Compare commits

1 Commits
Author SHA1 Message Date
sneak f71d3a01a9 Split source_management.go along its CRUD seams (closes #274)
check / check (push) Successful in 3m29s
Pure code movement. Every declaration of
internal/handlers/source_management.go moves unchanged into one of:
webhook_list.go, webhook_create.go, webhook_detail.go, webhook_edit.go
and webhook_delete.go for the webhook pages; event_log.go for the event
log; entrypoint.go for the entrypoint handlers; target_create.go,
target_delete.go and target_toggle.go for the target handlers; and
shared.go for the helpers several of them use. Only each file's package
line and imports are new. The README and a middleware comment that
named the removed file now name the new ones.

Model: opus-5-5
2026-10-03 04:04:43 +00:00
4 changed files with 52 additions and 33 deletions
+14 -3
View File
@@ -2840,8 +2840,9 @@ read as more than it is:
- **Lines carrying an authenticated operator's own input**, which are
not truncated at all. `webhook created` logs the submitted `name`
verbatim and `target URL blocked by SSRF protection` logs the target
host (both `internal/handlers/source_management.go`), as do the
verbatim (`internal/handlers/webhook_create.go`) and
`target URL blocked by SSRF protection` logs the target host
(`internal/handlers/target_create.go`), as do the
`target_name` lines in `internal/delivery/engine.go` and
`internal/delivery/target_http.go`. The only bound on any of them is
the 1 MB form body cap, so a 100 KB `name` writes a single line of
@@ -3220,7 +3221,17 @@ webhooker/
│ │ ├── index.go # Index page handler
│ │ ├── profile.go # User profile handler
│ │ ├── settings.go # Read-only Settings page handler
│ │ ├── source_management.go # Webhook CRUD handlers
│ │ ├── webhook_list.go # Webhook list page
│ │ ├── webhook_create.go # Webhook create
│ │ ├── webhook_detail.go # Webhook detail page
│ │ ├── webhook_edit.go # Webhook edit, archive renaming
│ │ ├── webhook_delete.go # Webhook delete, event database and archive writer removal
│ │ ├── event_log.go # Event log page: loaders, filters, delivery views
│ │ ├── entrypoint.go # Entrypoint create, edit, delete and toggle
│ │ ├── target_create.go # Target create, per-type config builders
│ │ ├── target_delete.go # Target delete
│ │ ├── target_toggle.go # Target toggle
│ │ ├── shared.go # Helpers shared by several handlers
│ │ └── webhook.go # Webhook receiver handler
│ ├── healthcheck/
│ │ └── healthcheck.go # Health check service (uptime, version)
@@ -29,31 +29,3 @@ func (h *Handlers) evictTargetArchiveWriter(targetID string) {
h.archives.EvictTarget(targetID)
}
// HandleTargetToggle handles toggling a target's active state.
func (h *Handlers) HandleTargetToggle() http.HandlerFunc {
return h.toggleChildResource(
"targetID",
func(webhookID, childID string) (bool, error) {
var tgt database.Target
err := h.db.DB().Where(
"id = ? AND webhook_id = ?",
childID, webhookID,
).First(&tgt).Error
if err != nil {
return false, err
}
// Only the active column: saving the whole row would
// write back the name and settings read above over an
// edit saved since.
active := !tgt.Active
return active, h.db.DB().Model(&tgt).
Update("active", active).Error
},
"failed to toggle target",
targetActivated, targetDeactivated,
)
}
+35
View File
@@ -0,0 +1,35 @@
package handlers
import (
"net/http"
"sneak.berlin/go/webhooker/internal/database"
)
// HandleTargetToggle handles toggling a target's active state.
func (h *Handlers) HandleTargetToggle() http.HandlerFunc {
return h.toggleChildResource(
"targetID",
func(webhookID, childID string) (bool, error) {
var tgt database.Target
err := h.db.DB().Where(
"id = ? AND webhook_id = ?",
childID, webhookID,
).First(&tgt).Error
if err != nil {
return false, err
}
// Only the active column: saving the whole row would
// write back the name and settings read above over an
// edit saved since.
active := !tgt.Active
return active, h.db.DB().Model(&tgt).
Update("active", active).Error
},
"failed to toggle target",
targetActivated, targetDeactivated,
)
}
+3 -2
View File
@@ -131,8 +131,9 @@ const (
//
// - Lines carrying an AUTHENTICATED operator's own input, which
// are not truncated at all: the webhook name on "webhook
// created" and the target host on "target URL blocked by SSRF
// protection" (both internal/handlers/source_management.go),
// created" (internal/handlers/webhook_create.go) and the target
// host on "target URL blocked by SSRF protection"
// (internal/handlers/target_create.go),
// and target_name in internal/delivery/engine.go and
// target_http.go. Each is bounded only by the 1 MB form body
// cap, so a 100 KB name writes one line of roughly 600 KB.