Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f71d3a01a9 |
@@ -2840,8 +2840,9 @@ read as more than it is:
|
|||||||
|
|
||||||
- **Lines carrying an authenticated operator's own input**, which are
|
- **Lines carrying an authenticated operator's own input**, which are
|
||||||
not truncated at all. `webhook created` logs the submitted `name`
|
not truncated at all. `webhook created` logs the submitted `name`
|
||||||
verbatim and `target URL blocked by SSRF protection` logs the target
|
verbatim (`internal/handlers/webhook_create.go`) and
|
||||||
host (both `internal/handlers/source_management.go`), as do the
|
`target URL blocked by SSRF protection` logs the target host
|
||||||
|
(`internal/handlers/target_create.go`), as do the
|
||||||
`target_name` lines in `internal/delivery/engine.go` and
|
`target_name` lines in `internal/delivery/engine.go` and
|
||||||
`internal/delivery/target_http.go`. The only bound on any of them is
|
`internal/delivery/target_http.go`. The only bound on any of them is
|
||||||
the 1 MB form body cap, so a 100 KB `name` writes a single line of
|
the 1 MB form body cap, so a 100 KB `name` writes a single line of
|
||||||
@@ -3220,7 +3221,17 @@ webhooker/
|
|||||||
│ │ ├── index.go # Index page handler
|
│ │ ├── index.go # Index page handler
|
||||||
│ │ ├── profile.go # User profile handler
|
│ │ ├── profile.go # User profile handler
|
||||||
│ │ ├── settings.go # Read-only Settings page handler
|
│ │ ├── settings.go # Read-only Settings page handler
|
||||||
│ │ ├── source_management.go # Webhook CRUD handlers
|
│ │ ├── webhook_list.go # Webhook list page
|
||||||
|
│ │ ├── webhook_create.go # Webhook create
|
||||||
|
│ │ ├── webhook_detail.go # Webhook detail page
|
||||||
|
│ │ ├── webhook_edit.go # Webhook edit, archive renaming
|
||||||
|
│ │ ├── webhook_delete.go # Webhook delete, event database and archive writer removal
|
||||||
|
│ │ ├── event_log.go # Event log page: loaders, filters, delivery views
|
||||||
|
│ │ ├── entrypoint.go # Entrypoint create, edit, delete and toggle
|
||||||
|
│ │ ├── target_create.go # Target create, per-type config builders
|
||||||
|
│ │ ├── target_delete.go # Target delete
|
||||||
|
│ │ ├── target_toggle.go # Target toggle
|
||||||
|
│ │ ├── shared.go # Helpers shared by several handlers
|
||||||
│ │ └── webhook.go # Webhook receiver handler
|
│ │ └── webhook.go # Webhook receiver handler
|
||||||
│ ├── healthcheck/
|
│ ├── healthcheck/
|
||||||
│ │ └── healthcheck.go # Health check service (uptime, version)
|
│ │ └── healthcheck.go # Health check service (uptime, version)
|
||||||
|
|||||||
@@ -29,31 +29,3 @@ func (h *Handlers) evictTargetArchiveWriter(targetID string) {
|
|||||||
|
|
||||||
h.archives.EvictTarget(targetID)
|
h.archives.EvictTarget(targetID)
|
||||||
}
|
}
|
||||||
|
|
||||||
// HandleTargetToggle handles toggling a target's active state.
|
|
||||||
func (h *Handlers) HandleTargetToggle() http.HandlerFunc {
|
|
||||||
return h.toggleChildResource(
|
|
||||||
"targetID",
|
|
||||||
func(webhookID, childID string) (bool, error) {
|
|
||||||
var tgt database.Target
|
|
||||||
|
|
||||||
err := h.db.DB().Where(
|
|
||||||
"id = ? AND webhook_id = ?",
|
|
||||||
childID, webhookID,
|
|
||||||
).First(&tgt).Error
|
|
||||||
if err != nil {
|
|
||||||
return false, err
|
|
||||||
}
|
|
||||||
|
|
||||||
// Only the active column: saving the whole row would
|
|
||||||
// write back the name and settings read above over an
|
|
||||||
// edit saved since.
|
|
||||||
active := !tgt.Active
|
|
||||||
|
|
||||||
return active, h.db.DB().Model(&tgt).
|
|
||||||
Update("active", active).Error
|
|
||||||
},
|
|
||||||
"failed to toggle target",
|
|
||||||
targetActivated, targetDeactivated,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,35 @@
|
|||||||
|
package handlers
|
||||||
|
|
||||||
|
import (
|
||||||
|
"net/http"
|
||||||
|
|
||||||
|
"sneak.berlin/go/webhooker/internal/database"
|
||||||
|
)
|
||||||
|
|
||||||
|
// HandleTargetToggle handles toggling a target's active state.
|
||||||
|
func (h *Handlers) HandleTargetToggle() http.HandlerFunc {
|
||||||
|
return h.toggleChildResource(
|
||||||
|
"targetID",
|
||||||
|
func(webhookID, childID string) (bool, error) {
|
||||||
|
var tgt database.Target
|
||||||
|
|
||||||
|
err := h.db.DB().Where(
|
||||||
|
"id = ? AND webhook_id = ?",
|
||||||
|
childID, webhookID,
|
||||||
|
).First(&tgt).Error
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
|
||||||
|
// Only the active column: saving the whole row would
|
||||||
|
// write back the name and settings read above over an
|
||||||
|
// edit saved since.
|
||||||
|
active := !tgt.Active
|
||||||
|
|
||||||
|
return active, h.db.DB().Model(&tgt).
|
||||||
|
Update("active", active).Error
|
||||||
|
},
|
||||||
|
"failed to toggle target",
|
||||||
|
targetActivated, targetDeactivated,
|
||||||
|
)
|
||||||
|
}
|
||||||
@@ -131,8 +131,9 @@ const (
|
|||||||
//
|
//
|
||||||
// - Lines carrying an AUTHENTICATED operator's own input, which
|
// - Lines carrying an AUTHENTICATED operator's own input, which
|
||||||
// are not truncated at all: the webhook name on "webhook
|
// are not truncated at all: the webhook name on "webhook
|
||||||
// created" and the target host on "target URL blocked by SSRF
|
// created" (internal/handlers/webhook_create.go) and the target
|
||||||
// protection" (both internal/handlers/source_management.go),
|
// host on "target URL blocked by SSRF protection"
|
||||||
|
// (internal/handlers/target_create.go),
|
||||||
// and target_name in internal/delivery/engine.go and
|
// and target_name in internal/delivery/engine.go and
|
||||||
// target_http.go. Each is bounded only by the 1 MB form body
|
// target_http.go. Each is bounded only by the 1 MB form body
|
||||||
// cap, so a 100 KB name writes one line of roughly 600 KB.
|
// cap, so a 100 KB name writes one line of roughly 600 KB.
|
||||||
|
|||||||
Reference in New Issue
Block a user