||
|
||||
deliveries = append(
|
||||
deliveries,
|
||||
seedDatabaseTargetDelivery(
|
||||
t, webhookDB, event, `{"expiry":"1h"}`,
|
||||
),
|
||||
)
|
||||
}
|
||||
|
||||
var wg sync.WaitGroup
|
||||
|
||||
wg.Add(2)
|
||||
|
||||
go func() {
|
||||
defer wg.Done()
|
||||
|
||||
for _, d := range deliveries {
|
||||
env.eng.ExportDeliverDatabase(webhookDB, d)
|
||||
}
|
||||
}()
|
||||
|
||||
go func() {
|
||||
defer wg.Done()
|
||||
|
||||
for range sweepConcurrentWrites {
|
||||
env.sweeper.ExportSweep(context.Background())
|
||||
}
|
||||
}()
|
||||
|
||||
wg.Wait()
|
||||
|
||||
assert.FileExists(t, env.archivePath(webhookID))
|
||||
}
|
||||
|
||||
// TestArchiveSweeper_StopsCleanly proves the background loop
|
||||
// exits on OnStop rather than leaking a goroutine.
|
||||
func TestArchiveSweeper_StopsCleanly(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSweeperTest(t)
|
||||
|
||||
webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
|
||||
env.seedArchiveRows(
|
||||
t, webhookID, time.Now().Add(-48*time.Hour),
|
||||
)
|
||||
|
||||
env.sweeper.ExportSetInterval(time.Millisecond)
|
||||
env.sweeper.ExportStart(context.Background())
|
||||
|
||||
// stop blocks on the loop's WaitGroup, so returning at all
|
||||
// proves the loop observed the cancellation and exited.
|
||||
env.sweeper.ExportStop()
|
||||
}
|
||||
@@ -94,23 +94,6 @@ type Notifier interface {
|
||||
Notify(tasks []Task)
|
||||
}
|
||||
|
||||
// WebhookEvictor releases the delivery engine's per-webhook
|
||||
// state for a webhook that no longer needs it — currently the
|
||||
// cached archive writer of the database target, whose open
|
||||
// file handle would otherwise outlive the webhook.
|
||||
//
|
||||
// It is deliberately separate from Notifier and deliberately
|
||||
// one method wide: archiving lifecycle is not notification, and
|
||||
// a single-method interface keeps the handlers package free of
|
||||
// any dependency on the engine's internals while staying
|
||||
// trivially fakeable in tests.
|
||||
//
|
||||
// EvictWebhook never deletes an archive file. It is idempotent
|
||||
// and is a no-op for a webhook with no engine state.
|
||||
type WebhookEvictor interface {
|
||||
EvictWebhook(webhookID string)
|
||||
}
|
||||
|
||||
// EngineParams are the fx dependencies for the delivery
|
||||
// engine.
|
||||
type EngineParams struct {
|
||||
@@ -144,10 +127,6 @@ type Engine struct {
|
||||
// httpTarget is retained so tests can reach the HTTP
|
||||
// target's shared client and circuit breakers.
|
||||
httpTarget *httpTarget
|
||||
|
||||
// dbTarget is retained so the engine can reach the archive
|
||||
// writer registry for webhook eviction and the idle sweep.
|
||||
dbTarget *databaseTarget
|
||||
}
|
||||
|
||||
// New creates and registers the delivery engine with the
|
||||
@@ -203,19 +182,6 @@ func (e *Engine) Notify(tasks []Task) {
|
||||
}
|
||||
}
|
||||
|
||||
// EvictWebhook implements WebhookEvictor. It releases the
|
||||
// engine's per-webhook archiving state: the database target's
|
||||
// cached archive writer is dropped from the registry and its
|
||||
// file handle closed. The archive file itself is left on disk
|
||||
// — it is long-term storage the operator owns.
|
||||
func (e *Engine) EvictWebhook(webhookID string) {
|
||||
if e.dbTarget == nil {
|
||||
return
|
||||
}
|
||||
|
||||
e.dbTarget.evict(webhookID)
|
||||
}
|
||||
|
||||
// ScheduleRetry schedules a task to be re-enqueued onto the
|
||||
// retry channel after delay. It implements the Scheduler
|
||||
// interface the targets use to own their durable retries.
|
||||
|
||||
@@ -328,90 +328,6 @@ func (e *ExportArchiveWriter) DB() *gorm.DB {
|
||||
return e.w.db
|
||||
}
|
||||
|
||||
// ExportHasArchiveWriter reports whether the database target
|
||||
// currently caches an archive writer for a webhook.
|
||||
func (e *Engine) ExportHasArchiveWriter(
|
||||
webhookID string,
|
||||
) bool {
|
||||
e.dbTarget.mu.Lock()
|
||||
defer e.dbTarget.mu.Unlock()
|
||||
|
||||
_, ok := e.dbTarget.writers[webhookID]
|
||||
|
||||
return ok
|
||||
}
|
||||
|
||||
// ExportArchiveHandleOpen reports whether the cached archive
|
||||
// writer for a webhook holds an open database handle. It
|
||||
// returns false when no writer is cached.
|
||||
func (e *Engine) ExportArchiveHandleOpen(
|
||||
webhookID string,
|
||||
) bool {
|
||||
e.dbTarget.mu.Lock()
|
||||
w, ok := e.dbTarget.writers[webhookID]
|
||||
e.dbTarget.mu.Unlock()
|
||||
|
||||
if !ok {
|
||||
return false
|
||||
}
|
||||
|
||||
w.mu.Lock()
|
||||
defer w.mu.Unlock()
|
||||
|
||||
return w.db != nil
|
||||
}
|
||||
|
||||
// ExportEnsureArchiveWriter creates (if needed) and returns the
|
||||
// archive file path of the cached writer for a webhook, so a
|
||||
// test can prime the registry the way a delivery would.
|
||||
func (e *Engine) ExportEnsureArchiveWriter(
|
||||
webhookID string,
|
||||
) (string, error) {
|
||||
w, err := e.dbTarget.writerFor(webhookID)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
return w.path, nil
|
||||
}
|
||||
|
||||
// NewTestArchiveSweeper builds an ArchiveSweeper backed by the
|
||||
// given main database and engine, without the fx lifecycle.
|
||||
// Intended for tests.
|
||||
func NewTestArchiveSweeper(
|
||||
db *database.Database,
|
||||
eng *Engine,
|
||||
log *slog.Logger,
|
||||
) *ArchiveSweeper {
|
||||
return &ArchiveSweeper{
|
||||
db: db,
|
||||
eng: eng,
|
||||
log: log,
|
||||
interval: time.Hour,
|
||||
}
|
||||
}
|
||||
|
||||
// ExportSweep runs a single archive sweep synchronously for
|
||||
// tests.
|
||||
func (s *ArchiveSweeper) ExportSweep(ctx context.Context) {
|
||||
s.sweep(ctx)
|
||||
}
|
||||
|
||||
// ExportStart starts the sweeper's background loop for tests.
|
||||
func (s *ArchiveSweeper) ExportStart(ctx context.Context) {
|
||||
s.start(ctx)
|
||||
}
|
||||
|
||||
// ExportStop stops the sweeper's background loop for tests.
|
||||
func (s *ArchiveSweeper) ExportStop() {
|
||||
s.stop()
|
||||
}
|
||||
|
||||
// ExportSetInterval overrides the sweep interval for tests.
|
||||
func (s *ArchiveSweeper) ExportSetInterval(d time.Duration) {
|
||||
s.interval = d
|
||||
}
|
||||
|
||||
// ExportParseArchiveExpiry exposes parseArchiveExpiry.
|
||||
func ExportParseArchiveExpiry(
|
||||
configJSON string,
|
||||
|
||||
@@ -90,15 +90,12 @@ func (e *Engine) initTargets(client *http.Client) {
|
||||
client: client,
|
||||
}
|
||||
|
||||
dbT := &databaseTarget{eng: e}
|
||||
|
||||
e.httpTarget = httpT
|
||||
e.dbTarget = dbT
|
||||
|
||||
e.targets = map[database.TargetType]Target{
|
||||
database.TargetTypeHTTP: httpT,
|
||||
database.TargetTypeSlack: slackT,
|
||||
database.TargetTypeDatabase: dbT,
|
||||
database.TargetTypeDatabase: &databaseTarget{eng: e},
|
||||
database.TargetTypeLog: &logTarget{eng: e},
|
||||
}
|
||||
}
|
||||
|
||||
@@ -5,7 +5,6 @@ import (
|
||||
"fmt"
|
||||
"path/filepath"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"gorm.io/gorm"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
@@ -112,11 +111,15 @@ func (t *databaseTarget) archive(d *database.Delivery) error {
|
||||
func (t *databaseTarget) writerFor(
|
||||
webhookID string,
|
||||
) (*archiveWriter, error) {
|
||||
path, err := t.archivePath(webhookID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
if t.eng.dbManager == nil {
|
||||
return nil, errArchiveNoDataDir
|
||||
}
|
||||
|
||||
dir := filepath.Dir(t.eng.dbManager.DBPath(webhookID))
|
||||
path := filepath.Join(
|
||||
dir, fmt.Sprintf("archive-%s.db", webhookID),
|
||||
)
|
||||
|
||||
t.mu.Lock()
|
||||
defer t.mu.Unlock()
|
||||
|
||||
@@ -132,86 +135,3 @@ func (t *databaseTarget) writerFor(
|
||||
|
||||
return w, nil
|
||||
}
|
||||
|
||||
// archivePath returns the archive file path for a webhook: it
|
||||
// lives beside the per-webhook event database in the data
|
||||
// directory. It does not touch the filesystem.
|
||||
func (t *databaseTarget) archivePath(
|
||||
webhookID string,
|
||||
) (string, error) {
|
||||
if t.eng.dbManager == nil {
|
||||
return "", errArchiveNoDataDir
|
||||
}
|
||||
|
||||
dir := filepath.Dir(t.eng.dbManager.DBPath(webhookID))
|
||||
|
||||
return filepath.Join(
|
||||
dir, fmt.Sprintf("archive-%s.db", webhookID),
|
||||
), nil
|
||||
}
|
||||
|
||||
// evict drops a webhook's archive writer from the registry and
|
||||
// closes its handle, so a deleted webhook does not leave a
|
||||
// writer (and an open archive handle within its debounce
|
||||
// window) alive for the process lifetime.
|
||||
//
|
||||
// The map entry is removed under the registry lock, which is
|
||||
// then released before the handle is closed under the writer's
|
||||
// own lock: that ordering keeps the registry available to other
|
||||
// webhooks while an in-flight write on this one drains, and
|
||||
// closing under the writer's lock means eviction can never race
|
||||
// a write.
|
||||
//
|
||||
// Eviction is idempotent and silent for a webhook with no
|
||||
// writer, which is the common case: a webhook with no database
|
||||
// target never creates one. It never deletes the archive file.
|
||||
func (t *databaseTarget) evict(webhookID string) {
|
||||
t.mu.Lock()
|
||||
|
||||
w, ok := t.writers[webhookID]
|
||||
if ok {
|
||||
delete(t.writers, webhookID)
|
||||
}
|
||||
|
||||
t.mu.Unlock()
|
||||
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
|
||||
w.evict()
|
||||
|
||||
t.eng.log.Info(
|
||||
"evicted archive writer",
|
||||
"webhook_id", webhookID,
|
||||
"path", w.path,
|
||||
)
|
||||
}
|
||||
|
||||
// sweepWebhook prunes one webhook's archive of rows older than
|
||||
// expiry, without requiring a write. It returns nil (nothing to
|
||||
// do) when the archive file does not exist, so a sweep never
|
||||
// creates an archive for a webhook that has a database target
|
||||
// but has never received an event.
|
||||
func (t *databaseTarget) sweepWebhook(
|
||||
webhookID string, expiry time.Duration,
|
||||
) error {
|
||||
path, err := t.archivePath(webhookID)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// Check before taking a writer at all: a webhook whose
|
||||
// archive has never been created gets no writer, no handle,
|
||||
// and no file.
|
||||
if !fileExists(path) {
|
||||
return nil
|
||||
}
|
||||
|
||||
w, err := t.writerFor(webhookID)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
return w.sweepExpired(expiry)
|
||||
}
|
||||
|
||||
@@ -24,20 +24,6 @@ const archiveExpiryNever = "never"
|
||||
// offline archiving, but never more than once per this window.
|
||||
const archiveReopenDebounce = time.Second
|
||||
|
||||
const (
|
||||
// archiveModeCreate is the SQLite URI mode used by the write
|
||||
// path: open the archive file, creating it if missing, so a
|
||||
// first write (or a write after the operator moved the file
|
||||
// away) recreates it.
|
||||
archiveModeCreate = "rwc"
|
||||
|
||||
// archiveModeExisting is the SQLite URI mode used by the idle
|
||||
// sweep: open read-write but never create. A sweep must never
|
||||
// conjure an empty archive file for a webhook that has a
|
||||
// database target but has never received an event.
|
||||
archiveModeExisting = "rw"
|
||||
)
|
||||
|
||||
var (
|
||||
// errArchiveMissingWebhookID is returned when an event to
|
||||
// archive has no webhook id to key its archive file on.
|
||||
@@ -58,15 +44,6 @@ var (
|
||||
errArchiveExpiryNotPositive = errors.New(
|
||||
"expiry must be a positive duration or \"never\"",
|
||||
)
|
||||
|
||||
// errArchiveWriterEvicted is returned when a writer that has
|
||||
// been evicted (its webhook was deleted, or its last database
|
||||
// target was removed) is used again. An evicted writer is no
|
||||
// longer in the registry, so reopening its file would leak a
|
||||
// handle nothing owns.
|
||||
errArchiveWriterEvicted = errors.New(
|
||||
"archive writer has been evicted",
|
||||
)
|
||||
)
|
||||
|
||||
// databaseTargetConfig is the optional per-target JSON config
|
||||
@@ -184,12 +161,6 @@ type archiveWriter struct {
|
||||
db *gorm.DB
|
||||
lastReopen time.Time
|
||||
reopens int
|
||||
|
||||
// evicted marks a writer that has been removed from the
|
||||
// per-webhook registry. Its handle is closed and it must
|
||||
// never open the file again: nothing holds it any more, so a
|
||||
// reopen would leak the handle for the process lifetime.
|
||||
evicted bool
|
||||
}
|
||||
|
||||
// newArchiveWriter builds an archiveWriter for a file path with
|
||||
@@ -214,12 +185,6 @@ func (w *archiveWriter) write(
|
||||
w.mu.Lock()
|
||||
defer w.mu.Unlock()
|
||||
|
||||
if w.evicted {
|
||||
return fmt.Errorf(
|
||||
"%w: %s", errArchiveWriterEvicted, w.path,
|
||||
)
|
||||
}
|
||||
|
||||
if w.db == nil || !fileExists(w.path) {
|
||||
err := w.reopen(expiry)
|
||||
if err != nil {
|
||||
@@ -247,19 +212,7 @@ func (w *archiveWriter) write(
|
||||
// its schema, records the reopen time, and prunes expired rows
|
||||
// when expiry is positive.
|
||||
func (w *archiveWriter) open(expiry time.Duration) error {
|
||||
return w.openMode(archiveModeCreate, expiry)
|
||||
}
|
||||
|
||||
// openMode opens the archive file with the given SQLite URI
|
||||
// mode, migrates its schema, records the reopen time, and
|
||||
// prunes expired rows when expiry is positive. The write path
|
||||
// passes archiveModeCreate so a missing file is recreated; the
|
||||
// idle sweep passes archiveModeExisting so a missing file is an
|
||||
// error rather than a newly conjured empty archive.
|
||||
func (w *archiveWriter) openMode(
|
||||
mode string, expiry time.Duration,
|
||||
) error {
|
||||
dbURL := fmt.Sprintf("file:%s?mode=%s", w.path, mode)
|
||||
dbURL := fmt.Sprintf("file:%s?mode=rwc", w.path)
|
||||
|
||||
sqlDB, err := sql.Open("sqlite", dbURL)
|
||||
if err != nil {
|
||||
@@ -322,63 +275,6 @@ func (w *archiveWriter) close() {
|
||||
w.db = nil
|
||||
}
|
||||
|
||||
// sweepExpired prunes an archive that may have gone idle, with
|
||||
// no write to trigger the usual on-reopen prune. It takes the
|
||||
// writer's own mutex for the whole operation, so a sweep is
|
||||
// ordered against concurrent writes rather than reaching around
|
||||
// them to the file.
|
||||
//
|
||||
// It never creates the archive file: a missing file is skipped,
|
||||
// and the reopen uses archiveModeExisting so SQLite itself
|
||||
// refuses to create one if the file disappears between the
|
||||
// check and the open.
|
||||
//
|
||||
// The archive is left CLOSED afterwards. An idle archive holding
|
||||
// no handle is what keeps the operator's move-the-file-away
|
||||
// workflow working; the next write reopens (and recreates) the
|
||||
// file as it always has.
|
||||
func (w *archiveWriter) sweepExpired(expiry time.Duration) error {
|
||||
w.mu.Lock()
|
||||
defer w.mu.Unlock()
|
||||
|
||||
if w.evicted {
|
||||
return fmt.Errorf(
|
||||
"%w: %s", errArchiveWriterEvicted, w.path,
|
||||
)
|
||||
}
|
||||
|
||||
if !fileExists(w.path) {
|
||||
return nil
|
||||
}
|
||||
|
||||
// Drop any live handle first so the prune runs against a
|
||||
// freshly opened file, matching the write path's semantics.
|
||||
w.close()
|
||||
|
||||
err := w.openMode(archiveModeExisting, expiry)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
w.close()
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// evict closes the writer's handle and marks it unusable. It is
|
||||
// called when the writer leaves the registry, either because the
|
||||
// webhook was deleted or because its last database target was
|
||||
// removed. The archive FILE is deliberately left on disk: it is
|
||||
// long-term storage an operator may still want.
|
||||
func (w *archiveWriter) evict() {
|
||||
w.mu.Lock()
|
||||
defer w.mu.Unlock()
|
||||
|
||||
w.evicted = true
|
||||
|
||||
w.close()
|
||||
}
|
||||
|
||||
// prune deletes archived rows older than expiry, measured from
|
||||
// each row's archived time. It runs on every (re)open, and
|
||||
// because the file is reopened after writes this keeps the
|
||||
|
||||
@@ -1,130 +0,0 @@
|
||||
package delivery_test
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"net/http"
|
||||
"path/filepath"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/delivery"
|
||||
)
|
||||
|
||||
// evictTestEngine builds an engine backed by a temporary data
|
||||
// directory and returns it along with that directory.
|
||||
func evictTestEngine(t *testing.T) (*delivery.Engine, string) {
|
||||
t.Helper()
|
||||
|
||||
dataDir := t.TempDir()
|
||||
|
||||
eng := delivery.NewTestEngineWithDB(
|
||||
nil,
|
||||
database.NewTestWebhookDBManager(dataDir),
|
||||
archiveTestLogger(),
|
||||
&http.Client{Timeout: 5 * time.Second},
|
||||
1,
|
||||
)
|
||||
|
||||
return eng, dataDir
|
||||
}
|
||||
|
||||
// TestEvictWebhook_ClosesAndRemovesWriter proves that evicting
|
||||
// a webhook drops its archive writer from the registry and
|
||||
// closes the open archive handle, rather than leaving both
|
||||
// alive for the process lifetime.
|
||||
func TestEvictWebhook_ClosesAndRemovesWriter(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
eng, dataDir := evictTestEngine(t)
|
||||
|
||||
webhookDB := testWebhookDB(t)
|
||||
event := seedEvent(t, webhookDB, `{"archived":true}`)
|
||||
d := seedDatabaseTargetDelivery(t, webhookDB, event, "")
|
||||
|
||||
eng.ExportDeliverDatabase(webhookDB, d)
|
||||
|
||||
webhookID := event.WebhookID
|
||||
|
||||
require.True(
|
||||
t, eng.ExportHasArchiveWriter(webhookID),
|
||||
"a delivery should have cached an archive writer",
|
||||
)
|
||||
require.True(
|
||||
t, eng.ExportArchiveHandleOpen(webhookID),
|
||||
"the writer should hold an open handle after a write",
|
||||
)
|
||||
|
||||
eng.EvictWebhook(webhookID)
|
||||
|
||||
assert.False(
|
||||
t, eng.ExportHasArchiveWriter(webhookID),
|
||||
"eviction should remove the registry entry",
|
||||
)
|
||||
assert.False(
|
||||
t, eng.ExportArchiveHandleOpen(webhookID),
|
||||
"eviction should close the archive handle",
|
||||
)
|
||||
|
||||
archivePath := filepath.Join(
|
||||
dataDir, fmt.Sprintf("archive-%s.db", webhookID),
|
||||
)
|
||||
assert.FileExists(
|
||||
t, archivePath,
|
||||
"eviction must not delete the archive file",
|
||||
)
|
||||
}
|
||||
|
||||
// TestEvictWebhook_UnknownWebhookIsNoOp proves eviction is safe
|
||||
// for the common case of a webhook that never had a database
|
||||
// target, and that repeating it does not panic.
|
||||
func TestEvictWebhook_UnknownWebhookIsNoOp(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
eng, _ := evictTestEngine(t)
|
||||
|
||||
assert.NotPanics(t, func() {
|
||||
eng.EvictWebhook("no-such-webhook")
|
||||
eng.EvictWebhook("no-such-webhook")
|
||||
})
|
||||
|
||||
assert.False(
|
||||
t, eng.ExportHasArchiveWriter("no-such-webhook"),
|
||||
"eviction must not create a writer",
|
||||
)
|
||||
}
|
||||
|
||||
// TestEvictWebhook_EvictedWriterDoesNotReopen proves an evicted
|
||||
// writer refuses further writes instead of silently reopening
|
||||
// the archive file: nothing holds it any more, so a reopened
|
||||
// handle would leak.
|
||||
func TestEvictWebhook_EvictedWriterDoesNotReopen(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
eng, _ := evictTestEngine(t)
|
||||
|
||||
webhookDB := testWebhookDB(t)
|
||||
event := seedEvent(t, webhookDB, `{"archived":true}`)
|
||||
d := seedDatabaseTargetDelivery(t, webhookDB, event, "")
|
||||
|
||||
eng.ExportDeliverDatabase(webhookDB, d)
|
||||
require.True(
|
||||
t, eng.ExportHasArchiveWriter(event.WebhookID),
|
||||
)
|
||||
|
||||
eng.EvictWebhook(event.WebhookID)
|
||||
|
||||
// A fresh delivery for the same webhook gets a brand new
|
||||
// writer from the registry, so archiving keeps working.
|
||||
second := seedDatabaseTargetDelivery(
|
||||
t, webhookDB, event, "",
|
||||
)
|
||||
eng.ExportDeliverDatabase(webhookDB, second)
|
||||
|
||||
assert.True(
|
||||
t, eng.ExportHasArchiveWriter(event.WebhookID),
|
||||
"a later delivery should recreate the writer",
|
||||
)
|
||||
}
|
||||
@@ -51,7 +51,6 @@ type HandlersParams struct {
|
||||
Healthcheck *healthcheck.Healthcheck
|
||||
Session *session.Session
|
||||
Notifier delivery.Notifier
|
||||
Evictor delivery.WebhookEvictor
|
||||
}
|
||||
|
||||
// Handlers provides HTTP handler methods for all application
|
||||
@@ -64,7 +63,6 @@ type Handlers struct {
|
||||
dbMgr *database.WebhookDBManager
|
||||
session *session.Session
|
||||
notifier delivery.Notifier
|
||||
evictor delivery.WebhookEvictor
|
||||
templates map[string]*template.Template
|
||||
}
|
||||
|
||||
@@ -99,7 +97,6 @@ func New(
|
||||
s.dbMgr = params.WebhookDBMgr
|
||||
s.session = params.Session
|
||||
s.notifier = params.Notifier
|
||||
s.evictor = params.Evictor
|
||||
|
||||
// Parse all page templates once at startup
|
||||
s.templates = map[string]*template.Template{
|
||||
|
||||
@@ -4,7 +4,6 @@ import (
|
||||
"context"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"sync"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
@@ -25,32 +24,6 @@ type noopNotifier struct{}
|
||||
|
||||
func (n *noopNotifier) Notify([]delivery.Task) {}
|
||||
|
||||
// recordingEvictor is a delivery.WebhookEvictor that records
|
||||
// the webhook ids it was asked to evict, so a test can prove
|
||||
// that a deletion path reached the delivery engine.
|
||||
type recordingEvictor struct {
|
||||
mu sync.Mutex
|
||||
evicted []string
|
||||
}
|
||||
|
||||
func (r *recordingEvictor) EvictWebhook(webhookID string) {
|
||||
r.mu.Lock()
|
||||
defer r.mu.Unlock()
|
||||
|
||||
r.evicted = append(r.evicted, webhookID)
|
||||
}
|
||||
|
||||
// Evicted returns a copy of the recorded webhook ids.
|
||||
func (r *recordingEvictor) Evicted() []string {
|
||||
r.mu.Lock()
|
||||
defer r.mu.Unlock()
|
||||
|
||||
out := make([]string, len(r.evicted))
|
||||
copy(out, r.evicted)
|
||||
|
||||
return out
|
||||
}
|
||||
|
||||
func newTestApp(
|
||||
t *testing.T,
|
||||
targets ...any,
|
||||
@@ -74,12 +47,6 @@ func newTestApp(
|
||||
func() delivery.Notifier {
|
||||
return &noopNotifier{}
|
||||
},
|
||||
func() *recordingEvictor {
|
||||
return &recordingEvictor{}
|
||||
},
|
||||
func(r *recordingEvictor) delivery.WebhookEvictor {
|
||||
return r
|
||||
},
|
||||
handlers.New,
|
||||
),
|
||||
fx.Populate(targets...),
|
||||
|
||||
@@ -1,305 +0,0 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"testing"
|
||||
|
||||
"github.com/go-chi/chi"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"gorm.io/gorm/clause"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/handlers"
|
||||
"sneak.berlin/go/webhooker/internal/session"
|
||||
)
|
||||
|
||||
const (
|
||||
deleteTestUserID = "test-user-id"
|
||||
deleteTestUsername = "testuser"
|
||||
|
||||
// paramSourceID and paramTargetID are the chi URL parameter
|
||||
// names the deletion handlers read.
|
||||
paramSourceID = "sourceID"
|
||||
paramTargetID = "targetID"
|
||||
)
|
||||
|
||||
// seedWebhook inserts a webhook owned by the test user and
|
||||
// returns it.
|
||||
func seedWebhook(
|
||||
t *testing.T,
|
||||
db *database.Database,
|
||||
) *database.Webhook {
|
||||
t.Helper()
|
||||
|
||||
wh := &database.Webhook{
|
||||
UserID: deleteTestUserID,
|
||||
Name: "delete-me",
|
||||
}
|
||||
|
||||
require.NoError(
|
||||
t,
|
||||
db.DB().Omit(clause.Associations).Create(wh).Error,
|
||||
)
|
||||
|
||||
return wh
|
||||
}
|
||||
|
||||
// seedTarget inserts a target of the given type for a webhook
|
||||
// and returns it.
|
||||
func seedTarget(
|
||||
t *testing.T,
|
||||
db *database.Database,
|
||||
webhookID string,
|
||||
targetType database.TargetType,
|
||||
) *database.Target {
|
||||
t.Helper()
|
||||
|
||||
tgt := &database.Target{
|
||||
WebhookID: webhookID,
|
||||
Name: "t-" + string(targetType),
|
||||
Type: targetType,
|
||||
Active: true,
|
||||
}
|
||||
|
||||
require.NoError(
|
||||
t,
|
||||
db.DB().Omit(clause.Associations).Create(tgt).Error,
|
||||
)
|
||||
|
||||
return tgt
|
||||
}
|
||||
|
||||
// archivePathFor returns the archive database path the
|
||||
// delivery engine would use for a webhook: beside the webhook's
|
||||
// event database in the data directory.
|
||||
func archivePathFor(
|
||||
t *testing.T,
|
||||
mgr *database.WebhookDBManager,
|
||||
webhookID string,
|
||||
) string {
|
||||
t.Helper()
|
||||
|
||||
return filepath.Join(
|
||||
filepath.Dir(mgr.DBPath(webhookID)),
|
||||
"archive-"+webhookID+".db",
|
||||
)
|
||||
}
|
||||
|
||||
// writeArchivePlaceholder creates a stand-in archive file so a
|
||||
// test can assert the file survives webhook deletion.
|
||||
func writeArchivePlaceholder(path string) error {
|
||||
return os.WriteFile(path, []byte("archive"), 0o600)
|
||||
}
|
||||
|
||||
// postRequest builds an authenticated POST request carrying the
|
||||
// given chi URL parameters.
|
||||
func postRequest(
|
||||
path string,
|
||||
cookies []*http.Cookie,
|
||||
params map[string]string,
|
||||
) *http.Request {
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(), http.MethodPost, path, nil,
|
||||
)
|
||||
|
||||
for _, c := range cookies {
|
||||
req.AddCookie(c)
|
||||
}
|
||||
|
||||
rctx := chi.NewRouteContext()
|
||||
for k, v := range params {
|
||||
rctx.URLParams.Add(k, v)
|
||||
}
|
||||
|
||||
return req.WithContext(
|
||||
context.WithValue(req.Context(), chi.RouteCtxKey, rctx),
|
||||
)
|
||||
}
|
||||
|
||||
// TestHandleSourceDelete_EvictsArchiveWriter proves that
|
||||
// deleting a webhook reaches the delivery engine and releases
|
||||
// the webhook's archive writer, exercised through the real
|
||||
// deletion handler rather than by calling the evictor directly.
|
||||
func TestHandleSourceDelete_EvictsArchiveWriter(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
sess *session.Session
|
||||
db *database.Database
|
||||
ev *recordingEvictor
|
||||
)
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &ev)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
wh := seedWebhook(t, db)
|
||||
seedTarget(t, db, wh.ID, database.TargetTypeDatabase)
|
||||
|
||||
cookies := authenticatedCookies(
|
||||
t, sess, deleteTestUserID, deleteTestUsername,
|
||||
)
|
||||
|
||||
req := postRequest(
|
||||
"/source/"+wh.ID+"/delete",
|
||||
cookies,
|
||||
map[string]string{paramSourceID: wh.ID},
|
||||
)
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
h.HandleSourceDelete().ServeHTTP(w, req)
|
||||
|
||||
require.Equal(t, http.StatusSeeOther, w.Code)
|
||||
assert.Equal(
|
||||
t, []string{wh.ID}, ev.Evicted(),
|
||||
"deleting a webhook should evict its archive writer",
|
||||
)
|
||||
}
|
||||
|
||||
// TestHandleSourceDelete_KeepsArchiveFile proves that deleting
|
||||
// a webhook does not remove its archive database file: the
|
||||
// archive is long-term storage the operator owns.
|
||||
func TestHandleSourceDelete_KeepsArchiveFile(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
sess *session.Session
|
||||
db *database.Database
|
||||
mgr *database.WebhookDBManager
|
||||
)
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &mgr)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
wh := seedWebhook(t, db)
|
||||
|
||||
// Place an archive file where the delivery engine would.
|
||||
archivePath := archivePathFor(t, mgr, wh.ID)
|
||||
require.NoError(
|
||||
t,
|
||||
writeArchivePlaceholder(archivePath),
|
||||
)
|
||||
|
||||
cookies := authenticatedCookies(
|
||||
t, sess, deleteTestUserID, deleteTestUsername,
|
||||
)
|
||||
|
||||
req := postRequest(
|
||||
"/source/"+wh.ID+"/delete",
|
||||
cookies,
|
||||
map[string]string{paramSourceID: wh.ID},
|
||||
)
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
h.HandleSourceDelete().ServeHTTP(w, req)
|
||||
|
||||
require.Equal(t, http.StatusSeeOther, w.Code)
|
||||
assert.FileExists(
|
||||
t, archivePath,
|
||||
"webhook deletion must not destroy the archive file",
|
||||
)
|
||||
}
|
||||
|
||||
// TestHandleTargetDelete_EvictsWhenLastDatabaseTargetGone
|
||||
// proves that removing the last database target releases the
|
||||
// archive writer.
|
||||
func TestHandleTargetDelete_EvictsWhenLastDatabaseTargetGone(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
sess *session.Session
|
||||
db *database.Database
|
||||
ev *recordingEvictor
|
||||
)
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &ev)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
wh := seedWebhook(t, db)
|
||||
tgt := seedTarget(
|
||||
t, db, wh.ID, database.TargetTypeDatabase,
|
||||
)
|
||||
|
||||
cookies := authenticatedCookies(
|
||||
t, sess, deleteTestUserID, deleteTestUsername,
|
||||
)
|
||||
|
||||
req := postRequest(
|
||||
"/source/"+wh.ID+"/targets/"+tgt.ID+"/delete",
|
||||
cookies,
|
||||
map[string]string{
|
||||
paramSourceID: wh.ID,
|
||||
paramTargetID: tgt.ID,
|
||||
},
|
||||
)
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
h.HandleTargetDelete().ServeHTTP(w, req)
|
||||
|
||||
require.Equal(t, http.StatusSeeOther, w.Code)
|
||||
assert.Equal(
|
||||
t, []string{wh.ID}, ev.Evicted(),
|
||||
"removing the last database target should evict",
|
||||
)
|
||||
}
|
||||
|
||||
// TestHandleTargetDelete_KeepsWriterWhileDatabaseTargetRemains
|
||||
// proves that deleting an unrelated target, or one of several
|
||||
// database targets, leaves a still-needed archive writer alone.
|
||||
func TestHandleTargetDelete_KeepsWriterWhileDatabaseTargetRemains(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
sess *session.Session
|
||||
db *database.Database
|
||||
ev *recordingEvictor
|
||||
)
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &ev)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
wh := seedWebhook(t, db)
|
||||
seedTarget(t, db, wh.ID, database.TargetTypeDatabase)
|
||||
other := seedTarget(t, db, wh.ID, database.TargetTypeLog)
|
||||
|
||||
cookies := authenticatedCookies(
|
||||
t, sess, deleteTestUserID, deleteTestUsername,
|
||||
)
|
||||
|
||||
req := postRequest(
|
||||
"/source/"+wh.ID+"/targets/"+other.ID+"/delete",
|
||||
cookies,
|
||||
map[string]string{
|
||||
paramSourceID: wh.ID,
|
||||
paramTargetID: other.ID,
|
||||
},
|
||||
)
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
h.HandleTargetDelete().ServeHTTP(w, req)
|
||||
|
||||
require.Equal(t, http.StatusSeeOther, w.Code)
|
||||
assert.Empty(
|
||||
t, ev.Evicted(),
|
||||
"a surviving database target must keep its writer",
|
||||
)
|
||||
}
|
||||
@@ -533,13 +533,6 @@ func (h *Handlers) deleteWebhookResources(
|
||||
return
|
||||
}
|
||||
|
||||
// Release the delivery engine's per-webhook archiving state
|
||||
// so a deleted webhook's archive writer (and any handle open
|
||||
// within its debounce window) does not linger for the
|
||||
// process lifetime. The archive file itself is deliberately
|
||||
// left on disk; see evictArchiveWriter.
|
||||
h.evictArchiveWriter(webhook.ID)
|
||||
|
||||
err = h.dbMgr.DeleteDB(webhook.ID)
|
||||
if err != nil {
|
||||
h.log.Error(
|
||||
@@ -558,64 +551,6 @@ func (h *Handlers) deleteWebhookResources(
|
||||
http.Redirect(w, r, "/sources", http.StatusSeeOther)
|
||||
}
|
||||
|
||||
// evictArchiveWriter asks the delivery engine to drop its
|
||||
// cached archive writer for a webhook, closing the archive file
|
||||
// handle.
|
||||
//
|
||||
// The archive database file is NOT deleted. Unlike the event
|
||||
// database — which is per-webhook working storage and is
|
||||
// hard-deleted with the webhook — an archive is explicitly
|
||||
// long-term storage that an operator may want to keep or move
|
||||
// away for offline retention. Destroying it as a side effect of
|
||||
// deleting a webhook would be a surprising and unrecoverable
|
||||
// data loss, so the file is left for the operator to handle.
|
||||
func (h *Handlers) evictArchiveWriter(webhookID string) {
|
||||
if h.evictor == nil {
|
||||
return
|
||||
}
|
||||
|
||||
h.evictor.EvictWebhook(webhookID)
|
||||
}
|
||||
|
||||
// evictArchiveWriterIfUnused releases a webhook's archive
|
||||
// writer once the webhook has no database target left to feed
|
||||
// it.
|
||||
//
|
||||
// It is called after any child resource of a webhook is
|
||||
// deleted, and is correct without knowing which kind was: it
|
||||
// evicts only when no database target remains, so deleting one
|
||||
// of several database targets — or deleting an unrelated
|
||||
// target type — leaves a still-needed writer alone. When no
|
||||
// database target ever existed there is no writer and eviction
|
||||
// is a no-op. Soft-deleted targets are excluded by GORM's
|
||||
// default scope, so the row just deleted is not counted.
|
||||
func (h *Handlers) evictArchiveWriterIfUnused(webhookID string) {
|
||||
var remaining int64
|
||||
|
||||
err := h.db.DB().
|
||||
Model(&database.Target{}).
|
||||
Where(
|
||||
"webhook_id = ? AND type = ?",
|
||||
webhookID, database.TargetTypeDatabase,
|
||||
).
|
||||
Count(&remaining).Error
|
||||
if err != nil {
|
||||
h.log.Error(
|
||||
"failed to count remaining database targets",
|
||||
"webhook_id", webhookID,
|
||||
"error", err,
|
||||
)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
if remaining > 0 {
|
||||
return
|
||||
}
|
||||
|
||||
h.evictArchiveWriter(webhookID)
|
||||
}
|
||||
|
||||
// HandleSourceLogs shows the request/response logs for a
|
||||
// webhook.
|
||||
func (h *Handlers) HandleSourceLogs() http.HandlerFunc {
|
||||
@@ -1089,31 +1024,23 @@ func (h *Handlers) HandleEntrypointDelete() http.HandlerFunc {
|
||||
return h.deleteChildResource(
|
||||
"entrypointID", &database.Entrypoint{},
|
||||
"failed to delete entrypoint",
|
||||
nil,
|
||||
)
|
||||
}
|
||||
|
||||
// HandleTargetDelete handles deleting a target. Deleting the
|
||||
// last database target of a webhook leaves its archive writer
|
||||
// with nothing to write, so the writer is evicted and its
|
||||
// handle closed; the archive file is left on disk.
|
||||
// HandleTargetDelete handles deleting a target.
|
||||
func (h *Handlers) HandleTargetDelete() http.HandlerFunc {
|
||||
return h.deleteChildResource(
|
||||
"targetID", &database.Target{},
|
||||
"failed to delete target",
|
||||
h.evictArchiveWriterIfUnused,
|
||||
)
|
||||
}
|
||||
|
||||
// deleteChildResource returns a handler that deletes a child
|
||||
// resource (entrypoint or target) belonging to a webhook. The
|
||||
// optional afterDelete hook runs with the webhook's id once the
|
||||
// delete has succeeded, before the redirect.
|
||||
// resource (entrypoint or target) belonging to a webhook.
|
||||
func (h *Handlers) deleteChildResource(
|
||||
idParam string,
|
||||
model any,
|
||||
errMsg string,
|
||||
afterDelete func(webhookID string),
|
||||
) http.HandlerFunc {
|
||||
return func(w http.ResponseWriter, r *http.Request) {
|
||||
userID, ok := h.getUserID(r)
|
||||
@@ -1153,10 +1080,6 @@ func (h *Handlers) deleteChildResource(
|
||||
return
|
||||
}
|
||||
|
||||
if afterDelete != nil {
|
||||
afterDelete(webhook.ID)
|
||||
}
|
||||
|
||||
http.Redirect(
|
||||
w, r,
|
||||
"/source/"+webhook.ID,
|
||||
|
||||
@@ -186,6 +186,10 @@ func (s *Middleware) RequireAuth() func(http.Handler) http.Handler {
|
||||
return
|
||||
}
|
||||
|
||||
// IsAuthenticated also enforces both session expiry
|
||||
// deadlines, so an idle-expired or absolutely-expired
|
||||
// session lands here and is sent back to the login
|
||||
// page.
|
||||
if !s.session.IsAuthenticated(sess) {
|
||||
s.log.Debug(
|
||||
"auth middleware: unauthenticated request",
|
||||
@@ -199,6 +203,26 @@ func (s *Middleware) RequireAuth() func(http.Handler) http.Handler {
|
||||
return
|
||||
}
|
||||
|
||||
// This request authenticated with the session, so it
|
||||
// counts as activity: push the idle deadline forward.
|
||||
// This is the only place sessions are refreshed, which
|
||||
// is what keeps an unauthenticated request from
|
||||
// extending someone else's session. Touch advances the
|
||||
// idle clock only -- the absolute cap is untouched --
|
||||
// and reports false when nothing changed, so most
|
||||
// requests do not re-issue the cookie. Save before the
|
||||
// handler runs, while the headers are still ours to
|
||||
// write.
|
||||
if s.session.Touch(sess) {
|
||||
err = s.session.Save(r, w, sess)
|
||||
if err != nil {
|
||||
s.log.Error(
|
||||
"auth middleware: failed to refresh session",
|
||||
"error", err,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
next.ServeHTTP(w, r)
|
||||
})
|
||||
}
|
||||
|
||||
@@ -8,6 +8,7 @@ import (
|
||||
"net/http/httptest"
|
||||
"os"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/gorilla/sessions"
|
||||
"github.com/stretchr/testify/assert"
|
||||
@@ -28,13 +29,30 @@ func testMiddleware(
|
||||
) (*middleware.Middleware, *session.Session) {
|
||||
t.Helper()
|
||||
|
||||
m, s, _ := testMiddlewareWithSessionClock(t, env, 0, nil)
|
||||
|
||||
return m, s
|
||||
}
|
||||
|
||||
// testMiddlewareWithSessionClock is testMiddleware with a
|
||||
// configurable session idle timeout and a manually advanced clock,
|
||||
// for the session-expiry tests. A nil clock uses the real one.
|
||||
func testMiddlewareWithSessionClock(
|
||||
t *testing.T,
|
||||
env string,
|
||||
idleTimeout time.Duration,
|
||||
clock *fakeClock,
|
||||
) (*middleware.Middleware, *session.Session, *fakeClock) {
|
||||
t.Helper()
|
||||
|
||||
log := slog.New(slog.NewTextHandler(
|
||||
os.Stderr,
|
||||
&slog.HandlerOptions{Level: slog.LevelDebug},
|
||||
))
|
||||
|
||||
cfg := &config.Config{
|
||||
Environment: env,
|
||||
Environment: env,
|
||||
SessionIdleTimeout: idleTimeout,
|
||||
}
|
||||
|
||||
// Create a real session manager with a known key
|
||||
@@ -53,11 +71,40 @@ func testMiddleware(
|
||||
SameSite: http.SameSiteLaxMode,
|
||||
}
|
||||
|
||||
sessManager := session.NewForTest(store, cfg, log, key)
|
||||
var now func() time.Time
|
||||
|
||||
if clock != nil {
|
||||
now = clock.Now
|
||||
}
|
||||
|
||||
sessManager := session.NewForTest(store, cfg, log, key, now)
|
||||
|
||||
m := middleware.NewForTest(log, cfg, sessManager)
|
||||
|
||||
return m, sessManager
|
||||
return m, sessManager, clock
|
||||
}
|
||||
|
||||
// fakeClock is a manually advanced clock, so session expiry can be
|
||||
// tested without sleeping.
|
||||
type fakeClock struct {
|
||||
t time.Time
|
||||
}
|
||||
|
||||
func (c *fakeClock) Now() time.Time {
|
||||
return c.t
|
||||
}
|
||||
|
||||
func (c *fakeClock) Advance(d time.Duration) {
|
||||
c.t = c.t.Add(d)
|
||||
}
|
||||
|
||||
// newFakeClock returns a clock started at a fixed instant.
|
||||
func newFakeClock() *fakeClock {
|
||||
return &fakeClock{
|
||||
t: time.Date(
|
||||
2026, time.January, 2, 3, 4, 5, 0, time.UTC,
|
||||
),
|
||||
}
|
||||
}
|
||||
|
||||
// --- Logging Middleware Tests ---
|
||||
@@ -387,6 +434,181 @@ func TestRequireAuth_UnauthenticatedSession_RedirectsToLogin(
|
||||
assert.Equal(t, "/pages/login", w.Header().Get("Location"))
|
||||
}
|
||||
|
||||
// --- RequireAuth Session Expiry Tests ---
|
||||
|
||||
// loginCookies authenticates a new session and returns the cookies
|
||||
// a browser would then send back.
|
||||
func loginCookies(
|
||||
t *testing.T,
|
||||
sessManager *session.Session,
|
||||
) []*http.Cookie {
|
||||
t.Helper()
|
||||
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(), http.MethodGet, "/login", nil)
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
sess, err := sessManager.Get(req)
|
||||
require.NoError(t, err)
|
||||
sessManager.SetUser(sess, "user-123", "testuser")
|
||||
require.NoError(t, sessManager.Save(req, w, sess))
|
||||
|
||||
cookies := w.Result().Cookies()
|
||||
require.NotEmpty(t, cookies, "session cookie should be set")
|
||||
|
||||
return cookies
|
||||
}
|
||||
|
||||
// runAuthed sends a request carrying cookies through RequireAuth
|
||||
// and reports whether the protected handler ran, plus the response.
|
||||
func runAuthed(
|
||||
t *testing.T,
|
||||
m *middleware.Middleware,
|
||||
cookies []*http.Cookie,
|
||||
) (bool, *httptest.ResponseRecorder) {
|
||||
t.Helper()
|
||||
|
||||
var called bool
|
||||
|
||||
handler := m.RequireAuth()(http.HandlerFunc(
|
||||
func(_ http.ResponseWriter, _ *http.Request) {
|
||||
called = true
|
||||
},
|
||||
))
|
||||
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(),
|
||||
http.MethodGet, "/dashboard", nil,
|
||||
)
|
||||
|
||||
for _, c := range cookies {
|
||||
req.AddCookie(c)
|
||||
}
|
||||
|
||||
w := httptest.NewRecorder()
|
||||
handler.ServeHTTP(w, req)
|
||||
|
||||
return called, w
|
||||
}
|
||||
|
||||
// sessionCookies filters a response's cookies down to the session
|
||||
// cookie, so tests can tell whether the session was re-issued.
|
||||
func sessionCookies(
|
||||
w *httptest.ResponseRecorder,
|
||||
) []*http.Cookie {
|
||||
var out []*http.Cookie
|
||||
|
||||
for _, c := range w.Result().Cookies() {
|
||||
if c.Name == session.SessionName {
|
||||
out = append(out, c)
|
||||
}
|
||||
}
|
||||
|
||||
return out
|
||||
}
|
||||
|
||||
func TestRequireAuth_IdleExpiredSession_RedirectsToLogin(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
idle := time.Hour
|
||||
|
||||
m, sessManager, clock := testMiddlewareWithSessionClock(
|
||||
t, config.EnvironmentDev, idle, newFakeClock(),
|
||||
)
|
||||
|
||||
cookies := loginCookies(t, sessManager)
|
||||
|
||||
clock.Advance(idle)
|
||||
|
||||
called, w := runAuthed(t, m, cookies)
|
||||
|
||||
assert.False(
|
||||
t, called,
|
||||
"handler should not run for an idle-expired session",
|
||||
)
|
||||
assert.Equal(t, http.StatusSeeOther, w.Code)
|
||||
assert.Equal(t, "/pages/login", w.Header().Get("Location"))
|
||||
assert.Empty(
|
||||
t, sessionCookies(w),
|
||||
"an expired session must not be refreshed",
|
||||
)
|
||||
}
|
||||
|
||||
func TestRequireAuth_RefreshesIdleDeadlineOnActivity(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
idle := time.Hour
|
||||
|
||||
m, sessManager, clock := testMiddlewareWithSessionClock(
|
||||
t, config.EnvironmentDev, idle, newFakeClock(),
|
||||
)
|
||||
|
||||
cookies := loginCookies(t, sessManager)
|
||||
|
||||
// Activity halfway through the idle window.
|
||||
clock.Advance(idle / 2)
|
||||
|
||||
called, w := runAuthed(t, m, cookies)
|
||||
require.True(t, called, "handler should run while valid")
|
||||
|
||||
refreshed := sessionCookies(w)
|
||||
require.NotEmpty(
|
||||
t, refreshed,
|
||||
"activity should re-issue the session cookie",
|
||||
)
|
||||
|
||||
// Past the original deadline. The refreshed cookie is still
|
||||
// good; the original one is not.
|
||||
clock.Advance(idle - time.Second)
|
||||
|
||||
calledRefreshed, _ := runAuthed(t, m, refreshed)
|
||||
assert.True(
|
||||
t, calledRefreshed,
|
||||
"refreshed session should outlive the original deadline",
|
||||
)
|
||||
|
||||
calledStale, staleW := runAuthed(t, m, cookies)
|
||||
assert.False(
|
||||
t, calledStale,
|
||||
"the pre-refresh cookie carries the old idle deadline",
|
||||
)
|
||||
assert.Equal(t, http.StatusSeeOther, staleW.Code)
|
||||
}
|
||||
|
||||
func TestRequireAuth_UnauthenticatedRequestDoesNotRefresh(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
m, sessManager, _ := testMiddlewareWithSessionClock(
|
||||
t, config.EnvironmentDev, time.Hour, newFakeClock(),
|
||||
)
|
||||
|
||||
// A session cookie that exists but was never authenticated.
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(), http.MethodGet, "/setup", nil)
|
||||
setupW := httptest.NewRecorder()
|
||||
|
||||
sess, err := sessManager.Get(req)
|
||||
require.NoError(t, err)
|
||||
require.NoError(t, sessManager.Save(req, setupW, sess))
|
||||
|
||||
cookies := setupW.Result().Cookies()
|
||||
require.NotEmpty(t, cookies)
|
||||
|
||||
called, w := runAuthed(t, m, cookies)
|
||||
|
||||
assert.False(t, called)
|
||||
assert.Empty(
|
||||
t, sessionCookies(w),
|
||||
"an unauthenticated request must not stamp the session",
|
||||
)
|
||||
}
|
||||
|
||||
// --- NoCache Middleware Tests ---
|
||||
|
||||
func TestNoCache_SetsHeaders(t *testing.T) {
|
||||
@@ -479,7 +701,7 @@ func metricsAuthMiddleware(
|
||||
store := sessions.NewCookieStore(key)
|
||||
store.Options = &sessions.Options{Path: "/", MaxAge: 86400}
|
||||
|
||||
sessManager := session.NewForTest(store, cfg, log, key)
|
||||
sessManager := session.NewForTest(store, cfg, log, key, nil)
|
||||
|
||||
return middleware.NewForTest(log, cfg, sessManager)
|
||||
}
|
||||
|
||||
@@ -10,6 +10,7 @@ import (
|
||||
"log/slog"
|
||||
"maps"
|
||||
"net/http"
|
||||
"time"
|
||||
|
||||
"github.com/gorilla/sessions"
|
||||
"go.uber.org/fx"
|
||||
@@ -32,6 +33,18 @@ const (
|
||||
// status.
|
||||
AuthenticatedKey = "authenticated"
|
||||
|
||||
// CreatedAtKey is the session key holding the Unix timestamp at
|
||||
// which the session was authenticated. It anchors the ABSOLUTE
|
||||
// expiry clock and is written exactly once, by SetUser. Nothing
|
||||
// refreshes it: an absolute deadline that moved with activity
|
||||
// would not be a cap at all.
|
||||
CreatedAtKey = "created_at"
|
||||
|
||||
// LastSeenKey is the session key holding the Unix timestamp of
|
||||
// the most recent authenticated request. It anchors the IDLE
|
||||
// expiry clock and is pushed forward by Touch.
|
||||
LastSeenKey = "last_seen"
|
||||
|
||||
// sessionKeyLength is the required length in bytes for the
|
||||
// session authentication key.
|
||||
sessionKeyLength = 32
|
||||
@@ -41,6 +54,19 @@ const (
|
||||
|
||||
// secondsPerDay is the number of seconds in a day.
|
||||
secondsPerDay = 86400
|
||||
|
||||
// sessionAbsoluteMaxAge is the hard upper bound on how long a
|
||||
// session may live, measured from CreatedAtKey. Activity never
|
||||
// extends it, so even a continuously used session ends here and
|
||||
// the user has to authenticate again.
|
||||
sessionAbsoluteMaxAge = sessionMaxAgeDays * secondsPerDay * time.Second
|
||||
|
||||
// idleRefreshDivisor rate-limits idle-deadline refreshes. Touch
|
||||
// only rewrites LastSeenKey once the stored value is older than
|
||||
// idleTimeout/idleRefreshDivisor, so an active session is
|
||||
// re-saved at most this many times per idle window instead of
|
||||
// once per request. See Touch for the tradeoff this buys.
|
||||
idleRefreshDivisor = 10
|
||||
)
|
||||
|
||||
// ErrSessionKeyLength is returned when the decoded session key
|
||||
@@ -62,6 +88,16 @@ type Session struct {
|
||||
key []byte // raw 32-byte auth key, also used for CSRF cookie signing
|
||||
log *slog.Logger
|
||||
config *config.Config
|
||||
|
||||
// idleTimeout is the sliding inactivity window. A session that
|
||||
// sees no authenticated request within this window expires,
|
||||
// independently of the absolute cap. Non-positive disables idle
|
||||
// expiry and leaves sessionAbsoluteMaxAge as the only bound.
|
||||
idleTimeout time.Duration
|
||||
|
||||
// now reads the current time. Injected so expiry can be tested
|
||||
// without sleeping.
|
||||
now func() time.Time
|
||||
}
|
||||
|
||||
// New creates a new session manager. The cookie store is
|
||||
@@ -73,8 +109,10 @@ func New(
|
||||
params Params,
|
||||
) (*Session, error) {
|
||||
s := &Session{
|
||||
log: params.Logger.Get(),
|
||||
config: params.Config,
|
||||
log: params.Logger.Get(),
|
||||
config: params.Config,
|
||||
idleTimeout: params.Config.SessionIdleTimeout,
|
||||
now: time.Now,
|
||||
}
|
||||
|
||||
lc.Append(fx.Hook{
|
||||
@@ -149,29 +187,98 @@ func (s *Session) Save(
|
||||
return sess.Save(r, w)
|
||||
}
|
||||
|
||||
// SetUser sets the user information in the session.
|
||||
// SetUser sets the user information in the session. It starts both
|
||||
// expiry clocks: CreatedAtKey (absolute, never refreshed again) and
|
||||
// LastSeenKey (idle, refreshed by Touch).
|
||||
func (s *Session) SetUser(
|
||||
sess *sessions.Session,
|
||||
userID, username string,
|
||||
) {
|
||||
now := s.now().Unix()
|
||||
|
||||
sess.Values[UserIDKey] = userID
|
||||
sess.Values[UsernameKey] = username
|
||||
sess.Values[AuthenticatedKey] = true
|
||||
sess.Values[CreatedAtKey] = now
|
||||
sess.Values[LastSeenKey] = now
|
||||
}
|
||||
|
||||
// ClearUser removes user information from the session.
|
||||
// ClearUser removes user information from the session, including
|
||||
// both expiry timestamps.
|
||||
func (s *Session) ClearUser(sess *sessions.Session) {
|
||||
delete(sess.Values, UserIDKey)
|
||||
delete(sess.Values, UsernameKey)
|
||||
delete(sess.Values, AuthenticatedKey)
|
||||
delete(sess.Values, CreatedAtKey)
|
||||
delete(sess.Values, LastSeenKey)
|
||||
}
|
||||
|
||||
// IsAuthenticated checks if the session has an authenticated
|
||||
// user.
|
||||
// sessionTime reads a Unix-second timestamp stored under key.
|
||||
func sessionTime(
|
||||
sess *sessions.Session,
|
||||
key string,
|
||||
) (time.Time, bool) {
|
||||
secs, ok := sess.Values[key].(int64)
|
||||
if !ok {
|
||||
return time.Time{}, false
|
||||
}
|
||||
|
||||
return time.Unix(secs, 0), true
|
||||
}
|
||||
|
||||
// IsAuthenticated checks if the session has an authenticated user
|
||||
// whose session has not passed either expiry deadline. Every
|
||||
// authentication decision goes through here, so neither clock can
|
||||
// be bypassed by a caller that forgets to check it.
|
||||
func (s *Session) IsAuthenticated(sess *sessions.Session) bool {
|
||||
auth, ok := sess.Values[AuthenticatedKey].(bool)
|
||||
if !ok || !auth {
|
||||
return false
|
||||
}
|
||||
|
||||
return ok && auth
|
||||
return !s.expired(sess)
|
||||
}
|
||||
|
||||
// Touch records authenticated activity by pushing the IDLE deadline
|
||||
// forward. It writes LastSeenKey only; CreatedAtKey is left alone so
|
||||
// the absolute cap keeps counting down even for a user who never
|
||||
// stops clicking.
|
||||
//
|
||||
// Callers must only invoke Touch for a request that authenticated
|
||||
// with this session. Refreshing on an unauthenticated request would
|
||||
// let anyone holding a stolen or abandoned cookie keep the session
|
||||
// alive by polling a public endpoint. Touch enforces that itself by
|
||||
// returning false for any session that is not currently
|
||||
// authenticated and unexpired.
|
||||
//
|
||||
// To avoid re-encrypting and re-emitting the session cookie on every
|
||||
// single request, the timestamp is advanced only once it is older
|
||||
// than idleTimeout/idleRefreshDivisor. The tradeoff is that
|
||||
// LastSeenKey lags real activity by up to that much, so a session
|
||||
// can expire slightly early relative to the user's true last
|
||||
// request -- never late.
|
||||
//
|
||||
// Touch reports whether it changed the session; only then does the
|
||||
// caller need to save it.
|
||||
func (s *Session) Touch(sess *sessions.Session) bool {
|
||||
if s.idleTimeout <= 0 {
|
||||
return false
|
||||
}
|
||||
|
||||
if !s.IsAuthenticated(sess) {
|
||||
return false
|
||||
}
|
||||
|
||||
now := s.now()
|
||||
|
||||
lastSeen, ok := sessionTime(sess, LastSeenKey)
|
||||
if ok && now.Sub(lastSeen) < s.idleTimeout/idleRefreshDivisor {
|
||||
return false
|
||||
}
|
||||
|
||||
sess.Values[LastSeenKey] = now.Unix()
|
||||
|
||||
return true
|
||||
}
|
||||
|
||||
// GetUserID retrieves the user ID from the session.
|
||||
@@ -253,3 +360,41 @@ func (s *Session) Regenerate(
|
||||
|
||||
return newSess, nil
|
||||
}
|
||||
|
||||
// expired reports whether the session has passed either of its two
|
||||
// independent deadlines. They are deliberately kept apart:
|
||||
//
|
||||
// - the ABSOLUTE deadline is CreatedAtKey + sessionAbsoluteMaxAge.
|
||||
// It is fixed at login and no amount of activity moves it.
|
||||
// - the IDLE deadline is LastSeenKey + idleTimeout. Activity moves
|
||||
// it forward via Touch.
|
||||
//
|
||||
// Whichever comes first ends the session.
|
||||
//
|
||||
// A session that claims to be authenticated but carries no
|
||||
// timestamps predates this check; it is treated as expired so the
|
||||
// user re-authenticates rather than being granted an unbounded
|
||||
// session.
|
||||
func (s *Session) expired(sess *sessions.Session) bool {
|
||||
now := s.now()
|
||||
|
||||
createdAt, ok := sessionTime(sess, CreatedAtKey)
|
||||
if !ok {
|
||||
return true
|
||||
}
|
||||
|
||||
if !now.Before(createdAt.Add(sessionAbsoluteMaxAge)) {
|
||||
return true
|
||||
}
|
||||
|
||||
if s.idleTimeout <= 0 {
|
||||
return false
|
||||
}
|
||||
|
||||
lastSeen, ok := sessionTime(sess, LastSeenKey)
|
||||
if !ok {
|
||||
return true
|
||||
}
|
||||
|
||||
return !now.Before(lastSeen.Add(s.idleTimeout))
|
||||
}
|
||||
|
||||
@@ -7,6 +7,7 @@ import (
|
||||
"net/http/httptest"
|
||||
"os"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/gorilla/sessions"
|
||||
"github.com/stretchr/testify/assert"
|
||||
@@ -17,11 +18,47 @@ import (
|
||||
|
||||
const testKeySize = 32
|
||||
|
||||
// testSession creates a Session with a real cookie store for
|
||||
// testing.
|
||||
// testIdleTimeout is the idle window used by the expiry tests.
|
||||
const testIdleTimeout = time.Hour
|
||||
|
||||
// testAbsoluteMaxAge restates the documented absolute session cap
|
||||
// independently of the implementation constant.
|
||||
const testAbsoluteMaxAge = 7 * 24 * time.Hour
|
||||
|
||||
// fakeClock is a manually advanced clock, so expiry can be tested
|
||||
// without sleeping.
|
||||
type fakeClock struct {
|
||||
t time.Time
|
||||
}
|
||||
|
||||
func (c *fakeClock) Now() time.Time {
|
||||
return c.t
|
||||
}
|
||||
|
||||
func (c *fakeClock) Advance(d time.Duration) {
|
||||
c.t = c.t.Add(d)
|
||||
}
|
||||
|
||||
// testSession creates a Session with a real cookie store and the
|
||||
// real clock.
|
||||
func testSession(t *testing.T) *session.Session {
|
||||
t.Helper()
|
||||
|
||||
s, _ := testSessionWithClock(t, testIdleTimeout, nil)
|
||||
|
||||
return s
|
||||
}
|
||||
|
||||
// testSessionWithClock creates a Session with a real cookie store,
|
||||
// the given idle timeout, and a manually advanced clock. Passing a
|
||||
// nil clock uses the real one.
|
||||
func testSessionWithClock(
|
||||
t *testing.T,
|
||||
idleTimeout time.Duration,
|
||||
clock *fakeClock,
|
||||
) (*session.Session, *fakeClock) {
|
||||
t.Helper()
|
||||
|
||||
key := make([]byte, testKeySize)
|
||||
|
||||
for i := range key {
|
||||
@@ -38,7 +75,8 @@ func testSession(t *testing.T) *session.Session {
|
||||
}
|
||||
|
||||
cfg := &config.Config{
|
||||
Environment: config.EnvironmentDev,
|
||||
Environment: config.EnvironmentDev,
|
||||
SessionIdleTimeout: idleTimeout,
|
||||
}
|
||||
|
||||
log := slog.New(slog.NewTextHandler(
|
||||
@@ -46,7 +84,46 @@ func testSession(t *testing.T) *session.Session {
|
||||
&slog.HandlerOptions{Level: slog.LevelDebug},
|
||||
))
|
||||
|
||||
return session.NewForTest(store, cfg, log, key)
|
||||
var now func() time.Time
|
||||
|
||||
if clock != nil {
|
||||
now = clock.Now
|
||||
}
|
||||
|
||||
return session.NewForTest(store, cfg, log, key, now), clock
|
||||
}
|
||||
|
||||
// newFakeClock returns a clock started at a fixed instant.
|
||||
func newFakeClock() *fakeClock {
|
||||
return &fakeClock{
|
||||
t: time.Date(
|
||||
2026, time.January, 2, 3, 4, 5, 0, time.UTC,
|
||||
),
|
||||
}
|
||||
}
|
||||
|
||||
// authenticatedSession returns a fresh session that has just been
|
||||
// logged in, along with its manager and clock.
|
||||
func authenticatedSession(
|
||||
t *testing.T,
|
||||
idleTimeout time.Duration,
|
||||
) (*session.Session, *sessions.Session, *fakeClock) {
|
||||
t.Helper()
|
||||
|
||||
s, clock := testSessionWithClock(
|
||||
t, idleTimeout, newFakeClock(),
|
||||
)
|
||||
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(), http.MethodGet, "/", nil)
|
||||
|
||||
sess, err := s.Get(req)
|
||||
require.NoError(t, err)
|
||||
|
||||
s.SetUser(sess, "user-123", "alice")
|
||||
require.True(t, s.IsAuthenticated(sess))
|
||||
|
||||
return s, sess, clock
|
||||
}
|
||||
|
||||
// --- Get and Save Tests ---
|
||||
@@ -430,6 +507,263 @@ func TestSessionConstants(t *testing.T) {
|
||||
assert.Equal(t, "user_id", session.UserIDKey)
|
||||
assert.Equal(t, "username", session.UsernameKey)
|
||||
assert.Equal(t, "authenticated", session.AuthenticatedKey)
|
||||
assert.Equal(t, "created_at", session.CreatedAtKey)
|
||||
assert.Equal(t, "last_seen", session.LastSeenKey)
|
||||
}
|
||||
|
||||
// --- Expiry Tests ---
|
||||
|
||||
func TestSetUser_StartsBothClocks(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
_, sess, clock := authenticatedSession(t, testIdleTimeout)
|
||||
|
||||
assert.Equal(
|
||||
t, clock.Now().Unix(), sess.Values[session.CreatedAtKey],
|
||||
"SetUser should anchor the absolute clock",
|
||||
)
|
||||
assert.Equal(
|
||||
t, clock.Now().Unix(), sess.Values[session.LastSeenKey],
|
||||
"SetUser should anchor the idle clock",
|
||||
)
|
||||
}
|
||||
|
||||
func TestIsAuthenticated_WithinIdleWindow(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
s, sess, clock := authenticatedSession(t, testIdleTimeout)
|
||||
|
||||
clock.Advance(testIdleTimeout - time.Second)
|
||||
|
||||
assert.True(
|
||||
t, s.IsAuthenticated(sess),
|
||||
"session should still be valid just inside the idle window",
|
||||
)
|
||||
}
|
||||
|
||||
func TestIsAuthenticated_IdleExpired(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
s, sess, clock := authenticatedSession(t, testIdleTimeout)
|
||||
|
||||
clock.Advance(testIdleTimeout)
|
||||
|
||||
assert.False(
|
||||
t, s.IsAuthenticated(sess),
|
||||
"session should expire once the idle window lapses",
|
||||
)
|
||||
}
|
||||
|
||||
// TestTouch_DoesNotExtendAbsoluteCap is the regression test for the
|
||||
// refresh-the-wrong-clock bug: a session that is used continuously
|
||||
// must survive well past the idle window and still die at the
|
||||
// absolute cap.
|
||||
func TestTouch_DoesNotExtendAbsoluteCap(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
s, sess, clock := authenticatedSession(t, testIdleTimeout)
|
||||
|
||||
createdAt := sess.Values[session.CreatedAtKey]
|
||||
|
||||
// Stay active: a request every half idle window, right up to
|
||||
// the absolute cap.
|
||||
step := testIdleTimeout / 2
|
||||
steps := int(testAbsoluteMaxAge/step) - 1
|
||||
|
||||
for i := range steps {
|
||||
clock.Advance(step)
|
||||
s.Touch(sess)
|
||||
|
||||
require.True(
|
||||
t, s.IsAuthenticated(sess),
|
||||
"active session should survive the idle window "+
|
||||
"(step %d of %d)", i+1, steps,
|
||||
)
|
||||
}
|
||||
|
||||
// One more step of activity takes the session to exactly the
|
||||
// absolute cap, measured from login. Nothing that happened in
|
||||
// the loop may have moved that deadline.
|
||||
clock.Advance(step)
|
||||
s.Touch(sess)
|
||||
|
||||
assert.False(
|
||||
t, s.IsAuthenticated(sess),
|
||||
"activity must not extend the absolute cap",
|
||||
)
|
||||
assert.Equal(
|
||||
t, createdAt, sess.Values[session.CreatedAtKey],
|
||||
"Touch must never rewrite the absolute-clock anchor",
|
||||
)
|
||||
}
|
||||
|
||||
func TestTouch_RefreshesIdleDeadline(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
s, sess, clock := authenticatedSession(t, testIdleTimeout)
|
||||
|
||||
// Halfway through the window, activity happens.
|
||||
clock.Advance(testIdleTimeout / 2)
|
||||
assert.True(
|
||||
t, s.Touch(sess),
|
||||
"Touch should refresh once past the lazy-refresh threshold",
|
||||
)
|
||||
|
||||
// Past the original deadline, but inside the refreshed one.
|
||||
clock.Advance(testIdleTimeout - time.Second)
|
||||
assert.True(
|
||||
t, s.IsAuthenticated(sess),
|
||||
"refreshed session should outlive the original deadline",
|
||||
)
|
||||
|
||||
// And it still expires an idle window after that activity.
|
||||
clock.Advance(time.Second)
|
||||
assert.False(
|
||||
t, s.IsAuthenticated(sess),
|
||||
"refreshed session should expire one window after activity",
|
||||
)
|
||||
}
|
||||
|
||||
func TestTouch_LazyBelowRefreshThreshold(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
s, sess, clock := authenticatedSession(t, testIdleTimeout)
|
||||
|
||||
before := sess.Values[session.LastSeenKey]
|
||||
|
||||
// A request arriving almost immediately is not worth a cookie
|
||||
// rewrite.
|
||||
clock.Advance(time.Second)
|
||||
|
||||
assert.False(
|
||||
t, s.Touch(sess),
|
||||
"Touch should not rewrite the session below the threshold",
|
||||
)
|
||||
assert.Equal(
|
||||
t, before, sess.Values[session.LastSeenKey],
|
||||
"last-seen should be unchanged below the threshold",
|
||||
)
|
||||
}
|
||||
|
||||
func TestTouch_UnauthenticatedSessionIsNotRefreshed(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
s, clock := testSessionWithClock(
|
||||
t, testIdleTimeout, newFakeClock(),
|
||||
)
|
||||
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(), http.MethodGet, "/", nil)
|
||||
|
||||
sess, err := s.Get(req)
|
||||
require.NoError(t, err)
|
||||
|
||||
clock.Advance(testIdleTimeout / 2)
|
||||
|
||||
assert.False(
|
||||
t, s.Touch(sess),
|
||||
"an unauthenticated session must not be refreshed",
|
||||
)
|
||||
|
||||
_, hasLastSeen := sess.Values[session.LastSeenKey]
|
||||
assert.False(
|
||||
t, hasLastSeen,
|
||||
"Touch must not stamp an unauthenticated session",
|
||||
)
|
||||
}
|
||||
|
||||
func TestTouch_IdleExpiredSessionIsNotRevived(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
s, sess, clock := authenticatedSession(t, testIdleTimeout)
|
||||
|
||||
clock.Advance(testIdleTimeout)
|
||||
require.False(t, s.IsAuthenticated(sess))
|
||||
|
||||
assert.False(
|
||||
t, s.Touch(sess),
|
||||
"an already expired session must not be refreshed",
|
||||
)
|
||||
assert.False(
|
||||
t, s.IsAuthenticated(sess),
|
||||
"Touch must not revive an expired session",
|
||||
)
|
||||
}
|
||||
|
||||
func TestIsAuthenticated_MissingTimestamps(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
s, _ := testSessionWithClock(
|
||||
t, testIdleTimeout, newFakeClock(),
|
||||
)
|
||||
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(), http.MethodGet, "/", nil)
|
||||
|
||||
sess, err := s.Get(req)
|
||||
require.NoError(t, err)
|
||||
|
||||
// A session from before idle expiry existed: authenticated,
|
||||
// but with no timestamps. Fail closed.
|
||||
sess.Values[session.AuthenticatedKey] = true
|
||||
|
||||
assert.False(
|
||||
t, s.IsAuthenticated(sess),
|
||||
"a session with no timestamps should be rejected",
|
||||
)
|
||||
}
|
||||
|
||||
func TestIsAuthenticated_MissingLastSeen(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
s, sess, _ := authenticatedSession(t, testIdleTimeout)
|
||||
|
||||
delete(sess.Values, session.LastSeenKey)
|
||||
|
||||
assert.False(
|
||||
t, s.IsAuthenticated(sess),
|
||||
"a session with no idle anchor should be rejected",
|
||||
)
|
||||
}
|
||||
|
||||
func TestIdleTimeoutDisabled_AbsoluteCapStillApplies(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
s, sess, clock := authenticatedSession(t, 0)
|
||||
|
||||
// Idle expiry is off, so an untouched session survives an
|
||||
// arbitrary idle stretch.
|
||||
clock.Advance(testAbsoluteMaxAge - time.Second)
|
||||
assert.True(
|
||||
t, s.IsAuthenticated(sess),
|
||||
"idle expiry should be disabled by a non-positive timeout",
|
||||
)
|
||||
|
||||
assert.False(
|
||||
t, s.Touch(sess),
|
||||
"Touch should be a no-op when idle expiry is disabled",
|
||||
)
|
||||
|
||||
// The absolute cap still ends it.
|
||||
clock.Advance(time.Second)
|
||||
assert.False(
|
||||
t, s.IsAuthenticated(sess),
|
||||
"the absolute cap must still apply with idle expiry off",
|
||||
)
|
||||
}
|
||||
|
||||
func TestClearUser_RemovesTimestamps(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
s, sess, _ := authenticatedSession(t, testIdleTimeout)
|
||||
|
||||
s.ClearUser(sess)
|
||||
|
||||
_, hasCreatedAt := sess.Values[session.CreatedAtKey]
|
||||
assert.False(t, hasCreatedAt, "CreatedAtKey should be removed")
|
||||
|
||||
_, hasLastSeen := sess.Values[session.LastSeenKey]
|
||||
assert.False(t, hasLastSeen, "LastSeenKey should be removed")
|
||||
}
|
||||
|
||||
// --- Edge Cases ---
|
||||
|
||||
@@ -2,6 +2,7 @@ package session
|
||||
|
||||
import (
|
||||
"log/slog"
|
||||
"time"
|
||||
|
||||
"github.com/gorilla/sessions"
|
||||
"sneak.berlin/go/webhooker/internal/config"
|
||||
@@ -12,16 +13,28 @@ import (
|
||||
// middleware and handler tests to use real session functionality. The key
|
||||
// parameter is the raw 32-byte authentication key used for session encryption
|
||||
// and CSRF cookie signing.
|
||||
//
|
||||
// The idle timeout is taken from cfg.SessionIdleTimeout, exactly as in
|
||||
// production. The now parameter supplies the clock used for expiry
|
||||
// checks so tests can advance time without sleeping; pass nil for the
|
||||
// real clock.
|
||||
func NewForTest(
|
||||
store *sessions.CookieStore,
|
||||
cfg *config.Config,
|
||||
log *slog.Logger,
|
||||
key []byte,
|
||||
now func() time.Time,
|
||||
) *Session {
|
||||
if now == nil {
|
||||
now = time.Now
|
||||
}
|
||||
|
||||
return &Session{
|
||||
store: store,
|
||||
key: key,
|
||||
config: cfg,
|
||||
log: log,
|
||||
store: store,
|
||||
key: key,
|
||||
config: cfg,
|
||||
log: log,
|
||||
idleTimeout: cfg.SessionIdleTimeout,
|
||||
now: now,
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user