Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
336f677584 |
@@ -33,5 +33,5 @@ jobs:
|
||||
# report success from cache.
|
||||
run: git rev-parse HEAD > .ci-fingerprint
|
||||
|
||||
- name: Build Docker image (runs make check)
|
||||
- name: Build Docker image (runs make fmt-check, golangci-lint, make test, make build)
|
||||
run: script/cibuild
|
||||
|
||||
@@ -19,8 +19,8 @@ before deploying one.
|
||||
### Prerequisites
|
||||
|
||||
- Go 1.26.1+ (the version in `go.mod`)
|
||||
- Docker (for linting, for the test stage of the CI gate, and for
|
||||
containerized deployment)
|
||||
- Docker (for `make lint` and so for `make check`, for the CI gate, and
|
||||
for containerized deployment)
|
||||
|
||||
golangci-lint is not a prerequisite and must not be installed on the
|
||||
host: `script/bootstrap` does not install it, and `make lint` runs the
|
||||
@@ -3335,8 +3335,9 @@ linked, which is what lets it run on the Alpine runtime image.
|
||||
inside the image, so a build that succeeds is a repo that is formatted,
|
||||
linted, tested and compiled. `script/lint` also uses Docker
|
||||
(`Dockerfile.lint`, see Linting above), so `make lint` and `make check`
|
||||
run the same pinned linter version the gate does; only `script/test`
|
||||
and `script/fmt-check` run on the host.
|
||||
run the same pinned linter version the gate does; of the steps
|
||||
`make check` runs, only `script/test` and `script/fmt-check` run on the
|
||||
host.
|
||||
|
||||
#### CI gate honesty
|
||||
|
||||
|
||||
@@ -139,7 +139,8 @@ func (h *Handlers) renderLoginError(
|
||||
),
|
||||
}
|
||||
|
||||
h.renderTemplateStatus(w, r, "login.html", data, status)
|
||||
w.WriteHeader(status)
|
||||
h.renderTemplate(w, r, "login.html", data)
|
||||
}
|
||||
|
||||
// authenticateUser looks up and verifies a user's credentials.
|
||||
|
||||
@@ -3,7 +3,6 @@ package handlers_test
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"html/template"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"net/url"
|
||||
@@ -405,60 +404,6 @@ func TestLogin_MissingCredentialsRejectedBeforeAnyHash(t *testing.T) {
|
||||
)
|
||||
}
|
||||
|
||||
// TestLogin_FormErrorAnswersItsStatusWithThePage proves that the login
|
||||
// form shown again with an error still answers 400 with the whole page.
|
||||
func TestLogin_FormErrorAnswersItsStatusWithThePage(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var h *handlers.Handlers
|
||||
|
||||
app := newTestApp(t, &h)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
w := submitLogin(h, sharedProxyPeer, "", "")
|
||||
|
||||
assert.Equal(t, http.StatusBadRequest, w.Code)
|
||||
assert.Contains(
|
||||
t, w.Body.String(), "Username and password are required",
|
||||
)
|
||||
assert.Contains(
|
||||
t, w.Body.String(), "</html>",
|
||||
"the page must render to completion",
|
||||
)
|
||||
}
|
||||
|
||||
// TestLogin_FormErrorRenderFailureAnswers500 proves that a login form
|
||||
// error page whose template fails answers 500 with the error page and
|
||||
// none of the form page, rather than the 400 it meant to send.
|
||||
func TestLogin_FormErrorRenderFailureAnswers500(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var h *handlers.Handlers
|
||||
|
||||
app := newTestApp(t, &h)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
// The page prints its error message and then fails.
|
||||
h.AddTemplateForTest("login.html", template.Must(
|
||||
template.New("login").Funcs(template.FuncMap{
|
||||
"fail": func() (string, error) { return "", errMidRender },
|
||||
}).Parse(`{{.Error}}{{fail}}`),
|
||||
))
|
||||
|
||||
w := submitLogin(h, sharedProxyPeer, "", "")
|
||||
|
||||
assert.Equal(t, http.StatusInternalServerError, w.Code)
|
||||
assert.NotContains(
|
||||
t, w.Body.String(), "Username and password are required",
|
||||
"the response must carry no part of the aborted page",
|
||||
)
|
||||
assert.Contains(t, w.Body.String(), "500 Internal Server Error")
|
||||
}
|
||||
|
||||
// TestLogin_SuccessCreatesSession is the control for the tests above:
|
||||
// the success path they assert on really does authenticate.
|
||||
func TestLogin_SuccessCreatesSession(t *testing.T) {
|
||||
|
||||
@@ -309,26 +309,12 @@ func (s *Handlers) getUserInfo(
|
||||
}
|
||||
|
||||
// renderTemplate renders a pre-parsed template with common
|
||||
// data and answers 200.
|
||||
// data
|
||||
func (s *Handlers) renderTemplate(
|
||||
w http.ResponseWriter,
|
||||
r *http.Request,
|
||||
pageTemplate string,
|
||||
data any,
|
||||
) {
|
||||
s.renderTemplateStatus(w, r, pageTemplate, data, http.StatusOK)
|
||||
}
|
||||
|
||||
// renderTemplateStatus is renderTemplate answering with status, for a
|
||||
// form shown again with an error. Call it instead of WriteHeader
|
||||
// followed by renderTemplate: the status is written only once the page
|
||||
// has rendered, so a failed render can still answer 500.
|
||||
func (s *Handlers) renderTemplateStatus(
|
||||
w http.ResponseWriter,
|
||||
r *http.Request,
|
||||
pageTemplate string,
|
||||
data any,
|
||||
status int,
|
||||
) {
|
||||
tmpl, ok := s.templates[pageTemplate]
|
||||
if !ok {
|
||||
@@ -341,9 +327,7 @@ func (s *Handlers) renderTemplateStatus(
|
||||
return
|
||||
}
|
||||
|
||||
s.executeTemplate(
|
||||
w, r, tmpl, s.pageData(r, data, noticeFor(r)), status,
|
||||
)
|
||||
s.executeTemplate(w, r, tmpl, s.pageData(r, data, noticeFor(r)))
|
||||
}
|
||||
|
||||
// pageData adds the fields the shared layout renders to a page's own
|
||||
@@ -379,20 +363,19 @@ func (s *Handlers) pageData(
|
||||
}
|
||||
}
|
||||
|
||||
// executeTemplate renders the template into a buffer and writes status
|
||||
// and the page to the response only once rendering has fully
|
||||
// succeeded. Executing straight into the ResponseWriter commits a
|
||||
// partial body and the status before a mid-render error can be
|
||||
// reported, leaving no way to serve a 500. Buffering makes a page's
|
||||
// rendered size resident memory per concurrent viewer, so every page
|
||||
// owes it a bound: the event log caps each stored body at
|
||||
// maxRenderedBodyBytes for exactly this reason.
|
||||
// executeTemplate renders the template into a buffer and writes to
|
||||
// the response only once rendering has fully succeeded. Executing
|
||||
// straight into the ResponseWriter commits a partial body and a 200
|
||||
// status before a mid-render error can be reported, leaving no way
|
||||
// to serve a 500. Buffering makes a page's rendered size resident
|
||||
// memory per concurrent viewer, so every page owes it a bound: the
|
||||
// event log caps each stored body at maxRenderedBodyBytes for exactly
|
||||
// this reason.
|
||||
func (s *Handlers) executeTemplate(
|
||||
w http.ResponseWriter,
|
||||
r *http.Request,
|
||||
tmpl *template.Template,
|
||||
data any,
|
||||
status int,
|
||||
) {
|
||||
var buf bytes.Buffer
|
||||
|
||||
@@ -407,7 +390,6 @@ func (s *Handlers) executeTemplate(
|
||||
}
|
||||
|
||||
w.Header().Set("Content-Type", "text/html; charset=utf-8")
|
||||
w.WriteHeader(status)
|
||||
|
||||
_, err = buf.WriteTo(w)
|
||||
if err != nil {
|
||||
|
||||
@@ -181,11 +181,6 @@ func (r *recordingArchives) Renames() []archiveRename {
|
||||
return out
|
||||
}
|
||||
|
||||
// newTestApp returns an app whose RequireStart fails the test when
|
||||
// starting takes longer than fx's default start timeout of 15s. That
|
||||
// limit catches a start that hangs, not a busy host: measured with make
|
||||
// test on 2026-10-02 at host load 58-69 on 48 cores, the slowest of this
|
||||
// package's starts took 0.49s.
|
||||
func newTestApp(
|
||||
t *testing.T,
|
||||
targets ...any,
|
||||
|
||||
@@ -350,12 +350,12 @@ func (h *Handlers) HandleSourceCreateSubmit() http.HandlerFunc {
|
||||
retentionStr := r.PostFormValue("retention_days")
|
||||
|
||||
if name == "" {
|
||||
h.renderTemplateStatus(
|
||||
w.WriteHeader(http.StatusBadRequest)
|
||||
h.renderTemplate(
|
||||
w, r, "sources_new.html",
|
||||
newSourceFormData(
|
||||
"Name is required", name, description,
|
||||
),
|
||||
http.StatusBadRequest,
|
||||
)
|
||||
|
||||
return
|
||||
@@ -365,13 +365,13 @@ func (h *Handlers) HandleSourceCreateSubmit() http.HandlerFunc {
|
||||
retentionStr, database.DefaultRetentionDays,
|
||||
)
|
||||
if retErr != nil {
|
||||
h.renderTemplateStatus(
|
||||
w.WriteHeader(http.StatusBadRequest)
|
||||
h.renderTemplate(
|
||||
w, r, "sources_new.html",
|
||||
newSourceFormData(
|
||||
retentionErrorMessage(retErr),
|
||||
name, description,
|
||||
),
|
||||
http.StatusBadRequest,
|
||||
)
|
||||
|
||||
return
|
||||
@@ -644,7 +644,8 @@ func (h *Handlers) applyWebhookEdit(
|
||||
tmplKeyError: "Name is required",
|
||||
}
|
||||
|
||||
h.renderTemplateStatus(w, r, "source_edit.html", data, http.StatusBadRequest)
|
||||
w.WriteHeader(http.StatusBadRequest)
|
||||
h.renderTemplate(w, r, "source_edit.html", data)
|
||||
|
||||
return
|
||||
}
|
||||
@@ -664,7 +665,8 @@ func (h *Handlers) applyWebhookEdit(
|
||||
tmplKeyError: retentionErrorMessage(retErr),
|
||||
}
|
||||
|
||||
h.renderTemplateStatus(w, r, "source_edit.html", data, http.StatusBadRequest)
|
||||
w.WriteHeader(http.StatusBadRequest)
|
||||
h.renderTemplate(w, r, "source_edit.html", data)
|
||||
|
||||
return
|
||||
}
|
||||
@@ -701,7 +703,8 @@ func (h *Handlers) applyWebhookEdit(
|
||||
"it, then save again.",
|
||||
}
|
||||
|
||||
h.renderTemplateStatus(w, r, "source_edit.html", data, http.StatusConflict)
|
||||
w.WriteHeader(http.StatusConflict)
|
||||
h.renderTemplate(w, r, "source_edit.html", data)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
+3
-9
@@ -2,10 +2,9 @@
|
||||
# script/test: run the test suite.
|
||||
#
|
||||
# -timeout is applied by `go test` per package, not to the run as a whole, so
|
||||
# it only has to clear the slowest single package. When this budget was set
|
||||
# that was internal/handlers, measured in a cache-defeated builder stage on the
|
||||
# 48-core shared build host (2026-08-18); load- and host-dependent, not
|
||||
# invariants:
|
||||
# it only has to clear the slowest single package. That is internal/handlers,
|
||||
# measured in a cache-defeated builder stage on the 48-core shared build host
|
||||
# (2026-08-18); load- and host-dependent, not invariants:
|
||||
#
|
||||
# 16.9s host load 5-20, GOMAXPROCS 48
|
||||
# 45.9s / 47.3s / 49.0s three runs at deliberate host load 31-73
|
||||
@@ -24,11 +23,6 @@
|
||||
# a condition CI runs under. If a CPU-limited runner ever puts a real run near
|
||||
# 67s, that is the datum to revisit the org figure with.
|
||||
#
|
||||
# Those figures predate tests hashing the admin password at 1 MB instead of
|
||||
# 64 MB (https://git.eeqj.de/sneak/webhooker/pulls/404). After that change, in
|
||||
# a cache-defeated build at host load 44-109 (2026-10-02), internal/handlers
|
||||
# took 8.5s and the slowest package was internal/database at 15.8s.
|
||||
#
|
||||
# -p 4 -parallel 8 keep the run under 2 GB of memory: at most four test
|
||||
# binaries build or run at once, each with at most eight parallel tests. Under
|
||||
# -race every test binary and every link costs a few hundred MB, so the
|
||||
|
||||
Reference in New Issue
Block a user