Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d899186216 |
@@ -2840,9 +2840,8 @@ read as more than it is:
|
||||
|
||||
- **Lines carrying an authenticated operator's own input**, which are
|
||||
not truncated at all. `webhook created` logs the submitted `name`
|
||||
verbatim (`internal/handlers/webhook_create.go`) and
|
||||
`target URL blocked by SSRF protection` logs the target host
|
||||
(`internal/handlers/target_create.go`), as do the
|
||||
verbatim and `target URL blocked by SSRF protection` logs the target
|
||||
host (both `internal/handlers/source_management.go`), as do the
|
||||
`target_name` lines in `internal/delivery/engine.go` and
|
||||
`internal/delivery/target_http.go`. The only bound on any of them is
|
||||
the 1 MB form body cap, so a 100 KB `name` writes a single line of
|
||||
@@ -3221,17 +3220,7 @@ webhooker/
|
||||
│ │ ├── index.go # Index page handler
|
||||
│ │ ├── profile.go # User profile handler
|
||||
│ │ ├── settings.go # Read-only Settings page handler
|
||||
│ │ ├── webhook_list.go # Webhook list page
|
||||
│ │ ├── webhook_create.go # Webhook create
|
||||
│ │ ├── webhook_detail.go # Webhook detail page
|
||||
│ │ ├── webhook_edit.go # Webhook edit, archive renaming
|
||||
│ │ ├── webhook_delete.go # Webhook delete, event database and archive writer removal
|
||||
│ │ ├── event_log.go # Event log page: loaders, filters, delivery views
|
||||
│ │ ├── entrypoint.go # Entrypoint create, edit, delete and toggle
|
||||
│ │ ├── target_create.go # Target create, per-type config builders
|
||||
│ │ ├── target_delete.go # Target delete
|
||||
│ │ ├── target_toggle.go # Target toggle
|
||||
│ │ ├── shared.go # Helpers shared by several handlers
|
||||
│ │ ├── source_management.go # Webhook CRUD handlers
|
||||
│ │ └── webhook.go # Webhook receiver handler
|
||||
│ ├── healthcheck/
|
||||
│ │ └── healthcheck.go # Health check service (uptime, version)
|
||||
|
||||
@@ -29,3 +29,31 @@ func (h *Handlers) evictTargetArchiveWriter(targetID string) {
|
||||
|
||||
h.archives.EvictTarget(targetID)
|
||||
}
|
||||
|
||||
// HandleTargetToggle handles toggling a target's active state.
|
||||
func (h *Handlers) HandleTargetToggle() http.HandlerFunc {
|
||||
return h.toggleChildResource(
|
||||
"targetID",
|
||||
func(webhookID, childID string) (bool, error) {
|
||||
var tgt database.Target
|
||||
|
||||
err := h.db.DB().Where(
|
||||
"id = ? AND webhook_id = ?",
|
||||
childID, webhookID,
|
||||
).First(&tgt).Error
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
|
||||
// Only the active column: saving the whole row would
|
||||
// write back the name and settings read above over an
|
||||
// edit saved since.
|
||||
active := !tgt.Active
|
||||
|
||||
return active, h.db.DB().Model(&tgt).
|
||||
Update("active", active).Error
|
||||
},
|
||||
"failed to toggle target",
|
||||
targetActivated, targetDeactivated,
|
||||
)
|
||||
}
|
||||
@@ -1,35 +0,0 @@
|
||||
package handlers
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
)
|
||||
|
||||
// HandleTargetToggle handles toggling a target's active state.
|
||||
func (h *Handlers) HandleTargetToggle() http.HandlerFunc {
|
||||
return h.toggleChildResource(
|
||||
"targetID",
|
||||
func(webhookID, childID string) (bool, error) {
|
||||
var tgt database.Target
|
||||
|
||||
err := h.db.DB().Where(
|
||||
"id = ? AND webhook_id = ?",
|
||||
childID, webhookID,
|
||||
).First(&tgt).Error
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
|
||||
// Only the active column: saving the whole row would
|
||||
// write back the name and settings read above over an
|
||||
// edit saved since.
|
||||
active := !tgt.Active
|
||||
|
||||
return active, h.db.DB().Model(&tgt).
|
||||
Update("active", active).Error
|
||||
},
|
||||
"failed to toggle target",
|
||||
targetActivated, targetDeactivated,
|
||||
)
|
||||
}
|
||||
@@ -131,9 +131,8 @@ const (
|
||||
//
|
||||
// - Lines carrying an AUTHENTICATED operator's own input, which
|
||||
// are not truncated at all: the webhook name on "webhook
|
||||
// created" (internal/handlers/webhook_create.go) and the target
|
||||
// host on "target URL blocked by SSRF protection"
|
||||
// (internal/handlers/target_create.go),
|
||||
// created" and the target host on "target URL blocked by SSRF
|
||||
// protection" (both internal/handlers/source_management.go),
|
||||
// and target_name in internal/delivery/engine.go and
|
||||
// target_http.go. Each is bounded only by the 1 MB form body
|
||||
// cap, so a 100 KB name writes one line of roughly 600 KB.
|
||||
|
||||
Reference in New Issue
Block a user