Compare commits
10
Commits
f71d3a01a9
..
next
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
46fe7baed0 | ||
|
|
ea8cba7264 | ||
|
|
a8fc0c5d32 | ||
|
|
7963188c1e | ||
|
|
16ed356b68 | ||
|
|
fe5e0d4173 | ||
|
|
9ccaa8ce01 | ||
|
|
935e18c6f1 | ||
|
|
af91d8a723 | ||
|
|
f703b72ce0 |
+2
-2
@@ -15,8 +15,8 @@ bin/
|
||||
# Extracted from 3p/ by `make assets` inside the build; a host copy is not
|
||||
# needed. The tarball in 3p/ must stay in the context.
|
||||
static/js/alpine.min.js
|
||||
# The js-deps stage installs ESLint; a host copy would overwrite it at the
|
||||
# js-lint stage's `COPY . .`.
|
||||
# The js-deps stage installs ESLint and prettier; a host copy would overwrite
|
||||
# them at the `COPY . .` of the stages built on it.
|
||||
node_modules/
|
||||
.env
|
||||
.env.*
|
||||
|
||||
@@ -33,5 +33,5 @@ jobs:
|
||||
# and built cannot report success from cache.
|
||||
run: git rev-parse HEAD > .ci-fingerprint
|
||||
|
||||
- name: Build Docker image (runs make fmt-check, golangci-lint, the stylesheet check, ESLint, make test, make build)
|
||||
- name: Build Docker image (runs the gofmt check, golangci-lint, the stylesheet check, ESLint, the Markdown check, make test, make build)
|
||||
run: script/cibuild
|
||||
|
||||
+1
-1
@@ -15,7 +15,7 @@ bin/
|
||||
# Go vendor directory
|
||||
vendor/
|
||||
|
||||
# ESLint and its dependencies, installed from yarn.lock
|
||||
# ESLint, prettier and their dependencies, installed from yarn.lock
|
||||
node_modules/
|
||||
|
||||
# IDE specific files
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
{
|
||||
"tabWidth": 4,
|
||||
"proseWrap": "always"
|
||||
}
|
||||
@@ -0,0 +1,3 @@
|
||||
# Install into node_modules/: the Dockerfile's lint and Markdown stages run
|
||||
# ESLint and prettier from node_modules/.bin.
|
||||
nodeLinker: node-modules
|
||||
+42
-16
@@ -4,8 +4,6 @@
|
||||
# compile on Alpine musl (off64_t is a glibc type).
|
||||
FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint
|
||||
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends make && rm -rf /var/lib/apt/lists/*
|
||||
|
||||
WORKDIR /src
|
||||
|
||||
# Copy go mod files first for better layer caching
|
||||
@@ -19,12 +17,14 @@ RUN go mod download
|
||||
# .dockerignore.
|
||||
COPY . .
|
||||
|
||||
# Run formatting check and linter. golangci-lint is invoked directly rather
|
||||
# than through `make lint`: this stage is already the pinned linter image, and
|
||||
# script/lint is a wrapper that builds Dockerfile.lint, so calling it here
|
||||
# would need a docker daemon inside the build. Keep these steps in step with
|
||||
# Dockerfile.lint, including --network=none (see its header for why).
|
||||
RUN make fmt-check
|
||||
# Run the Go formatting check and the linter. gofmt and golangci-lint are
|
||||
# invoked directly rather than through `make fmt-check` and `make lint`: this
|
||||
# stage is already the pinned linter image, and both scripts build docker
|
||||
# stages, so calling them here would need a docker daemon inside the build.
|
||||
# The Markdown half of `make fmt-check` is the markdown-check stage below.
|
||||
# Keep the golangci-lint steps in step with Dockerfile.lint, including
|
||||
# --network=none (see its header for why).
|
||||
RUN if [ -n "$(gofmt -s -l .)" ]; then echo "gofmt needed on:"; gofmt -s -l .; exit 1; fi
|
||||
RUN script/assets
|
||||
RUN --network=none golangci-lint config verify --config .golangci.yml
|
||||
RUN --network=none golangci-lint run --config .golangci.yml --build-tags browser ./...
|
||||
@@ -66,30 +66,56 @@ RUN sed 's/}/}\n/g' static/css/tailwind.css > /tmp/committed.css \
|
||||
}
|
||||
|
||||
# JavaScript lint stages: ESLint, at the version package.json and yarn.lock
|
||||
# pin, checks static/js/ against eslint.config.mjs. js-deps installs it and
|
||||
# stays cached until those two files change. script/lint forces only js-lint
|
||||
# to re-run, and the build stage below runs it too. COPY . . brings in the CI
|
||||
# cache barrier described in the lint stage above.
|
||||
# node:24.21.0-alpine (LTS, with yarn 1.22.22), 2026-09-18
|
||||
# pin, checks static/js/ against eslint.config.mjs. js-deps installs it, and
|
||||
# prettier for the Markdown stages below, and stays cached until package.json,
|
||||
# yarn.lock or .yarnrc.yml changes. script/lint forces only js-lint to re-run,
|
||||
# and the build stage below runs it too. COPY . . brings in the CI cache
|
||||
# barrier described in the lint stage above.
|
||||
#
|
||||
# The image's own corepack runs the yarn that package.json's packageManager
|
||||
# field names, yarn 4.18.1 (released 2026-09-24), and checks it against the
|
||||
# hash there. The image also ships yarn 1, which `corepack enable yarn`
|
||||
# replaces.
|
||||
# node:24.21.0-alpine (LTS), 2026-09-18
|
||||
FROM node:24.21.0-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1 AS js-deps
|
||||
WORKDIR /src
|
||||
COPY package.json yarn.lock ./
|
||||
RUN yarn install --frozen-lockfile --ignore-scripts
|
||||
COPY package.json yarn.lock .yarnrc.yml ./
|
||||
RUN corepack enable yarn && yarn install --immutable --mode=skip-build
|
||||
|
||||
FROM js-deps AS js-lint
|
||||
COPY . .
|
||||
RUN --network=none node_modules/.bin/eslint static/js
|
||||
|
||||
# Markdown stages: prettier, at the version package.json and yarn.lock pin,
|
||||
# formats every Markdown file in the tree with the settings in .prettierrc.
|
||||
# `make fmt` (script/fmt) writes the formatted files out from markdown-output.
|
||||
# markdown-check fails on any file prettier would change; `make fmt-check`
|
||||
# runs it, and so does the build stage below.
|
||||
FROM js-deps AS markdown
|
||||
COPY . .
|
||||
RUN --network=none node_modules/.bin/prettier --write '**/*.md' \
|
||||
&& mkdir /out \
|
||||
&& find . -name '*.md' ! -path './node_modules/*' -exec cp -p --parents {} /out \;
|
||||
|
||||
FROM scratch AS markdown-output
|
||||
COPY --from=markdown /out /
|
||||
|
||||
FROM js-deps AS markdown-check
|
||||
COPY . .
|
||||
RUN --network=none node_modules/.bin/prettier --check '**/*.md'
|
||||
|
||||
# Build stage
|
||||
# golang:1.26.1-bookworm (Debian-based), 2026-03-17
|
||||
# Using Debian-based image because gorm.io/driver/sqlite pulls in
|
||||
# mattn/go-sqlite3 (CGO), which does not compile on Alpine musl.
|
||||
FROM golang:1.26.1-bookworm@sha256:4465644228bc2857a954b092167e12aa59c006a3492282a6c820bf4755fd64a4 AS builder
|
||||
|
||||
# Depend on the lint, stylesheet check and JavaScript lint stages passing
|
||||
# Depend on the lint, stylesheet check, JavaScript lint and Markdown check
|
||||
# stages passing
|
||||
COPY --from=lint /src/go.sum /dev/null
|
||||
COPY --from=css-check /out/tailwind.css /dev/null
|
||||
COPY --from=js-lint /src/yarn.lock /dev/null
|
||||
COPY --from=markdown-check /src/yarn.lock /dev/null
|
||||
|
||||
# jq is a runtime dependency of script/ci-mark-superseded, which the test
|
||||
# suite executes. git is what script/version derives the version with.
|
||||
|
||||
@@ -2,403 +2,367 @@
|
||||
|
||||
One issue per unit of work, one branch and one PR per issue:
|
||||
|
||||
* ensure a tracked issue exists with a definition of done
|
||||
* branch from `next` (never from `main`)
|
||||
* do the work; open a PR based on `next` (never on `main`)
|
||||
* pass an independent review, then the manager squash-merges into `next`
|
||||
* push; nothing stays local-only
|
||||
- ensure a tracked issue exists with a definition of done
|
||||
- branch from `next` (never from `main`)
|
||||
- do the work; open a PR based on `next` (never on `main`)
|
||||
- pass an independent review, then the manager squash-merges into `next`
|
||||
- push; nothing stays local-only
|
||||
|
||||
`next` is the branch for the next milestone and must stay green and
|
||||
mergeable to `main` without notice. One `next` -> `main` PR accumulates
|
||||
the milestone; releases are cut from `main` separately.
|
||||
`next` is the branch for the next milestone and must stay green and mergeable to
|
||||
`main` without notice. One `next` -> `main` PR accumulates the milestone;
|
||||
releases are cut from `main` separately.
|
||||
|
||||
Issue branches do NOT touch this file — the manager maintains it on
|
||||
`next`. Every branch editing `TODO.md` conflicts with every other
|
||||
(#112).
|
||||
Issue branches do NOT touch this file — the manager maintains it on `next`.
|
||||
Every branch editing `TODO.md` conflicts with every other (#112).
|
||||
|
||||
# Status
|
||||
|
||||
The milestone (https://git.eeqj.de/sneak/webhooker/milestone/9) is the
|
||||
authoritative list, and the only place to read a count or a state of
|
||||
play from. This file records where the project is, not what is in
|
||||
flight: a sentence whose truth depends on a branch being unmerged is
|
||||
wrong the moment it merges, and this file has been wrong that way
|
||||
before.
|
||||
authoritative list, and the only place to read a count or a state of play from.
|
||||
This file records where the project is, not what is in flight: a sentence whose
|
||||
truth depends on a branch being unmerged is wrong the moment it merges, and this
|
||||
file has been wrong that way before.
|
||||
|
||||
The durability defect that held the tag has landed
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/256, commit `8d64259`).
|
||||
Every SQLite handle opens with WAL journaling and a busy timeout, a
|
||||
bookkeeping write that fails leaves its delivery in a recoverable
|
||||
state rather than a lying one, and recovery skips a delivery that
|
||||
already has a successful result row. Final pre-tag verification
|
||||
exercised it and confirmed it holds. Whatever the milestone still
|
||||
shows open is what remains before `v1.0.0`.
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/256, commit `8d64259`). Every SQLite
|
||||
handle opens with WAL journaling and a busy timeout, a bookkeeping write that
|
||||
fails leaves its delivery in a recoverable state rather than a lying one, and
|
||||
recovery skips a delivery that already has a successful result row. Final
|
||||
pre-tag verification exercised it and confirmed it holds. Whatever the milestone
|
||||
still shows open is what remains before `v1.0.0`.
|
||||
|
||||
Delivery is at-least-once by design, not by accident: a send whose
|
||||
result row does not land is attempted again, so a receiver can see a
|
||||
duplicate. That is deliberate — the alternative is a silent lost
|
||||
delivery — and the README says so under Rationale. It is not a defect
|
||||
to re-file.
|
||||
Delivery is at-least-once by design, not by accident: a send whose result row
|
||||
does not land is attempted again, so a receiver can see a duplicate. That is
|
||||
deliberate — the alternative is a silent lost delivery — and the README says so
|
||||
under Rationale. It is not a defect to re-file.
|
||||
|
||||
# Next Step
|
||||
|
||||
Clear the rest of the open 1.0.0 milestone
|
||||
(https://git.eeqj.de/sneak/webhooker/milestone/9) and tag `v1.0.0`.
|
||||
Merging `next` into `main` is a separate act from tagging and waits on
|
||||
neither of those: `next` is kept mergeable at all times, which is the
|
||||
point of the branch.
|
||||
(https://git.eeqj.de/sneak/webhooker/milestone/9) and tag `v1.0.0`. Merging
|
||||
`next` into `main` is a separate act from tagging and waits on neither of those:
|
||||
`next` is kept mergeable at all times, which is the point of the branch.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-08-24 Bind the plaintext HTTP listener deliberately, via
|
||||
`BIND_ADDRESS` defaulting to `127.0.0.1`, and document the
|
||||
reverse-proxy deployment. A hostname, an empty value or a value
|
||||
carrying a port is a startup error, and the `Dockerfile` sets
|
||||
`0.0.0.0` because a loopback bind inside a container is unreachable
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/268). The same commit
|
||||
removed the shutdown race: `httpServer` is built in the constructor
|
||||
rather than assigned from the serving goroutine, which orders the
|
||||
write before every fx hook and rules out the nil dereference a
|
||||
SIGTERM arriving first would have caused, and `sentryEnabled` is an
|
||||
`atomic.Bool` (https://git.eeqj.de/sneak/webhooker/issues/226)
|
||||
- 2026-08-24 Remove inbound request signature verification. The
|
||||
entrypoint UUID is the authentication secret, so the per-entrypoint
|
||||
shared secret, the `internal/signature` package, the receiver check,
|
||||
the model fields and the forms are all gone. This reverses the
|
||||
feature that landed earlier in the same milestone
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/67,
|
||||
- 2026-08-24 Bind the plaintext HTTP listener deliberately, via `BIND_ADDRESS`
|
||||
defaulting to `127.0.0.1`, and document the reverse-proxy deployment. A
|
||||
hostname, an empty value or a value carrying a port is a startup error, and
|
||||
the `Dockerfile` sets `0.0.0.0` because a loopback bind inside a container is
|
||||
unreachable (https://git.eeqj.de/sneak/webhooker/issues/268). The same commit
|
||||
removed the shutdown race: `httpServer` is built in the constructor rather
|
||||
than assigned from the serving goroutine, which orders the write before every
|
||||
fx hook and rules out the nil dereference a SIGTERM arriving first would have
|
||||
caused, and `sentryEnabled` is an `atomic.Bool`
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/226)
|
||||
- 2026-08-24 Remove inbound request signature verification. The entrypoint UUID
|
||||
is the authentication secret, so the per-entrypoint shared secret, the
|
||||
`internal/signature` package, the receiver check, the model fields and the
|
||||
forms are all gone. This reverses the feature that landed earlier in the same
|
||||
milestone (https://git.eeqj.de/sneak/webhooker/issues/67,
|
||||
https://git.eeqj.de/sneak/webhooker/issues/279)
|
||||
- 2026-08-24 Stamp the build version into the binary and render it in
|
||||
the UI footer. `script/version` is the single source — `$VERSION`,
|
||||
else `git describe --tags --always --dirty`, else `unknown` — so a
|
||||
`make build` binary and a `make docker` image from one checkout
|
||||
report the same thing, and nothing in it varies between two builds
|
||||
of the same commit, which the release gate's byte-identical
|
||||
assertion would catch
|
||||
- 2026-08-24 Stamp the build version into the binary and render it in the UI
|
||||
footer. `script/version` is the single source — `$VERSION`, else
|
||||
`git describe --tags --always --dirty`, else `unknown` — so a `make build`
|
||||
binary and a `make docker` image from one checkout report the same thing, and
|
||||
nothing in it varies between two builds of the same commit, which the release
|
||||
gate's byte-identical assertion would catch
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/253)
|
||||
- 2026-08-24 Derive cookie `Secure` and CSRF strictness from the
|
||||
request transport rather than from `WEBHOOKER_ENVIRONMENT`. Behind a
|
||||
real TLS proxy with the environment left at its `dev` default, the
|
||||
session cookie silently lost `Secure` while the CSRF cookie on the
|
||||
same response kept it. `X-Forwarded-Proto` is now matched
|
||||
case-insensitively on its first comma-separated element, so `HTTPS`
|
||||
and `https, http` no longer fall to the relaxed CSRF path
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/269)
|
||||
- 2026-08-24 Roll back a failed webhook deletion instead of committing
|
||||
it. A failing delete committed whatever had already succeeded,
|
||||
hard-deleted the per-webhook event database anyway, and redirected as
|
||||
though it had worked — orphaned config plus permanently destroyed
|
||||
history, reported as success. All three delete positions now roll
|
||||
back with the event database intact
|
||||
- 2026-08-24 Derive cookie `Secure` and CSRF strictness from the request
|
||||
transport rather than from `WEBHOOKER_ENVIRONMENT`. Behind a real TLS proxy
|
||||
with the environment left at its `dev` default, the session cookie silently
|
||||
lost `Secure` while the CSRF cookie on the same response kept it.
|
||||
`X-Forwarded-Proto` is now matched case-insensitively on its first
|
||||
comma-separated element, so `HTTPS` and `https, http` no longer fall to the
|
||||
relaxed CSRF path (https://git.eeqj.de/sneak/webhooker/issues/269)
|
||||
- 2026-08-24 Roll back a failed webhook deletion instead of committing it. A
|
||||
failing delete committed whatever had already succeeded, hard-deleted the
|
||||
per-webhook event database anyway, and redirected as though it had worked —
|
||||
orphaned config plus permanently destroyed history, reported as success. All
|
||||
three delete positions now roll back with the event database intact
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/262)
|
||||
- 2026-08-24 Name a deleted target on its historical deliveries, marked
|
||||
`(deleted)`, rather than leaving the event log unable to say where a
|
||||
delivery went. A deleted target's credentials stay masked exactly as
|
||||
a live one's, and it cannot become deliverable again through the
|
||||
receiver, resubmit, replay, the edit form or the toggle
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/211)
|
||||
- 2026-08-24 Bound both request-controlled `/metrics` label dimensions,
|
||||
so the unauthenticated receiver is no longer a memory-exhaustion
|
||||
vector: `handler` carries the chi route pattern, and `method` folds
|
||||
anything chi cannot route onto a single `(unmatched)` sentinel. Both
|
||||
were reproduced before the fix — 300 random method tokens took the
|
||||
series count from 106 to 7,631, and path flooding reached 62,532 —
|
||||
and a label audit across a live scrape found no third unbounded
|
||||
dimension (https://git.eeqj.de/sneak/webhooker/issues/254,
|
||||
`(deleted)`, rather than leaving the event log unable to say where a delivery
|
||||
went. A deleted target's credentials stay masked exactly as a live one's, and
|
||||
it cannot become deliverable again through the receiver, resubmit, replay, the
|
||||
edit form or the toggle (https://git.eeqj.de/sneak/webhooker/issues/211)
|
||||
- 2026-08-24 Bound both request-controlled `/metrics` label dimensions, so the
|
||||
unauthenticated receiver is no longer a memory-exhaustion vector: `handler`
|
||||
carries the chi route pattern, and `method` folds anything chi cannot route
|
||||
onto a single `(unmatched)` sentinel. Both were reproduced before the fix —
|
||||
300 random method tokens took the series count from 106 to 7,631, and path
|
||||
flooding reached 62,532 — and a label audit across a live scrape found no
|
||||
third unbounded dimension (https://git.eeqj.de/sneak/webhooker/issues/254,
|
||||
https://git.eeqj.de/sneak/webhooker/issues/261)
|
||||
- 2026-08-24 Validate `max_retries` on both target forms. `abc`, `2.7`
|
||||
and `-5` silently became 0 — fire-and-forget — including on the edit
|
||||
path, where it destroyed a working value, and `999999999` stored
|
||||
verbatim. The ceiling of 20 is the `max` both templates already
|
||||
declared (https://git.eeqj.de/sneak/webhooker/issues/221)
|
||||
- 2026-08-24 Resubmit a stored event as a new undelivered event, so a
|
||||
backend under development can be tested against real captured
|
||||
traffic. Per-delivery replay cannot serve that: it re-sends one
|
||||
finished delivery to its own original target, and a target created
|
||||
for a dev backend has no prior delivery to replay. Resubmit
|
||||
re-injects the stored event at the top of the receiver path and fans
|
||||
it out to whatever targets are active now
|
||||
- 2026-08-24 Validate `max_retries` on both target forms. `abc`, `2.7` and `-5`
|
||||
silently became 0 — fire-and-forget — including on the edit path, where it
|
||||
destroyed a working value, and `999999999` stored verbatim. The ceiling of 20
|
||||
is the `max` both templates already declared
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/221)
|
||||
- 2026-08-24 Resubmit a stored event as a new undelivered event, so a backend
|
||||
under development can be tested against real captured traffic. Per-delivery
|
||||
replay cannot serve that: it re-sends one finished delivery to its own
|
||||
original target, and a target created for a dev backend has no prior delivery
|
||||
to replay. Resubmit re-injects the stored event at the top of the receiver
|
||||
path and fans it out to whatever targets are active now
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/250)
|
||||
- 2026-08-20 Take an exclusive lock on `DATA_DIR` at startup, so two
|
||||
instances on one directory cannot both deliver
|
||||
- 2026-08-20 Take an exclusive lock on `DATA_DIR` at startup, so two instances
|
||||
on one directory cannot both deliver
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/201)
|
||||
- 2026-08-20 Shut down the app when the HTTP listener fails. The
|
||||
`OnStart` hook returned as soon as the serving goroutine was
|
||||
spawned, so a failed listen left fx reporting RUNNING and a live
|
||||
process with nothing bound — invisible to systemd and Docker restart
|
||||
policies (https://git.eeqj.de/sneak/webhooker/issues/200)
|
||||
- 2026-08-20 Shut down the app when the HTTP listener fails. The `OnStart` hook
|
||||
returned as soon as the serving goroutine was spawned, so a failed listen left
|
||||
fx reporting RUNNING and a live process with nothing bound — invisible to
|
||||
systemd and Docker restart policies
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/200)
|
||||
- 2026-08-20 Stop target credentials leaking into the per-webhook event
|
||||
databases (https://git.eeqj.de/sneak/webhooker/issues/206), log SQL
|
||||
with placeholders rather than bound values
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/207), and fail loudly on
|
||||
half-set metrics auth credentials
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/205)
|
||||
- 2026-08-20 Read queue depths with `Find`, not `Scan`. `Scan` swaps
|
||||
GORM's own trace recorder in for the logging adapter, and that
|
||||
recorder does not implement `gorm.ParamsFilter`, so those statements
|
||||
logged their bound values interpolated and bypassed the suppression
|
||||
above. The two units gated green against a `next` that lacked the
|
||||
other, and `next` went red when both landed
|
||||
databases (https://git.eeqj.de/sneak/webhooker/issues/206), log SQL with
|
||||
placeholders rather than bound values
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/207), and fail loudly on half-set
|
||||
metrics auth credentials (https://git.eeqj.de/sneak/webhooker/issues/205)
|
||||
- 2026-08-20 Read queue depths with `Find`, not `Scan`. `Scan` swaps GORM's own
|
||||
trace recorder in for the logging adapter, and that recorder does not
|
||||
implement `gorm.ParamsFilter`, so those statements logged their bound values
|
||||
interpolated and bypassed the suppression above. The two units gated green
|
||||
against a `next` that lacked the other, and `next` went red when both landed
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/234)
|
||||
- 2026-08-20 Render per-attempt delivery detail in the event log
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/202) and add replay of a
|
||||
terminally failed delivery
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/203)
|
||||
terminally failed delivery (https://git.eeqj.de/sneak/webhooker/issues/203)
|
||||
- 2026-08-20 Expose delivery metrics on `/metrics`
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/209) and document the
|
||||
backup, restore and upgrade procedures
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/209) and document the backup,
|
||||
restore and upgrade procedures
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/210)
|
||||
- 2026-08-20 Add a `webhooker resetpw` subcommand and a bootstrap
|
||||
banner. The admin bootstrap password was printed once among roughly
|
||||
45 fx lines, and under `docker run -d` went to container logs subject
|
||||
to rotation; there was no reset path at all, so recovery meant
|
||||
hand-deleting the users row, documented nowhere. The password is read
|
||||
from stdin or generated, never from argv where `/proc` would publish
|
||||
it (https://git.eeqj.de/sneak/webhooker/issues/208)
|
||||
- 2026-08-20 Add `ALLOWED_EGRESS_CIDRS`, an allowlist-only escape hatch
|
||||
for the SSRF guard, so a self-hosted proxy can forward into the
|
||||
operator's own network. The guard's always-blocked set cannot be
|
||||
reopened by configuration
|
||||
- 2026-08-20 Add a `webhooker resetpw` subcommand and a bootstrap banner. The
|
||||
admin bootstrap password was printed once among roughly 45 fx lines, and under
|
||||
`docker run -d` went to container logs subject to rotation; there was no reset
|
||||
path at all, so recovery meant hand-deleting the users row, documented
|
||||
nowhere. The password is read from stdin or generated, never from argv where
|
||||
`/proc` would publish it (https://git.eeqj.de/sneak/webhooker/issues/208)
|
||||
- 2026-08-20 Add `ALLOWED_EGRESS_CIDRS`, an allowlist-only escape hatch for the
|
||||
SSRF guard, so a self-hosted proxy can forward into the operator's own
|
||||
network. The guard's always-blocked set cannot be reopened by configuration
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/204)
|
||||
- 2026-08-20 Harden operator-set target headers, which were carried
|
||||
unsafely across a redirect
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/233)
|
||||
- 2026-08-20 Harden operator-set target headers, which were carried unsafely
|
||||
across a redirect (https://git.eeqj.de/sneak/webhooker/issues/233)
|
||||
- 2026-08-20 Add a target edit form with headers and timeout fields
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/127)
|
||||
- 2026-08-18 Raise `script/test`'s per-package timeout from 30s to 90s,
|
||||
matching the org-wide backstop. `go test` applies `-timeout` per
|
||||
package, and `internal/handlers` had grown past the old budget: a
|
||||
cache-defeated build failed outright at `GOMAXPROCS=4`, and every run
|
||||
under deliberate host load breached 30s. The measurement table lives
|
||||
in the script (#194)
|
||||
- 2026-08-18 Re-sync `REPO_POLICIES.md` from `prompts`. The local copy
|
||||
was stale and still mandated a 20s test target with a 30s timeout,
|
||||
which the org replaced with a 60s cap and a 90s backstop. A synced
|
||||
copy is not a source; reading it as one nearly produced a PR against
|
||||
`prompts` proposing a change already merged there (#196)
|
||||
- 2026-08-18 Report handler panics through the logger and answer 500.
|
||||
chi v1.5.5's `Recoverer` scans for a `panic(0x` frame the runtime no
|
||||
longer emits, then indexes `pkg[-1:]`, so it panicked inside its own
|
||||
stack printer before writing a byte: the recovery never ran, the
|
||||
client got a dropped connection instead of a 500, and the original
|
||||
panic was lost. A local middleware replaces it, bounded by
|
||||
`MaxPanicLogLineBytes` (#187)
|
||||
- 2026-08-18 Route GORM's logger through `slog` and bound it. Every
|
||||
`gorm.Open` left `logger.Default` in place at `Warn` with
|
||||
`IgnoreRecordNotFoundError` false, so **every record-not-found
|
||||
printed the fully interpolated SQL to stdout** — including the
|
||||
client-chosen path on `/webhook/{uuid}` and the submitted username on
|
||||
the login form, at no level the operator set and outside
|
||||
`internal/logger` entirely. Three call sites, not the two the issue
|
||||
named (#178)
|
||||
- 2026-08-18 Bound every `slog` line against client-chosen text. Eight
|
||||
sites reachable unauthenticated, found by reading every `slog` call in
|
||||
the tree rather than only the one reported; the budget moved to a
|
||||
shared `internal/logfield` so no second truncation exists. `DEBUG`
|
||||
being off by default is not a bound and is not treated as one (#176)
|
||||
- 2026-08-18 Stop a slow host turning a login-guard test into a
|
||||
segfault. A non-fatal `assert` on an acquire result was dereferenced
|
||||
on the next line, so one timing miss killed the whole
|
||||
`internal/middleware` binary and reddened CI for unrelated PRs. The
|
||||
fix also removed a real production race — `acquire` could shed a
|
||||
request with a slot standing free, because Go picks uniformly among
|
||||
ready `select` cases (#186)
|
||||
- 2026-08-18 Send the chi route pattern to Sentry rather than the
|
||||
concrete path. The receiver's path carries the entrypoint capability
|
||||
token, so every Sentry event from `/webhook/{uuid}` shipped a live
|
||||
credential to a third party. Request `Data`, `QueryString`, `Cookies`
|
||||
and `Env` are dropped and headers reduced to an allowlist (#179)
|
||||
- 2026-08-18 Read form fields from the POST body only. `r.FormValue`
|
||||
merges the query string, so a login could be driven by URL parameters
|
||||
— putting the password somewhere that lands in access logs, proxy
|
||||
logs and browser history (#160)
|
||||
- 2026-08-18 Verify login credentials before spending rate-limit
|
||||
budget, so a flood of wrong passwords cannot lock out the account it
|
||||
is guessing at. The manager took this decision rather than stall the
|
||||
queue; it is flagged on the issue for reversal (#150)
|
||||
- 2026-08-18 Run all linting in Docker via `Dockerfile.lint`. Host lint
|
||||
was wrong in both directions from version skew and shared caches.
|
||||
`script/lint` asserts the summary line, because `--no-cache-filter`
|
||||
silently ignores a stage name it does not match — the flag that makes
|
||||
the gate meaningful fails open (#109)
|
||||
- 2026-08-18 Serve an event's full stored body over HTTP. The list
|
||||
query truncates for rendering, and that truncated value was the only
|
||||
way to read a body, so the full payload was unreachable (#157)
|
||||
- 2026-08-18 Raise `script/test`'s per-package timeout from 30s to 90s, matching
|
||||
the org-wide backstop. `go test` applies `-timeout` per package, and
|
||||
`internal/handlers` had grown past the old budget: a cache-defeated build
|
||||
failed outright at `GOMAXPROCS=4`, and every run under deliberate host load
|
||||
breached 30s. The measurement table lives in the script (#194)
|
||||
- 2026-08-18 Re-sync `REPO_POLICIES.md` from `prompts`. The local copy was stale
|
||||
and still mandated a 20s test target with a 30s timeout, which the org
|
||||
replaced with a 60s cap and a 90s backstop. A synced copy is not a source;
|
||||
reading it as one nearly produced a PR against `prompts` proposing a change
|
||||
already merged there (#196)
|
||||
- 2026-08-18 Report handler panics through the logger and answer 500. chi
|
||||
v1.5.5's `Recoverer` scans for a `panic(0x` frame the runtime no longer emits,
|
||||
then indexes `pkg[-1:]`, so it panicked inside its own stack printer before
|
||||
writing a byte: the recovery never ran, the client got a dropped connection
|
||||
instead of a 500, and the original panic was lost. A local middleware replaces
|
||||
it, bounded by `MaxPanicLogLineBytes` (#187)
|
||||
- 2026-08-18 Route GORM's logger through `slog` and bound it. Every `gorm.Open`
|
||||
left `logger.Default` in place at `Warn` with `IgnoreRecordNotFoundError`
|
||||
false, so **every record-not-found printed the fully interpolated SQL to
|
||||
stdout** — including the client-chosen path on `/webhook/{uuid}` and the
|
||||
submitted username on the login form, at no level the operator set and outside
|
||||
`internal/logger` entirely. Three call sites, not the two the issue named
|
||||
(#178)
|
||||
- 2026-08-18 Bound every `slog` line against client-chosen text. Eight sites
|
||||
reachable unauthenticated, found by reading every `slog` call in the tree
|
||||
rather than only the one reported; the budget moved to a shared
|
||||
`internal/logfield` so no second truncation exists. `DEBUG` being off by
|
||||
default is not a bound and is not treated as one (#176)
|
||||
- 2026-08-18 Stop a slow host turning a login-guard test into a segfault. A
|
||||
non-fatal `assert` on an acquire result was dereferenced on the next line, so
|
||||
one timing miss killed the whole `internal/middleware` binary and reddened CI
|
||||
for unrelated PRs. The fix also removed a real production race — `acquire`
|
||||
could shed a request with a slot standing free, because Go picks uniformly
|
||||
among ready `select` cases (#186)
|
||||
- 2026-08-18 Send the chi route pattern to Sentry rather than the concrete path.
|
||||
The receiver's path carries the entrypoint capability token, so every Sentry
|
||||
event from `/webhook/{uuid}` shipped a live credential to a third party.
|
||||
Request `Data`, `QueryString`, `Cookies` and `Env` are dropped and headers
|
||||
reduced to an allowlist (#179)
|
||||
- 2026-08-18 Read form fields from the POST body only. `r.FormValue` merges the
|
||||
query string, so a login could be driven by URL parameters — putting the
|
||||
password somewhere that lands in access logs, proxy logs and browser history
|
||||
(#160)
|
||||
- 2026-08-18 Verify login credentials before spending rate-limit budget, so a
|
||||
flood of wrong passwords cannot lock out the account it is guessing at. The
|
||||
manager took this decision rather than stall the queue; it is flagged on the
|
||||
issue for reversal (#150)
|
||||
- 2026-08-18 Run all linting in Docker via `Dockerfile.lint`. Host lint was
|
||||
wrong in both directions from version skew and shared caches. `script/lint`
|
||||
asserts the summary line, because `--no-cache-filter` silently ignores a stage
|
||||
name it does not match — the flag that makes the gate meaningful fails open
|
||||
(#109)
|
||||
- 2026-08-18 Serve an event's full stored body over HTTP. The list query
|
||||
truncates for rendering, and that truncated value was the only way to read a
|
||||
body, so the full payload was unreachable (#157)
|
||||
- 2026-08-18 Bound the access log line against client-chosen text.
|
||||
`internal/logfield` budgets by *encoded* bytes, not runes, so a
|
||||
handler's JSON escaping cannot multiply a field past its allowance
|
||||
(#146)
|
||||
- 2026-08-18 Mark superseded CI commits `failure` rather than
|
||||
`skipped`. A skipped run rolls up green, so a commit that was never
|
||||
tested reported success (#152)
|
||||
- 2026-08-18 Set `fx.StopTimeout` inside the container stop grace, so
|
||||
shutdown hooks are bounded by a deadline the orchestrator will
|
||||
actually honour rather than being killed mid-flush (#134)
|
||||
- 2026-08-17 Bucket IPv6 rate-limit keys by `/64`. A single allocation
|
||||
hands out 2^64 addresses, so per-address keying let one client mint
|
||||
unlimited buckets. Manager decision, recorded on the issue (#125)
|
||||
- 2026-08-17 Correct release-blocking README and startup-warning
|
||||
inaccuracies, including claims about behaviour the code does not have
|
||||
(#151)
|
||||
`internal/logfield` budgets by _encoded_ bytes, not runes, so a handler's JSON
|
||||
escaping cannot multiply a field past its allowance (#146)
|
||||
- 2026-08-18 Mark superseded CI commits `failure` rather than `skipped`. A
|
||||
skipped run rolls up green, so a commit that was never tested reported success
|
||||
(#152)
|
||||
- 2026-08-18 Set `fx.StopTimeout` inside the container stop grace, so shutdown
|
||||
hooks are bounded by a deadline the orchestrator will actually honour rather
|
||||
than being killed mid-flush (#134)
|
||||
- 2026-08-17 Bucket IPv6 rate-limit keys by `/64`. A single allocation hands out
|
||||
2^64 addresses, so per-address keying let one client mint unlimited buckets.
|
||||
Manager decision, recorded on the issue (#125)
|
||||
- 2026-08-17 Correct release-blocking README and startup-warning inaccuracies,
|
||||
including claims about behaviour the code does not have (#151)
|
||||
- 2026-08-17 Fetch and verify Alpine.js at build time against
|
||||
`static/vendor.sha256` instead of committing the minified blob, so
|
||||
the dependency is pinned by hash rather than by trust (#145)
|
||||
- 2026-08-17 Bound the event log's rendered bodies in the query itself,
|
||||
so a large stored payload cannot be read into memory just to be
|
||||
truncated for display (#135)
|
||||
- 2026-08-17 Mask the `http` target's destination URL in the UI: it can
|
||||
carry a bearer credential in its path or query, and was rendered
|
||||
verbatim. Manager decision to mask unconditionally (#115)
|
||||
- 2026-08-14 Bound shutdown hooks by their stop context, so a hook that
|
||||
hangs cannot hold the process past its grace period (#102)
|
||||
- 2026-08-14 Render templates via a buffer rather than the
|
||||
`ResponseWriter`, so a template error part-way through cannot commit
|
||||
a 200 and then fail — the response is written only once it is whole
|
||||
(#123)
|
||||
- 2026-08-14 Align the session codec's max-age with the 7-day absolute
|
||||
cap. The codec accepted cookies the session layer considered expired,
|
||||
so the cap was enforced in one place and not the other (#108)
|
||||
- 2026-08-12 Warn when `TRUSTED_PROXIES` is empty in production, where
|
||||
the safe default silently discards forwarded headers and every client
|
||||
rate-limits as the proxy's address (#149)
|
||||
- 2026-08-12 Bound the receiver rate limit per client IP across the
|
||||
whole `/webhook/*` route. The existing limiter keyed on the request
|
||||
path and `/webhook/{uuid}` matches any single segment, so a client
|
||||
that invented a fresh path per request minted a fresh bucket per
|
||||
request: the limit on the only unauthenticated endpoint bounded
|
||||
nothing in aggregate, and every request still cost an entrypoint
|
||||
lookup before it 404ed. An outer limiter keyed on the client address
|
||||
alone now bounds that, chained in front of the unchanged
|
||||
`static/vendor.sha256` instead of committing the minified blob, so the
|
||||
dependency is pinned by hash rather than by trust (#145)
|
||||
- 2026-08-17 Bound the event log's rendered bodies in the query itself, so a
|
||||
large stored payload cannot be read into memory just to be truncated for
|
||||
display (#135)
|
||||
- 2026-08-17 Mask the `http` target's destination URL in the UI: it can carry a
|
||||
bearer credential in its path or query, and was rendered verbatim. Manager
|
||||
decision to mask unconditionally (#115)
|
||||
- 2026-08-14 Bound shutdown hooks by their stop context, so a hook that hangs
|
||||
cannot hold the process past its grace period (#102)
|
||||
- 2026-08-14 Render templates via a buffer rather than the `ResponseWriter`, so
|
||||
a template error part-way through cannot commit a 200 and then fail — the
|
||||
response is written only once it is whole (#123)
|
||||
- 2026-08-14 Align the session codec's max-age with the 7-day absolute cap. The
|
||||
codec accepted cookies the session layer considered expired, so the cap was
|
||||
enforced in one place and not the other (#108)
|
||||
- 2026-08-12 Warn when `TRUSTED_PROXIES` is empty in production, where the safe
|
||||
default silently discards forwarded headers and every client rate-limits as
|
||||
the proxy's address (#149)
|
||||
- 2026-08-12 Bound the receiver rate limit per client IP across the whole
|
||||
`/webhook/*` route. The existing limiter keyed on the request path and
|
||||
`/webhook/{uuid}` matches any single segment, so a client that invented a
|
||||
fresh path per request minted a fresh bucket per request: the limit on the
|
||||
only unauthenticated endpoint bounded nothing in aggregate, and every request
|
||||
still cost an entrypoint lookup before it 404ed. An outer limiter keyed on the
|
||||
client address alone now bounds that, chained in front of the unchanged
|
||||
per-entrypoint limiter (#139)
|
||||
- 2026-08-12 Correct release-blocking documentation inaccuracies: the
|
||||
README promised manual redelivery in the present tense in three
|
||||
places when nothing implements it (the same false claim also sat in
|
||||
the doc comment that was its source text), the env table omitted
|
||||
`RETENTION_SWEEP_INTERVAL`, and `TODO.md` itself omitted five landed
|
||||
units (#141)
|
||||
- 2026-08-12 Make the CI gate execute the checks it reports on. The
|
||||
workflow now writes a build-context fingerprint before calling
|
||||
`script/cibuild`, so a code commit invalidates the `COPY` layer of
|
||||
the lint and builder stages while a docs-only commit still replays
|
||||
from cache; a superseding run also rewrites the `failure` status
|
||||
Gitea leaves on commits it cancelled and never tested. Verified by
|
||||
pushing a deliberately broken test and watching CI go red (#119)
|
||||
- 2026-08-12 Require a positive `RETENTION_SWEEP_INTERVAL`: a
|
||||
non-positive value reached `time.NewTicker` in both the retention
|
||||
reaper and the archive sweeper, panicking two goroutines with no
|
||||
recover after startup had already reported success (#140)
|
||||
- 2026-08-12 Bound the `X-Forwarded-For` scan's allocation to the hop
|
||||
cap: the reverse walk cuts entries with `strings.LastIndexByte`
|
||||
instead of joining and splitting, so a 1 MB header allocates 16 bytes
|
||||
rather than 1.6 MB per request on the unauthenticated receiver.
|
||||
Semantics proven unchanged by differential testing against the
|
||||
previous implementation (#133)
|
||||
- 2026-08-12 Correct release-blocking documentation inaccuracies: the README
|
||||
promised manual redelivery in the present tense in three places when nothing
|
||||
implements it (the same false claim also sat in the doc comment that was its
|
||||
source text), the env table omitted `RETENTION_SWEEP_INTERVAL`, and `TODO.md`
|
||||
itself omitted five landed units (#141)
|
||||
- 2026-08-12 Make the CI gate execute the checks it reports on. The workflow now
|
||||
writes a build-context fingerprint before calling `script/cibuild`, so a code
|
||||
commit invalidates the `COPY` layer of the lint and builder stages while a
|
||||
docs-only commit still replays from cache; a superseding run also rewrites the
|
||||
`failure` status Gitea leaves on commits it cancelled and never tested.
|
||||
Verified by pushing a deliberately broken test and watching CI go red (#119)
|
||||
- 2026-08-12 Require a positive `RETENTION_SWEEP_INTERVAL`: a non-positive value
|
||||
reached `time.NewTicker` in both the retention reaper and the archive sweeper,
|
||||
panicking two goroutines with no recover after startup had already reported
|
||||
success (#140)
|
||||
- 2026-08-12 Bound the `X-Forwarded-For` scan's allocation to the hop cap: the
|
||||
reverse walk cuts entries with `strings.LastIndexByte` instead of joining and
|
||||
splitting, so a 1 MB header allocates 16 bytes rather than 1.6 MB per request
|
||||
on the unauthenticated receiver. Semantics proven unchanged by differential
|
||||
testing against the previous implementation (#133)
|
||||
- 2026-08-12 Cap the `X-Forwarded-For` hop walk at 64 entries, so an
|
||||
attacker-supplied chain cannot burn unbounded CPU in the rate-limit
|
||||
key function; running off the end falls back to the peer address
|
||||
(#124)
|
||||
- 2026-08-12 Gate forwarded-header trust behind a `TRUSTED_PROXIES` CIDR
|
||||
list: all three rate limiters key on the connection's own address
|
||||
unless the direct peer is a configured proxy, in which case
|
||||
`X-Forwarded-For` is walked right to left for the first non-proxy hop.
|
||||
Default trusts nothing, and a set-but-unparseable value aborts
|
||||
startup. Before this, any client could mint a fresh bucket or drain
|
||||
another's by rotating a spoofed header (#88)
|
||||
- 2026-08-11 Web UI cleanup: nav terminology unified on Webhooks, the
|
||||
Profile settings placeholder removed, a progressive-enhancement copy
|
||||
button for the entrypoint URL, and retention form copy that states the
|
||||
actual policy (deletion by the reaper, 0 retains forever) (#57)
|
||||
- 2026-08-11 Mask the webhook credential in delivery errors and logs:
|
||||
Go embeds the request URL in `*url.Error`, so every transport failure
|
||||
persisted the full Slack webhook URL into the per-webhook event
|
||||
database via `DeliveryResult.Error`, a field a future REST API would
|
||||
have served. `maskURLError` drops path, query and userinfo while
|
||||
preserving the wrapped cause, so `errors.Is`/`As` and `Timeout()`
|
||||
still work and DNS, TLS and timeout failures still read differently
|
||||
(#118)
|
||||
attacker-supplied chain cannot burn unbounded CPU in the rate-limit key
|
||||
function; running off the end falls back to the peer address (#124)
|
||||
- 2026-08-12 Gate forwarded-header trust behind a `TRUSTED_PROXIES` CIDR list:
|
||||
all three rate limiters key on the connection's own address unless the direct
|
||||
peer is a configured proxy, in which case `X-Forwarded-For` is walked right to
|
||||
left for the first non-proxy hop. Default trusts nothing, and a
|
||||
set-but-unparseable value aborts startup. Before this, any client could mint a
|
||||
fresh bucket or drain another's by rotating a spoofed header (#88)
|
||||
- 2026-08-11 Web UI cleanup: nav terminology unified on Webhooks, the Profile
|
||||
settings placeholder removed, a progressive-enhancement copy button for the
|
||||
entrypoint URL, and retention form copy that states the actual policy
|
||||
(deletion by the reaper, 0 retains forever) (#57)
|
||||
- 2026-08-11 Mask the webhook credential in delivery errors and logs: Go embeds
|
||||
the request URL in `*url.Error`, so every transport failure persisted the full
|
||||
Slack webhook URL into the per-webhook event database via
|
||||
`DeliveryResult.Error`, a field a future REST API would have served.
|
||||
`maskURLError` drops path, query and userinfo while preserving the wrapped
|
||||
cause, so `errors.Is`/`As` and `Timeout()` still work and DNS, TLS and timeout
|
||||
failures still read differently (#118)
|
||||
- 2026-08-11 Rate-limit the public webhook receiver endpoint
|
||||
(`RECEIVER_RATE_LIMIT`, default 120/min), keyed on client IP plus
|
||||
entrypoint path so one entrypoint cannot exhaust another's budget;
|
||||
over-limit requests get 429 with `Retry-After`. It was the one
|
||||
unauthenticated, internet-facing endpoint with no limit at all (#64)
|
||||
(`RECEIVER_RATE_LIMIT`, default 120/min), keyed on client IP plus entrypoint
|
||||
path so one entrypoint cannot exhaust another's budget; over-limit requests
|
||||
get 429 with `Retry-After`. It was the one unauthenticated, internet-facing
|
||||
endpoint with no limit at all (#64)
|
||||
- 2026-08-11 Enforce the body size limit before CSRF parses the form:
|
||||
`MaxBodySize` is now first in all four form-parsing route groups, so
|
||||
an oversized request is rejected with 413 instead of being read in
|
||||
full by the CSRF middleware before any cap applied (#90)
|
||||
- 2026-08-11 Mask target config on the source detail page, which
|
||||
rendered the stored blob verbatim and so exposed the Slack
|
||||
incoming-webhook URL — a bearer credential that cannot be revoked
|
||||
per-holder. Config reaches the template only as a `TargetView` of
|
||||
labelled fields, and header values are rendered as a count (#113)
|
||||
- 2026-08-11 Allow `retention_days` of 0 to mean retain forever, via a
|
||||
sentinel written in `BeforeSave` so the GORM column default cannot
|
||||
win the race. Also bounds the reaper's cutoff arithmetic: day counts
|
||||
above 106751 overflowed `time.Duration` and wrapped the cutoff into
|
||||
the future, where every row matched and the sweep deleted everything
|
||||
(#79)
|
||||
`MaxBodySize` is now first in all four form-parsing route groups, so an
|
||||
oversized request is rejected with 413 instead of being read in full by the
|
||||
CSRF middleware before any cap applied (#90)
|
||||
- 2026-08-11 Mask target config on the source detail page, which rendered the
|
||||
stored blob verbatim and so exposed the Slack incoming-webhook URL — a bearer
|
||||
credential that cannot be revoked per-holder. Config reaches the template only
|
||||
as a `TargetView` of labelled fields, and header values are rendered as a
|
||||
count (#113)
|
||||
- 2026-08-11 Allow `retention_days` of 0 to mean retain forever, via a sentinel
|
||||
written in `BeforeSave` so the GORM column default cannot win the race. Also
|
||||
bounds the reaper's cutoff arithmetic: day counts above 106751 overflowed
|
||||
`time.Duration` and wrapped the cutoff into the future, where every row
|
||||
matched and the sweep deleted everything (#79)
|
||||
- 2026-08-09 Inactivity-based session timeout: sliding idle expiry
|
||||
(`SESSION_IDLE_TIMEOUT`, default `24h`) refreshed on authenticated
|
||||
requests, with the 7-day absolute cap kept as an independent
|
||||
backstop that activity never extends (#66)
|
||||
(`SESSION_IDLE_TIMEOUT`, default `24h`) refreshed on authenticated requests,
|
||||
with the 7-day absolute cap kept as an independent backstop that activity
|
||||
never extends (#66)
|
||||
- 2026-08-09 Restart recovery and the 60s retry sweep terminally fail an
|
||||
orphaned `retrying` delivery whose target type no longer supports
|
||||
retries, recording a `DeliveryResult` with the reason instead of
|
||||
leaving the delivery stuck forever (#82)
|
||||
- 2026-08-09 Root the delivery engine's worker pool and the retention
|
||||
reaper's sweep loop at `context.Background()` rather than the fx
|
||||
`OnStart` hook context (#97), which carries fx's 15s start timeout and
|
||||
killed both roughly fifteen seconds after boot: the proxy silently
|
||||
stopped delivering webhooks entirely, and the reaper never ran a
|
||||
single sweep under its default one-hour interval
|
||||
- 2026-08-09 Archive writer lifecycle (#89): deleting a webhook (or its
|
||||
last `database` target) evicts the cached archive writer and closes
|
||||
its handle while deliberately leaving `archive-{webhookID}.db` on
|
||||
disk, and a new `ArchiveSweeper` prunes idle archives on the existing
|
||||
orphaned `retrying` delivery whose target type no longer supports retries,
|
||||
recording a `DeliveryResult` with the reason instead of leaving the delivery
|
||||
stuck forever (#82)
|
||||
- 2026-08-09 Root the delivery engine's worker pool and the retention reaper's
|
||||
sweep loop at `context.Background()` rather than the fx `OnStart` hook context
|
||||
(#97), which carries fx's 15s start timeout and killed both roughly fifteen
|
||||
seconds after boot: the proxy silently stopped delivering webhooks entirely,
|
||||
and the reaper never ran a single sweep under its default one-hour interval
|
||||
- 2026-08-09 Archive writer lifecycle (#89): deleting a webhook (or its last
|
||||
`database` target) evicts the cached archive writer and closes its handle
|
||||
while deliberately leaving `archive-{webhookID}.db` on disk, and a new
|
||||
`ArchiveSweeper` prunes idle archives on the existing
|
||||
`RETENTION_SWEEP_INTERVAL` without ever creating an archive file
|
||||
- 2026-08-09 Configuration parsing fails loudly on set-but-unparseable
|
||||
environment values: `envInt` removed in favour of `envPositiveInt`
|
||||
plus a `PORT` range check, `envBool` now parses with
|
||||
`strconv.ParseBool`, and defaults apply only to unset variables (#80)
|
||||
- 2026-08-07 Automatic event retention cleanup based on
|
||||
`retention_days`, deleting expired events, deliveries, and delivery
|
||||
results from each per-webhook event database (#63)
|
||||
environment values: `envInt` removed in favour of `envPositiveInt` plus a
|
||||
`PORT` range check, `envBool` now parses with `strconv.ParseBool`, and
|
||||
defaults apply only to unset variables (#80)
|
||||
- 2026-08-07 Automatic event retention cleanup based on `retention_days`,
|
||||
deleting expired events, deliveries, and delivery results from each
|
||||
per-webhook event database (#63)
|
||||
- 2026-08-07 Update golangci-lint to v2.12.2 (Docker image digest in
|
||||
`Dockerfile`, release-archive sha256 pins in `script/bootstrap`),
|
||||
adopt the canonical `.golangci.yml` (v2 `linters.settings` layout so
|
||||
`lll`/`funlen`/`cyclop`/`dupl` thresholds actually apply), and fix
|
||||
all newly surfaced lint findings
|
||||
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints,
|
||||
Makefile shims, README Entrypoints section
|
||||
`Dockerfile`, release-archive sha256 pins in `script/bootstrap`), adopt the
|
||||
canonical `.golangci.yml` (v2 `linters.settings` layout so
|
||||
`lll`/`funlen`/`cyclop`/`dupl` thresholds actually apply), and fix all newly
|
||||
surfaced lint findings
|
||||
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints, Makefile
|
||||
shims, README Entrypoints section
|
||||
- 2026-03-25 pin golangci-lint Docker image for linting (#55)
|
||||
- 2026-03-18 CSRF middleware detects TLS per-request, fixing login over
|
||||
plain HTTP and behind reverse proxies (#54)
|
||||
- 2026-03-18 CSRF middleware detects TLS per-request, fixing login over plain
|
||||
HTTP and behind reverse proxies (#54)
|
||||
- 2026-03-17 root path redirects based on auth state (#52)
|
||||
- 2026-03-17 CSRF protection, SSRF prevention for HTTP delivery targets
|
||||
with DNS rebinding defense, and per-IP login rate limiting (#42)
|
||||
- 2026-03-17 CSRF protection, SSRF prevention for HTTP delivery targets with DNS
|
||||
rebinding defense, and per-IP login rate limiting (#42)
|
||||
- 2026-03-17 Slack target type for incoming webhook notifications (#47)
|
||||
- 2026-03-17 Dockerfile absolute paths and static linking (#49);
|
||||
absolute dev DATA_DIR default and clarified env docs (#46)
|
||||
- 2026-03-05 security headers middleware, session regeneration on
|
||||
login, request body size limits (#41)
|
||||
- 2026-03-04 tests for delivery, middleware, and session packages
|
||||
(#32); removed the build-architecture global (#31)
|
||||
- 2026-03-04 1.0 MVP merge: Webhook/Entrypoint/Target rename, core
|
||||
delivery engine with bounded worker pool and circuit breaker,
|
||||
parallel fan-out, per-webhook event databases, management UI (#16)
|
||||
- 2026-03-01 repo brought to REPO_POLICIES standards; TODO.md folded
|
||||
into README (#6)
|
||||
- 2026-03-17 Dockerfile absolute paths and static linking (#49); absolute dev
|
||||
DATA_DIR default and clarified env docs (#46)
|
||||
- 2026-03-05 security headers middleware, session regeneration on login, request
|
||||
body size limits (#41)
|
||||
- 2026-03-04 tests for delivery, middleware, and session packages (#32); removed
|
||||
the build-architecture global (#31)
|
||||
- 2026-03-04 1.0 MVP merge: Webhook/Entrypoint/Target rename, core delivery
|
||||
engine with bounded worker pool and circuit breaker, parallel fan-out,
|
||||
per-webhook event databases, management UI (#16)
|
||||
- 2026-03-01 repo brought to REPO_POLICIES standards; TODO.md folded into README
|
||||
(#6)
|
||||
|
||||
# Future Steps
|
||||
|
||||
- Delivery status and retry management UI. Replay of a terminally
|
||||
failed delivery and per-attempt detail already landed
|
||||
- Delivery status and retry management UI. Replay of a terminally failed
|
||||
delivery and per-attempt detail already landed
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/203,
|
||||
https://git.eeqj.de/sneak/webhooker/issues/202)
|
||||
- Per-webhook rate limiting in the receiver handler (per-webhook config
|
||||
plus handler enforcement; global limits must not apply to receiver
|
||||
endpoints)
|
||||
- API key authentication for programmatic access (APIKey model exists;
|
||||
Bearer token middleware does not)
|
||||
- Per-webhook rate limiting in the receiver handler (per-webhook config plus
|
||||
handler enforcement; global limits must not apply to receiver endpoints)
|
||||
- API key authentication for programmatic access (APIKey model exists; Bearer
|
||||
token middleware does not)
|
||||
- REST API v1
|
||||
- CRUD for webhooks, entrypoints, targets
|
||||
- event viewing and filtering endpoints
|
||||
@@ -406,9 +370,9 @@ point of the branch.
|
||||
- OpenAPI specification
|
||||
- Analytics dashboard: success rates, response times, volume
|
||||
- A remember-me option at login
|
||||
- Password reset flow for a forgotten password over the web. The
|
||||
authenticated password *change* flow already landed, and a lost
|
||||
password is recoverable from the console with `webhooker resetpw`
|
||||
- Password reset flow for a forgotten password over the web. The authenticated
|
||||
password _change_ flow already landed, and a lost password is recoverable from
|
||||
the console with `webhooker resetpw`
|
||||
(https://git.eeqj.de/sneak/webhooker/issues/208)
|
||||
- Later, nice to have
|
||||
- email delivery target type
|
||||
|
||||
@@ -30,8 +30,10 @@ type Event struct {
|
||||
WebhookID string `gorm:"type:uuid;not null" json:"webhookId"`
|
||||
EntrypointID string `gorm:"type:uuid;not null;index:idx_events_entrypoint_id,priority:1" json:"entrypointId"`
|
||||
|
||||
// Request data
|
||||
// Request data. RawQuery is the receiving request's query string
|
||||
// as sent, without the leading "?".
|
||||
Method string `gorm:"not null" json:"method"`
|
||||
RawQuery string `gorm:"type:text" json:"rawQuery"`
|
||||
Headers string `gorm:"type:text" json:"headers"` // JSON
|
||||
Body string `gorm:"type:text" json:"body"`
|
||||
ContentType string `json:"contentType"`
|
||||
|
||||
@@ -110,6 +110,7 @@ type Task struct {
|
||||
MaxRetries int
|
||||
|
||||
Method string
|
||||
RawQuery string
|
||||
Headers string
|
||||
ContentType string
|
||||
Body *string
|
||||
@@ -1752,6 +1753,7 @@ func buildEventFromTask(task *Task) database.Event {
|
||||
event := database.Event{
|
||||
EntrypointID: task.EntrypointID,
|
||||
Method: task.Method,
|
||||
RawQuery: task.RawQuery,
|
||||
Headers: task.Headers,
|
||||
ContentType: task.ContentType,
|
||||
}
|
||||
@@ -2102,6 +2104,7 @@ func buildRecoveryTask(
|
||||
TargetConfig: target.Config,
|
||||
MaxRetries: target.MaxRetries,
|
||||
Method: event.Method,
|
||||
RawQuery: event.RawQuery,
|
||||
Headers: event.Headers,
|
||||
ContentType: event.ContentType,
|
||||
Body: bodyPtr,
|
||||
|
||||
@@ -673,6 +673,11 @@ func TestRecoverPendingDeliveries(t *testing.T) {
|
||||
t, s.WebhookDB, s.WebhookID, targetID, 3,
|
||||
)
|
||||
|
||||
// A recovered delivery still carries its event's query string.
|
||||
require.NoError(t, s.WebhookDB.Model(&database.Event{}).
|
||||
Where("webhook_id = ?", s.WebhookID).
|
||||
Update("raw_query", eventQuery).Error)
|
||||
|
||||
s.Engine.ExportRecoverPendingDeliveries(
|
||||
context.Background(), s.WebhookDB,
|
||||
s.WebhookID,
|
||||
@@ -687,6 +692,8 @@ func TestRecoverPendingDeliveries(t *testing.T) {
|
||||
database.TargetTypeLog,
|
||||
task.TargetType,
|
||||
)
|
||||
|
||||
assert.Equal(t, eventQuery, task.RawQuery)
|
||||
case <-time.After(2 * time.Second):
|
||||
t.Fatalf("expected task %d", i)
|
||||
}
|
||||
|
||||
@@ -11,6 +11,7 @@ import (
|
||||
"net/http/httptest"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strconv"
|
||||
"strings"
|
||||
"sync"
|
||||
"sync/atomic"
|
||||
@@ -1990,6 +1991,10 @@ func assertLogLineComplete(
|
||||
"log line must contain the full request headers",
|
||||
)
|
||||
|
||||
assert.Contains(t, out, "raw_query="+strconv.Quote(event.RawQuery),
|
||||
"log line must contain the query string",
|
||||
)
|
||||
|
||||
assert.Contains(t, out, event.EntrypointID,
|
||||
"log line must contain the entrypoint id",
|
||||
)
|
||||
@@ -2012,6 +2017,7 @@ func TestDeliverLog_LogsFullContent(t *testing.T) {
|
||||
event := seedEvent(
|
||||
t, db, `{"log-body-marker":"abc123"}`,
|
||||
)
|
||||
event.RawQuery = eventQuery
|
||||
|
||||
dlv := seedDelivery(
|
||||
t, db, event.ID, uuid.New().String(),
|
||||
|
||||
@@ -39,6 +39,9 @@ type TargetConfigForm struct {
|
||||
// Timeout is the HTTP target's per-request timeout in seconds,
|
||||
// empty when unset.
|
||||
Timeout string
|
||||
// ForwardQuery is the HTTP target's setting that passes each
|
||||
// event's query string on to it.
|
||||
ForwardQuery bool
|
||||
// Expiry is the database (archive) target's row expiry.
|
||||
Expiry string
|
||||
// Rotation is the database (archive) target's rotation.
|
||||
@@ -67,6 +70,7 @@ func NewTargetConfigForm(
|
||||
URL: cfg.URL,
|
||||
Headers: FormatTargetHeaders(cfg.Headers),
|
||||
Timeout: FormatTargetTimeout(cfg.Timeout),
|
||||
ForwardQuery: cfg.ForwardQuery,
|
||||
}, nil
|
||||
case database.TargetTypeSlack:
|
||||
cfg, err := parseSlackConfig(t.Config)
|
||||
|
||||
@@ -171,6 +171,13 @@ func httpConfigFields(t *database.Target) []ConfigField {
|
||||
})
|
||||
}
|
||||
|
||||
if cfg.ForwardQuery {
|
||||
fields = append(fields, ConfigField{
|
||||
Label: "Query string",
|
||||
Value: "passed on to this target",
|
||||
})
|
||||
}
|
||||
|
||||
fields = append(fields, maxRetriesField(t))
|
||||
|
||||
return fields
|
||||
|
||||
@@ -223,7 +223,8 @@ func TestNewTargetViews_HTTP(t *testing.T) {
|
||||
Type: database.TargetTypeHTTP,
|
||||
Config: `{"url":"` + viewExampleHook + `",` +
|
||||
`"timeout":30,` +
|
||||
`"headers":{"Authorization":"Bearer sekrit"}}`,
|
||||
`"headers":{"Authorization":"Bearer sekrit"},` +
|
||||
`"forwardQuery":true}`,
|
||||
MaxRetries: 5,
|
||||
})
|
||||
|
||||
@@ -235,6 +236,7 @@ func TestNewTargetViews_HTTP(t *testing.T) {
|
||||
"Destination URL": viewMaskedOrigin,
|
||||
"Timeout": "30s",
|
||||
"Headers": "1 configured",
|
||||
"Query string": "passed on to this target",
|
||||
viewMaxRetries: "5",
|
||||
},
|
||||
fields,
|
||||
|
||||
@@ -184,6 +184,7 @@ func (t *databaseTarget) archive(d *database.Delivery) error {
|
||||
WebhookID: webhookID,
|
||||
EntrypointID: d.Event.EntrypointID,
|
||||
Method: d.Event.Method,
|
||||
RawQuery: d.Event.RawQuery,
|
||||
Headers: d.Event.Headers,
|
||||
Body: d.Event.Body,
|
||||
ContentType: d.Event.ContentType,
|
||||
|
||||
@@ -101,6 +101,7 @@ type archivedEvent struct {
|
||||
WebhookID string
|
||||
EntrypointID string
|
||||
Method string
|
||||
RawQuery string
|
||||
Headers string
|
||||
Body string
|
||||
ContentType string
|
||||
|
||||
@@ -360,6 +360,7 @@ func writeRow(w io.Writer, ev *archivedEvent, period string) error {
|
||||
"webhook_id": ev.WebhookID,
|
||||
"entrypoint_id": ev.EntrypointID,
|
||||
"method": ev.Method,
|
||||
"raw_query": ev.RawQuery,
|
||||
"headers": ev.Headers,
|
||||
"body": ev.Body,
|
||||
"content_type": ev.ContentType,
|
||||
|
||||
@@ -166,6 +166,7 @@ func TestArchiveExport_MatchesStoredRows(t *testing.T) {
|
||||
WebhookID: exportWebhookID,
|
||||
EntrypointID: "ep-1",
|
||||
Method: "POST",
|
||||
RawQuery: eventQuery,
|
||||
Headers: `{"X-Test":["yes"]}`,
|
||||
Body: body,
|
||||
ContentType: testContentType,
|
||||
@@ -215,12 +216,13 @@ func assertExportedRow(
|
||||
assert.Equal(t, row.WebhookID, ev["webhook_id"])
|
||||
assert.Equal(t, row.EntrypointID, ev["entrypoint_id"])
|
||||
assert.Equal(t, row.Method, ev["method"])
|
||||
assert.Equal(t, row.RawQuery, ev["raw_query"])
|
||||
assert.Equal(t, row.Headers, ev["headers"])
|
||||
assert.Equal(t, row.ContentType, ev["content_type"])
|
||||
|
||||
if row.Body != binaryBody {
|
||||
assert.Equal(t, row.Body, ev["body"])
|
||||
assert.Len(t, ev, 9, "the nine columns and nothing else: %v", ev)
|
||||
assert.Len(t, ev, 10, "the ten columns and nothing else: %v", ev)
|
||||
|
||||
return
|
||||
}
|
||||
@@ -229,7 +231,7 @@ func assertExportedRow(
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, binaryBody, string(body))
|
||||
assert.Equal(t, "base64", ev["body_encoding"])
|
||||
assert.Len(t, ev, 10, "the nine columns and body_encoding: %v", ev)
|
||||
assert.Len(t, ev, 11, "the ten columns and body_encoding: %v", ev)
|
||||
}
|
||||
|
||||
// TestArchiveExport_Empty proves an archive with nothing in it exports
|
||||
|
||||
@@ -85,6 +85,7 @@ func TestDeliverDatabase_ArchivesEvent(t *testing.T) {
|
||||
|
||||
webhookDB := testWebhookDB(t)
|
||||
event := seedEvent(t, webhookDB, `{"archived":true}`)
|
||||
event.RawQuery = eventQuery
|
||||
d := seedDatabaseTargetDelivery(t, webhookDB, event, tgt)
|
||||
|
||||
env.eng.ExportDeliverDatabase(webhookDB, d)
|
||||
@@ -113,6 +114,7 @@ func TestDeliverDatabase_ArchivesEvent(t *testing.T) {
|
||||
assert.Equal(t, event.ID, rows[0].EventID)
|
||||
assert.Equal(t, event.WebhookID, rows[0].WebhookID)
|
||||
assert.Equal(t, event.Method, rows[0].Method)
|
||||
assert.Equal(t, eventQuery, rows[0].RawQuery)
|
||||
assert.JSONEq(t, `{"archived":true}`, rows[0].Body)
|
||||
}
|
||||
|
||||
|
||||
@@ -8,6 +8,7 @@ import (
|
||||
"fmt"
|
||||
"io"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"sort"
|
||||
"sync"
|
||||
"time"
|
||||
@@ -32,6 +33,11 @@ type HTTPTargetConfig struct {
|
||||
URL string `json:"url"`
|
||||
Headers map[string]string `json:"headers,omitempty"`
|
||||
Timeout int `json:"timeout,omitempty"`
|
||||
|
||||
// ForwardQuery passes each event's query string on to the target,
|
||||
// appended to URL. Off, the target URL is sent exactly as
|
||||
// configured.
|
||||
ForwardQuery bool `json:"forwardQuery,omitempty"`
|
||||
}
|
||||
|
||||
// httpCore holds the retry, backoff, and circuit-breaker
|
||||
@@ -444,6 +450,10 @@ func (t *httpTarget) doHTTPRequest(
|
||||
)
|
||||
}
|
||||
|
||||
if cfg.ForwardQuery {
|
||||
appendQuery(req.URL, event.RawQuery)
|
||||
}
|
||||
|
||||
originScoped := applyRequestHeaders(
|
||||
req, event, cfg, t.eng.userAgent(),
|
||||
)
|
||||
@@ -474,6 +484,19 @@ func (t *httpTarget) doHTTPRequest(
|
||||
return resp.StatusCode, string(body), dur, nil
|
||||
}
|
||||
|
||||
// appendQuery adds an event's query string to a delivery's URL, joined
|
||||
// with "&" to any query string the target URL already has.
|
||||
func appendQuery(u *url.URL, rawQuery string) {
|
||||
switch {
|
||||
case rawQuery == "":
|
||||
return
|
||||
case u.RawQuery == "":
|
||||
u.RawQuery = rawQuery
|
||||
default:
|
||||
u.RawQuery += "&" + rawQuery
|
||||
}
|
||||
}
|
||||
|
||||
// clientForRequest returns the client for one delivery attempt.
|
||||
// originScoped is the header set applyRequestHeaders built for that
|
||||
// attempt; a request with neither a per-target timeout nor an
|
||||
|
||||
@@ -0,0 +1,172 @@
|
||||
package delivery_test
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"testing"
|
||||
|
||||
"github.com/google/uuid"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/delivery"
|
||||
)
|
||||
|
||||
// eventQuery is the query string the events in these tests arrived
|
||||
// with.
|
||||
const eventQuery = "a=1&b=2"
|
||||
|
||||
// httpTargetConfig is the stored configuration of an HTTP target at
|
||||
// targetURL.
|
||||
func httpTargetConfig(
|
||||
t *testing.T, targetURL string, forwardQuery bool,
|
||||
) string {
|
||||
t.Helper()
|
||||
|
||||
cfg, err := json.Marshal(delivery.HTTPTargetConfig{
|
||||
URL: targetURL, ForwardQuery: forwardQuery,
|
||||
})
|
||||
require.NoError(t, err)
|
||||
|
||||
return string(cfg)
|
||||
}
|
||||
|
||||
// deliverWithQuery sends one event that arrived with eventQuery to an
|
||||
// HTTP target configured with cfg, through the path a received event's
|
||||
// delivery takes, and returns the attempt it recorded.
|
||||
func deliverWithQuery(t *testing.T, cfg string) database.DeliveryResult {
|
||||
t.Helper()
|
||||
|
||||
s := newISetup(t)
|
||||
|
||||
event := iSeedEvent(t, s.WebhookDB, s.WebhookID, "{}")
|
||||
d := iSeedDelivery(
|
||||
t, s.WebhookDB, event.ID, uuid.NewString(),
|
||||
database.DeliveryStatusPending,
|
||||
)
|
||||
task := iTask(
|
||||
d, event, s.WebhookID, d.TargetID, "query", cfg, 0, 1, &event.Body,
|
||||
)
|
||||
task.RawQuery = eventQuery
|
||||
|
||||
s.Engine.ExportProcessNewTask(context.TODO(), &task)
|
||||
|
||||
var result database.DeliveryResult
|
||||
|
||||
require.NoError(t, s.WebhookDB.Where(
|
||||
"delivery_id = ?", d.ID,
|
||||
).First(&result).Error)
|
||||
|
||||
return result
|
||||
}
|
||||
|
||||
// TestDeliverHTTP_ForwardQuery proves the URL a delivery is sent to:
|
||||
// with the target's setting off, the target URL exactly as configured;
|
||||
// with it on, the event's query string appended, joined with "&" to a
|
||||
// query string the target URL already has.
|
||||
func TestDeliverHTTP_ForwardQuery(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
// The target URL's path, without and with a query string of its
|
||||
// own.
|
||||
const (
|
||||
plain = "/in"
|
||||
withQuery = "/in?key=k"
|
||||
)
|
||||
|
||||
tests := map[string]struct {
|
||||
path string
|
||||
forwardQuery bool
|
||||
want string
|
||||
}{
|
||||
"off": {
|
||||
path: plain, want: plain,
|
||||
},
|
||||
"off, the target URL has a query string": {
|
||||
path: withQuery, want: withQuery,
|
||||
},
|
||||
"on": {
|
||||
path: plain, forwardQuery: true, want: plain + "?" + eventQuery,
|
||||
},
|
||||
"on, the target URL has a query string": {
|
||||
path: withQuery, forwardQuery: true,
|
||||
want: withQuery + "&" + eventQuery,
|
||||
},
|
||||
}
|
||||
|
||||
for name, tc := range tests {
|
||||
t.Run(name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
received := make(chan string, 1)
|
||||
|
||||
ts := httptest.NewServer(http.HandlerFunc(
|
||||
func(w http.ResponseWriter, r *http.Request) {
|
||||
received <- r.RequestURI
|
||||
|
||||
w.WriteHeader(http.StatusOK)
|
||||
},
|
||||
))
|
||||
t.Cleanup(ts.Close)
|
||||
|
||||
result := deliverWithQuery(t, httpTargetConfig(
|
||||
t, ts.URL+tc.path, tc.forwardQuery,
|
||||
))
|
||||
|
||||
assert.True(t, result.Success)
|
||||
require.Len(t, received, 1)
|
||||
assert.Equal(t, tc.want, <-received)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// TestDeliverHTTP_ForwardedQueryKeepsTheTargetURLMasked proves the
|
||||
// credential in a target URL's own query string stays masked once the
|
||||
// event's query string is appended to it: in a response or error that
|
||||
// echoes the URL the target was sent, as the event log's Redactor shows
|
||||
// it, and in the error a failed connection stores.
|
||||
func TestDeliverHTTP_ForwardedQueryKeepsTheTargetURLMasked(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
const secret = "s3cr3t"
|
||||
|
||||
received := make(chan string, 1)
|
||||
|
||||
ts := httptest.NewServer(http.HandlerFunc(
|
||||
func(w http.ResponseWriter, r *http.Request) {
|
||||
received <- r.RequestURI
|
||||
|
||||
w.WriteHeader(http.StatusBadRequest)
|
||||
},
|
||||
))
|
||||
t.Cleanup(ts.Close)
|
||||
|
||||
target := &database.Target{
|
||||
Type: database.TargetTypeHTTP,
|
||||
Config: httpTargetConfig(t, ts.URL+"/in?token="+secret, true),
|
||||
}
|
||||
|
||||
deliverWithQuery(t, target.Config)
|
||||
require.Len(t, received, 1)
|
||||
|
||||
sent := <-received
|
||||
require.Equal(t, "/in?token="+secret+"&"+eventQuery, sent)
|
||||
|
||||
redactor := delivery.NewRedactor(target)
|
||||
|
||||
for _, echoed := range []string{sent, ts.URL + sent} {
|
||||
shown := redactor.Redact("rejected " + echoed)
|
||||
assert.NotContains(t, shown, secret, echoed)
|
||||
assert.Contains(t, shown, delivery.RedactionMarker, echoed)
|
||||
}
|
||||
|
||||
// Nothing listens on port 1.
|
||||
failed := deliverWithQuery(t, httpTargetConfig(
|
||||
t, "http://127.0.0.1:1/in?token="+secret, true,
|
||||
))
|
||||
require.NotEmpty(t, failed.Error)
|
||||
assert.NotContains(t, failed.Error, secret)
|
||||
assert.NotContains(t, failed.Error, eventQuery)
|
||||
}
|
||||
@@ -9,9 +9,9 @@ import (
|
||||
)
|
||||
|
||||
// logTarget is a fire-and-forget target that logs the entire
|
||||
// inbound webhook — the full request body and headers, plus
|
||||
// the method, content type, and the webhook and entrypoint
|
||||
// ids — then records a single successful attempt.
|
||||
// inbound webhook — the full request body, query string and
|
||||
// headers, plus the method, content type, and the webhook and
|
||||
// entrypoint ids — then records a single successful attempt.
|
||||
//
|
||||
// This is the one log call in the service that deliberately writes
|
||||
// unbounded client-chosen bytes, so it is the one exception to the
|
||||
@@ -46,6 +46,7 @@ func (t *logTarget) Deliver(
|
||||
"webhook_id", d.Event.WebhookID,
|
||||
"entrypoint_id", d.Event.EntrypointID,
|
||||
"method", d.Event.Method,
|
||||
"raw_query", d.Event.RawQuery,
|
||||
"content_type", d.Event.ContentType,
|
||||
"headers", d.Event.Headers,
|
||||
"body", d.Event.Body,
|
||||
|
||||
@@ -162,18 +162,22 @@ func targetSecrets(t *database.Target) []string {
|
||||
}
|
||||
|
||||
// urlSecrets returns the substrings of a destination URL that
|
||||
// must not survive into a rendered page: the whole URL, the
|
||||
// parts of it MaskURL elides, and any userinfo.
|
||||
// must not survive into a rendered page: the whole URL; its
|
||||
// path, unless that is empty or "/"; its query string, and the
|
||||
// request URI that carries it, which a remote echoing the
|
||||
// request line shows even when the URL has no path; and its
|
||||
// userinfo and password.
|
||||
//
|
||||
// No length floor is applied to the path, and none to the
|
||||
// userinfo. A short path or a four-byte username is treated as
|
||||
// a credential exactly like a long one, because the field takes
|
||||
// an arbitrary URL and no part of it can be assumed non-secret —
|
||||
// the same rule MaskURL applies. headerSecrets does carry a
|
||||
// floor, and the difference is deliberate: a header is picked
|
||||
// out by a name-shaped guess and its value may be ordinary
|
||||
// text, whereas a URL's path and userinfo are credential
|
||||
// material by position.
|
||||
// No length floor is applied to the path, the query string or
|
||||
// the userinfo. A short path or a four-byte username is
|
||||
// treated as a credential exactly like a long one, because the
|
||||
// field takes an arbitrary URL and no part of it can be
|
||||
// assumed non-secret — the same rule MaskURL applies.
|
||||
// headerSecrets does carry a floor, and the difference is
|
||||
// deliberate: a header is picked out by a name-shaped guess
|
||||
// and its value may be ordinary text, whereas a URL's path,
|
||||
// query string and userinfo are credential material by
|
||||
// position.
|
||||
func urlSecrets(raw string) []string {
|
||||
raw = strings.TrimSpace(raw)
|
||||
if raw == "" {
|
||||
@@ -188,12 +192,11 @@ func urlSecrets(raw string) []string {
|
||||
}
|
||||
|
||||
if parsed.Path != "" && parsed.Path != "/" {
|
||||
requestURI := parsed.RequestURI()
|
||||
secrets = append(secrets, requestURI)
|
||||
|
||||
if escaped := parsed.EscapedPath(); escaped != requestURI {
|
||||
secrets = append(secrets, escaped)
|
||||
secrets = append(secrets, parsed.EscapedPath())
|
||||
}
|
||||
|
||||
if parsed.RawQuery != "" {
|
||||
secrets = append(secrets, parsed.RequestURI(), parsed.RawQuery)
|
||||
}
|
||||
|
||||
if parsed.User != nil {
|
||||
|
||||
@@ -202,6 +202,48 @@ func TestRedactor_RemovesHTTPURLQueryAndUserinfo(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// TestRedactor_RemovesEchoedQueryOfURLWithoutPath covers an
|
||||
// HTTP target URL whose credential is all in its query string.
|
||||
// Written with or without the "/", the request line sends it
|
||||
// as "/?token=…", and a target passing the event's query string
|
||||
// on sends that after an "&". The event's part stays visible:
|
||||
// the event's page shows it anyway.
|
||||
func TestRedactor_RemovesEchoedQueryOfURLWithoutPath(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
const secret = "s3cr3t"
|
||||
|
||||
marker := delivery.RedactionMarker
|
||||
|
||||
// An echoed request line, and what the event log shows of it.
|
||||
echoes := map[string]string{
|
||||
"POST /?token=" + secret + " HTTP/1.1": "POST " + marker +
|
||||
" HTTP/1.1",
|
||||
"POST ?token=" + secret + " HTTP/1.1": "POST ?" + marker +
|
||||
" HTTP/1.1",
|
||||
"POST /?token=" + secret + "&a=1&b=2 HTTP/1.1": "POST " +
|
||||
marker + "&a=1&b=2 HTTP/1.1",
|
||||
"POST ?token=" + secret + "&a=1&b=2 HTTP/1.1": "POST ?" +
|
||||
marker + "&a=1&b=2 HTTP/1.1",
|
||||
}
|
||||
|
||||
for _, dest := range []string{
|
||||
"https://example.com/?token=" + secret,
|
||||
"https://example.com?token=" + secret,
|
||||
} {
|
||||
r := delivery.NewRedactor(&database.Target{
|
||||
Type: database.TargetTypeHTTP,
|
||||
Config: `{"url":"` + dest + `"}`,
|
||||
})
|
||||
|
||||
for echoed, want := range echoes {
|
||||
assert.Equal(
|
||||
t, want, r.Redact(echoed), "%s: %s", dest, echoed,
|
||||
)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// TestRedactor_LeavesUnrelatedTextAlone pins that the
|
||||
// redactor matches literally: it does not guess at what a
|
||||
// secret looks like, so ordinary response content survives.
|
||||
|
||||
@@ -310,6 +310,7 @@ func createReplayDelivery(
|
||||
TargetConfig: target.Config,
|
||||
MaxRetries: target.MaxRetries,
|
||||
Method: event.Method,
|
||||
RawQuery: event.RawQuery,
|
||||
Headers: event.Headers,
|
||||
ContentType: event.ContentType,
|
||||
Body: replayBody(event.Body),
|
||||
|
||||
@@ -26,6 +26,9 @@ const paramDeliveryID = "deliveryID"
|
||||
// dispatches to it: the notifier is recorded, not run.
|
||||
const replayTargetURL = "http://93.184.216.34/hook"
|
||||
|
||||
// replayEventQuery is the query string a seeded event arrived with.
|
||||
const replayEventQuery = "a=1&b=2"
|
||||
|
||||
// seedFailedDelivery records an event, a terminally failed delivery of
|
||||
// it to the given target, and the attempt that failed.
|
||||
func seedFailedDelivery(
|
||||
@@ -42,6 +45,7 @@ func seedFailedDelivery(
|
||||
WebhookID: webhookID,
|
||||
EntrypointID: "entrypoint-" + webhookID,
|
||||
Method: http.MethodPost,
|
||||
RawQuery: replayEventQuery,
|
||||
Headers: `{"X-Test":["yes"]}`,
|
||||
Body: `{"replay":"me"}`,
|
||||
ContentType: contentTypeJSON,
|
||||
@@ -296,6 +300,10 @@ func assertReplayTask(
|
||||
"replay must use the target's current configuration",
|
||||
)
|
||||
assert.Equal(t, event.Method, task.Method)
|
||||
assert.Equal(
|
||||
t, replayEventQuery, task.RawQuery,
|
||||
"replay re-sends the stored query string",
|
||||
)
|
||||
assert.Equal(t, event.Headers, task.Headers)
|
||||
assert.Equal(t, event.ContentType, task.ContentType)
|
||||
assert.Equal(t, 1, task.AttemptNum)
|
||||
|
||||
@@ -324,7 +324,8 @@ func loadEventLogRows(
|
||||
var rows []eventLogRow
|
||||
|
||||
err = eventsWithStatus(webhookDB, webhookID, statuses).Select(
|
||||
eventLogColumns, maxRenderedBodyBytes, maxRenderedBodyBytes,
|
||||
eventLogColumns,
|
||||
maxRenderedBodyBytes, maxRenderedBodyBytes, maxRenderedBodyBytes,
|
||||
).Order("created_at DESC").Limit(recentEventLimit).Find(&rows).Error
|
||||
|
||||
return rows, totalEvents, err
|
||||
|
||||
@@ -17,19 +17,23 @@ import (
|
||||
// bytes rather than characters, so the cap bounds the page in
|
||||
// bytes whatever the payload's encoding. Cutting in SQLite
|
||||
// rather than in Go is the point of the projection — an
|
||||
// oversized body or set of request headers never becomes a Go
|
||||
// string at all.
|
||||
// oversized body, query string or set of request headers never
|
||||
// becomes a Go string at all.
|
||||
const eventLogColumns = "id, created_at, method, content_type, " +
|
||||
"resubmitted_from_id, entrypoint_id, " +
|
||||
"substr(cast(raw_query as blob), 1, ?) AS raw_query, " +
|
||||
"length(cast(raw_query as blob)) AS raw_query_bytes, " +
|
||||
"substr(cast(headers as blob), 1, ?) AS headers, " +
|
||||
"length(cast(headers as blob)) AS headers_bytes, " +
|
||||
"substr(cast(body as blob), 1, ?) AS body, " +
|
||||
"length(cast(body as blob)) AS body_bytes"
|
||||
|
||||
// eventColumns is eventLogColumns for the event's own page, which
|
||||
// shows the whole body and every request header.
|
||||
// shows the whole body, the whole query string and every request
|
||||
// header.
|
||||
const eventColumns = "id, created_at, method, content_type, " +
|
||||
"resubmitted_from_id, entrypoint_id, headers, " +
|
||||
"resubmitted_from_id, entrypoint_id, raw_query, " +
|
||||
"length(cast(raw_query as blob)) AS raw_query_bytes, headers, " +
|
||||
"length(cast(headers as blob)) AS headers_bytes, " +
|
||||
"cast(body as blob) AS body, " +
|
||||
"length(cast(body as blob)) AS body_bytes"
|
||||
@@ -57,6 +61,13 @@ type EventLogView struct {
|
||||
// entrypoint's secret.
|
||||
Entrypoint string
|
||||
|
||||
// RawQuery is the query string the event arrived with.
|
||||
// RawQueryCut reports one left out, RawQuery then empty, because
|
||||
// it holds more than maxRenderedBodyBytes; only the event log
|
||||
// leaves it out.
|
||||
RawQuery string
|
||||
RawQueryCut bool
|
||||
|
||||
// Headers is the event's request headers as text, one
|
||||
// "Name: value" line per value, sorted by name. HeadersCut
|
||||
// reports headers left out because they hold more than
|
||||
@@ -85,9 +96,9 @@ func (v EventLogView) ResubmittedFrom() bool {
|
||||
}
|
||||
|
||||
// eventLogRow is one row of the event log projection, or of
|
||||
// eventColumns. In the event log its headers and body columns
|
||||
// arrive already cut to the cap by SQLite, each with its true
|
||||
// size beside it.
|
||||
// eventColumns. In the event log its query string, headers and
|
||||
// body columns arrive already cut to the cap by SQLite, each with
|
||||
// its true size beside it.
|
||||
type eventLogRow struct {
|
||||
ID string
|
||||
CreatedAt time.Time
|
||||
@@ -95,6 +106,8 @@ type eventLogRow struct {
|
||||
ContentType string
|
||||
ResubmittedFromID *string
|
||||
EntrypointID string
|
||||
RawQuery string
|
||||
RawQueryBytes int64
|
||||
Headers string
|
||||
HeadersBytes int64
|
||||
Body []byte
|
||||
@@ -114,6 +127,13 @@ func (r *eventLogRow) view(
|
||||
|
||||
headers, fit := requestHeaderLines(r.Headers, maxHeaderBytes)
|
||||
|
||||
rawQuery := r.RawQuery
|
||||
rawQueryCut := r.RawQueryBytes > int64(len(rawQuery))
|
||||
|
||||
if rawQueryCut {
|
||||
rawQuery = ""
|
||||
}
|
||||
|
||||
return EventLogView{
|
||||
ID: r.ID,
|
||||
Method: r.Method,
|
||||
@@ -123,6 +143,8 @@ func (r *eventLogRow) view(
|
||||
Body: newBodyView(
|
||||
"/hook/"+webhookID+"/events/"+r.ID, r.Body, r.BodyBytes,
|
||||
),
|
||||
RawQuery: rawQuery,
|
||||
RawQueryCut: rawQueryCut,
|
||||
Headers: strings.Join(headers, "\n"),
|
||||
HeadersCut: !fit || r.HeadersBytes > int64(len(r.Headers)),
|
||||
ResubmittedFromID: from,
|
||||
|
||||
@@ -1,13 +1,16 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"slices"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/go-chi/chi"
|
||||
"github.com/google/uuid"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
@@ -17,14 +20,15 @@ import (
|
||||
|
||||
// arrivedAt is how a page names the entrypoint an event arrived at.
|
||||
func arrivedAt(name string) string {
|
||||
return `Arrived at <span class="text-gray-900">` + name + `</span>`
|
||||
return `Arrived at <span class="text-gray-900 wrap-anywhere">` + name +
|
||||
`</span>`
|
||||
}
|
||||
|
||||
// copiedRequestArrivedAt is how a page names, for a resubmitted copy,
|
||||
// the entrypoint the request it copies arrived at.
|
||||
func copiedRequestArrivedAt(name string) string {
|
||||
return `The request it copies arrived at <span class="text-gray-900">` +
|
||||
name + `</span>`
|
||||
return `The request it copies arrived at ` +
|
||||
`<span class="text-gray-900 wrap-anywhere">` + name + `</span>`
|
||||
}
|
||||
|
||||
// headerBox is how a page shows an event's request header lines: as
|
||||
@@ -115,6 +119,7 @@ func TestEventRequest_EachEventShowsItsOwnEntrypointAndHeaders(
|
||||
t.Helper()
|
||||
|
||||
assert.Contains(t, page, arrivedAt("Billing sender"))
|
||||
assert.Contains(t, page, "No query string.")
|
||||
assert.Contains(t, page, headerBox(
|
||||
"Accept: */*",
|
||||
"User-Agent: shop/1 build\t7",
|
||||
@@ -330,3 +335,70 @@ func TestEventRequest_ManyShortHeaderLines(t *testing.T) {
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// TestHandleWebhook_StoresAndShowsTheQueryString posts to an
|
||||
// entrypoint's URL with a query string and proves the event stores it
|
||||
// as sent, and shows it escaped in the event log and on its own page,
|
||||
// in a box like the one the request headers show in.
|
||||
func TestHandleWebhook_StoresAndShowsTheQueryString(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
f := newRecentEventsFixture(t)
|
||||
ep := seedEntrypoint(t, f.db, f.webhook.ID)
|
||||
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(), http.MethodPost,
|
||||
"/h/"+ep.Path+"?a=1&b=2", strings.NewReader("{}"),
|
||||
)
|
||||
|
||||
rctx := chi.NewRouteContext()
|
||||
rctx.URLParams.Add("uuid", ep.Path)
|
||||
|
||||
req = req.WithContext(context.WithValue(
|
||||
req.Context(), chi.RouteCtxKey, rctx,
|
||||
))
|
||||
|
||||
w := httptest.NewRecorder()
|
||||
f.h.HandleWebhook().ServeHTTP(w, req)
|
||||
|
||||
require.Equal(t, http.StatusOK, w.Code)
|
||||
|
||||
var stored database.Event
|
||||
|
||||
require.NoError(t, f.webhookDB.First(&stored).Error)
|
||||
assert.Equal(t, "a=1&b=2", stored.RawQuery)
|
||||
|
||||
page := renderSourceLogsPage(t, f.h, f.sess, f.webhook.ID)
|
||||
assert.Contains(t, page, headerBox("a=1&b=2"))
|
||||
|
||||
w = serveEventPage(t, f.h, f.sess, f.webhook.ID, stored.ID)
|
||||
require.Equal(t, http.StatusOK, w.Code)
|
||||
assert.Contains(t, w.Body.String(), headerBox("a=1&b=2"))
|
||||
}
|
||||
|
||||
// TestEventRequest_QueryStringOverTheLimit proves the event log leaves
|
||||
// out a query string that holds more than it shows of a body, and links
|
||||
// to the event's own page, which shows it whole.
|
||||
func TestEventRequest_QueryStringOverTheLimit(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
f := newRecentEventsFixture(t)
|
||||
ep := f.entrypoint(t, "Billing sender")
|
||||
event := f.eventAt(t, ep, `{}`, time.Now())
|
||||
query := "q=" + strings.Repeat("x", bodyCap)
|
||||
|
||||
require.NoError(t, f.webhookDB.Model(event).Update(
|
||||
"raw_query", query,
|
||||
).Error)
|
||||
|
||||
page := renderSourceLogsPage(t, f.h, f.sess, f.webhook.ID)
|
||||
assert.Contains(t, page, `<a href="/hook/`+f.webhook.ID+`/events/`+
|
||||
event.ID+`" class="btn-small">Show the query string</a>`)
|
||||
assert.NotContains(t, page, "q=x")
|
||||
assert.Less(t, len(page), 4*bodyCap)
|
||||
|
||||
w := serveEventPage(t, f.h, f.sess, f.webhook.ID, event.ID)
|
||||
require.Equal(t, http.StatusOK, w.Code)
|
||||
assert.Contains(t, w.Body.String(), headerBox(query))
|
||||
assert.NotContains(t, w.Body.String(), "Show the query string")
|
||||
}
|
||||
|
||||
@@ -30,6 +30,7 @@ type resubmitSource struct {
|
||||
ID string
|
||||
EntrypointID string
|
||||
Method string
|
||||
RawQuery string
|
||||
Headers string
|
||||
ContentType string
|
||||
Body []byte
|
||||
@@ -39,7 +40,7 @@ type resubmitSource struct {
|
||||
// The cast to blob is what makes the driver hand back the stored bytes
|
||||
// rather than a string conversion, the same reason eventBodyQuery
|
||||
// casts.
|
||||
const resubmitColumns = "id, entrypoint_id, method, headers, " +
|
||||
const resubmitColumns = "id, entrypoint_id, method, raw_query, headers, " +
|
||||
"content_type, cast(body as blob) AS body"
|
||||
|
||||
// HandleEventResubmit re-injects a stored event as a new undelivered
|
||||
@@ -193,6 +194,7 @@ func (h *Handlers) queueResubmit(
|
||||
WebhookID: webhook.ID,
|
||||
EntrypointID: src.EntrypointID,
|
||||
Method: src.Method,
|
||||
RawQuery: src.RawQuery,
|
||||
HeadersJSON: src.Headers,
|
||||
ContentType: src.ContentType,
|
||||
Body: src.Body,
|
||||
|
||||
@@ -22,9 +22,13 @@ import (
|
||||
// dispatches to it: the notifier is recorded, not run.
|
||||
const resubmitTargetURL = "http://93.184.216.34/hook"
|
||||
|
||||
// resubmitEventHeaders is the stored header JSON a seeded event
|
||||
// carries, so a test can prove the copy takes it verbatim.
|
||||
const resubmitEventHeaders = `{"X-Test":["yes"],"X-Trace":["abc"]}`
|
||||
// resubmitEventHeaders and resubmitEventQuery are the stored header
|
||||
// JSON and query string a seeded event carries, so a test can prove the
|
||||
// copy takes them verbatim.
|
||||
const (
|
||||
resubmitEventHeaders = `{"X-Test":["yes"],"X-Trace":["abc"]}`
|
||||
resubmitEventQuery = "a=1&b=2"
|
||||
)
|
||||
|
||||
// seedStoredEvent records one event in a webhook's own database with
|
||||
// no deliveries at all, which is the state a captured event is in when
|
||||
@@ -43,6 +47,7 @@ func seedStoredEvent(
|
||||
WebhookID: webhookID,
|
||||
EntrypointID: "entrypoint-" + webhookID,
|
||||
Method: http.MethodPost,
|
||||
RawQuery: resubmitEventQuery,
|
||||
Headers: resubmitEventHeaders,
|
||||
Body: body,
|
||||
ContentType: contentTypeJSON,
|
||||
@@ -202,6 +207,7 @@ func assertEventCopy(
|
||||
t.Helper()
|
||||
|
||||
assert.Equal(t, original.Method, fresh.Method)
|
||||
assert.Equal(t, resubmitEventQuery, fresh.RawQuery)
|
||||
assert.Equal(t, original.Headers, fresh.Headers)
|
||||
assert.Equal(t, original.Body, fresh.Body)
|
||||
assert.Equal(t, int64(len(original.Body)), fresh.BodyBytes)
|
||||
@@ -236,6 +242,7 @@ func assertResubmitTask(
|
||||
assert.Equal(t, target.ID, task.TargetID)
|
||||
assert.Equal(t, target.Type, task.TargetType)
|
||||
assert.Equal(t, fresh.Method, task.Method)
|
||||
assert.Equal(t, fresh.RawQuery, task.RawQuery)
|
||||
assert.Equal(t, fresh.Headers, task.Headers)
|
||||
assert.Equal(t, fresh.ContentType, task.ContentType)
|
||||
assert.Equal(t, 1, task.AttemptNum)
|
||||
|
||||
@@ -173,6 +173,9 @@ type targetFormInput struct {
|
||||
Headers string
|
||||
// Timeout is an HTTP target's per-request timeout in seconds.
|
||||
Timeout string
|
||||
// ForwardQuery is an HTTP target's checkbox that passes each
|
||||
// event's query string on to it.
|
||||
ForwardQuery bool
|
||||
// MaxRetries is an HTTP or Slack target's max_retries.
|
||||
MaxRetries string
|
||||
// Expiry is a database (archive) target's row expiry.
|
||||
@@ -200,6 +203,7 @@ func targetFormInputFrom(r *http.Request) targetFormInput {
|
||||
URL: r.PostFormValue("url"),
|
||||
Headers: r.PostFormValue("headers"),
|
||||
Timeout: r.PostFormValue("timeout"),
|
||||
ForwardQuery: r.PostFormValue("forward_query") != "",
|
||||
MaxRetries: r.PostFormValue("max_retries"),
|
||||
Expiry: r.PostFormValue("expiry"),
|
||||
Rotation: r.PostFormValue("rotation"),
|
||||
@@ -232,8 +236,8 @@ func (h *Handlers) buildTargetConfig(
|
||||
}
|
||||
|
||||
// buildHTTPTargetConfig builds config JSON for an HTTP target: an
|
||||
// SSRF-validated destination plus the optional headers and timeout
|
||||
// the delivery path honours.
|
||||
// SSRF-validated destination plus the optional headers, timeout and
|
||||
// query string setting the delivery path honours.
|
||||
func (h *Handlers) buildHTTPTargetConfig(
|
||||
ctx context.Context,
|
||||
in targetFormInput,
|
||||
@@ -259,6 +263,7 @@ func (h *Handlers) buildHTTPTargetConfig(
|
||||
URL: in.URL,
|
||||
Headers: headers,
|
||||
Timeout: timeout,
|
||||
ForwardQuery: in.ForwardQuery,
|
||||
})
|
||||
|
||||
return configJSON, "", err
|
||||
|
||||
@@ -81,6 +81,7 @@ func (h *Handlers) HandleTargetEdit() http.HandlerFunc {
|
||||
URL: cfg.URL,
|
||||
Headers: cfg.Headers,
|
||||
Timeout: cfg.Timeout,
|
||||
ForwardQuery: cfg.ForwardQuery,
|
||||
MaxRetries: strconv.Itoa(target.MaxRetries),
|
||||
Expiry: cfg.Expiry,
|
||||
Rotation: cfg.Rotation,
|
||||
|
||||
@@ -442,6 +442,59 @@ func TestHandleTargetEdit_CallsTheDatabaseTypeArchive(t *testing.T) {
|
||||
assert.Contains(t, page, `class="label">Archive rotation</label>`)
|
||||
}
|
||||
|
||||
// TestHandleTarget_ForwardQuery covers the HTTP target's setting that
|
||||
// passes each event's query string on to it: the add target form
|
||||
// stores it checked, the edit form starts with it checked and turns it
|
||||
// off when saved unchecked, and both forms come back with it checked
|
||||
// when refused.
|
||||
func TestHandleTarget_ForwardQuery(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
const checkbox = `name="forward_query" value="on" checked`
|
||||
|
||||
env := setupSourceTest(t)
|
||||
webhook := seedWebhookWithRetention(t, env.db, 30)
|
||||
targetsPath := "/hook/" + webhook.ID + "/targets"
|
||||
|
||||
form := url.Values{}
|
||||
form.Set("name", "forwarding")
|
||||
form.Set("type", string(database.TargetTypeHTTP))
|
||||
form.Set("url", editOriginalURL)
|
||||
form.Set("forward_query", "on")
|
||||
|
||||
w := serveTarget(env, http.MethodPost, targetsPath, form)
|
||||
require.Equal(t, http.StatusSeeOther, w.Code, w.Body.String())
|
||||
|
||||
targets := targetsForWebhook(t, env.db, webhook.ID)
|
||||
require.Len(t, targets, 1)
|
||||
assert.True(t, storedHTTPConfig(t, env, targets[0].ID).ForwardQuery)
|
||||
|
||||
w = serveTarget(
|
||||
env, http.MethodGet, targetsPath+"/"+targets[0].ID+"/edit", nil,
|
||||
)
|
||||
require.Equal(t, http.StatusOK, w.Code)
|
||||
assert.Contains(t, w.Body.String(), checkbox)
|
||||
|
||||
edit := editForm(editOriginalURL, "", "")
|
||||
|
||||
w = submitTargetEdit(env, webhook.ID, targets[0].ID, edit)
|
||||
require.Equal(t, http.StatusSeeOther, w.Code, w.Body.String())
|
||||
assert.False(t, storedHTTPConfig(t, env, targets[0].ID).ForwardQuery)
|
||||
|
||||
edit.Set("url", editBlockedURL)
|
||||
edit.Set("forward_query", "on")
|
||||
|
||||
w = submitTargetEdit(env, webhook.ID, targets[0].ID, edit)
|
||||
require.Equal(t, http.StatusBadRequest, w.Code)
|
||||
assert.Contains(t, w.Body.String(), checkbox)
|
||||
|
||||
form.Set("url", editBlockedURL)
|
||||
|
||||
w = serveTarget(env, http.MethodPost, targetsPath, form)
|
||||
require.Equal(t, http.StatusBadRequest, w.Code)
|
||||
assert.Contains(t, w.Body.String(), "data-forward-query")
|
||||
}
|
||||
|
||||
// TestHandleTargetEditSubmit_Rejects covers every submission that
|
||||
// must not reach storage.
|
||||
//
|
||||
|
||||
@@ -230,6 +230,7 @@ type eventSource struct {
|
||||
WebhookID string
|
||||
EntrypointID string
|
||||
Method string
|
||||
RawQuery string
|
||||
HeadersJSON string
|
||||
ContentType string
|
||||
Body []byte
|
||||
@@ -245,6 +246,7 @@ func (s eventSource) event() *database.Event {
|
||||
WebhookID: s.WebhookID,
|
||||
EntrypointID: s.EntrypointID,
|
||||
Method: s.Method,
|
||||
RawQuery: s.RawQuery,
|
||||
Headers: s.HeadersJSON,
|
||||
Body: string(s.Body),
|
||||
BodyBytes: int64(len(s.Body)),
|
||||
@@ -264,6 +266,7 @@ func requestEventSource(
|
||||
WebhookID: entrypoint.WebhookID,
|
||||
EntrypointID: entrypoint.ID,
|
||||
Method: r.Method,
|
||||
RawQuery: r.URL.RawQuery,
|
||||
HeadersJSON: string(headersJSON),
|
||||
ContentType: r.Header.Get("Content-Type"),
|
||||
Body: body,
|
||||
@@ -441,6 +444,7 @@ func buildDeliveryTasks(
|
||||
TargetConfig: targets[i].Config,
|
||||
MaxRetries: targets[i].MaxRetries,
|
||||
Method: event.Method,
|
||||
RawQuery: event.RawQuery,
|
||||
Headers: event.Headers,
|
||||
ContentType: event.ContentType,
|
||||
Body: bodyPtr,
|
||||
|
||||
@@ -98,20 +98,25 @@ func TestAlpineRunsUnderTheSecurityPolicy(t *testing.T) {
|
||||
checkRefusedNewWebhook(ctx, t, srv.URL+"/hooks/new")
|
||||
checkEventLog(ctx, t, page+"/events", event.ID, older.ID, target.Name)
|
||||
checkMobileMenu(ctx, t, page)
|
||||
checkPhoneWidth(ctx, t, page, page+"/events", target.Name)
|
||||
|
||||
assert.Empty(t, problems(), "the browser reported problems")
|
||||
}
|
||||
|
||||
// seedBrowserWebhook seeds the webhook the browser test loads, owned by
|
||||
// userID: an entrypoint, two events, and a target whose delivery of the
|
||||
// newer event failed once with a 502. It returns the webhook, the older
|
||||
// and the newer event, and the target.
|
||||
// newer event failed once with a 502. The webhook's name and the newer
|
||||
// event's content type are each too long for one line on a phone. It
|
||||
// returns the webhook, the older and the newer event, and the target.
|
||||
func seedBrowserWebhook(
|
||||
t *testing.T, env *testEnv, userID string,
|
||||
) (*database.Webhook, *database.Event, *database.Event, *database.Target) {
|
||||
t.Helper()
|
||||
|
||||
webhook := env.seedWebhook(t, userID)
|
||||
require.NoError(t, env.db.DB().Model(webhook).Update(
|
||||
"name", "payment_provider_production_notifications",
|
||||
).Error)
|
||||
require.NoError(t, env.db.DB().Omit(clause.Associations).Create(
|
||||
&database.Entrypoint{
|
||||
WebhookID: webhook.ID,
|
||||
@@ -126,6 +131,9 @@ func seedBrowserWebhook(
|
||||
|
||||
webhookDB, err := env.dbMgr.GetDB(webhook.ID)
|
||||
require.NoError(t, err)
|
||||
require.NoError(t, webhookDB.Model(event).Update(
|
||||
"content_type", "application/vnd.paymentprovider.event+json",
|
||||
).Error)
|
||||
require.NoError(t, webhookDB.Omit(clause.Associations).Create(
|
||||
&database.DeliveryResult{
|
||||
DeliveryID: dlv.ID,
|
||||
@@ -501,6 +509,7 @@ func checkRefusedTarget(ctx context.Context, t *testing.T, url string) {
|
||||
const (
|
||||
refusedURL = "http://127.0.0.1/hook"
|
||||
urlField = `form[action$="/targets"] input[name="url"]`
|
||||
forwardQuery = `form[action$="/targets"] input[name="forward_query"]`
|
||||
reason = `//div[@class="alert-error"]`
|
||||
)
|
||||
|
||||
@@ -511,6 +520,7 @@ func checkRefusedTarget(ctx context.Context, t *testing.T, url string) {
|
||||
ctx,
|
||||
chromedp.SetValue(targetName, "refused", chromedp.ByQuery),
|
||||
chromedp.SetValue(urlField, refusedURL, chromedp.ByQuery),
|
||||
chromedp.Click(forwardQuery, chromedp.ByQuery),
|
||||
))
|
||||
|
||||
click(ctx, t, saveButton)
|
||||
@@ -518,18 +528,26 @@ func checkRefusedTarget(ctx context.Context, t *testing.T, url string) {
|
||||
assert.True(t, shown(ctx, reason),
|
||||
"a refused target does not show the reason")
|
||||
|
||||
var name, typed string
|
||||
var (
|
||||
name, typed string
|
||||
checked bool
|
||||
)
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
chromedp.Value(targetName, &name, chromedp.ByQuery),
|
||||
chromedp.Value(urlField, &typed, chromedp.ByQuery),
|
||||
chromedp.JavascriptAttribute(
|
||||
forwardQuery, "checked", &checked, chromedp.ByQuery,
|
||||
),
|
||||
))
|
||||
|
||||
assert.Equal(t, "refused", name,
|
||||
"a refused target does not keep the name entered")
|
||||
assert.Equal(t, refusedURL, typed,
|
||||
"a refused target does not keep the url entered")
|
||||
assert.True(t, checked,
|
||||
"a refused target does not keep the query string setting checked")
|
||||
assert.True(t, shown(ctx, targetName),
|
||||
"a refused target does not come back with the form open")
|
||||
assert.True(t, hidden(ctx, typeSelect),
|
||||
@@ -545,10 +563,15 @@ func checkRefusedTarget(ctx context.Context, t *testing.T, url string) {
|
||||
ctx,
|
||||
chromedp.Value(targetName, &name, chromedp.ByQuery),
|
||||
chromedp.Value(urlField, &typed, chromedp.ByQuery),
|
||||
chromedp.JavascriptAttribute(
|
||||
forwardQuery, "checked", &checked, chromedp.ByQuery,
|
||||
),
|
||||
))
|
||||
|
||||
assert.Empty(t, name, "after Cancel, the next Add keeps the name entered")
|
||||
assert.Empty(t, typed, "after Cancel, the next Add keeps the url entered")
|
||||
assert.False(t, checked,
|
||||
"after Cancel, the next Add keeps the query string setting checked")
|
||||
}
|
||||
|
||||
// checkTargetDeliveries loads a webhook page and checks that the row of
|
||||
@@ -1292,3 +1315,60 @@ func checkMobileMenu(ctx context.Context, t *testing.T, url string) {
|
||||
click(ctx, t, button)
|
||||
assert.True(t, hidden(ctx, menu), "the menu button does not close the menu")
|
||||
}
|
||||
|
||||
// scrollsSideways reports whether the page is wider than the window. A
|
||||
// page's clientWidth is the window's width less its scroll bar.
|
||||
const scrollsSideways = `document.documentElement.scrollWidth >
|
||||
document.documentElement.clientWidth`
|
||||
|
||||
// cutOffElements lists each element, without elements inside it, that
|
||||
// is shown but runs past the page's edge or its card's, by more than a
|
||||
// pixel of rounding. A card hides what runs past its edge.
|
||||
const cutOffElements = `[...document.querySelectorAll("body *")]
|
||||
.filter((el) => {
|
||||
const box = el.getBoundingClientRect();
|
||||
const card = el.closest(".card")?.getBoundingClientRect();
|
||||
const left = card ? card.left : 0;
|
||||
const right = card ? card.right : document.documentElement.clientWidth;
|
||||
return el.children.length === 0 && box.width > 0 &&
|
||||
(box.left < left - 1 || box.right > right + 1);
|
||||
})
|
||||
.map((el) => el.outerHTML.slice(0, 120))`
|
||||
|
||||
// checkPhoneWidth loads the webhook page, url, and its event log,
|
||||
// eventLog, in a phone-sized window, the event log with the attempts of
|
||||
// the newest event's delivery to targetName shown. It checks that
|
||||
// neither page scrolls sideways and that nothing shown on either, no
|
||||
// status, time or control, is cut off at the page's or its card's edge.
|
||||
func checkPhoneWidth(
|
||||
ctx context.Context, t *testing.T, url, eventLog, targetName string,
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
var (
|
||||
sideways bool
|
||||
cutOff []string
|
||||
)
|
||||
|
||||
measure := chromedp.Tasks{
|
||||
chromedp.Evaluate(scrollsSideways, &sideways),
|
||||
chromedp.Evaluate(cutOffElements, &cutOff),
|
||||
}
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
chromedp.EmulateViewport(phoneWidth, phoneHeight),
|
||||
loadPage(url),
|
||||
measure,
|
||||
))
|
||||
assert.False(t, sideways, "the webhook page scrolls sideways on a phone")
|
||||
assert.Empty(t, cutOff, "the webhook page cuts these off on a phone")
|
||||
|
||||
require.NoError(t, chromedp.Run(ctx, loadPage(eventLog)))
|
||||
click(ctx, t, `//span[text()="`+targetName+`"]`)
|
||||
require.True(t, shown(ctx, `//span[text()="Attempt 1"]`),
|
||||
"clicking the delivery does not show its attempts")
|
||||
require.NoError(t, chromedp.Run(ctx, measure))
|
||||
assert.False(t, sideways, "the event log scrolls sideways on a phone")
|
||||
assert.Empty(t, cutOff, "the event log cuts these off on a phone")
|
||||
}
|
||||
|
||||
+4
-2
@@ -1,6 +1,8 @@
|
||||
{
|
||||
"private": true,
|
||||
"devDependencies": {
|
||||
"eslint": "10.11.0"
|
||||
}
|
||||
"eslint": "10.11.0",
|
||||
"prettier": "3.9.9"
|
||||
},
|
||||
"packageManager": "yarn@4.18.1+sha512.b2e1e7524f654f2749d32b4ebcb4622473cb5bcbc485df2007e12a154e50162a4d795526768bc5f5b8f81717bfd79deb2472813d86fb5ae2eb551fa9c872b08f"
|
||||
}
|
||||
|
||||
+5
-4
@@ -3,8 +3,8 @@
|
||||
# this repo. Idempotent: every install is guarded by a check so already
|
||||
# installed tools are skipped. Base tooling comes from nix, apt, brew,
|
||||
# or apk (detected in that order); assumes NOTHING is present (not git,
|
||||
# make, or go). golangci-lint, node and ESLint are deliberately not
|
||||
# installed: linting runs only in docker, via script/lint.
|
||||
# make, or go). golangci-lint, node, ESLint and prettier are deliberately
|
||||
# not installed: they run only in docker, via script/lint and script/fmt.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
@@ -60,9 +60,10 @@ main() {
|
||||
if missing go; then pkg_install go golang go go; fi
|
||||
|
||||
# Not installed here: docker is platform-specific and out of scope for a
|
||||
# package-manager bootstrap, but script/lint and script/css need it.
|
||||
# package-manager bootstrap, but script/lint, script/fmt and script/css
|
||||
# need it.
|
||||
if missing docker; then
|
||||
echo "bootstrap: docker not found; script/lint and script/css require it" >&2
|
||||
echo "bootstrap: docker not found; script/lint, script/fmt and script/css require it" >&2
|
||||
fi
|
||||
|
||||
go mod download
|
||||
|
||||
+4
-4
@@ -1,8 +1,8 @@
|
||||
#!/bin/sh
|
||||
# script/cibuild: run the CI build. The Dockerfile runs the checks
|
||||
# (make fmt-check, lint, test), so a successful build implies a green
|
||||
# repo. Generic: needs no adaptation. The Gitea workflow runs this on
|
||||
# push.
|
||||
# script/cibuild: run the CI build. The Dockerfile runs the checks (the
|
||||
# gofmt check, golangci-lint, the stylesheet check, ESLint, the Markdown
|
||||
# check, make test), so a successful build implies a green repo. Generic:
|
||||
# needs no adaptation. The Gitea workflow runs this on push.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
+4
-1
@@ -1,5 +1,7 @@
|
||||
#!/bin/sh
|
||||
# script/fmt: format all files (writes).
|
||||
# script/fmt: format all files (writes): the Go code with gofmt and
|
||||
# goimports, the Markdown with prettier. prettier is never installed
|
||||
# locally: it runs in docker, in the Dockerfile's Markdown stages.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
@@ -10,6 +12,7 @@ main() {
|
||||
if command -v goimports >/dev/null 2>&1; then
|
||||
goimports -w .
|
||||
fi
|
||||
docker build --target markdown-output --output type=local,dest=. .
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
@@ -12,6 +12,7 @@ main() {
|
||||
gofmt -s -l .
|
||||
exit 1
|
||||
fi
|
||||
docker build --target markdown-check --output type=cacheonly .
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
File diff suppressed because one or more lines are too long
@@ -138,6 +138,7 @@ document.addEventListener("alpine:init", function () {
|
||||
url: "",
|
||||
headers: "",
|
||||
timeout: "",
|
||||
forwardQuery: false,
|
||||
maxRetries: "",
|
||||
expiry: "",
|
||||
rotation: "",
|
||||
@@ -150,6 +151,8 @@ document.addEventListener("alpine:init", function () {
|
||||
this.url = refused.destination;
|
||||
this.headers = refused.headers;
|
||||
this.timeout = refused.timeout;
|
||||
this.forwardQuery =
|
||||
this.$root.hasAttribute("data-forward-query");
|
||||
this.maxRetries = refused.maxRetries;
|
||||
this.expiry = refused.expiry;
|
||||
this.rotation = refused.rotation;
|
||||
@@ -169,6 +172,7 @@ document.addEventListener("alpine:init", function () {
|
||||
this.url = "";
|
||||
this.headers = "";
|
||||
this.timeout = "";
|
||||
this.forwardQuery = false;
|
||||
this.maxRetries = "";
|
||||
this.expiry = "";
|
||||
this.rotation = "";
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
an event's own page. Spans only, since a button may hold no div. -->
|
||||
<span class="flex flex-1 flex-wrap items-center justify-between gap-3">
|
||||
<span class="flex flex-wrap items-center gap-3">
|
||||
<span class="text-sm text-gray-700">{{.Target.DisplayName}}</span>
|
||||
<span class="text-sm text-gray-700 wrap-anywhere">{{.Target.DisplayName}}</span>
|
||||
{{if .Replay}}<span class="text-xs text-gray-500">replay</span>{{end}}
|
||||
<span class="text-xs {{if eq .Status "delivered"}}text-green-600{{else if eq .Status "failed"}}text-red-600{{else if eq .Status "retrying"}}text-yellow-600{{else}}text-gray-400{{end}}">{{with .Paused}}waiting: target paused after repeated failures, next try no earlier than {{.Until}} ({{.Relative}}){{else}}{{.Status}}{{end}}</span>
|
||||
</span>
|
||||
|
||||
@@ -1,14 +1,22 @@
|
||||
{{define "event_request"}}
|
||||
<!-- The entrypoint an event arrived at and its request headers, as
|
||||
handlers.EventLogView carries them: the same in the event log and
|
||||
the event's own page. The entrypoint's URL is never shown. A
|
||||
resubmitted copy, even a copy of a copy, did not arrive at an
|
||||
entrypoint; the request it copies did. -->
|
||||
<!-- The entrypoint an event arrived at, its query string and its
|
||||
request headers, as handlers.EventLogView carries them: the same in
|
||||
the event log and the event's own page. The entrypoint's URL is
|
||||
never shown. A resubmitted copy, even a copy of a copy, did not
|
||||
arrive at an entrypoint; the request it copies did. -->
|
||||
<div class="space-y-2 text-xs">
|
||||
{{if .ResubmittedFrom}}
|
||||
<p class="text-gray-500">The request it copies arrived at <span class="text-gray-900">{{.Entrypoint}}</span></p>
|
||||
<p class="text-gray-500">The request it copies arrived at <span class="text-gray-900 wrap-anywhere">{{.Entrypoint}}</span></p>
|
||||
{{else}}
|
||||
<p class="text-gray-500">Arrived at <span class="text-gray-900">{{.Entrypoint}}</span></p>
|
||||
<p class="text-gray-500">Arrived at <span class="text-gray-900 wrap-anywhere">{{.Entrypoint}}</span></p>
|
||||
{{end}}
|
||||
{{if .RawQueryCut}}
|
||||
<p class="text-gray-500">The query string is larger than the event log shows. <a href="{{.Body.EventURL}}" class="btn-small">Show the query string</a></p>
|
||||
{{else if .RawQuery}}
|
||||
<p class="text-gray-500">Query string</p>
|
||||
<pre class="rounded-md border border-gray-200 bg-white p-2 text-xs text-gray-700 overflow-x-auto whitespace-pre-wrap break-all">{{.RawQuery}}</pre>
|
||||
{{else}}
|
||||
<p class="text-gray-500">No query string.</p>
|
||||
{{end}}
|
||||
{{if .HeadersCut}}
|
||||
<p class="text-gray-500">The request headers are larger than the event log shows. <a href="{{.Body.EventURL}}" class="btn-small">Show the request headers</a></p>
|
||||
|
||||
@@ -6,15 +6,18 @@
|
||||
<!-- 108rem, half again the 72rem (max-w-6xl) of the webhook list, the
|
||||
event log, the navbar and the footer, so an entrypoint URL fits on
|
||||
one line. An inline style, because the committed tailwind.css has
|
||||
no class this wide. -->
|
||||
no class this wide. wrap-anywhere goes only on names and
|
||||
descriptions: a row too wide for a phone must still run past the
|
||||
edge, where the browser test sees it, rather than break its
|
||||
controls mid-word. -->
|
||||
<div class="mx-auto px-6 py-8" style="max-width: 108rem">
|
||||
<div class="mb-6">
|
||||
<a href="/hooks" class="btn-small">← Back to webhooks</a>
|
||||
<div class="flex flex-wrap justify-between items-center gap-2 mt-2">
|
||||
<div>
|
||||
<h1 class="text-2xl font-medium text-gray-900">{{.Webhook.Name}}</h1>
|
||||
<h1 class="text-2xl font-medium text-gray-900 wrap-anywhere">{{.Webhook.Name}}</h1>
|
||||
{{if .Webhook.Description}}
|
||||
<p class="text-sm text-gray-500 mt-1">{{.Webhook.Description}}</p>
|
||||
<p class="text-sm text-gray-500 mt-1 wrap-anywhere">{{.Webhook.Description}}</p>
|
||||
{{end}}
|
||||
</div>
|
||||
<div class="flex gap-2">
|
||||
@@ -60,7 +63,7 @@
|
||||
{{range .Entrypoints}}
|
||||
<div class="p-4" x-data="collapsible">
|
||||
<div class="flex flex-wrap items-center justify-between gap-2 mb-1">
|
||||
<span x-show="closed" class="text-sm font-medium text-gray-900">{{if .Description}}{{.Description}}{{else}}Entrypoint{{end}}</span>
|
||||
<span x-show="closed" class="text-sm font-medium text-gray-900 wrap-anywhere">{{if .Description}}{{.Description}}{{else}}Entrypoint{{end}}</span>
|
||||
<!-- Edit shows this form in place of the
|
||||
description and hides until it closes, and
|
||||
Cancel resets what was typed. With
|
||||
@@ -132,6 +135,7 @@
|
||||
data-destination="{{.TargetForm.URL}}"
|
||||
data-headers="{{.TargetForm.Headers}}"
|
||||
data-timeout="{{.TargetForm.Timeout}}"
|
||||
{{if .TargetForm.ForwardQuery}}data-forward-query{{end}}
|
||||
data-max-retries="{{.TargetForm.MaxRetries}}"
|
||||
data-expiry="{{.TargetForm.Expiry}}"
|
||||
data-rotation="{{.TargetForm.Rotation}}">
|
||||
@@ -180,6 +184,13 @@
|
||||
<label class="text-sm text-gray-700">Timeout (seconds, blank = default):</label>
|
||||
<input type="number" name="timeout" :value="timeout" min="0" max="300" class="input text-sm w-24">
|
||||
</div>
|
||||
<div>
|
||||
<label class="flex items-center gap-2 text-sm text-gray-700">
|
||||
<input type="checkbox" name="forward_query" value="on" :checked="forwardQuery" class="h-4 w-4">
|
||||
Pass the query string on to this target
|
||||
</label>
|
||||
<p class="text-xs text-gray-500 mt-1">Appends the query string each event arrived with to the URL above, after any query string the URL already has.</p>
|
||||
</div>
|
||||
<div>
|
||||
<div class="flex gap-2 items-center">
|
||||
<label class="text-sm text-gray-700">Delivery attempts:</label>
|
||||
@@ -249,7 +260,7 @@
|
||||
{{range .Targets}}
|
||||
<div class="p-4">
|
||||
<div class="flex flex-wrap items-center justify-between gap-2 mb-1">
|
||||
<span class="text-sm font-medium text-gray-900">{{.Name}}</span>
|
||||
<span class="text-sm font-medium text-gray-900 wrap-anywhere">{{.Name}}</span>
|
||||
<div class="flex flex-wrap items-center gap-2">
|
||||
<span class="badge-info">{{if eq .Type "database"}}archive{{else}}{{.Type}}{{end}}</span>
|
||||
{{if .Active}}
|
||||
|
||||
@@ -3,10 +3,15 @@
|
||||
{{define "title"}}Full Event Log - {{.Webhook.Name}} - Webhooker{{end}}
|
||||
|
||||
{{define "content"}}
|
||||
<!-- wrap-anywhere goes only on names, IDs and content types: a row too
|
||||
wide for a phone must still run past the edge, where the browser
|
||||
test sees it, rather than break its statuses, times or controls
|
||||
mid-word. So a target's name in an event's row, which shares its
|
||||
element with the delivery's status, goes without. -->
|
||||
<div class="max-w-6xl mx-auto px-6 py-8">
|
||||
<div class="mb-6">
|
||||
<a href="/hook/{{.Webhook.ID}}" class="btn-small">← Back to {{.Webhook.Name}}</a>
|
||||
<div class="flex justify-between items-center mt-2">
|
||||
<a href="/hook/{{.Webhook.ID}}" class="btn-small wrap-anywhere">← Back to {{.Webhook.Name}}</a>
|
||||
<div class="flex flex-wrap justify-between items-center gap-2 mt-2">
|
||||
<h1 class="text-2xl font-medium text-gray-900">Full Event Log</h1>
|
||||
<!-- Under a filter, this counts the events the filter lists. -->
|
||||
<span class="text-sm text-gray-500">{{if gt .TotalEvents (len .Events)}}{{len .Events}} most recent of {{.TotalEvents}} events{{else}}{{.TotalEvents}}{{if not .Show}} total{{end}} event{{if ne .TotalEvents 1}}s{{end}}{{end}}{{if eq .Show "failed"}} with a failed delivery{{else if eq .Show "pending"}} with a delivery pending or retrying{{end}}</span>
|
||||
@@ -28,8 +33,8 @@
|
||||
<div role="button" tabindex="0" class="btn-small w-full flex flex-wrap justify-between gap-2" :aria-expanded="open" @mousedown="cancelPendingToggle" @click="toggleUnlessSelecting" @keydown.enter.prevent="toggle" @keydown.space.prevent="toggle">
|
||||
<span class="flex flex-wrap items-center gap-3">
|
||||
<span class="badge-info">{{.Method}}</span>
|
||||
<span class="text-sm font-mono text-gray-700">{{.ID}}</span>
|
||||
<span class="text-sm text-gray-500">{{.ContentType}}</span>
|
||||
<span class="text-sm font-mono text-gray-700 wrap-anywhere">{{.ID}}</span>
|
||||
<span class="text-sm text-gray-500 wrap-anywhere">{{.ContentType}}</span>
|
||||
{{if .ResubmittedFrom}}
|
||||
<span class="text-xs text-gray-500" title="This event is a copy of {{.ResubmittedFromID}}">resubmitted copy</span>
|
||||
{{end}}
|
||||
@@ -54,7 +59,7 @@
|
||||
<div x-show="open" x-cloak class="mt-3 p-3 bg-gray-50 rounded-md">
|
||||
<div class="mb-3 flex flex-wrap items-center justify-between gap-2">
|
||||
<div class="text-xs text-gray-500">
|
||||
{{if .ResubmittedFrom}}Resubmitted from event <a href="/hook/{{$.Webhook.ID}}/events/{{.ResubmittedFromID}}" class="btn-small font-mono">{{.ResubmittedFromID}}</a>.{{end}}
|
||||
{{if .ResubmittedFrom}}Resubmitted from event <a href="/hook/{{$.Webhook.ID}}/events/{{.ResubmittedFromID}}" class="btn-small font-mono wrap-anywhere">{{.ResubmittedFromID}}</a>.{{end}}
|
||||
{{if .ResubmitCount}}Resubmitted as {{.ResubmitCount}} new event{{if ne .ResubmitCount 1}}s{{end}}.{{end}}
|
||||
</div>
|
||||
<form method="POST" action="/hook/{{$.Webhook.ID}}/events/{{.ID}}/resubmit" class="inline">
|
||||
|
||||
@@ -47,6 +47,14 @@
|
||||
<input type="number" id="timeout" name="timeout" value="{{.TargetForm.Timeout}}" min="0" max="{{.MaxTimeout}}" class="input">
|
||||
<p class="text-xs text-gray-500 mt-1">Per-request timeout, at most {{.MaxTimeout}} seconds. Leave blank to use the default.</p>
|
||||
</div>
|
||||
|
||||
<div class="form-group">
|
||||
<label class="flex items-center gap-2 text-sm font-medium text-gray-700">
|
||||
<input type="checkbox" id="forward_query" name="forward_query" value="on"{{if .TargetForm.ForwardQuery}} checked{{end}} class="h-4 w-4">
|
||||
Pass the query string on to this target
|
||||
</label>
|
||||
<p class="text-xs text-gray-500 mt-1">Appends the query string each event arrived with to the destination URL, after any query string the URL already has.</p>
|
||||
</div>
|
||||
{{end}}
|
||||
|
||||
{{if eq .Target.Type "slack"}}
|
||||
|
||||
Reference in New Issue
Block a user