Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
011a9b703f |
@@ -28,10 +28,10 @@ jobs:
|
||||
|
||||
- name: Fingerprint the build context
|
||||
# Writes the hash of the commit being checked into the context, which
|
||||
# invalidates the `COPY . .` layer of every check stage: a commit
|
||||
# that was never linted, format-checked, stylesheet-checked, tested
|
||||
# and built cannot report success from cache.
|
||||
# invalidates the `COPY . .` layer of both check stages: a commit
|
||||
# that was never linted, format-checked, tested and built cannot
|
||||
# report success from cache.
|
||||
run: git rev-parse HEAD > .ci-fingerprint
|
||||
|
||||
- name: Build Docker image (runs make fmt-check, golangci-lint, the stylesheet check, make test, make build)
|
||||
- name: Build Docker image (runs make fmt-check, golangci-lint, make test, make build)
|
||||
run: script/cibuild
|
||||
|
||||
+1
-39
@@ -25,55 +25,17 @@ COPY . .
|
||||
# would need a docker daemon inside the build. Keep these steps in step with
|
||||
# Dockerfile.lint, including --network=none (see its header for why).
|
||||
RUN make fmt-check
|
||||
RUN script/assets
|
||||
RUN --network=none golangci-lint config verify --config .golangci.yml
|
||||
RUN --network=none golangci-lint run --config .golangci.yml --build-tags browser ./...
|
||||
|
||||
# Stylesheet stages. static/css/tailwind.css is generated, by this pinned
|
||||
# tailwindcss, from static/css/input.css and the files its @source lines
|
||||
# name. `make css` (script/css) writes it out from the css-output stage.
|
||||
# The css-check stage fails when the committed file differs from what is
|
||||
# generated; `make check` runs it, and so does the build stage below.
|
||||
#
|
||||
# tailwindcss v4.2.1 standalone CLI, released 2026-02-23: one binary per
|
||||
# architecture, each pinned by its sha256 from the release's sha256sums.txt.
|
||||
# debian:bookworm-slim, 2026-10-02: the binary needs glibc.
|
||||
FROM debian:bookworm-slim@sha256:3783cc01769c7b2b1b83a5c5ad96c815348e28ed7da68e2e3687004faa906251 AS tailwind-amd64
|
||||
ADD --checksum=sha256:39e8d4e24b3c83b0a6e69e100a972fbc75d5fef8dce47b3ddac3cf92dea81fe3 --chmod=755 \
|
||||
https://github.com/tailwindlabs/tailwindcss/releases/download/v4.2.1/tailwindcss-linux-x64 /usr/local/bin/tailwindcss
|
||||
|
||||
FROM debian:bookworm-slim@sha256:3783cc01769c7b2b1b83a5c5ad96c815348e28ed7da68e2e3687004faa906251 AS tailwind-arm64
|
||||
ADD --checksum=sha256:d87e6486bb3f70b04ef1dcaacc4ee6548a5a15fbf521b31bc24d2c774f68a951 --chmod=755 \
|
||||
https://github.com/tailwindlabs/tailwindcss/releases/download/v4.2.1/tailwindcss-linux-arm64 /usr/local/bin/tailwindcss
|
||||
|
||||
# TARGETARCH, set by docker, is the architecture being built for.
|
||||
FROM tailwind-${TARGETARCH} AS css
|
||||
WORKDIR /src
|
||||
COPY . .
|
||||
RUN tailwindcss -i static/css/input.css -o /out/tailwind.css --minify
|
||||
|
||||
FROM scratch AS css-output
|
||||
COPY --from=css /out/tailwind.css /
|
||||
|
||||
# Both files are split after each "}", one rule per line, so that when they
|
||||
# differ the diff shows the rules that differ.
|
||||
FROM css AS css-check
|
||||
RUN sed 's/}/}\n/g' static/css/tailwind.css > /tmp/committed.css \
|
||||
&& sed 's/}/}\n/g' /out/tailwind.css > /tmp/generated.css \
|
||||
&& diff -U0 /tmp/committed.css /tmp/generated.css || { \
|
||||
echo "static/css/tailwind.css is not what make css generates; run make css" >&2; \
|
||||
exit 1; \
|
||||
}
|
||||
|
||||
# Build stage
|
||||
# golang:1.26.1-bookworm (Debian-based), 2026-03-17
|
||||
# Using Debian-based image because gorm.io/driver/sqlite pulls in
|
||||
# mattn/go-sqlite3 (CGO), which does not compile on Alpine musl.
|
||||
FROM golang:1.26.1-bookworm@sha256:4465644228bc2857a954b092167e12aa59c006a3492282a6c820bf4755fd64a4 AS builder
|
||||
|
||||
# Depend on the lint and stylesheet check stages passing
|
||||
# Depend on lint stage passing
|
||||
COPY --from=lint /src/go.sum /dev/null
|
||||
COPY --from=css-check /out/tailwind.css /dev/null
|
||||
|
||||
# jq is a runtime dependency of script/ci-mark-superseded, which the test
|
||||
# suite executes. git is what script/version derives the version with.
|
||||
|
||||
@@ -31,10 +31,6 @@ FROM deps AS lint
|
||||
|
||||
COPY . .
|
||||
|
||||
# static/static.go embeds the Alpine.js file this extracts from 3p/; without
|
||||
# it the static package does not compile and cannot be linted.
|
||||
RUN script/assets
|
||||
|
||||
# `run` silently ignores config keys it does not recognize, so a typo would
|
||||
# disable a setting without a word. `config verify` is what catches that.
|
||||
RUN --network=none golangci-lint config verify --config .golangci.yml
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
.PHONY: bootstrap setup assets test test-browser lint fmt fmt-check check build run dev deps docker clean hooks css css-check version
|
||||
.PHONY: bootstrap setup assets test test-browser lint fmt fmt-check check build run dev deps docker clean hooks css version
|
||||
|
||||
# Default target
|
||||
.DEFAULT_GOAL := check
|
||||
@@ -74,7 +74,4 @@ hooks:
|
||||
@script/install-precommit
|
||||
|
||||
css:
|
||||
@script/css
|
||||
|
||||
css-check:
|
||||
@script/css-check
|
||||
tailwindcss -i static/css/input.css -o static/css/tailwind.css --minify
|
||||
|
||||
@@ -19,14 +19,12 @@ before deploying one.
|
||||
### Prerequisites
|
||||
|
||||
- Go 1.26.1+ (the version in `go.mod`)
|
||||
- Docker (for `make lint` and `make css`, and so for `make check`, for the
|
||||
browser test in `make test-browser`, for the CI gate, and for
|
||||
containerized deployment)
|
||||
- Docker (for `make lint` and so for `make check`, for the browser test in
|
||||
`make test-browser`, for the CI gate, and for containerized deployment)
|
||||
|
||||
golangci-lint is not a prerequisite and must not be installed on the
|
||||
host: `script/bootstrap` does not install it, and `make lint` runs the
|
||||
digest-pinned linter image via `Dockerfile.lint`. The same holds for
|
||||
tailwindcss (see [Stylesheet](#stylesheet)).
|
||||
digest-pinned linter image via `Dockerfile.lint`.
|
||||
|
||||
### Quick Start
|
||||
|
||||
@@ -38,7 +36,7 @@ cd webhooker
|
||||
# Install the Go toolchain if missing, and the Go dependencies
|
||||
make bootstrap
|
||||
|
||||
# Run all checks (test, lint, format check, stylesheet check)
|
||||
# Run all checks (test, lint, format check)
|
||||
make check
|
||||
|
||||
# Run the server from the clone. DATA_DIR defaults to
|
||||
@@ -61,7 +59,7 @@ make fmt-check # Fail if gofmt would change anything (writes nothing)
|
||||
make lint # Run golangci-lint in Docker (Dockerfile.lint)
|
||||
make test # Run tests with race detection
|
||||
make test-browser # Run the browser test in Docker (Dockerfile.browser)
|
||||
make check # test + lint + fmt-check + css-check (CI gate)
|
||||
make check # test + lint + fmt-check (CI gate)
|
||||
make build # Build binary to bin/webhooker (version-stamped)
|
||||
make version # Print the version this checkout would stamp
|
||||
make run # build, then run ./bin/webhooker
|
||||
@@ -69,8 +67,7 @@ make dev # go run ./cmd/webhooker
|
||||
make deps # go mod download + go mod tidy
|
||||
make docker # Build Docker image
|
||||
make hooks # Install git pre-commit hook that runs script/precommit
|
||||
make css # Regenerate static/css/tailwind.css (tailwindcss in Docker)
|
||||
make css-check # Fail if static/css/tailwind.css is stale (writes nothing)
|
||||
make css # Regenerate static/css/tailwind.css (needs tailwindcss)
|
||||
make clean # Remove bin/
|
||||
```
|
||||
|
||||
@@ -82,8 +79,7 @@ directory, read once at startup before anything else looks at the
|
||||
environment.
|
||||
|
||||
The file is optional and having none is the normal case for a
|
||||
deployment. An empty file is the same as none: it has nothing in it to
|
||||
apply. A file that is there but cannot be parsed aborts startup
|
||||
deployment. A file that is there but cannot be parsed aborts startup
|
||||
with a message naming it, because a single malformed line makes none
|
||||
of the file apply: every variable in it silently reverts to its
|
||||
default, which is exactly the failure [Invalid values abort
|
||||
@@ -143,7 +139,7 @@ TTY detection, and security headers are always applied.
|
||||
| `METRICS_USERNAME` | Basic auth username for `/metrics`. Must be set together with `METRICS_PASSWORD`; one without the other fails startup | `""` |
|
||||
| `METRICS_PASSWORD` | Basic auth password for `/metrics`. Must be set together with `METRICS_USERNAME`; one without the other fails startup | `""` |
|
||||
| `SENTRY_DSN` | Sentry error reporting DSN. Unset leaves error reporting off; a value the Sentry SDK cannot parse fails startup rather than serving with reporting silently off | `""` |
|
||||
| `RETENTION_SWEEP_INTERVAL` | How often the retention reaper and archive sweeper run (Go duration, must be positive). A value that does not parse, or is zero or negative, fails startup | `1h` |
|
||||
| `RETENTION_SWEEP_INTERVAL` | How often the retention reaper and archive sweeper run (Go duration, must be positive) | `1h` |
|
||||
| `SESSION_IDLE_TIMEOUT` | Idle session timeout (Go duration) | `24h` |
|
||||
| `RECEIVER_RATE_LIMIT` | Receiver requests/minute per IP per entrypoint (10x that per IP across the route) | `120` |
|
||||
| `TRUSTED_PROXIES` | CIDRs whose forwarded headers are trusted. A set value replaces the default. If any client can reach webhooker, or the proxy in front of it, from an RFC 1918 source address, set it to the proxy's address alone. See [Trusted proxies](#trusted-proxies) | `10.0.0.0/8,172.16.0.0/12,192.168.0.0/16` (RFC 1918) |
|
||||
@@ -461,19 +457,6 @@ Your proxy must therefore **append** the peer address to
|
||||
`option forwardfor`, Caddy and AWS ALB by default), and must append a
|
||||
bare address with no port.
|
||||
|
||||
Every log line that names a client carries two addresses: `remoteIP`,
|
||||
the connecting peer, which behind a proxy is the proxy; and `clientIP`,
|
||||
the client the rate limiters identify by the rules above, which is the
|
||||
field to read when tracing who sent what. Those lines are the
|
||||
`http request` access log line, the rate-limit rejection lines
|
||||
(`login failure limit exceeded` among them), the
|
||||
`csrf: token validation failed` warning and the receiver's
|
||||
`webhook request received` line. `clientIP` is only as trustworthy as
|
||||
`TRUSTED_PROXIES`: for a request from a peer inside the list, it is
|
||||
read out of the `X-Forwarded-For` that peer sent, so a peer that does
|
||||
not belong in the list can make it name any address it likes. For a
|
||||
request from any other peer, both fields name the peer.
|
||||
|
||||
#### Sessions
|
||||
|
||||
Sessions are bounded by two independent clocks, and end at whichever
|
||||
@@ -561,20 +544,18 @@ If it is lost, run `webhooker resetpw admin` on a stopped deployment.
|
||||
```
|
||||
|
||||
It is a banner rather than a log line because that is the only time it
|
||||
is ever shown: as one `INFO` record it would sit among the records fx
|
||||
writes as each start hook runs, and under `docker run -d`
|
||||
is ever shown: as one `INFO` record it sat among the roughly 45 fx
|
||||
`PROVIDE`/`RUN`/`HOOK` lines a boot writes, and under `docker run -d`
|
||||
it is one line in a log subject to rotation. The database stores only
|
||||
its Argon2id hash. There is no second account and no forgot-password
|
||||
flow, so the banner and the reset command below are the only two ways
|
||||
in.
|
||||
|
||||
A start that finds no `webhooker.db` in `DATA_DIR`, or a zero-length
|
||||
one (which SQLite opens as an empty database), also logs
|
||||
A start that finds no `webhooker.db` in `DATA_DIR` also logs
|
||||
`created a new, empty database` at `WARN`, with the file's path,
|
||||
shortly before the banner. On a deployment that has run before, that
|
||||
line means `webhooker.db` was lost: either the file was missing, most
|
||||
often because the volume holding `DATA_DIR` is not mounted, or it was
|
||||
zero-length, as a truncated copy leaves it.
|
||||
line means `DATA_DIR` was empty, most often because its volume is not
|
||||
mounted.
|
||||
|
||||
#### Recovering a lost admin password
|
||||
|
||||
@@ -618,8 +599,7 @@ What it will not do:
|
||||
the old password, so a reset underneath it would report a change the
|
||||
service does not honour.
|
||||
- **Create anything.** A `DATA_DIR` that does not exist, or that holds
|
||||
no `webhooker.db` or a zero-length one, is an error naming the path
|
||||
rather than a new empty deployment —
|
||||
no `webhooker.db`, is an error rather than a new empty deployment —
|
||||
a mistyped path must not be built out and then reported as a success.
|
||||
- **Create an account.** A username that does not exist is an error.
|
||||
`resetpw` changes an existing account's password and nothing else.
|
||||
@@ -635,8 +615,7 @@ Changing a password you still know needs none of this — use
|
||||
|
||||
`DEBUG=true` lowers the log level to `DEBUG`, which turns on every
|
||||
statement GORM runs, the two by-design lookup misses on the
|
||||
unauthenticated routes, the rate limiter's own rejections, and fx's
|
||||
records of building the dependency graph at startup. It is
|
||||
unauthenticated routes, and the rate limiter's own rejections. It is
|
||||
meant to be safe to turn on while diagnosing a live service and safe to
|
||||
paste the output of into a bug report.
|
||||
|
||||
@@ -862,9 +841,9 @@ reports.
|
||||
was given, so on any port other than 443 `$host` makes every form
|
||||
POST — including login — fail with `403 origin invalid`, with
|
||||
nothing in the error naming the cause.
|
||||
5. **Keep the proxy's access log.** webhooker's own access log names
|
||||
the client in its `clientIP` field only while `TRUSTED_PROXIES`
|
||||
covers the proxy; the proxy's log names it regardless. nginx's
|
||||
5. **Keep the proxy's access log.** webhooker's own access log records
|
||||
the peer address, which behind a proxy is always the proxy. The
|
||||
proxy's log is the only record of which client sent what. nginx's
|
||||
default `combined` format already logs `$remote_addr`; do not
|
||||
replace it with one that drops the client address, and retain those
|
||||
logs as long as you would want to answer a question about traffic.
|
||||
@@ -893,8 +872,9 @@ server {
|
||||
# webhooker's message.
|
||||
client_max_body_size 1m;
|
||||
|
||||
# $remote_addr is the client. webhooker's own log names it, as
|
||||
# clientIP, only while TRUSTED_PROXIES covers this proxy.
|
||||
# $remote_addr is the client. webhooker's own log records this
|
||||
# proxy and nothing else, so this file is the only place the
|
||||
# client's address is written down.
|
||||
access_log /var/log/nginx/webhooker.access.log combined;
|
||||
|
||||
location / {
|
||||
@@ -1000,16 +980,6 @@ its sidecars; a killed or crashed instance leaves them, and they must be
|
||||
carried with the `.db`. An archive the service has not opened since a
|
||||
crash keeps that crash's sidecars, even across a later clean stop.
|
||||
|
||||
A missing sidecar is therefore normal, and SQLite makes new ones, so a
|
||||
`-wal` lost from a copy cannot be reported: the transactions it held
|
||||
are simply gone. SQLite reads a `-wal` up to its first damaged frame,
|
||||
as after a crash, and rebuilds a damaged `-shm`. A sidecar with the
|
||||
wrong mode is set back to `0600` when its database is opened. A
|
||||
directory in place of either is refused then, with an error naming it:
|
||||
for `webhooker.db` the server and `webhooker resetpw` stop, and an event
|
||||
or archive database fails as a damaged one does (see
|
||||
[Database Architecture](#database-architecture)).
|
||||
|
||||
Configuration is **not** in `DATA_DIR` — it comes from the environment
|
||||
and from a `.env` file read out of the process working directory. Back
|
||||
that up with your deployment config, separately.
|
||||
@@ -1067,8 +1037,7 @@ Archive databases are the one exception the service is built for: the
|
||||
archive writer closes and reopens its handle around writes (debounced
|
||||
to at most one reopen per second), so an operator can move an
|
||||
`archive-….db` away for offline retention while the service runs,
|
||||
and it is recreated on the next write. The webhook page names each
|
||||
`database` target's archive file. See
|
||||
and it is recreated on the next write. See
|
||||
[Database Architecture](#database-architecture). That is a
|
||||
move-the-file-away workflow, not a substitute for the backup procedures
|
||||
above.
|
||||
@@ -1093,19 +1062,13 @@ with any `-wal`/`-shm` beside it, or wait until there are none.
|
||||
1. Stop the service.
|
||||
|
||||
2. Restore the **whole set together**: `webhooker.db` *and* every
|
||||
`events-*.db` *and* every `archive-*.db`. A restore that leaves out
|
||||
`webhooker.db` or an `events-*.db` is reported, not refused; one
|
||||
that leaves out an `archive-*.db` or a `-wal` (step 3) is not
|
||||
reported at all. Every database is opened `mode=rwc`, so a
|
||||
missing `events-{uuid}.db` is **created empty**: the webhook comes
|
||||
back with its configuration intact and its entire event history
|
||||
gone. The first start after the restore logs
|
||||
`created a new, empty database` at `WARN` for each such file, with
|
||||
its path, as it does for a missing `webhooker.db`. A missing
|
||||
`archive-*.db` is recreated at its target's next delivery without a
|
||||
warning, since moving one away is a supported workflow. Event
|
||||
databases restored without `webhooker.db` are simply orphaned;
|
||||
nothing references their UUIDs.
|
||||
`events-*.db` *and* every `archive-*.db`. A partial restore fails
|
||||
quietly rather than loudly. Every database is opened `mode=rwc`, so a
|
||||
missing `events-{uuid}.db` is **created empty** on first access
|
||||
instead of erroring — the webhook comes back with its configuration
|
||||
intact and its entire event history silently gone. Event databases
|
||||
restored without `webhooker.db` are simply orphaned; nothing
|
||||
references their UUIDs.
|
||||
|
||||
3. Carry any `*.db-wal` and `*.db-shm` files that are in the backup.
|
||||
They are part of the database, and dropping a `-wal` silently
|
||||
@@ -1130,7 +1093,7 @@ unconditionally against whatever files it finds:
|
||||
- the main database on connect — `Setting`, `User`, `APIKey`, `Webhook`,
|
||||
`Entrypoint`, `Target`
|
||||
- each event database when it is lazily opened — `Event`, `Delivery`,
|
||||
`DeliveryResult`, `EventTotals`, `TargetTotals`, `EntrypointTotals`
|
||||
`DeliveryResult`, `EventTotals`, `TargetTotals`
|
||||
- each archive database on every open and reopen
|
||||
|
||||
There is no schema version table, no migration ledger, and no down
|
||||
@@ -1295,11 +1258,11 @@ What that means for an operator:
|
||||
This repository adheres to the
|
||||
[Scripts to Rule Them All](https://github.com/github/scripts-to-rule-them-all)
|
||||
standard: normalized scripts in `script/` are the entrypoints for the
|
||||
development workflow. Thirteen of the Makefile's nineteen targets are thin
|
||||
shims that call them; `build`, `run`, `dev`, `deps`, `clean` and `version`
|
||||
are inline commands with no script behind them, though `build`, `run` and
|
||||
`dev` first run `script/assets`, and `build` and `version` both take their
|
||||
value from `script/version`.
|
||||
development workflow. Eleven of the Makefile's eighteen targets are thin
|
||||
shims that call them; `build`, `run`, `dev`, `deps`, `clean`, `css` and
|
||||
`version` are inline commands with no script behind them, though `build`,
|
||||
`run` and `dev` first run `script/assets`, and `build` and `version` both
|
||||
take their value from `script/version`.
|
||||
|
||||
`script/test`, `make build` and `make dev` each run `script/assets`
|
||||
first, which writes the ignored `static/js/alpine.min.js` (see
|
||||
@@ -1321,11 +1284,7 @@ We provide:
|
||||
- `script/lint` — run golangci-lint in Docker (see Linting below)
|
||||
- `script/fmt` — format all code (writes)
|
||||
- `script/fmt-check` — check formatting (read-only)
|
||||
- `script/css` — regenerate `static/css/tailwind.css` in Docker (writes;
|
||||
see [Stylesheet](#stylesheet))
|
||||
- `script/css-check` — fail if `static/css/tailwind.css` differs from what
|
||||
`script/css` would generate (read-only)
|
||||
- `script/check` — run test, lint, fmt-check, and css-check
|
||||
- `script/check` — run test, lint, and fmt-check
|
||||
- `script/version` — output the version to stamp into the binary (see
|
||||
[Version stamping](#version-stamping))
|
||||
- `script/docker` — build the Docker image tagged via
|
||||
@@ -1351,28 +1310,18 @@ markup. The CSP build runs no expressions, so every Alpine directive in
|
||||
`x-data="{ open: false }"` or `@click="open = !open"`.
|
||||
|
||||
A browser test in `internal/server` loads the webhook page and the event log
|
||||
under the real policy and checks that: the add entrypoint form stays hidden
|
||||
until Add is clicked; for every target type, the targets section's Add shows
|
||||
only a choice of type with Next and Cancel, Next shows only that type's fields
|
||||
(no url field for `database` or `log`), Cancel at either step closes the form,
|
||||
and saving adds the target; a refused target comes back with its form open, the
|
||||
values entered and the reason, and after Cancel the next Add starts with an
|
||||
empty form and no reason; the Copy button beside an entrypoint URL reads
|
||||
"Copied" once clicked; an entrypoint's Edit button shows its edit form in place
|
||||
of its description and hides until the form closes, Cancel hides the form and
|
||||
drops what was typed, as does leaving the page and going back to it, and Save
|
||||
changes the description; of the recent events on the webhook page only the
|
||||
newest starts expanded, each expands and collapses, and Open leads to the
|
||||
event's own page; an event in the event log expands and collapses when its
|
||||
row's caret or its ID is clicked, and from the keyboard, but not when its ID is
|
||||
selected with the mouse, and a delivery's attempts inside it expand and
|
||||
collapse; and at phone width the menu button opens and closes the mobile menu.
|
||||
It also fails if the browser reports a console warning or error, an uncaught
|
||||
exception, or anything the policy refused. `make check` and the image build lint
|
||||
it but do not run it, and `make test` leaves it out (its file is built only with
|
||||
the `browser` build tag). Run it with `make test-browser` after changing
|
||||
`templates/` or `static/js/`: that builds `Dockerfile.browser`, which runs the
|
||||
test in a digest-pinned headless browser image, so the host needs no browser.
|
||||
under the real policy and checks that: both add forms stay hidden until Add is
|
||||
clicked; choosing Slack in the add target form leaves the HTTP fields out of
|
||||
what it submits, also after leaving the page and going back to it, when the
|
||||
browser restores the choice; an event expands and collapses, and so do a
|
||||
delivery's attempts inside it; and at phone width the menu button opens and
|
||||
closes the mobile menu. It also fails if the browser reports a console warning
|
||||
or error, an uncaught exception, or anything the policy refused. `make check`
|
||||
and the image build lint it but do not run it, and `make test` leaves it out
|
||||
(its file is built only with the `browser` build tag). Run it with
|
||||
`make test-browser` after changing `templates/` or `static/js/`: that builds
|
||||
`Dockerfile.browser`, which runs the test in a digest-pinned headless browser
|
||||
image, so the host needs no browser.
|
||||
|
||||
The package's tarball is committed as `3p/alpinejs-csp-3.14.9.tgz`, byte for
|
||||
byte as the npm registry publishes it. It is a dependency, not this repo's build
|
||||
@@ -1385,9 +1334,7 @@ apply. The directory is `3p/` rather than `vendor/` because Go treats a root
|
||||
where `go:embed` picks it up. `script/test`, `make build` and `make dev` run
|
||||
it first, and the Dockerfile builds through `make test` and `make build`, so
|
||||
nothing downloads Alpine.js. The extracted file is not committed, and
|
||||
`.dockerignore` keeps any host copy out of the build context. `static/static.go`
|
||||
names every file it embeds, so a build that skips the extraction, such as a
|
||||
bare `go build`, fails with an error naming `js/alpine.min.js`.
|
||||
`.dockerignore` keeps any host copy out of the build context.
|
||||
|
||||
To move to a new version: download
|
||||
`https://registry.npmjs.org/@alpinejs/csp/-/csp-<version>.tgz`, check it against
|
||||
@@ -1396,23 +1343,6 @@ the `dist.integrity` hash listed at
|
||||
`3p/` with it as `alpinejs-csp-<version>.tgz`, update its file name in
|
||||
`script/assets`, and run `make check` and `make test-browser`.
|
||||
|
||||
## Stylesheet
|
||||
|
||||
`static/css/tailwind.css` is generated by Tailwind and committed. To change the
|
||||
styles, edit the templates, `static/js/app.js`,
|
||||
`internal/handlers/recent_events.go` or `static/css/input.css`, run `make css`,
|
||||
and commit the regenerated file with the change. Tailwind takes classes only
|
||||
from the files that `input.css` names in its `@source` lines; a class written in
|
||||
any other file is not generated until that file is named there too. `make check`
|
||||
and the image build fail when the committed file differs from what `make css`
|
||||
generates. `static/css/style.css` is hand-written and is not generated.
|
||||
|
||||
`make css` runs the Tailwind standalone CLI in Docker, at the version and sha256
|
||||
pinned in the Dockerfile's stylesheet stages; it is never installed on the host.
|
||||
To move to a new version, change the version in both download URLs and both
|
||||
sha256 sums, taken from the release's `sha256sums.txt`, then run `make css` and
|
||||
commit the result.
|
||||
|
||||
## Rationale
|
||||
|
||||
Webhook integrations between services are inherently fragile. The
|
||||
@@ -1556,9 +1486,6 @@ tier** (event ingestion, delivery, and logging).
|
||||
│ ┌──────────────┐ (one row per target: running counts │
|
||||
│ │ TargetTotals │ of its deliveries) │
|
||||
│ └──────────────┘ │
|
||||
│ ┌──────────────────┐ (one row per entrypoint: when the │
|
||||
│ │ EntrypointTotals │ last event arrived on its URL) │
|
||||
│ └──────────────────┘ │
|
||||
└─────────────────────────────────────────────────────────────┘
|
||||
```
|
||||
|
||||
@@ -1605,13 +1532,6 @@ more entrypoints (receiver URLs) and one or more targets (delivery
|
||||
destinations) into a logical unit. A user creates a webhook to set up
|
||||
event routing.
|
||||
|
||||
The new webhook form can also give the webhook its first targets: an
|
||||
optional HTTP target URL creates an `http` target named `HTTP`, and the
|
||||
archive checkbox creates a `database` target named `Archive` whose
|
||||
`expiry` is the pruning chosen beside it (never, 1h, 12h, 24h, 30d, 90d
|
||||
or 365d). Both are validated as on the add target form, and the webhook
|
||||
and its targets are created together or not at all.
|
||||
|
||||
| Field | Type | Description |
|
||||
| ---------------- | ------- | ----------- |
|
||||
| `id` | UUID | Primary key |
|
||||
@@ -1679,11 +1599,6 @@ different event sources that all feed into the same processing pipeline
|
||||
(e.g., one entrypoint for GitHub, another for Stripe, both routing to
|
||||
the same targets).
|
||||
|
||||
The webhook page shows, for each entrypoint, when the last event arrived
|
||||
on its URL, which retention leaves in place, or "never" if none ever has,
|
||||
and how many events arrived on it within the webhook's retention period.
|
||||
A resubmitted event did not arrive on the URL and counts in neither.
|
||||
|
||||
#### Target
|
||||
|
||||
A delivery destination for events. Each target defines where and how
|
||||
@@ -1893,11 +1808,10 @@ retries) is individually logged for full observability.
|
||||
|
||||
**Relations:** Belongs to Delivery.
|
||||
|
||||
#### EventTotals, TargetTotals and EntrypointTotals
|
||||
#### EventTotals and TargetTotals
|
||||
|
||||
Running counts in each event database, read by the statistics pane at the
|
||||
top of the webhook page and by the webhook list, and each entrypoint's last
|
||||
event, read by the webhook page's entrypoint list. `EventTotals` is one row:
|
||||
top of the webhook page and by the webhook list. `EventTotals` is one row:
|
||||
|
||||
| Field | Type | Description |
|
||||
| ---------------- | --------- | ----------- |
|
||||
@@ -1916,26 +1830,18 @@ event, read by the webhook page's entrypoint list. `EventTotals` is one row:
|
||||
| `deliveries_removed` | integer | Its deliveries retention has deleted |
|
||||
| `failed_removed` | integer | Its failed deliveries retention has deleted |
|
||||
|
||||
`EntrypointTotals` is one row per entrypoint, created by the first event
|
||||
that arrives on its URL:
|
||||
|
||||
| Field | Type | Description |
|
||||
| --------------- | --------- | ----------- |
|
||||
| `entrypoint_id` | UUID | The entrypoint (primary key) |
|
||||
| `last_event_at` | timestamp | When the newest event arrived on its URL; a resubmitted event leaves it as it is, and so does retention |
|
||||
|
||||
Each count changes in the transaction that writes or deletes the rows it counts,
|
||||
and each `last_event_at` in the transaction that stores the event. The pane's
|
||||
lifetime events are `events`, and its lifetime deliveries and failures are
|
||||
`deliveries` and `failed` summed over the targets; each figure within retention
|
||||
is the same less what retention removed, so neither needs the rows themselves.
|
||||
Its last event is `last_event_at` in `EventTotals`, so it still shows once
|
||||
retention has removed every event; each entrypoint's last event, from
|
||||
`EntrypointTotals`, does too. Its last-10-minutes and last-24-hours figures are
|
||||
counted from the `events` and `deliveries` indexes over just that window, the
|
||||
deliveries in one query grouped by target. Its failure percentage for a window
|
||||
is the deliveries that became `failed` in it out of all that became `delivered`
|
||||
or `failed` in it, and a dash when none did.
|
||||
Each count changes in the transaction that writes or deletes the rows it
|
||||
counts. The pane's lifetime events are `events`, and its lifetime
|
||||
deliveries and failures are `deliveries` and `failed` summed over the
|
||||
targets; each figure within retention is the same less what retention
|
||||
removed, so neither needs the rows themselves. Its last event is
|
||||
`last_event_at`, written in the transaction that stores the event, so it
|
||||
still shows once retention has removed every event. Its last-10-minutes and
|
||||
last-24-hours figures are counted from the `events` and `deliveries`
|
||||
indexes over just that window, the deliveries in one query grouped by
|
||||
target. Its failure percentage for a window is the deliveries that became
|
||||
`failed` in it out of all that became `delivered` or `failed` in it, and
|
||||
a dash when none did.
|
||||
|
||||
The webhook list at `/hooks` shows three of the pane's figures for each
|
||||
webhook: its events within retention and its last event, both from
|
||||
@@ -1945,12 +1851,6 @@ counted with the pane's query. It opens each webhook's event database once
|
||||
with the number of webhooks and, for each, with the deliveries that
|
||||
finished in the last 24 hours, never with the events stored.
|
||||
|
||||
The target list on the webhook page shows, for each target, its
|
||||
`delivered` and `failed` totals, which retention does not reduce, and its
|
||||
deliveries that became `delivered` and `failed` in the last 24 hours,
|
||||
counted with the pane's query. Deliveries still `pending` or `retrying`
|
||||
count in neither.
|
||||
|
||||
#### Event-tier indexes
|
||||
|
||||
These indexes on the per-webhook event databases are declared in the model
|
||||
@@ -1958,36 +1858,28 @@ tags, so `AutoMigrate` creates them on a fresh database:
|
||||
|
||||
| Table | Columns | Serves |
|
||||
| ------------------ | --------------------------- | ------ |
|
||||
| `deliveries` | `status`, `deleted_at`, `finished_at`, `target_id` | Startup recovery, the retry and pending sweeps every 60 seconds and the queue-depth sampler every 30 seconds, which select deliveries by status, and the webhook page's statistics and target list and the webhook list, which count each target's deliveries by status and when they finished |
|
||||
| `deliveries` | `status`, `deleted_at`, `finished_at`, `target_id` | Startup recovery, the retry and pending sweeps every 60 seconds and the queue-depth sampler every 30 seconds, which select deliveries by status, and the webhook page's statistics and the webhook list, which count each target's deliveries by status and when they finished |
|
||||
| `deliveries` | `event_id`, `deleted_at` | The event log, which loads each event's deliveries, and retention, which counts and deletes the deliveries of expired events |
|
||||
| `delivery_results` | `delivery_id`, `deleted_at` | The event log, which loads the attempts of a page's deliveries, and retention, which deletes the attempts of expired events |
|
||||
| `events` | `deleted_at`, `created_at` | The webhook page's statistics, which count recent events |
|
||||
| `events` | `resubmitted_from_id`, `deleted_at` | The event log, which counts the events resubmitted from each event on a page |
|
||||
| `events` | `entrypoint_id`, `deleted_at`, `resubmitted_from_id`, `created_at` | The webhook page's entrypoint list, which counts the events that arrived on each entrypoint's URL within the retention period |
|
||||
| `events` | `created_at` | Retention, which selects expired events by age |
|
||||
|
||||
GORM's soft delete adds `deleted_at IS NULL` to these queries; retention leaves
|
||||
it out. SQLite keeps no statistics on these tables, and without them it rates
|
||||
the `deleted_at` index, which every live row matches, above an index on a column
|
||||
matched against several values or compared with a range. So every index but the
|
||||
last also covers `deleted_at`. It comes second in the `event_id` and
|
||||
`delivery_id` indexes, so that retention can use them without it. The event
|
||||
log's count, the one query on the `resubmitted_from_id` index, always carries
|
||||
`deleted_at IS NULL` and uses both columns. The entrypoint list's count, the one
|
||||
query on the `entrypoint_id` index, uses all four, `resubmitted_from_id IS NULL`
|
||||
leaving out resubmitted copies and `created_at` last because it compares it with
|
||||
a range (`>=`). In the statistics' `events` index `deleted_at` comes first,
|
||||
because they compare `created_at` with a range (`>=`) and SQLite narrows by a
|
||||
GORM's soft delete adds `deleted_at IS NULL` to these queries; retention
|
||||
leaves it out. SQLite keeps no statistics on these tables, and without them it
|
||||
rates the `deleted_at` index, which every live row matches, above an index on
|
||||
a column matched against several values or compared with a range. So every
|
||||
index but the last also covers `deleted_at`. It comes second, so that
|
||||
retention can use the index without it, except in `events`, where the
|
||||
statistics compare `created_at` with a range (`>=`) and SQLite narrows by a
|
||||
range only on the last column it uses.
|
||||
|
||||
#### Common Fields
|
||||
|
||||
Every entity except `Setting`, `EventTotals`, `TargetTotals` and
|
||||
`EntrypointTotals` includes these fields from `BaseModel`. `Setting` is a bare
|
||||
key-value row with no `id`, no timestamps and no soft delete. Of the three
|
||||
totals tables, `event_totals` holds counts and `last_event_at`, keyed by a
|
||||
numeric `id`; `target_totals` holds counts, keyed by `target_id`; and
|
||||
`entrypoint_totals` holds `last_event_at`, keyed by `entrypoint_id`:
|
||||
Every entity except `Setting`, `EventTotals` and `TargetTotals` includes
|
||||
these fields from `BaseModel`. `Setting` is a bare key-value row with no
|
||||
`id`, no timestamps and no soft delete, and the two totals tables hold
|
||||
counts, plus `last_event_at` in `event_totals`, keyed by a numeric `id`
|
||||
and by `target_id`:
|
||||
|
||||
| Field | Type | Description |
|
||||
| ------------ | --------- | ----------- |
|
||||
@@ -2029,24 +1921,14 @@ encryption key is generated and stored, and an `admin` user is created.
|
||||
- **Events** — captured incoming webhook payloads
|
||||
- **Deliveries** — event-to-target pairings and their status
|
||||
- **DeliveryResults** — individual delivery attempt logs
|
||||
- **EventTotals**, **TargetTotals** and **EntrypointTotals** — running
|
||||
counts of the above, the deliveries per target, and each entrypoint's
|
||||
last event, kept through retention
|
||||
- **EventTotals** and **TargetTotals** — running counts of the above,
|
||||
the deliveries per target, kept through retention
|
||||
|
||||
Per-webhook databases are created automatically when a webhook is
|
||||
created. They are managed by the `WebhookDBManager` component, which
|
||||
created (and lazily on first access for webhooks that predate this
|
||||
feature). They are managed by the `WebhookDBManager` component, which
|
||||
handles connection pooling, lazy opening, migrations, and cleanup.
|
||||
|
||||
A per-webhook database that is missing or zero-length later means its
|
||||
webhook's events and pending deliveries are gone. The next time it is
|
||||
opened, an empty one is created in its place, so the webhook keeps
|
||||
receiving, and `created a new, empty database` is logged at `WARN` with
|
||||
the file's path. Every webhook's database is opened when the service
|
||||
starts, so this appears at the latest at the first start after the
|
||||
file was lost. A file there that SQLite cannot open fails that
|
||||
webhook alone, with an `ERROR` naming the webhook on every access and a
|
||||
500 to its senders, so one damaged file does not stop the others.
|
||||
|
||||
This separation provides:
|
||||
|
||||
- **Isolation** — a high-volume webhook won't cause lock contention or
|
||||
@@ -2111,9 +1993,7 @@ After each write the archive handle is closed
|
||||
and reopened, debounced to at most once per second, so an operator can
|
||||
move the archive file away for offline archiving without stopping the
|
||||
service; a moved or removed archive file is recreated automatically on
|
||||
the next write. A zero-length archive file is written to as a new
|
||||
archive: SQLite opens it as an empty database, so it holds nothing to
|
||||
lose. An optional `expiry` in the target's config JSON (e.g.
|
||||
the next write. An optional `expiry` in the target's config JSON (e.g.
|
||||
`{"expiry":"720h"}`) is validated when the target is created — the
|
||||
default (unset or the literal `never`) keeps rows forever — and rows
|
||||
older than the expiry are pruned each time the archive is (re)opened. An
|
||||
@@ -2137,37 +2017,6 @@ Because each `database` target has its own archive file, a target's
|
||||
webhook with different expiries keep two archives, each pruned on its
|
||||
own schedule.
|
||||
|
||||
The webhook page shows, for each `database` target, its archive file's
|
||||
name, its size on disk and when it was last written. The size counts
|
||||
the `.db` and its `-wal` together, and the last write is the later of
|
||||
their two modification times, since a write lands in the `-wal` first.
|
||||
Both are read from the files' metadata; the archive is never opened.
|
||||
Before the first write, and after the file has been moved away, the page
|
||||
shows `not created yet` beside the name.
|
||||
|
||||
Each `database` target on the webhook page has a **Download** button,
|
||||
which returns its archive as one gzipped JSON file,
|
||||
`archive-{webhook_name}-{target_name}-{YYYYMMDDTHHMMSSZ}.json.gz`, the
|
||||
names made safe as above and the time in UTC. The file holds one
|
||||
object: `webhook` and `target`, each an `id` and a `name`;
|
||||
`exported_at`; and `archived_events`, one object per archived row with
|
||||
every column, keyed by column name. A body that is not valid UTF-8 is
|
||||
written in base64, with `"body_encoding": "base64"` beside it. An
|
||||
archive that does not exist yet, or was moved away, downloads with an
|
||||
empty `archived_events`; the download never creates the file.
|
||||
|
||||
The download streams: each row is read and written out compressed
|
||||
before the next is read, so neither the archive nor the JSON is held in
|
||||
memory. It reads on a connection of its own, inside one read-only
|
||||
transaction, so the file holds the archive as it stood when the
|
||||
download started, and archive writes go on meanwhile, since under WAL a
|
||||
reader never blocks a writer. While it runs, the `-wal` cannot be
|
||||
checkpointed past what it reads, so a long download lets the `-wal`
|
||||
grow. It finds the file by the stored names under the lock that webhook
|
||||
edits, target edits and target creation hold, and lets go once the file
|
||||
is open: a rename during the download moves the file without affecting
|
||||
it.
|
||||
|
||||
Deleting a webhook releases its archives: the delivery engine's cached
|
||||
archive writers are dropped and their file handles closed, so nothing
|
||||
lingers after the webhook is gone. The archive **files themselves are
|
||||
@@ -2624,21 +2473,20 @@ trade.
|
||||
Net: **one `INFO` line per request, of at most 2,560 bytes.** That
|
||||
ceiling is arithmetic, not an observation: 3 × (512 + 11) for `url`,
|
||||
`useragent` and `referer`, plus 128 + 11 for `request_id`, plus 32 + 11
|
||||
for `method`, plus a 405-byte fixed portion (the field names, the
|
||||
punctuation, both timestamps at their longest, `remoteIP` and
|
||||
`clientIP` each charged as an IPv6 address with a zone, the status and
|
||||
the latency) — 2,156 bytes, stated at 2,560 so the figure has headroom.
|
||||
`internal/middleware/accesslog_test.go` asserts it against 8 KB of
|
||||
client-chosen text in the path, in the query, and in each of
|
||||
`User-Agent`, `Referer`, `X-Request-Id` and `X-Forwarded-For`,
|
||||
for `method`, plus a 336-byte fixed portion (the field names, the
|
||||
punctuation, both timestamps at their longest, an IPv6 `remoteIP` with
|
||||
a zone, the status and the latency) — 2,087 bytes, stated at 2,560 so
|
||||
the figure has headroom. `internal/middleware/accesslog_test.go`
|
||||
asserts it against 8 KB of client-chosen text in the path, in the
|
||||
query, and in each of `User-Agent`, `Referer` and `X-Request-Id`,
|
||||
including cases built from the characters the handlers escape, and
|
||||
against a 5xx that keeps its concrete path while all three header fields
|
||||
are also at their budget and an `X-Forwarded-For` sent from a trusted
|
||||
proxy ends in an IPv6 client address at its longest followed by an 8 KB
|
||||
zone, where `clientIP` must name the address without the zone. Every
|
||||
case runs through both handlers `internal/logger` can select — the JSON
|
||||
one and the text one it installs on a tty — since the two do not escape
|
||||
alike and the ceiling is quoted unqualified.
|
||||
against the widest access log line the service can be made to write: a
|
||||
5xx that keeps its concrete path while all three header fields are also
|
||||
at their budget. Every case runs through both handlers
|
||||
`internal/logger` can select — the JSON one and the text one it installs
|
||||
on a tty — since the two do not escape alike and the ceiling is quoted
|
||||
unqualified. Measured over a real connection, the widest access log line
|
||||
is 1,972 bytes.
|
||||
|
||||
Multiply that ceiling by the request rate to size log storage. Note
|
||||
that the rate is not bounded by the limits above on every route:
|
||||
@@ -2746,10 +2594,11 @@ on all three arms of `Trace`, including the routine one an operator
|
||||
reaches at `DEBUG`, which is the only level at which a successful
|
||||
`INSERT` is written at all. One GORM path does not consult the filter —
|
||||
`(*gorm.DB).Scan`, which records the statement through GORM's own trace
|
||||
recorder. No production code path calls it; only tests do, and what a
|
||||
test binds is fixture data. `internal/gormlog/scan_guard_test.go` fails
|
||||
if a non-test file calls it. `Pluck`, `Row` and `Raw` all run through
|
||||
the normal callback processor and are filtered.
|
||||
recorder. No production code path calls it; its one caller is
|
||||
`internal/database/database_test.go:91`, whose `SELECT 1` binds
|
||||
nothing, and `internal/gormlog/scan_guard_test.go` fails if a non-test
|
||||
file calls it. `Pluck`, `Row` and `Raw` all run through the normal
|
||||
callback processor and are filtered.
|
||||
See `#### What DEBUG=true exposes` under Configuration.
|
||||
|
||||
What that ceiling does **not** cover, stated here so the figure is not
|
||||
@@ -2775,20 +2624,16 @@ read as more than it is:
|
||||
that type on a specific webhook, and each line it writes is bounded
|
||||
per event by the 1 MB receiver body cap. Adding one is a decision to
|
||||
spend log volume on that webhook's payloads.
|
||||
- **The Go runtime**, which does not go through `internal/logger`. The
|
||||
runtime writes an unrecovered panic or a fatal error itself, as plain
|
||||
text on standard error, and that output cannot be redirected. A panic
|
||||
in a background worker rather than in a request handler is the case
|
||||
that reaches it, since nothing recovers those. It carries no
|
||||
client-chosen value at a client-chosen length: the service's own
|
||||
`panic` calls are invariant guards over constants and over
|
||||
`crypto/rand`, apart from the one that hands `http.ErrAbortHandler`
|
||||
back to `net/http`, described below.
|
||||
- **A failure before fx's logger is built**, such as an invalid
|
||||
configuration value. fx's logger takes the configuration, so when
|
||||
that fails fx's own console logger still prints the failure as plain
|
||||
text on standard error. Its values come from the operator's
|
||||
environment, not from a client.
|
||||
- **Two writers that do not go through `internal/logger` at all**, both
|
||||
on standard error. `fx` prints the dependency graph and the lifecycle
|
||||
hooks through its default console logger at startup and shutdown —
|
||||
nothing calls `fx.WithLogger`, and `fx.New` builds that logger over
|
||||
`os.Stderr`. The Go runtime writes a panic or a fatal error itself; a
|
||||
panic in a background worker rather than in a request handler is the
|
||||
case that reaches it, since nothing recovers those. Neither carries a
|
||||
client-chosen value at a client-chosen length: the five `panic` calls
|
||||
in this service are invariant guards over constants and over
|
||||
`crypto/rand`.
|
||||
- **`net/http`'s own faults**, which are _not_ a separate writer.
|
||||
`internal/server/http.go` builds its server with a nil `ErrorLog`, so
|
||||
`net/http` falls back to the `log` package's default logger — and
|
||||
@@ -2979,9 +2824,9 @@ remedies are to block the source at the reverse proxy, or to
|
||||
rate-limit `POST /pages/login` there — the one place a limit can be
|
||||
applied without reintroducing the lockout, because the proxy sees the
|
||||
real client address. `TRUSTED_PROXIES` does not stop the saturation.
|
||||
The flood's source is in the `clientIP` field of webhooker's access
|
||||
log while `TRUSTED_PROXIES` covers the proxy, and in the proxy's own
|
||||
access log either way (see [Trusted proxies](#trusted-proxies)).
|
||||
The flood's source is in the proxy's access log: webhooker's own logs
|
||||
record the proxy's address, not the client's (see
|
||||
[Deployment behind a reverse proxy](#deployment-behind-a-reverse-proxy)).
|
||||
|
||||
Finer-grained per-webhook rate limits (configured in the web UI and
|
||||
enforced in the webhook handler) can layer on top of this env-level
|
||||
@@ -3025,18 +2870,15 @@ returns to the page that was asked for.
|
||||
| `POST` | `/hook/{id}/edit` | Edit webhook submission |
|
||||
| `POST` | `/hook/{id}/delete` | Delete webhook |
|
||||
| `GET` | `/hook/{id}/events` | Full Event Log |
|
||||
| `GET` | `/hook/{id}/events/{eventID}` | One event's own page: its details, its whole body and every delivery of it |
|
||||
| `GET` | `/hook/{id}/events/{eventID}/body` | Download an event's stored body. The pages show a body as text, cut at 32 KiB in the recent events and the event log, and leave a binary one out, so this is the only route that serves the stored bytes; it is offered wherever a body is cut or binary |
|
||||
| `GET` | `/hook/{id}/events/{eventID}/body` | Download an event's full stored body. The log page renders each body only up to its cap, so this is the only route that serves a whole one; it is offered wherever a body is shown truncated |
|
||||
| `POST` | `/hook/{id}/deliveries/{deliveryID}/replay` | Replay a finished delivery: creates a new delivery for the same event against the target's current configuration (30 per minute per bucket, then `429`) |
|
||||
| `POST` | `/hook/{id}/events/{eventID}/resubmit` | Resubmit a stored event: creates a new event copying it and fans that out to every currently active target (30 per minute per bucket, then `429`) |
|
||||
| `POST` | `/hook/{id}/entrypoints` | Add entrypoint to webhook |
|
||||
| `POST` | `/hook/{id}/entrypoints/{entrypointID}/edit` | Change an entrypoint's description; its URL stays the same |
|
||||
| `POST` | `/hook/{id}/entrypoints/{entrypointID}/delete` | Delete an entrypoint |
|
||||
| `POST` | `/hook/{id}/entrypoints/{entrypointID}/toggle` | Enable or disable an entrypoint |
|
||||
| `POST` | `/hook/{id}/targets` | Add target to webhook |
|
||||
| `GET` | `/hook/{id}/targets/{targetID}/edit` | Edit target form. The one page that renders a target's destination URL and header values in full, rather than masked |
|
||||
| `POST` | `/hook/{id}/targets/{targetID}/edit` | Edit target submission |
|
||||
| `GET` | `/hook/{id}/targets/{targetID}/download` | Download a `database` target's archive as one gzipped JSON file. See [Database Architecture](#database-architecture) |
|
||||
| `POST` | `/hook/{id}/targets/{targetID}/delete` | Delete a target |
|
||||
| `POST` | `/hook/{id}/targets/{targetID}/toggle` | Enable or disable a target |
|
||||
|
||||
@@ -3082,8 +2924,7 @@ webhooker/
|
||||
│ ├── resetpw/
|
||||
│ │ └── resetpw.go # `webhooker resetpw`: set an account's password, stopped deployments only
|
||||
│ ├── config/
|
||||
│ │ ├── config.go # Configuration loading from environment variables
|
||||
│ │ └── testing.go # ClearEnvForTest: an empty environment for one test
|
||||
│ │ └── config.go # Configuration loading from environment variables
|
||||
│ ├── database/
|
||||
│ │ ├── base_model.go # BaseModel with UUID primary keys
|
||||
│ │ ├── database.go # GORM connection, migrations, admin seed
|
||||
@@ -3096,7 +2937,7 @@ webhooker/
|
||||
│ │ ├── model_event.go # Event entity (per-webhook DB)
|
||||
│ │ ├── model_delivery.go # Delivery entity (per-webhook DB)
|
||||
│ │ ├── model_delivery_result.go # DeliveryResult entity (per-webhook DB)
|
||||
│ │ ├── model_totals.go # EventTotals, TargetTotals and EntrypointTotals (per-webhook DB)
|
||||
│ │ ├── model_totals.go # EventTotals and TargetTotals (per-webhook DB)
|
||||
│ │ ├── model_apikey.go # APIKey entity
|
||||
│ │ ├── password.go # Argon2id hashing and verification
|
||||
│ │ ├── retention.go # Retention reaper (per-webhook event expiry)
|
||||
@@ -3118,7 +2959,6 @@ webhooker/
|
||||
│ │ ├── target_slack.go # Slack/Mattermost incoming-webhook target
|
||||
│ │ ├── target_database.go # Database archive target
|
||||
│ │ ├── target_database_archive.go # Archive file lifecycle and pruning
|
||||
│ │ ├── target_database_export.go # Archive download as gzipped JSON
|
||||
│ │ ├── target_log.go # Log target (stdout)
|
||||
│ │ ├── target_config_view.go # Masked target config for templates
|
||||
│ │ ├── archive_sweeper.go # Periodic pruning of idle archives
|
||||
@@ -3143,7 +2983,7 @@ webhooker/
|
||||
│ ├── lifecycle/
|
||||
│ │ └── lifecycle.go # Shared stop-hook waiter, bounded by the stop context
|
||||
│ ├── logger/
|
||||
│ │ └── logger.go # slog setup with TTY detection; fx's event logger
|
||||
│ │ └── logger.go # slog setup with TTY detection
|
||||
│ ├── metrics/
|
||||
│ │ └── metrics.go # Delivery Prometheus collectors, labelled by target type
|
||||
│ ├── middleware/
|
||||
@@ -3167,15 +3007,15 @@ webhooker/
|
||||
│ ├── static.go # //go:embed directive
|
||||
│ ├── css/input.css # Tailwind input, source for tailwind.css (make css)
|
||||
│ ├── css/tailwind.css # Generated stylesheet the pages load
|
||||
│ ├── css/style.css # Hand-written, loaded after tailwind.css: btn-small, the pointer cursor for input.css's buttons, the webhook list cards' focus outline
|
||||
│ ├── css/style.css # Older hand-written stylesheet, no longer loaded
|
||||
│ ├── js/app.js # Copy-to-clipboard, and the Alpine.js components
|
||||
│ └── js/alpine.min.js # Alpine.js CSP build, extracted from 3p/ by make assets, not committed
|
||||
├── templates/ # Go HTML templates (base, login, sources, etc.)
|
||||
├── script/ # Scripts to Rule Them All entrypoints
|
||||
├── Dockerfile # Stages: lint, stylesheet, test+build, Alpine runtime
|
||||
├── Dockerfile # Three stages: lint, test+build, Alpine runtime
|
||||
├── Dockerfile.lint # Lint-only image built by script/lint
|
||||
├── Dockerfile.browser # Browser test image built by script/test-browser
|
||||
├── Makefile # 13 of 19 targets shim script/; 6 are inline
|
||||
├── Makefile # 11 of 18 targets shim script/; 7 are inline
|
||||
├── go.mod / go.sum
|
||||
└── .golangci.yml # Linter configuration
|
||||
```
|
||||
@@ -3224,7 +3064,7 @@ Applied to all routes in this order:
|
||||
(HSTS, X-Content-Type-Options, X-Frame-Options, CSP, Referrer-Policy,
|
||||
Permissions-Policy)
|
||||
3. **Logging** — Structured request logging (method, URL, status,
|
||||
latency, remote IP, client IP, user agent, request ID)
|
||||
latency, remote IP, user agent, request ID)
|
||||
4. **Metrics** — Prometheus HTTP metrics (if `METRICS_USERNAME` and
|
||||
`METRICS_PASSWORD` are both set)
|
||||
5. **CORS** — Cross-origin resource sharing headers
|
||||
@@ -3372,9 +3212,9 @@ check, see [The login endpoint](#the-login-endpoint).
|
||||
`ENTRYPOINT` script, which sets the data directory's owner and mode
|
||||
before the app starts; the image's health check; and `docker exec`,
|
||||
unless given `--user`
|
||||
- GORM soft deletes on every entity that carries `BaseModel`, which is all of
|
||||
them but `Setting`, `EventTotals`, `TargetTotals` and `EntrypointTotals`
|
||||
(data preserved for audit)
|
||||
- GORM soft deletes on every entity that carries `BaseModel`, which is
|
||||
all of them but `Setting`, `EventTotals` and `TargetTotals` (data
|
||||
preserved for audit)
|
||||
|
||||
### Shutdown
|
||||
|
||||
@@ -3385,9 +3225,9 @@ each hook. The order, read off the fx stop-hook log:
|
||||
|
||||
1. `ArchiveSweeper`
|
||||
2. `RetentionReaper`
|
||||
3. `server` — the HTTP drain, bounded by `server.ShutdownTimeout`
|
||||
(**3 seconds**) and by what the hooks before it left, then a Sentry
|
||||
flush if `SENTRY_DSN` is set
|
||||
3. `server` — the HTTP drain, bounded separately by
|
||||
`server.ShutdownTimeout` (**3 seconds**), then a Sentry flush if
|
||||
`SENTRY_DSN` is set
|
||||
4. `delivery.Engine` — waits for its workers, then closes the archive
|
||||
databases
|
||||
5. `healthcheck`
|
||||
@@ -3407,30 +3247,23 @@ exhaust the sequence budget at the instant it finished, and every
|
||||
later hook — the delivery engine, the healthcheck, the webhook DB
|
||||
manager and the database close — would be skipped in exactly the
|
||||
case where the drain mattered. 3 seconds leaves 2 seconds
|
||||
(`server.TailHookReserve`) for the tail. The reserve is that
|
||||
remainder, not a figure sized to the tail, which takes about a
|
||||
millisecond.
|
||||
(`server.TailHookReserve`) for the tail, which is far more than the
|
||||
microseconds it needs.
|
||||
|
||||
That reserve belongs to the tail hooks, not to the server hook, and
|
||||
the server hook could take it in two ways. The hooks before it may
|
||||
already have spent part of the budget, so a full 3-second drain
|
||||
would come out of the reserve; the drain is therefore also bounded
|
||||
by whatever is left on the stop context minus the reserve. And the
|
||||
Sentry flush runs after the drain **inside the same hook**, and
|
||||
`sentry.Flush` takes a bare duration and honours no context, so an
|
||||
unreachable Sentry endpoint would add its own timeout on top of a
|
||||
full-length drain and consume the whole sequence budget by itself.
|
||||
It is clamped the same way, and skipped when that leaves too little
|
||||
to be worth attempting — so a full-length drain means Sentry events
|
||||
are dropped rather than the database close being skipped.
|
||||
the Sentry flush is what could take it: it runs after the drain
|
||||
**inside the same hook**, and `sentry.Flush` takes a bare duration
|
||||
and honours no context, so an unreachable Sentry endpoint would add
|
||||
its own timeout on top of a full-length drain and consume the whole
|
||||
sequence budget by itself. It is therefore clamped to whatever is
|
||||
left on the stop context minus the reserve, and skipped when that
|
||||
leaves too little to be worth attempting — so a full-length drain
|
||||
means Sentry events are dropped rather than the database close being
|
||||
skipped.
|
||||
|
||||
This does not make the database close unconditional. A slow
|
||||
`ArchiveSweeper` or `RetentionReaper` is enough to cut the shutdown
|
||||
short, not only one that consumes the whole budget: what they spend
|
||||
comes out of the drain first, so after 2 seconds of theirs a request
|
||||
still in flight gets 1 second to finish, and after 3 it gets none.
|
||||
Past 3 seconds they spend the reserve itself, and one that takes the
|
||||
whole budget skips every hook after it, the database close included.
|
||||
This does not make the database close unconditional: a wedged
|
||||
`ArchiveSweeper` or `RetentionReaper` still runs first and can
|
||||
consume the whole budget on its own.
|
||||
|
||||
The value is chosen to sit inside the container stop grace period.
|
||||
Docker's default `docker stop` grace is 10 seconds and the Dockerfile
|
||||
@@ -3489,26 +3322,17 @@ Three properties are load-bearing:
|
||||
|
||||
### Docker
|
||||
|
||||
The Dockerfile uses a multi-stage build. Each stage is pinned by
|
||||
digest, and the lint and builder stages are separate images so the
|
||||
linter's version is fixed independently of the compiler's:
|
||||
The Dockerfile uses a three-stage build. Each stage is pinned by
|
||||
digest, and the two check stages are separate images so the linter's
|
||||
version is fixed independently of the compiler's:
|
||||
|
||||
1. **Lint stage** (`golangci/golangci-lint:v2.12.2`, Debian-based) —
|
||||
installs `make`, downloads dependencies, copies the source, and runs
|
||||
`make fmt-check`, then `script/assets` to extract Alpine.js from
|
||||
`3p/`, then `golangci-lint config verify` and `golangci-lint run`,
|
||||
both with `--network=none`.
|
||||
2. **Stylesheet stages** (`debian:bookworm-slim`, with the Tailwind
|
||||
standalone CLI pinned by version and sha256, one binary per
|
||||
architecture) — generate `static/css/tailwind.css` from
|
||||
`static/css/input.css` and the files its `@source` lines name.
|
||||
`css-check` fails when the committed file differs from the generated
|
||||
one, and `make css` writes the generated file out from `css-output`
|
||||
(see [Stylesheet](#stylesheet)).
|
||||
3. **Builder stage** (`golang:1.26.1-bookworm`) — depends on the lint
|
||||
and `css-check` stages passing (it copies a file from each), runs
|
||||
`make test` and `make build` (both extract Alpine.js from `3p/`
|
||||
first), and finally
|
||||
`make fmt-check`, then `golangci-lint config verify` and
|
||||
`golangci-lint run`, both with `--network=none`.
|
||||
2. **Builder stage** (`golang:1.26.1-bookworm`) — depends on the lint
|
||||
stage passing (it copies a file from it), runs `make test` and
|
||||
`make build` (both extract Alpine.js from `3p/` first), and finally
|
||||
rebuilds the binary with `CGO_ENABLED=1` and static linking so it
|
||||
runs on musl. Both builds go through `make build`, the relink adding
|
||||
its `-extldflags` via `GO_LDFLAGS`, so neither can drop the `-X` that
|
||||
@@ -3516,7 +3340,7 @@ linter's version is fixed independently of the compiler's:
|
||||
given, otherwise derived from the `.git` in the context, and the
|
||||
stage fails if a context with `.git` would stamp `unknown` (see
|
||||
[Version stamping](#version-stamping)).
|
||||
4. **Runtime stage** (`alpine:3.21`) — copies the static binary and
|
||||
3. **Runtime stage** (`alpine:3.21`) — copies the static binary and
|
||||
`deploy/docker-entrypoint.sh`, creates the `/var/lib/webhooker`
|
||||
directory for all SQLite databases, exposes port 8080, and includes
|
||||
a health check against `/.well-known/healthcheck`. It sets no
|
||||
@@ -3528,18 +3352,18 @@ The lint stage invokes `golangci-lint` directly rather than `make lint`:
|
||||
it is already the pinned linter image, and `make lint` builds
|
||||
`Dockerfile.lint`, which would need a docker daemon inside this build.
|
||||
|
||||
The lint and builder stages use Debian rather than Alpine because
|
||||
Both check stages use Debian rather than Alpine because
|
||||
`gorm.io/driver/sqlite` pulls in `mattn/go-sqlite3`, which needs CGO
|
||||
and does not compile against musl. Only the final binary is statically
|
||||
linked, which is what lets it run on the Alpine runtime image.
|
||||
|
||||
`script/cibuild` — `docker build .` — is the CI gate: the checks run
|
||||
inside the image, so a build that succeeds is a repo that is formatted,
|
||||
linted, tested and compiled, with a current stylesheet. `script/lint`
|
||||
also uses Docker (`Dockerfile.lint`, see Linting above), so `make lint`
|
||||
and `make check` run the same pinned linter version the gate does; of
|
||||
the steps `make check` runs, only `script/test` and `script/fmt-check`
|
||||
run on the host.
|
||||
linted, tested and compiled. `script/lint` also uses Docker
|
||||
(`Dockerfile.lint`, see Linting above), so `make lint` and `make check`
|
||||
run the same pinned linter version the gate does; of the steps
|
||||
`make check` runs, only `script/test` and `script/fmt-check` run on the
|
||||
host.
|
||||
|
||||
#### CI gate honesty
|
||||
|
||||
@@ -3549,10 +3373,9 @@ check meaningless. The `check` workflow therefore writes
|
||||
`.ci-fingerprint` into the build context before building. Its value is
|
||||
the hash of the commit being checked, so every commit, docs-only ones
|
||||
and a squash merge whose tree matches an already-built branch included,
|
||||
gets a new fingerprint, invalidates the `COPY . .` layer of every check
|
||||
stage, and really runs `make fmt-check`, `golangci-lint`, the stylesheet
|
||||
check, `make test`, and `make build`. A run that reports success ran
|
||||
them.
|
||||
gets a new fingerprint, invalidates the `COPY . .` layer of both check
|
||||
stages, and really runs `make fmt-check`, `golangci-lint`, `make test`,
|
||||
and `make build`. A run that reports success ran them.
|
||||
|
||||
The module download layer sits above `COPY . .` and stays cached.
|
||||
|
||||
|
||||
+7
-23
@@ -8,7 +8,6 @@ import (
|
||||
"time"
|
||||
|
||||
"go.uber.org/fx"
|
||||
"go.uber.org/fx/fxevent"
|
||||
"sneak.berlin/go/webhooker/internal/config"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/datadir"
|
||||
@@ -38,19 +37,17 @@ import (
|
||||
// hook that used the whole budget would exhaust it at that instant,
|
||||
// and fx would skip every hook after the server — the delivery
|
||||
// engine, the healthcheck, the webhook DB manager and the database
|
||||
// close. That hook is the HTTP drain plus the Sentry flush that
|
||||
// follows it in the same hook, and each is clamped to the stop
|
||||
// close. That hook is the 3s HTTP drain plus the Sentry flush that
|
||||
// follows it in the same hook, so the flush is clamped to the stop
|
||||
// context's remaining time less server.TailHookReserve rather than
|
||||
// running for its own fixed 3s and 2s; the reserve is what the tail
|
||||
// hooks live on, and they are microsecond-scale in normal operation.
|
||||
// running for its own fixed 2s; the reserve is what the tail hooks
|
||||
// live on, and they are microsecond-scale in normal operation.
|
||||
// TestStopTimeout_LeavesHeadroomForTailHooks pins the arithmetic
|
||||
// across every drain length and every amount of budget the hooks
|
||||
// before the server may already have spent.
|
||||
// across every drain length.
|
||||
//
|
||||
// This does not make the database close unconditional: the
|
||||
// ArchiveSweeper and RetentionReaper hooks run before the server.
|
||||
// What they spend comes out of the drain first, but past 3s it comes
|
||||
// out of the reserve, and they can consume the whole budget.
|
||||
// ArchiveSweeper and RetentionReaper hooks run before the server
|
||||
// and can still consume the whole budget on their own.
|
||||
const stopTimeout = 5 * time.Second
|
||||
|
||||
// exitUsage is the status for a command line this binary cannot make
|
||||
@@ -171,19 +168,6 @@ func run(stderr io.Writer) int {
|
||||
func newApp() *fx.App {
|
||||
return fx.New(
|
||||
fx.StopTimeout(stopTimeout),
|
||||
// fx's own events go through the service's logger, not fx's
|
||||
// console logger on standard error. The exception is a failure
|
||||
// before this logger is built, such as an invalid configuration
|
||||
// value, which fx's console logger still prints there. fx holds
|
||||
// its events back until this logger is built and then replays
|
||||
// them, so it takes the configuration, which sets the level
|
||||
// DEBUG=true asks for: without it the replay would run at INFO
|
||||
// and drop every record of how the graph was built.
|
||||
fx.WithLogger(
|
||||
func(l *logger.Logger, _ *config.Config) fxevent.Logger {
|
||||
return logger.NewFxLogger(l.Get())
|
||||
},
|
||||
),
|
||||
fx.Provide(
|
||||
globals.New,
|
||||
logger.New,
|
||||
|
||||
+9
-129
@@ -2,19 +2,12 @@ package main
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"encoding/json"
|
||||
"io"
|
||||
"log/slog"
|
||||
"net"
|
||||
"os"
|
||||
"strconv"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"sneak.berlin/go/webhooker/internal/config"
|
||||
"sneak.berlin/go/webhooker/internal/datadir"
|
||||
"sneak.berlin/go/webhooker/internal/resetpw"
|
||||
"sneak.berlin/go/webhooker/internal/server"
|
||||
@@ -37,7 +30,6 @@ const dockerStopGrace = 10 * time.Second
|
||||
// fx.New applies options before it executes invokes, so the timeout
|
||||
// is set whether or not the graph itself can be constructed here.
|
||||
func TestNewApp_StopTimeout(t *testing.T) {
|
||||
config.ClearEnvForTest(t)
|
||||
t.Setenv("DATA_DIR", t.TempDir())
|
||||
|
||||
got := newApp().StopTimeout()
|
||||
@@ -46,100 +38,6 @@ func TestNewApp_StopTimeout(t *testing.T) {
|
||||
require.Less(t, got, dockerStopGrace)
|
||||
}
|
||||
|
||||
// freePort returns a loopback TCP port that was free a moment ago, by
|
||||
// taking one and releasing it.
|
||||
func freePort(t *testing.T) int {
|
||||
t.Helper()
|
||||
|
||||
var listenCfg net.ListenConfig
|
||||
|
||||
l, err := listenCfg.Listen(t.Context(), "tcp", "127.0.0.1:0")
|
||||
require.NoError(t, err)
|
||||
|
||||
addr, ok := l.Addr().(*net.TCPAddr)
|
||||
require.True(t, ok, "listener is not TCP")
|
||||
require.NoError(t, l.Close())
|
||||
|
||||
return addr.Port
|
||||
}
|
||||
|
||||
// TestNewApp_SendsFxEventsToTheLogger starts and stops the app main
|
||||
// runs, with DEBUG=true, and reads back what reached the service's
|
||||
// logger. fx's own events must arrive there as structured records:
|
||||
// the start at INFO, and at DEBUG the records of how the graph was
|
||||
// built.
|
||||
//
|
||||
// fx holds its events back until its logger is built and then replays
|
||||
// them all at once, so the earliest of them arriving shows the replay
|
||||
// ran at DEBUG: that globals.New was provided, which fx records before
|
||||
// anything is built, and the run of logger.New, which happens before
|
||||
// the configuration sets the level.
|
||||
func TestNewApp_SendsFxEventsToTheLogger(t *testing.T) {
|
||||
config.ClearEnvForTest(t)
|
||||
t.Setenv("DATA_DIR", t.TempDir())
|
||||
t.Setenv("PORT", strconv.Itoa(freePort(t)))
|
||||
t.Setenv("DEBUG", "true")
|
||||
|
||||
// internal/logger writes to whatever os.Stdout is when it builds
|
||||
// its handler. A file is not a terminal, so that handler is the
|
||||
// JSON one the service uses in production.
|
||||
out, err := os.CreateTemp(t.TempDir(), "stdout")
|
||||
require.NoError(t, err)
|
||||
|
||||
stdout := os.Stdout
|
||||
os.Stdout = out
|
||||
|
||||
t.Cleanup(func() {
|
||||
os.Stdout = stdout
|
||||
_ = out.Close()
|
||||
})
|
||||
|
||||
app := newApp()
|
||||
require.NoError(t, app.Start(t.Context()))
|
||||
require.NoError(t, app.Stop(t.Context()))
|
||||
|
||||
_, err = out.Seek(0, io.SeekStart)
|
||||
require.NoError(t, err)
|
||||
|
||||
written, err := io.ReadAll(out)
|
||||
require.NoError(t, err)
|
||||
|
||||
type record struct {
|
||||
Level string `json:"level"`
|
||||
Msg string `json:"msg"`
|
||||
Name string `json:"name"`
|
||||
Constructor string `json:"constructor"`
|
||||
}
|
||||
|
||||
var records []record
|
||||
|
||||
for line := range strings.Lines(string(written)) {
|
||||
var r record
|
||||
|
||||
// The first-boot banner is plain text, not a record.
|
||||
if json.Unmarshal([]byte(line), &r) == nil {
|
||||
records = append(records, r)
|
||||
}
|
||||
}
|
||||
|
||||
const pkg = "sneak.berlin/go/webhooker/internal/"
|
||||
|
||||
info := slog.LevelInfo.String()
|
||||
debug := slog.LevelDebug.String()
|
||||
|
||||
assert.Contains(t, records, record{Level: info, Msg: "started"})
|
||||
assert.Contains(t, records, record{
|
||||
Level: debug, Msg: "provided", Constructor: pkg + "globals.New()",
|
||||
})
|
||||
assert.Contains(t, records, record{
|
||||
Level: debug, Msg: "run", Name: pkg + "logger.New()",
|
||||
})
|
||||
assert.Contains(t, records, record{Level: debug, Msg: "invoking"})
|
||||
assert.Contains(t, records, record{
|
||||
Level: debug, Msg: "initialized custom fxevent.Logger",
|
||||
})
|
||||
}
|
||||
|
||||
// TestRunRefusesLockedDataDir pins what an operator's second start
|
||||
// does. The entry point must refuse before it builds the fx graph —
|
||||
// nothing may open a database in a DATA_DIR another process holds —
|
||||
@@ -252,40 +150,22 @@ const tailHeadroom = 2 * time.Second
|
||||
// can produce, since a shorter drain leaves the flush more room and
|
||||
// the worst case is not necessarily at either extreme.
|
||||
//
|
||||
// Nor does the hook start on a full budget: the ArchiveSweeper and
|
||||
// RetentionReaper hooks run before it, and whatever they spent is
|
||||
// gone. The outer sweep walks every amount they can spend. Once they
|
||||
// have eaten into the headroom themselves, the hook must spend
|
||||
// nothing of what is left. A drain that starts on the full budget
|
||||
// must still get all of ShutdownTimeout, so a smaller stopTimeout
|
||||
// cannot silently shorten every drain.
|
||||
//
|
||||
// Shrinking either budget, or unbounding the drain or the flush
|
||||
// again, must fail here rather than silently recreating a hook that
|
||||
// swallows the whole sequence.
|
||||
// Shrinking either budget, or unbounding the flush again, must fail
|
||||
// here rather than silently recreating a hook that swallows the
|
||||
// whole sequence.
|
||||
func TestStopTimeout_LeavesHeadroomForTailHooks(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
require.Less(t, server.ShutdownTimeout, stopTimeout)
|
||||
require.Equal(
|
||||
t, server.ShutdownTimeout, server.DrainBudget(stopTimeout),
|
||||
"a drain that starts on the full stop budget is cut short",
|
||||
)
|
||||
|
||||
const step = 10 * time.Millisecond
|
||||
|
||||
for spent := time.Duration(0); spent <= stopTimeout; spent += step {
|
||||
remaining := stopTimeout - spent
|
||||
longest := max(server.DrainBudget(remaining), 0)
|
||||
for drain := time.Duration(0); drain <= server.ShutdownTimeout; drain += step {
|
||||
hook := drain + server.SentryFlushBudget(stopTimeout-drain)
|
||||
|
||||
for drain := time.Duration(0); drain <= longest; drain += step {
|
||||
hook := drain + server.SentryFlushBudget(remaining-drain)
|
||||
|
||||
require.GreaterOrEqual(
|
||||
t, remaining-hook, min(remaining, tailHeadroom),
|
||||
"a %s drain after %s of earlier hooks leaves "+
|
||||
"the tail hooks short", drain, spent,
|
||||
)
|
||||
}
|
||||
require.LessOrEqual(
|
||||
t, hook+tailHeadroom, stopTimeout,
|
||||
"a %s drain leaves the tail hooks short", drain,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -20,7 +20,7 @@ require (
|
||||
github.com/prometheus/client_model v0.5.0
|
||||
github.com/slok/go-http-metrics v0.11.0
|
||||
github.com/stretchr/testify v1.11.1
|
||||
go.uber.org/fx v1.24.0
|
||||
go.uber.org/fx v1.20.1
|
||||
golang.org/x/crypto v0.38.0
|
||||
gopkg.in/yaml.v3 v3.0.1
|
||||
gorm.io/driver/sqlite v1.5.4
|
||||
@@ -42,6 +42,7 @@ require (
|
||||
github.com/jinzhu/now v1.1.5 // indirect
|
||||
github.com/kballard/go-shellquote v0.0.0-20180428030007-95032a82bc51 // indirect
|
||||
github.com/klauspost/cpuid/v2 v2.2.10 // indirect
|
||||
github.com/kr/text v0.2.0 // indirect
|
||||
github.com/mattn/go-isatty v0.0.20 // indirect
|
||||
github.com/mattn/go-sqlite3 v1.14.17 // indirect
|
||||
github.com/matttproud/golang_protobuf_extensions/v2 v2.0.0 // indirect
|
||||
@@ -50,9 +51,10 @@ require (
|
||||
github.com/prometheus/procfs v0.12.0 // indirect
|
||||
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
|
||||
github.com/zeebo/xxh3 v1.0.2 // indirect
|
||||
go.uber.org/dig v1.19.0 // indirect
|
||||
go.uber.org/multierr v1.10.0 // indirect
|
||||
go.uber.org/zap v1.26.0 // indirect
|
||||
go.uber.org/atomic v1.9.0 // indirect
|
||||
go.uber.org/dig v1.17.0 // indirect
|
||||
go.uber.org/multierr v1.9.0 // indirect
|
||||
go.uber.org/zap v1.23.0 // indirect
|
||||
golang.org/x/mod v0.17.0 // indirect
|
||||
golang.org/x/sync v0.14.0 // indirect
|
||||
golang.org/x/sys v0.47.0 // indirect
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
github.com/99designs/basicauth-go v0.0.0-20230316000542-bf6f9cbbf0f8 h1:nMpu1t4amK3vJWBibQ5X/Nv0aXL+b69TQf2uK5PH7Go=
|
||||
github.com/99designs/basicauth-go v0.0.0-20230316000542-bf6f9cbbf0f8/go.mod h1:3cARGAK9CfW3HoxCy1a0G4TKrdiKke8ftOMEOHyySYs=
|
||||
github.com/benbjohnson/clock v1.3.0 h1:ip6w0uFQkncKQ979AypyG0ER7mqUSBdKLOgAle/AT8A=
|
||||
github.com/benbjohnson/clock v1.3.0/go.mod h1:J11/hYXuz8f4ySSvYwY0FKfm+ezbsZBKZxNJlLklBHA=
|
||||
github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM=
|
||||
github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw=
|
||||
github.com/cespare/xxhash/v2 v2.2.0 h1:DC2CZ1Ep5Y4k3ZQ899DldepgrayRUGE6BBZ/cd9Cj44=
|
||||
@@ -10,6 +12,9 @@ github.com/chromedp/chromedp v0.16.0 h1:rOO4deOm4CbZgBCa8mD9g2rDyIoNs0BkgvNrlbp5
|
||||
github.com/chromedp/chromedp v0.16.0/go.mod h1:rbuGKFT1vMcFcFqKfPIO1GpX/N+2s8onm2qMxZLbU5U=
|
||||
github.com/chromedp/sysutil v1.1.0 h1:PUFNv5EcprjqXZD9nJb9b/c9ibAbxiYo4exNWZyipwM=
|
||||
github.com/chromedp/sysutil v1.1.0/go.mod h1:WiThHUdltqCNKGc4gaU50XgYjwjYIhKWoHGPTUfWTJ8=
|
||||
github.com/creack/pty v1.1.9/go.mod h1:oKZEueFk5CKHvIhNR5MUki03XCEU+Q6VDXinZuGJ33E=
|
||||
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc h1:U9qPSI2PIWSS1VwoXQT9A3Wy9MM3WgvqSxFWenqJduM=
|
||||
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||
github.com/dustin/go-humanize v1.0.1 h1:GzkhY7T5VNhEkwH0PVJgjz+fX1rhBrR7pRT3mDkpeCY=
|
||||
@@ -78,6 +83,7 @@ github.com/pingcap/errors v0.11.4 h1:lFuQV/oaUMGcD2tqt+01ROSmJs75VG1ToEOkZIZ4nE4
|
||||
github.com/pingcap/errors v0.11.4/go.mod h1:Oi8TUi2kEtXXLMJk9l1cGmz20kV3TaQ0usTwv5KuLY8=
|
||||
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
|
||||
github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
|
||||
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
|
||||
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 h1:Jamvg5psRIccs7FGNTlIRMkT8wgtp5eCXdBlqhYGL6U=
|
||||
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
|
||||
github.com/prometheus/client_golang v1.18.0 h1:HzFfmkOzH5Q8L8G+kSJKUx5dtG87sewO+FoDDqP5Tbk=
|
||||
@@ -94,24 +100,28 @@ github.com/rogpeppe/go-internal v1.10.0 h1:TMyTOH3F/DB16zRVcYyreMH6GnZZrwQVAoYjR
|
||||
github.com/rogpeppe/go-internal v1.10.0/go.mod h1:UQnix2H7Ngw/k4C5ijL5+65zddjncjaFoBhdsK/akog=
|
||||
github.com/slok/go-http-metrics v0.11.0 h1:ABJUpekCZSkQT1wQrFvS4kGbhea/w6ndFJaWJeh3zL0=
|
||||
github.com/slok/go-http-metrics v0.11.0/go.mod h1:ZGKeYG1ET6TEJpQx18BqAJAvxw9jBAZXCHU7bWQqqAc=
|
||||
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
|
||||
github.com/stretchr/objx v0.5.2 h1:xuMeJ0Sdp5ZMRXx/aWO6RZxdr3beISkG5/G/aIRr3pY=
|
||||
github.com/stretchr/objx v0.5.2/go.mod h1:FRsXN1f5AsAjCGJKqEizvkpNtU+EGNCLh3NxZ/8L+MA=
|
||||
github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI=
|
||||
github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
|
||||
github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
|
||||
github.com/zeebo/assert v1.3.0 h1:g7C04CbJuIDKNPFHmsk4hwZDO5O+kntRxzaUoNXj+IQ=
|
||||
github.com/zeebo/assert v1.3.0/go.mod h1:Pq9JiuJQpG8JLJdtkwrJESF0Foym2/D9XMU5ciN/wJ0=
|
||||
github.com/zeebo/xxh3 v1.0.2 h1:xZmwmqxHZA8AI603jOQ0tMqmBr9lPeFwGg6d+xy9DC0=
|
||||
github.com/zeebo/xxh3 v1.0.2/go.mod h1:5NWz9Sef7zIDm2JHfFlcQvNekmcEl9ekUZQQKCYaDcA=
|
||||
go.uber.org/dig v1.19.0 h1:BACLhebsYdpQ7IROQ1AGPjrXcP5dF80U3gKoFzbaq/4=
|
||||
go.uber.org/dig v1.19.0/go.mod h1:Us0rSJiThwCv2GteUN0Q7OKvU7n5J4dxZ9JKUXozFdE=
|
||||
go.uber.org/fx v1.24.0 h1:wE8mruvpg2kiiL1Vqd0CC+tr0/24XIB10Iwp2lLWzkg=
|
||||
go.uber.org/fx v1.24.0/go.mod h1:AmDeGyS+ZARGKM4tlH4FY2Jr63VjbEDJHtqXTGP5hbo=
|
||||
go.uber.org/goleak v1.2.0 h1:xqgm/S+aQvhWFTtR0XK3Jvg7z8kGV8P4X14IzwN3Eqk=
|
||||
go.uber.org/goleak v1.2.0/go.mod h1:XJYK+MuIchqpmGmUSAzotztawfKvYLUIgg7guXrwVUo=
|
||||
go.uber.org/multierr v1.10.0 h1:S0h4aNzvfcFsC3dRF1jLoaov7oRaKqRGC/pUEJ2yvPQ=
|
||||
go.uber.org/multierr v1.10.0/go.mod h1:20+QtiLqy0Nd6FdQB9TLXag12DsQkrbs3htMFfDN80Y=
|
||||
go.uber.org/zap v1.26.0 h1:sI7k6L95XOKS281NhVKOFCUNIvv9e0w4BF8N3u+tCRo=
|
||||
go.uber.org/zap v1.26.0/go.mod h1:dtElttAiwGvoJ/vj4IwHBS/gXsEu/pZ50mUIRWuG0so=
|
||||
go.uber.org/atomic v1.9.0 h1:ECmE8Bn/WFTYwEW/bpKD3M8VtR/zQVbavAoalC1PYyE=
|
||||
go.uber.org/atomic v1.9.0/go.mod h1:fEN4uk6kAWBTFdckzkM89CLk9XfWZrxpCo0nPH17wJc=
|
||||
go.uber.org/dig v1.17.0 h1:5Chju+tUvcC+N7N6EV08BJz41UZuO3BmHcN4A287ZLI=
|
||||
go.uber.org/dig v1.17.0/go.mod h1:rTxpf7l5I0eBTlE6/9RL+lDybC7WFwY2QH55ZSjy1mU=
|
||||
go.uber.org/fx v1.20.1 h1:zVwVQGS8zYvhh9Xxcu4w1M6ESyeMzebzj2NbSayZ4Mk=
|
||||
go.uber.org/fx v1.20.1/go.mod h1:iSYNbHf2y55acNCwCXKx7LbWb5WG1Bnue5RDXz1OREg=
|
||||
go.uber.org/goleak v1.1.11 h1:wy28qYRKZgnJTxGxvye5/wgWr1EKjmUDGYox5mGlRlI=
|
||||
go.uber.org/goleak v1.1.11/go.mod h1:cwTWslyiVhfpKIDGSZEM2HlOvcqm+tG4zioyIeLoqMQ=
|
||||
go.uber.org/multierr v1.9.0 h1:7fIwc/ZtS0q++VgcfqFDxSBZVv/Xo49/SYnDFupUwlI=
|
||||
go.uber.org/multierr v1.9.0/go.mod h1:X2jQV1h+kxSjClGpnseKVIxpmcjrj7MNnI0bnlfKTVQ=
|
||||
go.uber.org/zap v1.23.0 h1:OjGQ5KQDEUawVHxNwQgPpiypGHOxo2mNZsOqTak4fFY=
|
||||
go.uber.org/zap v1.23.0/go.mod h1:D+nX8jyLsMHMYrln8A0rJjFt/T/9/bGgIhAqxv5URuY=
|
||||
golang.org/x/crypto v0.38.0 h1:jt+WWG8IZlBnVbomuhg2Mdq0+BBQaHbtqHEFEigjUV8=
|
||||
golang.org/x/crypto v0.38.0/go.mod h1:MvrbAqul58NNYPKnOra203SB9vpuZW0e+RRZV+Ggqjw=
|
||||
golang.org/x/mod v0.17.0 h1:zY54UmvipHiNd+pm+m0x9KhZ9hl1/7QNMyxXbc6ICqA=
|
||||
|
||||
+10
-19
@@ -80,7 +80,8 @@ const (
|
||||
// process over a Docker network or a private LAN connects from.
|
||||
defaultTrustedProxies = "10.0.0.0/8,172.16.0.0/12,192.168.0.0/16"
|
||||
|
||||
// maxPort is the highest valid TCP port number.
|
||||
// maxPort is the highest valid TCP port number. The lower
|
||||
// bound (at least 1) is enforced by envPositiveInt.
|
||||
maxPort = 65535
|
||||
|
||||
// mappedV4Offset is the number of leading bits an IPv4-mapped
|
||||
@@ -104,7 +105,7 @@ var ErrInvalidEnvironment = errors.New("invalid environment")
|
||||
var ErrNonPositiveValue = errors.New("value must be positive")
|
||||
|
||||
// ErrInvalidPort is returned when an environment variable holding a
|
||||
// TCP port number is set to a number outside 1 to 65535.
|
||||
// TCP port number is set above the valid port range.
|
||||
var ErrInvalidPort = errors.New("invalid port")
|
||||
|
||||
// ErrInvalidCIDR is returned when an environment variable holding a
|
||||
@@ -362,27 +363,17 @@ func envPositiveInt(
|
||||
// envPort returns the value of the named environment variable parsed
|
||||
// as a TCP port number. Returns defaultValue if not set. A set value
|
||||
// that is unparseable, below 1, or above maxPort is a hard error
|
||||
// naming the key and the bad value; every out-of-range value wraps
|
||||
// ErrInvalidPort, including one too large or too small for an int.
|
||||
// naming the key and the bad value.
|
||||
func envPort(key string, defaultValue int) (int, error) {
|
||||
v := os.Getenv(key)
|
||||
if v == "" {
|
||||
return defaultValue, nil
|
||||
port, err := envPositiveInt(key, defaultValue)
|
||||
if err != nil {
|
||||
return 0, err
|
||||
}
|
||||
|
||||
// strconv.ErrRange means a number too large or too small for an
|
||||
// int, which is outside the port range as well.
|
||||
port, err := strconv.Atoi(v)
|
||||
if err != nil && !errors.Is(err, strconv.ErrRange) {
|
||||
if port > maxPort {
|
||||
return 0, fmt.Errorf(
|
||||
"invalid integer for %s: %q: %w", key, v, err,
|
||||
)
|
||||
}
|
||||
|
||||
if err != nil || port < 1 || port > maxPort {
|
||||
return 0, fmt.Errorf(
|
||||
"%w: %s must be from 1 to %d, got %q",
|
||||
ErrInvalidPort, key, maxPort, v,
|
||||
"%w: %s must be at most %d, got %d",
|
||||
ErrInvalidPort, key, maxPort, port,
|
||||
)
|
||||
}
|
||||
|
||||
|
||||
@@ -3,6 +3,7 @@ package config_test
|
||||
import (
|
||||
"bytes"
|
||||
"log/slog"
|
||||
"os"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
@@ -70,12 +71,14 @@ func TestEnvironmentConfig(t *testing.T) {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
|
||||
if tt.envValue != "" {
|
||||
t.Setenv(
|
||||
"WEBHOOKER_ENVIRONMENT", tt.envValue,
|
||||
)
|
||||
} else {
|
||||
require.NoError(t, os.Unsetenv(
|
||||
"WEBHOOKER_ENVIRONMENT",
|
||||
))
|
||||
}
|
||||
|
||||
for k, v := range tt.envVars {
|
||||
@@ -196,11 +199,14 @@ func TestRetentionSweepInterval(t *testing.T) {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
|
||||
|
||||
if tt.set {
|
||||
t.Setenv("RETENTION_SWEEP_INTERVAL", tt.value)
|
||||
} else {
|
||||
require.NoError(t, os.Unsetenv(
|
||||
"RETENTION_SWEEP_INTERVAL",
|
||||
))
|
||||
}
|
||||
|
||||
if tt.expectError {
|
||||
@@ -335,11 +341,14 @@ func TestSessionIdleTimeout(t *testing.T) {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
|
||||
|
||||
if tt.set {
|
||||
t.Setenv("SESSION_IDLE_TIMEOUT", tt.value)
|
||||
} else {
|
||||
require.NoError(t, os.Unsetenv(
|
||||
"SESSION_IDLE_TIMEOUT",
|
||||
))
|
||||
}
|
||||
|
||||
if tt.expectError {
|
||||
@@ -388,12 +397,16 @@ func TestDefaultDataDir(t *testing.T) {
|
||||
t.Run("env="+name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
|
||||
if env != "" {
|
||||
t.Setenv("WEBHOOKER_ENVIRONMENT", env)
|
||||
} else {
|
||||
require.NoError(t, os.Unsetenv(
|
||||
"WEBHOOKER_ENVIRONMENT",
|
||||
))
|
||||
}
|
||||
|
||||
require.NoError(t, os.Unsetenv("DATA_DIR"))
|
||||
|
||||
var cfg *config.Config
|
||||
|
||||
app := fxtest.New(
|
||||
@@ -433,9 +446,9 @@ func TestDataDirHelper(t *testing.T) {
|
||||
t.Run(name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
|
||||
if set != "" {
|
||||
if set == "" {
|
||||
require.NoError(t, os.Unsetenv("DATA_DIR"))
|
||||
} else {
|
||||
t.Setenv("DATA_DIR", set)
|
||||
}
|
||||
|
||||
@@ -498,11 +511,14 @@ func TestReceiverRateLimit(t *testing.T) {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
|
||||
|
||||
if tt.set {
|
||||
t.Setenv("RECEIVER_RATE_LIMIT", tt.value)
|
||||
} else {
|
||||
require.NoError(t, os.Unsetenv(
|
||||
"RECEIVER_RATE_LIMIT",
|
||||
))
|
||||
}
|
||||
|
||||
if tt.expectError {
|
||||
@@ -614,11 +630,12 @@ func TestTrustedProxies(t *testing.T) {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
|
||||
|
||||
if tt.set {
|
||||
t.Setenv("TRUSTED_PROXIES", tt.value)
|
||||
} else {
|
||||
require.NoError(t, os.Unsetenv("TRUSTED_PROXIES"))
|
||||
}
|
||||
|
||||
if tt.expectError {
|
||||
@@ -725,11 +742,14 @@ func TestAllowedEgressCIDRs(t *testing.T) {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
|
||||
|
||||
if tt.set {
|
||||
t.Setenv("ALLOWED_EGRESS_CIDRS", tt.value)
|
||||
} else {
|
||||
require.NoError(
|
||||
t, os.Unsetenv("ALLOWED_EGRESS_CIDRS"),
|
||||
)
|
||||
}
|
||||
|
||||
if tt.expectError {
|
||||
@@ -797,10 +817,13 @@ func TestEgressAllowlistWarning(t *testing.T) {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
t.Setenv("WEBHOOKER_ENVIRONMENT", config.EnvironmentDev)
|
||||
|
||||
if tt.allowed != "" {
|
||||
if tt.allowed == "" {
|
||||
require.NoError(
|
||||
t, os.Unsetenv("ALLOWED_EGRESS_CIDRS"),
|
||||
)
|
||||
} else {
|
||||
t.Setenv("ALLOWED_EGRESS_CIDRS", tt.allowed)
|
||||
}
|
||||
|
||||
@@ -933,14 +956,20 @@ func TestMetricsAuthConfig(t *testing.T) {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
|
||||
if tt.username.set {
|
||||
t.Setenv("METRICS_USERNAME", tt.username.value)
|
||||
} else {
|
||||
require.NoError(
|
||||
t, os.Unsetenv("METRICS_USERNAME"),
|
||||
)
|
||||
}
|
||||
|
||||
if tt.password.set {
|
||||
t.Setenv("METRICS_PASSWORD", tt.password.value)
|
||||
} else {
|
||||
require.NoError(
|
||||
t, os.Unsetenv("METRICS_PASSWORD"),
|
||||
)
|
||||
}
|
||||
|
||||
if tt.expectError {
|
||||
|
||||
@@ -22,6 +22,17 @@ const malformedDotEnv = "PORT 19615\n" +
|
||||
"this is not = valid ! syntax\n" +
|
||||
"\"unclosed\n"
|
||||
|
||||
// unsetDotEnvKey makes dotEnvKey genuinely absent for the duration of
|
||||
// the test and restores it afterwards. t.Setenv registers the restore;
|
||||
// the Unsetenv that follows is what the test actually needs, because a
|
||||
// variable set to the empty string is still present in os.Environ and
|
||||
// godotenv would refuse to overwrite it.
|
||||
func unsetDotEnvKey(t *testing.T) {
|
||||
t.Helper()
|
||||
t.Setenv(dotEnvKey, "placeholder")
|
||||
require.NoError(t, os.Unsetenv(dotEnvKey))
|
||||
}
|
||||
|
||||
// writeDotEnv writes contents to a .env file in a fresh temporary
|
||||
// directory and returns its path.
|
||||
func writeDotEnv(t *testing.T, contents string) string {
|
||||
@@ -39,9 +50,9 @@ func writeDotEnv(t *testing.T, contents string) string {
|
||||
// normally rather than be refused for a file it was never meant to
|
||||
// have.
|
||||
//
|
||||
//nolint:paralleltest // ClearEnvForTest uses t.Setenv.
|
||||
//nolint:paralleltest // unsetDotEnvKey uses t.Setenv.
|
||||
func TestLoadDotEnv_MissingFileIsFine(t *testing.T) {
|
||||
config.ClearEnvForTest(t)
|
||||
unsetDotEnvKey(t)
|
||||
|
||||
absent := filepath.Join(t.TempDir(), config.DotEnvPath)
|
||||
require.NoError(t, config.LoadDotEnvFileForTest(absent))
|
||||
@@ -54,9 +65,9 @@ func TestLoadDotEnv_MissingFileIsFine(t *testing.T) {
|
||||
// reaches the environment, which is the whole reason the file is read
|
||||
// at all.
|
||||
//
|
||||
//nolint:paralleltest // ClearEnvForTest uses t.Setenv.
|
||||
//nolint:paralleltest // unsetDotEnvKey uses t.Setenv.
|
||||
func TestLoadDotEnv_AppliesValues(t *testing.T) {
|
||||
config.ClearEnvForTest(t)
|
||||
unsetDotEnvKey(t)
|
||||
|
||||
path := writeDotEnv(t, "# a comment\n"+dotEnvKey+"=from-dot-env\n")
|
||||
|
||||
@@ -82,9 +93,9 @@ func TestLoadDotEnv_RealEnvironmentWins(t *testing.T) {
|
||||
// reverts to its default; the process used to start that way with no
|
||||
// log line naming the file at all.
|
||||
//
|
||||
//nolint:paralleltest // ClearEnvForTest uses t.Setenv.
|
||||
//nolint:paralleltest // unsetDotEnvKey uses t.Setenv.
|
||||
func TestLoadDotEnv_MalformedFileAborts(t *testing.T) {
|
||||
config.ClearEnvForTest(t)
|
||||
unsetDotEnvKey(t)
|
||||
|
||||
path := writeDotEnv(
|
||||
t, malformedDotEnv+dotEnvKey+"=from-dot-env\n",
|
||||
@@ -132,7 +143,7 @@ func TestLoadDotEnv_UnreadableFileAborts(t *testing.T) {
|
||||
//
|
||||
//nolint:paralleltest // t.Chdir moves the whole process.
|
||||
func TestLoadDotEnv_ReadsTheWorkingDirectory(t *testing.T) {
|
||||
config.ClearEnvForTest(t)
|
||||
unsetDotEnvKey(t)
|
||||
|
||||
dir := t.TempDir()
|
||||
require.NoError(t, os.WriteFile(
|
||||
|
||||
+91
-78
@@ -1,6 +1,7 @@
|
||||
package config_test
|
||||
|
||||
import (
|
||||
"os"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
@@ -120,10 +121,10 @@ func TestEnvBool(t *testing.T) {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
|
||||
if tt.set {
|
||||
t.Setenv(testEnvKey, tt.value)
|
||||
} else {
|
||||
require.NoError(t, os.Unsetenv(testEnvKey))
|
||||
}
|
||||
|
||||
got, err := config.EnvBoolForTest(
|
||||
@@ -144,62 +145,17 @@ func TestEnvBool(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// envIntCase is one row of the envPositiveInt and envPort tables.
|
||||
type envIntCase struct {
|
||||
name string
|
||||
set bool
|
||||
value string
|
||||
expectError bool
|
||||
errIs error
|
||||
expected int
|
||||
}
|
||||
|
||||
// runEnvIntCases runs each row through parse, which is
|
||||
// envPositiveInt or envPort, with testEnvKey set to the row's value
|
||||
// or left unset.
|
||||
func runEnvIntCases(
|
||||
t *testing.T,
|
||||
parse func(key string, defaultValue int) (int, error),
|
||||
defaultValue int,
|
||||
tests []envIntCase,
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
|
||||
if tt.set {
|
||||
t.Setenv(testEnvKey, tt.value)
|
||||
}
|
||||
|
||||
got, err := parse(testEnvKey, defaultValue)
|
||||
|
||||
if tt.expectError {
|
||||
require.Error(t, err)
|
||||
assert.Contains(t, err.Error(), testEnvKey)
|
||||
assert.Contains(t, err.Error(), tt.value)
|
||||
|
||||
if tt.errIs != nil {
|
||||
require.ErrorIs(t, err, tt.errIs)
|
||||
}
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, tt.expected, got)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
//nolint:paralleltest // runEnvIntCases uses t.Setenv.
|
||||
func TestEnvPositiveInt(t *testing.T) {
|
||||
const defaultValue = 7
|
||||
|
||||
runEnvIntCases(t, config.EnvPositiveIntForTest, defaultValue, []envIntCase{
|
||||
tests := []struct {
|
||||
name string
|
||||
set bool
|
||||
value string
|
||||
expectError bool
|
||||
errIs error
|
||||
expected int
|
||||
}{
|
||||
{
|
||||
name: "unset returns the default integer",
|
||||
expected: defaultValue,
|
||||
@@ -236,14 +192,51 @@ func TestEnvPositiveInt(t *testing.T) {
|
||||
expectError: true,
|
||||
errIs: config.ErrNonPositiveValue,
|
||||
},
|
||||
})
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
if tt.set {
|
||||
t.Setenv(testEnvKey, tt.value)
|
||||
} else {
|
||||
require.NoError(t, os.Unsetenv(testEnvKey))
|
||||
}
|
||||
|
||||
got, err := config.EnvPositiveIntForTest(
|
||||
testEnvKey, defaultValue,
|
||||
)
|
||||
|
||||
if tt.expectError {
|
||||
require.Error(t, err)
|
||||
assert.Contains(t, err.Error(), testEnvKey)
|
||||
assert.Contains(t, err.Error(), tt.value)
|
||||
|
||||
if tt.errIs != nil {
|
||||
require.ErrorIs(t, err, tt.errIs)
|
||||
}
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, tt.expected, got)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
//nolint:paralleltest // runEnvIntCases uses t.Setenv.
|
||||
func TestEnvPort(t *testing.T) {
|
||||
const defaultValue = 8080
|
||||
|
||||
runEnvIntCases(t, config.EnvPortForTest, defaultValue, []envIntCase{
|
||||
tests := []struct {
|
||||
name string
|
||||
set bool
|
||||
value string
|
||||
expectError bool
|
||||
errIs error
|
||||
expected int
|
||||
}{
|
||||
{
|
||||
name: "unset returns the default port",
|
||||
expected: defaultValue,
|
||||
@@ -271,14 +264,7 @@ func TestEnvPort(t *testing.T) {
|
||||
set: true,
|
||||
value: "0",
|
||||
expectError: true,
|
||||
errIs: config.ErrInvalidPort,
|
||||
},
|
||||
{
|
||||
name: "negative is rejected",
|
||||
set: true,
|
||||
value: "-1",
|
||||
expectError: true,
|
||||
errIs: config.ErrInvalidPort,
|
||||
errIs: config.ErrNonPositiveValue,
|
||||
},
|
||||
{
|
||||
name: "above the port range is rejected",
|
||||
@@ -287,14 +273,37 @@ func TestEnvPort(t *testing.T) {
|
||||
expectError: true,
|
||||
errIs: config.ErrInvalidPort,
|
||||
},
|
||||
{
|
||||
name: "too large for an int is rejected",
|
||||
set: true,
|
||||
value: "99999999999999999999",
|
||||
expectError: true,
|
||||
errIs: config.ErrInvalidPort,
|
||||
},
|
||||
})
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
if tt.set {
|
||||
t.Setenv(testEnvKey, tt.value)
|
||||
} else {
|
||||
require.NoError(t, os.Unsetenv(testEnvKey))
|
||||
}
|
||||
|
||||
got, err := config.EnvPortForTest(
|
||||
testEnvKey, defaultValue,
|
||||
)
|
||||
|
||||
if tt.expectError {
|
||||
require.Error(t, err)
|
||||
assert.Contains(t, err.Error(), testEnvKey)
|
||||
|
||||
if tt.errIs != nil {
|
||||
require.ErrorIs(t, err, tt.errIs)
|
||||
}
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, tt.expected, got)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// TestEnvBindAddress covers BIND_ADDRESS parsing.
|
||||
@@ -310,10 +319,10 @@ func TestEnvBindAddress(t *testing.T) {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
|
||||
if tt.set {
|
||||
t.Setenv(testEnvKey, tt.value)
|
||||
} else {
|
||||
require.NoError(t, os.Unsetenv(testEnvKey))
|
||||
}
|
||||
|
||||
got, err := config.EnvBindAddressForTest(
|
||||
@@ -476,7 +485,6 @@ func TestNewRejectsBadEnvValues(t *testing.T) {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
|
||||
t.Setenv(tt.key, tt.value)
|
||||
|
||||
@@ -638,9 +646,14 @@ func sentryEnvValueCases() []badEnvValueCase {
|
||||
// break the legitimate unset case: absent variables still get their
|
||||
// documented defaults.
|
||||
func TestNewUsesDefaultsWhenUnset(t *testing.T) {
|
||||
config.ClearEnvForTest(t)
|
||||
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
|
||||
|
||||
for _, key := range []string{
|
||||
envKeyPort, envKeyDebug, envKeyBindAddress, envKeySentryDSN,
|
||||
} {
|
||||
require.NoError(t, os.Unsetenv(key))
|
||||
}
|
||||
|
||||
cfg, err := buildConfig(t)
|
||||
require.NoError(t, err)
|
||||
require.NotNil(t, cfg)
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
package config_test
|
||||
|
||||
import (
|
||||
"os"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
@@ -100,10 +101,10 @@ func TestEnvSentryDSN(t *testing.T) {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
// Cannot use t.Parallel() here because t.Setenv
|
||||
// is incompatible with parallel subtests.
|
||||
config.ClearEnvForTest(t)
|
||||
|
||||
if tt.set {
|
||||
t.Setenv(envKeySentryDSN, tt.value)
|
||||
} else {
|
||||
require.NoError(t, os.Unsetenv(envKeySentryDSN))
|
||||
}
|
||||
|
||||
got, err := config.EnvSentryDSNForTest(envKeySentryDSN)
|
||||
|
||||
@@ -1,50 +0,0 @@
|
||||
package config
|
||||
|
||||
import (
|
||||
"os"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// ClearEnvForTest unsets every variable in the process environment
|
||||
// for the rest of the test, so a test sees only the variables it sets
|
||||
// itself, not whatever the developer's shell exports. When the test
|
||||
// ends it leaves the environment exactly as it found it: each variable
|
||||
// it unset is put back, and any variable added since is removed.
|
||||
func ClearEnvForTest(t *testing.T) {
|
||||
t.Helper()
|
||||
|
||||
present := make(map[string]bool)
|
||||
|
||||
for _, entry := range os.Environ() {
|
||||
key, _, _ := strings.Cut(entry, "=")
|
||||
present[key] = true
|
||||
|
||||
// t.Setenv registers the restore; the Unsetenv after it is
|
||||
// what makes the key absent, since a key set to the empty
|
||||
// string is still present, and godotenv will not overwrite a
|
||||
// present key.
|
||||
t.Setenv(key, "")
|
||||
|
||||
err := os.Unsetenv(key)
|
||||
if err != nil {
|
||||
t.Fatalf("unsetting %s: %v", key, err)
|
||||
}
|
||||
}
|
||||
|
||||
// A variable the test adds other than through t.Setenv, as loading
|
||||
// a .env file does, has no restore of its own.
|
||||
t.Cleanup(func() {
|
||||
for _, entry := range os.Environ() {
|
||||
key, _, _ := strings.Cut(entry, "=")
|
||||
if present[key] {
|
||||
continue
|
||||
}
|
||||
|
||||
err := os.Unsetenv(key)
|
||||
if err != nil {
|
||||
t.Errorf("unsetting %s: %v", key, err)
|
||||
}
|
||||
}
|
||||
})
|
||||
}
|
||||
@@ -1,36 +0,0 @@
|
||||
package config_test
|
||||
|
||||
import (
|
||||
"os"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"sneak.berlin/go/webhooker/internal/config"
|
||||
)
|
||||
|
||||
// TestClearEnvForTest_RemovesAddedVariables pins that a variable set
|
||||
// after the clear other than through t.Setenv, as a test's .env file
|
||||
// sets one, is gone once the test ends, so it cannot reach the tests
|
||||
// that run after it.
|
||||
//
|
||||
//nolint:paralleltest // ClearEnvForTest uses t.Setenv.
|
||||
func TestClearEnvForTest_RemovesAddedVariables(t *testing.T) {
|
||||
// The outer clear keeps a value of the key exported in the shell
|
||||
// from making it a variable the inner clear has to put back.
|
||||
config.ClearEnvForTest(t)
|
||||
|
||||
t.Run("loads a .env file after the clear", func(t *testing.T) {
|
||||
config.ClearEnvForTest(t)
|
||||
|
||||
path := writeDotEnv(t, dotEnvKey+"=from-dot-env\n")
|
||||
require.NoError(t, config.LoadDotEnvFileForTest(path))
|
||||
require.Equal(t, "from-dot-env", os.Getenv(dotEnvKey))
|
||||
})
|
||||
|
||||
_, present := os.LookupEnv(dotEnvKey)
|
||||
assert.False(
|
||||
t, present,
|
||||
"a variable set after the clear must not outlive the test",
|
||||
)
|
||||
}
|
||||
@@ -4,7 +4,6 @@ import (
|
||||
"bytes"
|
||||
"context"
|
||||
"log/slog"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
@@ -120,26 +119,3 @@ func TestNewDatabase_IsLoggedWithItsPath(t *testing.T) {
|
||||
t, second, created, "an existing database is not new",
|
||||
)
|
||||
}
|
||||
|
||||
// TestZeroLengthDatabase_IsLoggedAsNew covers what
|
||||
// https://git.eeqj.de/sneak/webhooker/issues/290 found: SQLite opens a
|
||||
// zero-length file as an empty database, so a start on one is a first
|
||||
// start, and it must say so exactly as a start with no file does.
|
||||
func TestZeroLengthDatabase_IsLoggedAsNew(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
dir := t.TempDir()
|
||||
path := filepath.Join(dir, database.MainDBFileName)
|
||||
require.NoError(t, os.WriteFile(path, nil, database.SQLiteFilePerm))
|
||||
|
||||
var out bytes.Buffer
|
||||
|
||||
db, err := database.Open(dir, slog.New(slog.NewTextHandler(&out, nil)))
|
||||
require.NoError(t, err)
|
||||
require.NoError(t, db.Close())
|
||||
|
||||
assert.Contains(
|
||||
t, out.String(),
|
||||
`level=WARN msg="created a new, empty database" path=`+path,
|
||||
)
|
||||
}
|
||||
|
||||
@@ -8,6 +8,7 @@ import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"io"
|
||||
"io/fs"
|
||||
"log/slog"
|
||||
"os"
|
||||
"path/filepath"
|
||||
@@ -202,7 +203,8 @@ func (d *Database) connectTo(dataDir string) error {
|
||||
// Checked before opening, which creates the file. A DATA_DIR that
|
||||
// is unexpectedly empty -- its volume not mounted, say -- looks
|
||||
// exactly like a first start, so a new database is a warning.
|
||||
created := missingOrEmpty(dbPath)
|
||||
_, statErr := os.Stat(dbPath)
|
||||
created := errors.Is(statErr, fs.ErrNotExist)
|
||||
|
||||
// Opened through OpenSQLite so this handle carries the same WAL
|
||||
// journaling, busy timeout, immediate-transaction locking, and pool
|
||||
@@ -211,15 +213,13 @@ func (d *Database) connectTo(dataDir string) error {
|
||||
if err != nil {
|
||||
d.log.Error(
|
||||
"failed to open database",
|
||||
"path", dbPath,
|
||||
"error", err,
|
||||
)
|
||||
|
||||
return err
|
||||
}
|
||||
|
||||
// Then use it with GORM. Its errors are SQLite's alone and name no
|
||||
// file, so the path is added to them here.
|
||||
// Then use it with GORM
|
||||
db, err := gorm.Open(sqlite.Dialector{
|
||||
Conn: sqlDB,
|
||||
}, &gorm.Config{
|
||||
@@ -229,11 +229,10 @@ func (d *Database) connectTo(dataDir string) error {
|
||||
if err != nil {
|
||||
d.log.Error(
|
||||
"failed to connect to database",
|
||||
"path", dbPath,
|
||||
"error", err,
|
||||
)
|
||||
|
||||
return fmt.Errorf("connecting to %s: %w", dbPath, err)
|
||||
return err
|
||||
}
|
||||
|
||||
d.db = db
|
||||
@@ -244,12 +243,8 @@ func (d *Database) connectTo(dataDir string) error {
|
||||
d.log.Info("connected to database", "path", dbPath)
|
||||
}
|
||||
|
||||
err = d.migrate()
|
||||
if err != nil {
|
||||
return fmt.Errorf("migrating %s: %w", dbPath, err)
|
||||
}
|
||||
|
||||
return nil
|
||||
// Run migrations
|
||||
return d.migrate()
|
||||
}
|
||||
|
||||
func (d *Database) migrate() error {
|
||||
|
||||
@@ -1,15 +1,9 @@
|
||||
package database_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"log/slog"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"go.uber.org/fx/fxtest"
|
||||
"sneak.berlin/go/webhooker/internal/config"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
@@ -106,22 +100,3 @@ func TestDatabaseConnection(t *testing.T) {
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// TestOpen_UnreadableDatabaseIsNamed pins
|
||||
// https://git.eeqj.de/sneak/webhooker/issues/459: when SQLite cannot
|
||||
// read webhooker.db, the error that stops the server and `webhooker
|
||||
// resetpw` names the file, not only SQLite's own message.
|
||||
func TestOpen_UnreadableDatabaseIsNamed(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
dir := t.TempDir()
|
||||
path := filepath.Join(dir, database.MainDBFileName)
|
||||
require.NoError(t, os.WriteFile(
|
||||
path, bytes.Repeat([]byte("junk"), 1024), database.SQLiteFilePerm,
|
||||
))
|
||||
|
||||
_, err := database.Open(dir, slog.New(slog.DiscardHandler))
|
||||
require.Error(t, err)
|
||||
assert.Contains(t, err.Error(), path)
|
||||
assert.Contains(t, err.Error(), "file is not a database")
|
||||
}
|
||||
|
||||
@@ -199,77 +199,6 @@ func TestStatisticsQueriesUseTheirIndexes(t *testing.T) {
|
||||
"(deleted_at=? AND created_at>?)")
|
||||
}
|
||||
|
||||
// TestResubmitCountUsesItsIndex does the same for the event log's count
|
||||
// of the events resubmitted from each of a page's events (resubmitCounts
|
||||
// in the handlers). It passes a full page of 25 ids: with an index on
|
||||
// resubmitted_from_id alone, SQLite uses it for three ids and turns to
|
||||
// the deleted_at index from five.
|
||||
func TestResubmitCountUsesItsIndex(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
mgr, lc := setupTestWebhookDBManager(t)
|
||||
ctx := context.Background()
|
||||
require.NoError(t, lc.Start(ctx))
|
||||
|
||||
defer func() { require.NoError(t, lc.Stop(ctx)) }()
|
||||
|
||||
db, err := mgr.GetDB(uuid.New().String())
|
||||
require.NoError(t, err)
|
||||
|
||||
dry := db.Session(&gorm.Session{DryRun: true})
|
||||
|
||||
page := make([]string, 25)
|
||||
for i := range page {
|
||||
page[i] = uuid.New().String()
|
||||
}
|
||||
|
||||
var counts []struct{ Total int }
|
||||
|
||||
assertPlanUses(t, db, dry.Model(&database.Event{}).
|
||||
Select("resubmitted_from_id, count(*) AS total").
|
||||
Where("resubmitted_from_id IN ?", page).
|
||||
Group("resubmitted_from_id").Find(&counts),
|
||||
"idx_events_resubmitted_from_id "+
|
||||
"(resubmitted_from_id=? AND deleted_at=?)")
|
||||
}
|
||||
|
||||
// TestEntrypointEventsUseTheirIndex does the same for the webhook
|
||||
// page's count, for each entrypoint, of the events that arrived on its
|
||||
// URL since the retention cutoff (addEntrypointEvents in the
|
||||
// handlers), which must come from the index alone. It passes 25
|
||||
// entrypoints, as TestResubmitCountUsesItsIndex passes 25 events.
|
||||
func TestEntrypointEventsUseTheirIndex(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
mgr, lc := setupTestWebhookDBManager(t)
|
||||
ctx := context.Background()
|
||||
require.NoError(t, lc.Start(ctx))
|
||||
|
||||
defer func() { require.NoError(t, lc.Stop(ctx)) }()
|
||||
|
||||
db, err := mgr.GetDB(uuid.New().String())
|
||||
require.NoError(t, err)
|
||||
|
||||
dry := db.Session(&gorm.Session{DryRun: true})
|
||||
|
||||
entrypoints := make([]string, 25)
|
||||
for i := range entrypoints {
|
||||
entrypoints[i] = uuid.New().String()
|
||||
}
|
||||
|
||||
var rows []struct{ Events int }
|
||||
|
||||
assertPlanUses(t, db, dry.Model(&database.Event{}).
|
||||
Select("entrypoint_id, count(*) AS events").
|
||||
Where("entrypoint_id IN ? AND resubmitted_from_id IS NULL",
|
||||
entrypoints).
|
||||
Where("created_at >= ?", time.Now()).
|
||||
Group("entrypoint_id").Find(&rows),
|
||||
"COVERING INDEX idx_events_entrypoint_id "+
|
||||
"(entrypoint_id=? AND deleted_at=? AND "+
|
||||
"resubmitted_from_id=? AND created_at>?)")
|
||||
}
|
||||
|
||||
// assertPlanUses asserts that SQLite's plan for a statement GORM built
|
||||
// in a dry run, run with the same SQL and arguments GORM would send,
|
||||
// names each of the given indexes.
|
||||
|
||||
@@ -19,16 +19,11 @@ type Event struct {
|
||||
// narrows by a < only on the last column it uses. Its final delete
|
||||
// has no deleted_at condition and uses the index on created_at
|
||||
// alone. The other tables keep the unindexed BaseModel created_at.
|
||||
// DeletedAt is also the second column of the resubmitted_from_id
|
||||
// index, for the reason DeliveryResult gives. The entrypoint_id
|
||||
// index, for the webhook page's entrypoint list, has it second too,
|
||||
// resubmitted_from_id third, and created_at last, which the list
|
||||
// compares with a range.
|
||||
CreatedAt time.Time `gorm:"index;index:idx_events_deleted_at_created_at,priority:2;index:idx_events_entrypoint_id,priority:4" json:"createdAt"`
|
||||
DeletedAt gorm.DeletedAt `gorm:"index:idx_events_deleted_at_created_at,priority:1;index:idx_events_resubmitted_from_id,priority:2;index:idx_events_entrypoint_id,priority:2" json:"deletedAt,omitzero"`
|
||||
CreatedAt time.Time `gorm:"index;index:idx_events_deleted_at_created_at,priority:2" json:"createdAt"`
|
||||
DeletedAt gorm.DeletedAt `gorm:"index:idx_events_deleted_at_created_at,priority:1" json:"deletedAt,omitzero"`
|
||||
|
||||
WebhookID string `gorm:"type:uuid;not null" json:"webhookId"`
|
||||
EntrypointID string `gorm:"type:uuid;not null;index:idx_events_entrypoint_id,priority:1" json:"entrypointId"`
|
||||
WebhookID string `gorm:"type:uuid;not null" json:"webhookId"`
|
||||
EntrypointID string `gorm:"type:uuid;not null" json:"entrypointId"`
|
||||
|
||||
// Request data
|
||||
Method string `gorm:"not null" json:"method"`
|
||||
@@ -37,8 +32,8 @@ type Event struct {
|
||||
ContentType string `json:"contentType"`
|
||||
|
||||
// BodyBytes is the size of Body in bytes, recorded when the event
|
||||
// is stored, so that the recent events list, which reads only the
|
||||
// start of each body, knows the whole body's size.
|
||||
// is stored so the recent events list can show it without reading
|
||||
// the body.
|
||||
BodyBytes int64 `gorm:"not null" json:"bodyBytes"`
|
||||
|
||||
// ResubmittedFromID names the event this one was copied from by
|
||||
@@ -47,7 +42,7 @@ type Event struct {
|
||||
// existed. It is not a foreign key: the source event can be
|
||||
// reaped by retention while its copies remain, and the id is
|
||||
// kept as the record of where the copy came from either way.
|
||||
ResubmittedFromID *string `gorm:"type:uuid;index:idx_events_resubmitted_from_id,priority:1;index:idx_events_entrypoint_id,priority:3" json:"resubmittedFromId,omitempty"`
|
||||
ResubmittedFromID *string `gorm:"type:uuid;index" json:"resubmittedFromId,omitempty"`
|
||||
|
||||
// Relations. No model marshals the record it belongs to, so
|
||||
// Webhook and Entrypoint are left out of the JSON.
|
||||
|
||||
@@ -52,21 +52,6 @@ func (TargetTotals) TableName() string {
|
||||
return "target_totals"
|
||||
}
|
||||
|
||||
// EntrypointTotals is one row per entrypoint, created by the first
|
||||
// event that arrives on its URL: when the newest such event arrived,
|
||||
// which retention leaves as it is. A resubmitted copy did not arrive
|
||||
// on the URL and does not change it.
|
||||
type EntrypointTotals struct {
|
||||
EntrypointID string `gorm:"type:uuid;primaryKey"`
|
||||
|
||||
LastEventAt time.Time `gorm:"not null"`
|
||||
}
|
||||
|
||||
// TableName names the table AddEntrypointTotals updates.
|
||||
func (EntrypointTotals) TableName() string {
|
||||
return "entrypoint_totals"
|
||||
}
|
||||
|
||||
// AddEventTotals adds each count in add to the webhook's event totals,
|
||||
// and records add.LastEventAt as when the newest event arrived if it is
|
||||
// set. Call it on the transaction that writes or deletes the events it
|
||||
@@ -112,25 +97,3 @@ func AddTargetTotals(tx *gorm.DB, add TargetTotals) error {
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// AddEntrypointTotals records add.LastEventAt as when the newest event
|
||||
// arrived on the URL of the entrypoint add.EntrypointID names, creating
|
||||
// its row the first time. Call it on the transaction that stores the
|
||||
// event.
|
||||
func AddEntrypointTotals(tx *gorm.DB, add EntrypointTotals) error {
|
||||
err := tx.Exec(
|
||||
`INSERT INTO entrypoint_totals (entrypoint_id, last_event_at)
|
||||
VALUES (?, ?)
|
||||
ON CONFLICT (entrypoint_id) DO UPDATE SET
|
||||
last_event_at = excluded.last_event_at`,
|
||||
add.EntrypointID, add.LastEventAt,
|
||||
).Error
|
||||
if err != nil {
|
||||
return fmt.Errorf(
|
||||
"adding to totals of entrypoint %s: %w",
|
||||
add.EntrypointID, err,
|
||||
)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -111,13 +111,6 @@ func (w *Webhook) RetainsForever() bool {
|
||||
return retainsForever(w.RetentionDays)
|
||||
}
|
||||
|
||||
// RetentionCutoff returns the time before which this webhook's events
|
||||
// have expired, as the reaper computes it, and false when the webhook
|
||||
// retains them forever.
|
||||
func (w *Webhook) RetentionCutoff(now time.Time) (time.Time, bool) {
|
||||
return retentionCutoff(now, w.RetentionDays)
|
||||
}
|
||||
|
||||
// RetentionLabel returns the webhook's retention policy as display
|
||||
// text, so that no template has to know about the sentinel value.
|
||||
func (w *Webhook) RetentionLabel() string {
|
||||
|
||||
@@ -3,7 +3,7 @@ package database
|
||||
// Migrate runs database migrations for the main application database.
|
||||
// Only configuration-tier models are stored in the main database.
|
||||
// Event-tier models (Event, Delivery, DeliveryResult, EventTotals,
|
||||
// TargetTotals, EntrypointTotals) live in
|
||||
// TargetTotals) live in
|
||||
// per-webhook dedicated databases managed by WebhookDBManager.
|
||||
func (d *Database) Migrate() error {
|
||||
return d.db.AutoMigrate(
|
||||
|
||||
@@ -184,8 +184,18 @@ func (r *RetentionReaper) sweep(ctx context.Context) {
|
||||
|
||||
wh := webhooks[i]
|
||||
|
||||
// A missing database has nothing to reap. Restart recovery
|
||||
// reports a lost one (see WebhookDBManager.GetDB).
|
||||
// Skip retain-forever webhooks before building any query.
|
||||
// RetainsForever covers both the RetentionForeverDays
|
||||
// sentinel and the non-positive values that predate it: the
|
||||
// sentinel is a positive number, so without this the reaper
|
||||
// would compute a cutoff a thousand years in the past and
|
||||
// issue a DELETE matching nothing on every single sweep.
|
||||
if wh.RetainsForever() {
|
||||
continue
|
||||
}
|
||||
|
||||
// Nothing to reap if the per-webhook database has never
|
||||
// been created.
|
||||
if !r.dbManager.DBExists(wh.ID) {
|
||||
continue
|
||||
}
|
||||
@@ -202,13 +212,6 @@ func (r *RetentionReaper) reapWebhook(
|
||||
webhookID string,
|
||||
retentionDays int,
|
||||
) {
|
||||
// A retain-forever webhook has no cutoff, so its database is not
|
||||
// even opened.
|
||||
cutoff, ok := retentionCutoff(time.Now(), retentionDays)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
|
||||
db, err := r.dbManager.GetDB(webhookID)
|
||||
if err != nil {
|
||||
r.log.Error(
|
||||
@@ -220,6 +223,11 @@ func (r *RetentionReaper) reapWebhook(
|
||||
return
|
||||
}
|
||||
|
||||
cutoff, ok := retentionCutoff(time.Now(), retentionDays)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
|
||||
deleted, err := reapExpired(ctx, db, cutoff)
|
||||
if err != nil {
|
||||
r.log.Error(
|
||||
|
||||
@@ -362,7 +362,7 @@ func TestRetentionReaper_HugeFiniteRetentionRetainsRecentEvents(
|
||||
t,
|
||||
overflowingRetentionDays,
|
||||
database.RetentionForeverDays,
|
||||
"the test value must not be treated as retain-forever",
|
||||
"the test value must not be rescued by the forever skip",
|
||||
)
|
||||
|
||||
webhookID := createWebhook(
|
||||
|
||||
@@ -182,29 +182,6 @@ func TestOpenSQLiteTightensFilesLeftWorldReadable(t *testing.T) {
|
||||
requireDatabaseSetOwnerOnly(t, path)
|
||||
}
|
||||
|
||||
// TestOpenSQLiteRefusesADirectorySidecar covers a directory in place
|
||||
// of -wal or -shm. Beside a -shm directory SQLite opens the database
|
||||
// read-only without a word, and every write then fails naming no file,
|
||||
// so the open must stop instead, naming the directory.
|
||||
func TestOpenSQLiteRefusesADirectorySidecar(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
for _, suffix := range []string{"-wal", "-shm"} {
|
||||
t.Run(suffix, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
path := filepath.Join(t.TempDir(), database.MainDBFileName)
|
||||
require.NoError(t, os.Mkdir(path+suffix, 0o700))
|
||||
|
||||
_, err := database.OpenSQLite(
|
||||
path, database.SQLiteModeCreate,
|
||||
)
|
||||
require.Error(t, err)
|
||||
assert.Contains(t, err.Error(), path+suffix)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// TestOpenSQLiteExistingModeDoesNotCreateTheFile guards the mechanism
|
||||
// the fix uses: OpenSQLite now creates the database file itself, and
|
||||
// must not do so for a caller that asked for an existing database. An
|
||||
|
||||
@@ -7,7 +7,6 @@ import (
|
||||
"io/fs"
|
||||
"net/url"
|
||||
"os"
|
||||
"syscall"
|
||||
"time"
|
||||
|
||||
_ "modernc.org/sqlite" // Pure Go SQLite driver
|
||||
@@ -94,8 +93,7 @@ const (
|
||||
const SQLiteFilePerm fs.FileMode = 0o600
|
||||
|
||||
// reserveSQLiteFile puts path at SQLiteFilePerm before the driver ever
|
||||
// touches it, and tightens any sidecar already on disk. A directory in
|
||||
// place of any of them is an error naming it.
|
||||
// touches it, and tightens any sidecar already on disk.
|
||||
//
|
||||
// The mode has to be settled here rather than by a chmod after opening,
|
||||
// because SQLite picks it: robust_open substitutes
|
||||
@@ -145,15 +143,7 @@ func reserveSQLiteFile(path string, create bool) error {
|
||||
for _, p := range append(
|
||||
[]string{path}, sqliteSidecarPaths(path)...,
|
||||
) {
|
||||
// Chmod accepts a directory, and SQLite opens a database whose
|
||||
// -shm is one read-only, without a word: every write then
|
||||
// fails naming no file.
|
||||
info, err := os.Stat(p)
|
||||
if err == nil && info.IsDir() {
|
||||
return fmt.Errorf("securing %s: %w", p, syscall.EISDIR)
|
||||
}
|
||||
|
||||
err = os.Chmod(p, SQLiteFilePerm)
|
||||
err := os.Chmod(p, SQLiteFilePerm)
|
||||
if err != nil && !errors.Is(err, fs.ErrNotExist) {
|
||||
return fmt.Errorf("securing %s: %w", p, err)
|
||||
}
|
||||
@@ -162,20 +152,6 @@ func reserveSQLiteFile(path string, create bool) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// missingOrEmpty reports whether opening path in SQLiteModeCreate
|
||||
// would start a new, empty database: the file is not there, or it is
|
||||
// zero-length, which SQLite opens as an empty database. A file left at
|
||||
// zero length by an interrupted first start or a truncated copy holds
|
||||
// as little as a missing one, and must be reported the same way.
|
||||
func missingOrEmpty(path string) bool {
|
||||
info, err := os.Stat(path)
|
||||
if errors.Is(err, fs.ErrNotExist) {
|
||||
return true
|
||||
}
|
||||
|
||||
return err == nil && info.Size() == 0
|
||||
}
|
||||
|
||||
// sqliteSidecarPaths returns the files SQLite maintains beside a
|
||||
// database under WAL. They carry the same rows as the database itself,
|
||||
// so a fix that tightens only the main file has fixed nothing.
|
||||
|
||||
@@ -33,23 +33,10 @@ var errInvalidCachedDBType = errors.New(
|
||||
"invalid cached database type",
|
||||
)
|
||||
|
||||
// ErrEventDBNotRemoved is in DeleteDB's error when the event
|
||||
// database file itself could not be removed: it is still on disk.
|
||||
var ErrEventDBNotRemoved = errors.New(
|
||||
"event database file not removed",
|
||||
)
|
||||
|
||||
// ErrSidecarNotRemoved is in DeleteDB's error when the event
|
||||
// database file was removed, so its events are gone, but its -wal
|
||||
// or -shm sidecar could not be.
|
||||
var ErrSidecarNotRemoved = errors.New(
|
||||
"event database file removed, but a -wal or -shm sidecar was not",
|
||||
)
|
||||
|
||||
// WebhookDBManager manages per-webhook SQLite database files
|
||||
// for event storage. Each webhook gets its own dedicated
|
||||
// database containing Events, Deliveries, DeliveryResults and the
|
||||
// running totals of them (EventTotals, TargetTotals, EntrypointTotals).
|
||||
// running totals of them (EventTotals, TargetTotals).
|
||||
// Database connections are opened lazily and cached.
|
||||
type WebhookDBManager struct {
|
||||
dataDir string
|
||||
@@ -98,37 +85,34 @@ func NewWebhookDBManager(
|
||||
return m, nil
|
||||
}
|
||||
|
||||
// GetDB returns the database connection for a webhook, opening it on
|
||||
// first use.
|
||||
//
|
||||
// The file is made by CreateDB when the webhook is created. One that is
|
||||
// missing or zero-length here means the webhook's events and pending
|
||||
// deliveries are gone: an empty database is created in its place so
|
||||
// the webhook keeps receiving, and that is logged as a warning naming
|
||||
// the file, as a new main database is.
|
||||
// GetDB returns the database connection for a webhook,
|
||||
// creating the database file lazily if it doesn't exist.
|
||||
func (m *WebhookDBManager) GetDB(
|
||||
webhookID string,
|
||||
) (*gorm.DB, error) {
|
||||
return m.getDB(webhookID, false)
|
||||
}
|
||||
// Fast path: already open
|
||||
if val, ok := m.dbs.Load(webhookID); ok {
|
||||
return asGormDB(val, webhookID)
|
||||
}
|
||||
|
||||
// GetDBIf is GetDB, done only when check reports true. check runs under
|
||||
// the lock DeleteDB holds while it removes the files, so a caller can
|
||||
// confirm the webhook still exists and open its database with no delete
|
||||
// in between. The handle is nil when check reports false. check must
|
||||
// not call the manager.
|
||||
func (m *WebhookDBManager) GetDBIf(
|
||||
webhookID string, check func() (bool, error),
|
||||
) (*gorm.DB, error) {
|
||||
// Slow path: open the database under the lock, looking in the
|
||||
// cache again first. A caller that raced another one here then
|
||||
// waits for its handle instead of opening a second one.
|
||||
m.mu.Lock()
|
||||
defer m.mu.Unlock()
|
||||
|
||||
ok, err := check()
|
||||
if err != nil || !ok {
|
||||
if val, ok := m.dbs.Load(webhookID); ok {
|
||||
return asGormDB(val, webhookID)
|
||||
}
|
||||
|
||||
db, err := m.openDB(webhookID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
return m.getDBLocked(webhookID, false)
|
||||
m.dbs.Store(webhookID, db)
|
||||
|
||||
return db, nil
|
||||
}
|
||||
|
||||
// asGormDB returns a value read from the cache as the database
|
||||
@@ -146,12 +130,12 @@ func asGormDB(val any, webhookID string) (*gorm.DB, error) {
|
||||
return db, nil
|
||||
}
|
||||
|
||||
// CreateDB creates a new webhook's database file and runs
|
||||
// migrations.
|
||||
// CreateDB explicitly creates a new per-webhook database file
|
||||
// and runs migrations.
|
||||
func (m *WebhookDBManager) CreateDB(
|
||||
webhookID string,
|
||||
) error {
|
||||
_, err := m.getDB(webhookID, true)
|
||||
_, err := m.GetDB(webhookID)
|
||||
|
||||
return err
|
||||
}
|
||||
@@ -167,10 +151,7 @@ func (m *WebhookDBManager) DBExists(
|
||||
}
|
||||
|
||||
// DeleteDB closes the connection and deletes the database file
|
||||
// for a webhook, with its -wal and -shm sidecars. The files are
|
||||
// permanently removed. Each file is tried even when another could
|
||||
// not be removed, and the error wraps ErrEventDBNotRemoved or
|
||||
// ErrSidecarNotRemoved to say which was left, naming each file.
|
||||
// for a webhook. The file is permanently removed.
|
||||
func (m *WebhookDBManager) DeleteDB(
|
||||
webhookID string,
|
||||
) error {
|
||||
@@ -189,23 +170,16 @@ func (m *WebhookDBManager) DeleteDB(
|
||||
}
|
||||
}
|
||||
|
||||
// Delete the main DB file and WAL/SHM files
|
||||
path := m.dbPath(webhookID)
|
||||
|
||||
dbErr := removeFile(path)
|
||||
sidecarErr := errors.Join(
|
||||
removeFile(path+"-wal"),
|
||||
removeFile(path+"-shm"),
|
||||
)
|
||||
|
||||
if dbErr != nil {
|
||||
return fmt.Errorf(
|
||||
"%w: %w",
|
||||
ErrEventDBNotRemoved, errors.Join(dbErr, sidecarErr),
|
||||
)
|
||||
}
|
||||
|
||||
if sidecarErr != nil {
|
||||
return fmt.Errorf("%w: %w", ErrSidecarNotRemoved, sidecarErr)
|
||||
for _, suffix := range []string{"", "-wal", "-shm"} {
|
||||
err := os.Remove(path + suffix)
|
||||
if err != nil && !os.IsNotExist(err) {
|
||||
return fmt.Errorf(
|
||||
"deleting webhook database file %s%s: %w",
|
||||
path, suffix, err,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
m.log.Info(
|
||||
@@ -216,17 +190,6 @@ func (m *WebhookDBManager) DeleteDB(
|
||||
return nil
|
||||
}
|
||||
|
||||
// removeFile removes path. A file that is already gone counts as
|
||||
// removed; the error from any other failure names the file.
|
||||
func removeFile(path string) error {
|
||||
err := os.Remove(path)
|
||||
if errors.Is(err, os.ErrNotExist) {
|
||||
return nil
|
||||
}
|
||||
|
||||
return err
|
||||
}
|
||||
|
||||
// CloseAll closes all open per-webhook database connections.
|
||||
// Called during application shutdown.
|
||||
func (m *WebhookDBManager) CloseAll() error {
|
||||
@@ -269,54 +232,6 @@ func (m *WebhookDBManager) DBPath(
|
||||
return m.dbPath(webhookID)
|
||||
}
|
||||
|
||||
// getDB is GetDB, and CreateDB when isNew is true: the webhook has just
|
||||
// been created, so a missing file is expected rather than lost.
|
||||
func (m *WebhookDBManager) getDB(
|
||||
webhookID string, isNew bool,
|
||||
) (*gorm.DB, error) {
|
||||
// Fast path: already open
|
||||
if val, ok := m.dbs.Load(webhookID); ok {
|
||||
return asGormDB(val, webhookID)
|
||||
}
|
||||
|
||||
m.mu.Lock()
|
||||
defer m.mu.Unlock()
|
||||
|
||||
return m.getDBLocked(webhookID, isNew)
|
||||
}
|
||||
|
||||
// getDBLocked is getDB's slow path, run with m.mu held. It looks in the
|
||||
// cache again first: a caller that raced another one to the lock then
|
||||
// gets its handle instead of opening a second one.
|
||||
func (m *WebhookDBManager) getDBLocked(
|
||||
webhookID string, isNew bool,
|
||||
) (*gorm.DB, error) {
|
||||
if val, ok := m.dbs.Load(webhookID); ok {
|
||||
return asGormDB(val, webhookID)
|
||||
}
|
||||
|
||||
// Checked before opening, which creates the file. See GetDB.
|
||||
path := m.dbPath(webhookID)
|
||||
replaced := !isNew && missingOrEmpty(path)
|
||||
|
||||
db, err := m.openDB(webhookID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
if replaced {
|
||||
m.log.Warn(
|
||||
"created a new, empty database",
|
||||
"webhook_id", webhookID,
|
||||
"path", path,
|
||||
)
|
||||
}
|
||||
|
||||
m.dbs.Store(webhookID, db)
|
||||
|
||||
return db, nil
|
||||
}
|
||||
|
||||
func (m *WebhookDBManager) dbPath(
|
||||
webhookID string,
|
||||
) string {
|
||||
@@ -381,7 +296,7 @@ func (m *WebhookDBManager) openDB(
|
||||
// Run migrations for event-tier models only
|
||||
err = db.AutoMigrate(
|
||||
&Event{}, &Delivery{}, &DeliveryResult{},
|
||||
&EventTotals{}, &TargetTotals{}, &EntrypointTotals{},
|
||||
&EventTotals{}, &TargetTotals{},
|
||||
)
|
||||
if err != nil {
|
||||
_ = sqlDB.Close()
|
||||
|
||||
@@ -182,91 +182,17 @@ func TestWebhookDBManager_DeleteDB(t *testing.T) {
|
||||
}
|
||||
require.NoError(t, db.Create(event).Error)
|
||||
|
||||
// Under WAL, an open database that has been written to has both
|
||||
// sidecars beside it.
|
||||
dbPath := mgr.DBPath(webhookID)
|
||||
require.FileExists(t, dbPath+"-wal")
|
||||
require.FileExists(t, dbPath+"-shm")
|
||||
|
||||
// Delete the DB
|
||||
require.NoError(t, mgr.DeleteDB(webhookID))
|
||||
|
||||
// File should no longer exist
|
||||
assert.False(t, mgr.DBExists(webhookID))
|
||||
|
||||
// Verify the files are actually gone from disk
|
||||
assert.NoFileExists(t, dbPath)
|
||||
assert.NoFileExists(t, dbPath+"-wal")
|
||||
assert.NoFileExists(t, dbPath+"-shm")
|
||||
}
|
||||
|
||||
// blockRemoval puts a non-empty directory at path, which os.Remove
|
||||
// cannot remove whoever runs the test, root included.
|
||||
func blockRemoval(t *testing.T, path string) {
|
||||
t.Helper()
|
||||
|
||||
require.NoError(t, os.MkdirAll(filepath.Join(path, "keep"), 0o700))
|
||||
}
|
||||
|
||||
// TestWebhookDBManager_DeleteDBKeepsDatabaseFile proves that when the
|
||||
// event database file cannot be removed, the error says so, and both
|
||||
// sidecars are still removed.
|
||||
func TestWebhookDBManager_DeleteDBKeepsDatabaseFile(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
mgr, lc := setupTestWebhookDBManager(t)
|
||||
ctx := context.Background()
|
||||
require.NoError(t, lc.Start(ctx))
|
||||
|
||||
defer func() { require.NoError(t, lc.Stop(ctx)) }()
|
||||
|
||||
webhookID := uuid.New().String()
|
||||
// Verify the file is actually gone from disk
|
||||
dbPath := mgr.DBPath(webhookID)
|
||||
|
||||
blockRemoval(t, dbPath)
|
||||
require.NoError(t, os.WriteFile(dbPath+"-wal", nil, 0o600))
|
||||
require.NoError(t, os.WriteFile(dbPath+"-shm", nil, 0o600))
|
||||
|
||||
err := mgr.DeleteDB(webhookID)
|
||||
|
||||
require.ErrorIs(t, err, database.ErrEventDBNotRemoved)
|
||||
require.NotErrorIs(t, err, database.ErrSidecarNotRemoved)
|
||||
assert.Contains(t, err.Error(), dbPath)
|
||||
assert.NoFileExists(t, dbPath+"-wal")
|
||||
assert.NoFileExists(t, dbPath+"-shm")
|
||||
}
|
||||
|
||||
// TestWebhookDBManager_DeleteDBKeepsSidecar proves that when the
|
||||
// event database file is removed but a sidecar is not, the error
|
||||
// says the database file is gone, and the other sidecar is still
|
||||
// removed.
|
||||
func TestWebhookDBManager_DeleteDBKeepsSidecar(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
mgr, lc := setupTestWebhookDBManager(t)
|
||||
ctx := context.Background()
|
||||
require.NoError(t, lc.Start(ctx))
|
||||
|
||||
defer func() { require.NoError(t, lc.Stop(ctx)) }()
|
||||
|
||||
webhookID := uuid.New().String()
|
||||
dbPath := mgr.DBPath(webhookID)
|
||||
|
||||
require.NoError(t, mgr.CreateDB(webhookID))
|
||||
// Closing removes the sidecars, so the ones below are the only
|
||||
// ones there.
|
||||
require.NoError(t, mgr.CloseAll())
|
||||
|
||||
blockRemoval(t, dbPath+"-wal")
|
||||
require.NoError(t, os.WriteFile(dbPath+"-shm", nil, 0o600))
|
||||
|
||||
err := mgr.DeleteDB(webhookID)
|
||||
|
||||
require.ErrorIs(t, err, database.ErrSidecarNotRemoved)
|
||||
require.NotErrorIs(t, err, database.ErrEventDBNotRemoved)
|
||||
assert.Contains(t, err.Error(), dbPath+"-wal")
|
||||
assert.NoFileExists(t, dbPath)
|
||||
assert.NoFileExists(t, dbPath+"-shm")
|
||||
_, err = os.Stat(dbPath)
|
||||
assert.True(t, os.IsNotExist(err))
|
||||
}
|
||||
|
||||
func TestWebhookDBManager_LazyCreation(t *testing.T) {
|
||||
@@ -289,75 +215,6 @@ func TestWebhookDBManager_LazyCreation(t *testing.T) {
|
||||
assert.True(t, mgr.DBExists(webhookID))
|
||||
}
|
||||
|
||||
// A webhook's database is made by CreateDB along with the webhook. One
|
||||
// that GetDB finds missing or zero-length has lost the webhook's events
|
||||
// and pending deliveries, so the empty database made in its place is
|
||||
// logged as a warning naming the file
|
||||
// (https://git.eeqj.de/sneak/webhooker/issues/290). CreateDB, and
|
||||
// reopening a database that is there, log no such warning.
|
||||
func TestWebhookDBManager_LostDatabaseIsLogged(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
const created = `level=WARN msg="created a new, empty database"`
|
||||
|
||||
open := func(
|
||||
t *testing.T, prepare func(*database.WebhookDBManager, string),
|
||||
) (string, string) {
|
||||
t.Helper()
|
||||
|
||||
var logs bytes.Buffer
|
||||
|
||||
mgr := database.NewTestWebhookDBManagerWithLogger(
|
||||
t.TempDir(),
|
||||
slog.New(slog.NewTextHandler(&logs, nil)),
|
||||
)
|
||||
|
||||
webhookID := uuid.New().String()
|
||||
prepare(mgr, webhookID)
|
||||
|
||||
_, err := mgr.GetDB(webhookID)
|
||||
require.NoError(t, err)
|
||||
require.NoError(t, mgr.CloseAll())
|
||||
|
||||
return logs.String(),
|
||||
" webhook_id=" + webhookID + " path=" + mgr.DBPath(webhookID)
|
||||
}
|
||||
|
||||
t.Run("missing", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
logs, fields := open(
|
||||
t, func(*database.WebhookDBManager, string) {},
|
||||
)
|
||||
assert.Contains(t, logs, created+fields)
|
||||
})
|
||||
|
||||
t.Run("zero-length", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
logs, fields := open(
|
||||
t, func(mgr *database.WebhookDBManager, webhookID string) {
|
||||
require.NoError(t, os.WriteFile(
|
||||
mgr.DBPath(webhookID), nil, database.SQLiteFilePerm,
|
||||
))
|
||||
},
|
||||
)
|
||||
assert.Contains(t, logs, created+fields)
|
||||
})
|
||||
|
||||
t.Run("created with the webhook, then reopened", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
logs, _ := open(
|
||||
t, func(mgr *database.WebhookDBManager, webhookID string) {
|
||||
require.NoError(t, mgr.CreateDB(webhookID))
|
||||
require.NoError(t, mgr.CloseAll())
|
||||
},
|
||||
)
|
||||
assert.NotContains(t, logs, created)
|
||||
})
|
||||
}
|
||||
|
||||
func TestWebhookDBManager_DeliveryWorkflow(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
@@ -45,13 +45,8 @@ type ArchiveSweeper struct {
|
||||
eng *Engine
|
||||
log *slog.Logger
|
||||
interval time.Duration
|
||||
|
||||
// cancel needs no lock: fx calls the stop hook only after the
|
||||
// start hook has returned, so stop never reads it while start
|
||||
// is still setting it.
|
||||
cancel context.CancelFunc
|
||||
|
||||
wg sync.WaitGroup
|
||||
cancel context.CancelFunc
|
||||
wg sync.WaitGroup
|
||||
}
|
||||
|
||||
// NewArchiveSweeper creates the archive sweeper and registers
|
||||
@@ -168,18 +163,10 @@ func (s *ArchiveSweeper) sweep(ctx context.Context) {
|
||||
var targets []database.Target
|
||||
|
||||
err := s.db.DB().
|
||||
WithContext(ctx).
|
||||
Model(&database.Target{}).
|
||||
Where("type = ?", database.TargetTypeDatabase).
|
||||
Find(&targets).Error
|
||||
if err != nil {
|
||||
// The app stopping as a sweep starts cancels the listing.
|
||||
// Stopping is not a failure, so it must not produce an
|
||||
// error line.
|
||||
if ctx.Err() != nil {
|
||||
return
|
||||
}
|
||||
|
||||
s.log.Error(
|
||||
"archive sweep: failed to list database targets",
|
||||
"error", err,
|
||||
|
||||
@@ -1,11 +1,9 @@
|
||||
package delivery_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"database/sql"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"os"
|
||||
"path/filepath"
|
||||
@@ -22,7 +20,6 @@ import (
|
||||
_ "modernc.org/sqlite" // Pure Go SQLite driver.
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/delivery"
|
||||
"sneak.berlin/go/webhooker/internal/gormlog"
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -71,8 +68,7 @@ func setupArchiveTest(t *testing.T) *archiveEnv {
|
||||
t.Cleanup(func() { _ = sqlDB.Close() })
|
||||
|
||||
gdb, err := gorm.Open(
|
||||
sqlite.Dialector{Conn: sqlDB},
|
||||
&gorm.Config{Logger: gormlog.New(slog.New(slog.DiscardHandler))},
|
||||
sqlite.Dialector{Conn: sqlDB}, &gorm.Config{},
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
@@ -170,8 +166,7 @@ func (env *archiveEnv) seedArchiveRows(
|
||||
require.NoError(t, err)
|
||||
|
||||
gdb, err := gorm.Open(
|
||||
sqlite.Dialector{Conn: sqlDB},
|
||||
&gorm.Config{Logger: gormlog.New(slog.New(slog.DiscardHandler))},
|
||||
sqlite.Dialector{Conn: sqlDB}, &gorm.Config{},
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
@@ -230,8 +225,7 @@ func countArchivedRows(path string) (int64, error) {
|
||||
defer func() { _ = sqlDB.Close() }()
|
||||
|
||||
gdb, err := gorm.Open(
|
||||
sqlite.Dialector{Conn: sqlDB},
|
||||
&gorm.Config{Logger: gormlog.New(slog.New(slog.DiscardHandler))},
|
||||
sqlite.Dialector{Conn: sqlDB}, &gorm.Config{},
|
||||
)
|
||||
if err != nil {
|
||||
return 0, err
|
||||
@@ -687,64 +681,6 @@ func TestArchiveSweep_ClosesHandleOfRegisteredWriter(
|
||||
)
|
||||
}
|
||||
|
||||
// TestArchiveSweep_ClosesHandleBeforeReopening proves the sweep
|
||||
// closes the handle it finds open before it reopens the file.
|
||||
// TestArchiveSweep_LeavesArchiveClosed cannot see this: without the
|
||||
// close, the reopen replaces the handle without closing it, the
|
||||
// sweep then closes only the new one, and one connection leaks per
|
||||
// archive per sweep.
|
||||
func TestArchiveSweep_ClosesHandleBeforeReopening(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
path := filepath.Join(t.TempDir(), "archive.db")
|
||||
|
||||
w := delivery.NewExportArchiveWriter(
|
||||
path, archiveTestLogger(), 0,
|
||||
)
|
||||
|
||||
require.NoError(t, w.Open(time.Hour))
|
||||
|
||||
before, err := w.DB().DB()
|
||||
require.NoError(t, err)
|
||||
|
||||
require.NoError(t, w.SweepExpired(time.Hour))
|
||||
|
||||
assert.Error(
|
||||
t, before.PingContext(t.Context()),
|
||||
"the handle open before the sweep must be closed by it",
|
||||
)
|
||||
}
|
||||
|
||||
// TestArchiveSweep_CancelledSweepLogsNoError proves a sweep whose
|
||||
// context is already cancelled, as when the app stops just as a
|
||||
// sweep starts, returns without an error line: stopping is not a
|
||||
// failure.
|
||||
func TestArchiveSweep_CancelledSweepLogsNoError(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupArchiveTest(t)
|
||||
|
||||
var errorLines bytes.Buffer
|
||||
|
||||
sweeper := delivery.NewTestArchiveSweeper(
|
||||
env.mainDB, env.eng,
|
||||
slog.New(slog.NewTextHandler(
|
||||
&errorLines,
|
||||
&slog.HandlerOptions{Level: slog.LevelError},
|
||||
)),
|
||||
)
|
||||
|
||||
ctx, cancel := context.WithCancel(context.Background())
|
||||
cancel()
|
||||
|
||||
sweeper.ExportSweep(ctx)
|
||||
|
||||
assert.Empty(
|
||||
t, errorLines.String(),
|
||||
"a cancelled sweep must not log at error level",
|
||||
)
|
||||
}
|
||||
|
||||
// TestArchiveSweep_NeverExpiryUntouched proves the sweep is a
|
||||
// no-op for the default retention policy, so archives with no
|
||||
// expiry (or the literal "never") behave exactly as before.
|
||||
|
||||
@@ -699,9 +699,10 @@ func (e *Engine) recoverInFlight(ctx context.Context) {
|
||||
default:
|
||||
}
|
||||
|
||||
// Opened even when its file is missing, so that a lost
|
||||
// database is reported at start, not when the webhook next
|
||||
// receives an event, which for a quiet webhook may be never.
|
||||
if !e.dbManager.DBExists(webhookID) {
|
||||
continue
|
||||
}
|
||||
|
||||
e.recoverWebhookDeliveries(ctx, webhookID)
|
||||
}
|
||||
}
|
||||
@@ -709,24 +710,7 @@ func (e *Engine) recoverInFlight(ctx context.Context) {
|
||||
func (e *Engine) recoverWebhookDeliveries(
|
||||
ctx context.Context, webhookID string,
|
||||
) {
|
||||
// The web interface is already serving, so the webhook may have
|
||||
// been deleted since the list was read. Opening its database then
|
||||
// would create the file again after the delete removed it.
|
||||
stillExists := func() (bool, error) {
|
||||
var count int64
|
||||
|
||||
err := e.database.DB().
|
||||
Model(&database.Webhook{}).
|
||||
Where("id = ?", webhookID).
|
||||
Count(&count).Error
|
||||
if err != nil {
|
||||
return false, fmt.Errorf("confirming webhook exists: %w", err)
|
||||
}
|
||||
|
||||
return count > 0, nil
|
||||
}
|
||||
|
||||
webhookDB, err := e.dbManager.GetDBIf(webhookID, stillExists)
|
||||
webhookDB, err := e.dbManager.GetDB(webhookID)
|
||||
if err != nil {
|
||||
e.log.Error(
|
||||
"failed to get webhook database for recovery",
|
||||
@@ -737,10 +721,6 @@ func (e *Engine) recoverWebhookDeliveries(
|
||||
return
|
||||
}
|
||||
|
||||
if webhookDB == nil {
|
||||
return
|
||||
}
|
||||
|
||||
e.recoverPendingDeliveries(
|
||||
ctx, webhookDB, webhookID,
|
||||
)
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
package delivery_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
@@ -24,7 +23,6 @@ import (
|
||||
_ "modernc.org/sqlite"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/delivery"
|
||||
"sneak.berlin/go/webhooker/internal/gormlog"
|
||||
)
|
||||
|
||||
// iSetup holds common integration test dependencies.
|
||||
@@ -82,8 +80,7 @@ func iMainDB(t *testing.T) *gorm.DB {
|
||||
t.Cleanup(func() { _ = sqlDB.Close() })
|
||||
|
||||
db, err := gorm.Open(
|
||||
sqlite.Dialector{Conn: sqlDB},
|
||||
&gorm.Config{Logger: gormlog.New(slog.New(slog.DiscardHandler))},
|
||||
sqlite.Dialector{Conn: sqlDB}, &gorm.Config{},
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
@@ -358,14 +355,9 @@ func TestProcessRetryTask_SuccessfulRetry(t *testing.T) {
|
||||
|
||||
s := newISetup(t)
|
||||
|
||||
var receivedBody string
|
||||
|
||||
ts := httptest.NewServer(
|
||||
http.HandlerFunc(
|
||||
func(w http.ResponseWriter, r *http.Request) {
|
||||
body, _ := io.ReadAll(r.Body)
|
||||
receivedBody = string(body)
|
||||
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.WriteHeader(http.StatusOK)
|
||||
},
|
||||
),
|
||||
@@ -405,8 +397,6 @@ func TestProcessRetryTask_SuccessfulRetry(t *testing.T) {
|
||||
context.TODO(), &task,
|
||||
)
|
||||
|
||||
assert.Equal(t, event.Body, receivedBody)
|
||||
|
||||
iAssertStatus(t, s.WebhookDB, d.ID,
|
||||
database.DeliveryStatusDelivered,
|
||||
)
|
||||
@@ -453,14 +443,9 @@ func TestProcessRetryTask_LargeBody_FetchFromDB(
|
||||
|
||||
s := newISetup(t)
|
||||
|
||||
var receivedBody string
|
||||
|
||||
ts := httptest.NewServer(
|
||||
http.HandlerFunc(
|
||||
func(w http.ResponseWriter, r *http.Request) {
|
||||
body, _ := io.ReadAll(r.Body)
|
||||
receivedBody = string(body)
|
||||
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.WriteHeader(http.StatusOK)
|
||||
},
|
||||
),
|
||||
@@ -497,8 +482,6 @@ func TestProcessRetryTask_LargeBody_FetchFromDB(
|
||||
context.TODO(), &task,
|
||||
)
|
||||
|
||||
assert.Equal(t, largeBody, receivedBody)
|
||||
|
||||
iAssertStatus(t, s.WebhookDB, d.ID,
|
||||
database.DeliveryStatusDelivered,
|
||||
)
|
||||
@@ -1137,85 +1120,6 @@ func TestRecoverInFlight_WithPendingDeliveries(
|
||||
}
|
||||
}
|
||||
|
||||
// TestRecoverInFlight_ReportsAMissingWebhookDatabase covers a webhook
|
||||
// whose database file is gone, after a partial restore say. Restart
|
||||
// recovery opens every webhook's database, so the empty one made in its
|
||||
// place is reported at start, naming the file
|
||||
// (https://git.eeqj.de/sneak/webhooker/issues/290).
|
||||
func TestRecoverInFlight_ReportsAMissingWebhookDatabase(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
mainDB := iMainDB(t)
|
||||
webhookID := uuid.New().String()
|
||||
iCreateWebhook(t, mainDB, webhookID, "lost-database")
|
||||
|
||||
var logs bytes.Buffer
|
||||
|
||||
dbMgr := database.NewTestWebhookDBManagerWithLogger(
|
||||
t.TempDir(), slog.New(slog.NewTextHandler(&logs, nil)),
|
||||
)
|
||||
t.Cleanup(func() { _ = dbMgr.CloseAll() })
|
||||
|
||||
engine := delivery.NewTestEngineWithDB(
|
||||
database.NewTestDatabase(mainDB), dbMgr,
|
||||
slog.New(slog.DiscardHandler),
|
||||
&http.Client{Timeout: 5 * time.Second}, 1,
|
||||
)
|
||||
|
||||
engine.ExportRecoverInFlight(context.Background())
|
||||
|
||||
assert.Contains(
|
||||
t, logs.String(),
|
||||
`level=WARN msg="created a new, empty database" webhook_id=`+
|
||||
webhookID+" path="+dbMgr.DBPath(webhookID),
|
||||
)
|
||||
}
|
||||
|
||||
// TestRecoverInFlight_SkipsAWebhookDeletedAfterTheListIsRead covers a
|
||||
// webhook deleted from the web interface while restart recovery runs.
|
||||
// Its database file is gone, and recovery must not create it again.
|
||||
func TestRecoverInFlight_SkipsAWebhookDeletedAfterTheListIsRead(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
mainDB := iMainDB(t)
|
||||
webhookID := uuid.New().String()
|
||||
iCreateWebhook(t, mainDB, webhookID, "deleted-during-recovery")
|
||||
|
||||
// The first query to return is recovery's read of the list of
|
||||
// webhooks. Deleting the webhook right after it puts the delete
|
||||
// between that read and the opening of the webhook's database.
|
||||
deleted := false
|
||||
|
||||
require.NoError(t, mainDB.Callback().Query().After("gorm:query").
|
||||
Register("delete-after-list", func(*gorm.DB) {
|
||||
if deleted {
|
||||
return
|
||||
}
|
||||
|
||||
deleted = true
|
||||
|
||||
require.NoError(t, mainDB.Delete(
|
||||
&database.Webhook{}, "id = ?", webhookID,
|
||||
).Error)
|
||||
}))
|
||||
|
||||
dbMgr := database.NewTestWebhookDBManager(t.TempDir())
|
||||
t.Cleanup(func() { _ = dbMgr.CloseAll() })
|
||||
|
||||
engine := delivery.NewTestEngineWithDB(
|
||||
database.NewTestDatabase(mainDB), dbMgr,
|
||||
slog.New(slog.DiscardHandler),
|
||||
&http.Client{Timeout: 5 * time.Second}, 1,
|
||||
)
|
||||
|
||||
engine.ExportRecoverInFlight(context.Background())
|
||||
|
||||
require.True(t, deleted)
|
||||
assert.False(t, dbMgr.DBExists(webhookID))
|
||||
}
|
||||
|
||||
// --- HTTP Config with custom headers ---
|
||||
|
||||
func TestDeliverHTTP_CustomTargetHeaders(t *testing.T) {
|
||||
@@ -1507,32 +1411,6 @@ func TestDeliverHTTP_InvalidConfig(t *testing.T) {
|
||||
)
|
||||
}
|
||||
|
||||
// TestDeliverHTTP_InvalidConfigUnrecordedStaysPending: a delivery is
|
||||
// failed for an invalid config only once the reason is recorded.
|
||||
// Unrecorded, it stays pending, where the sweep finds it again.
|
||||
func TestDeliverHTTP_InvalidConfigUnrecordedStaysPending(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
db := testWebhookDB(t)
|
||||
e := testEngine(t, 1)
|
||||
|
||||
event, del := iSeedEventAndDelivery(
|
||||
t, db, `{"config":"invalid"}`, "",
|
||||
)
|
||||
|
||||
task, d := iHTTPTaskAndDelivery(
|
||||
event, del, "bad-config", `not-json`, 0, 1,
|
||||
)
|
||||
|
||||
require.NoError(t, db.Exec("drop table delivery_results").Error)
|
||||
|
||||
e.ExportDeliverHTTP(context.TODO(), db, d, task)
|
||||
|
||||
iAssertStatus(t, db, del.ID,
|
||||
database.DeliveryStatusPending,
|
||||
)
|
||||
}
|
||||
|
||||
// --- Notify batching ---
|
||||
|
||||
func TestNotify_MultipleTasks(t *testing.T) {
|
||||
|
||||
@@ -5,7 +5,6 @@ import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"io"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
@@ -26,7 +25,6 @@ import (
|
||||
_ "modernc.org/sqlite"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/delivery"
|
||||
"sneak.berlin/go/webhooker/internal/gormlog"
|
||||
"sneak.berlin/go/webhooker/internal/metrics"
|
||||
)
|
||||
|
||||
@@ -51,8 +49,7 @@ func testWebhookDB(t *testing.T) *gorm.DB {
|
||||
t.Cleanup(func() { _ = sqlDB.Close() })
|
||||
|
||||
db, err := gorm.Open(
|
||||
sqlite.Dialector{Conn: sqlDB},
|
||||
&gorm.Config{Logger: gormlog.New(slog.New(slog.DiscardHandler))},
|
||||
sqlite.Dialector{Conn: sqlDB}, &gorm.Config{},
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
@@ -1059,21 +1056,6 @@ func TestParseHTTPConfig_MissingURL(t *testing.T) {
|
||||
)
|
||||
}
|
||||
|
||||
func TestParseHTTPConfig_Undecodable(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
e := testEngine(t, 1)
|
||||
|
||||
_, err := e.ExportParseHTTPConfig(
|
||||
`{"url":"https://example.com/hook","timeout":"soon"}`,
|
||||
)
|
||||
|
||||
assert.Error(t, err,
|
||||
"config that does not decode should return error, "+
|
||||
"even when the part that did names a URL",
|
||||
)
|
||||
}
|
||||
|
||||
func TestScheduleRetry_SendsToRetryChannel(
|
||||
t *testing.T,
|
||||
) {
|
||||
@@ -1259,33 +1241,6 @@ func TestDoHTTPRequest_ForwardsHeaders(t *testing.T) {
|
||||
)
|
||||
}
|
||||
|
||||
// A response that ends before the length it announced is an error, not
|
||||
// a short body.
|
||||
func TestDoHTTPRequest_CutShortResponseIsAnError(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
ts := httptest.NewServer(
|
||||
http.HandlerFunc(
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.Header().Set("Content-Length", "100")
|
||||
_, _ = w.Write([]byte("cut short"))
|
||||
},
|
||||
),
|
||||
)
|
||||
defer ts.Close()
|
||||
|
||||
e := testEngine(t, 1)
|
||||
|
||||
_, body, _, err := e.ExportDoHTTPRequest(
|
||||
context.TODO(),
|
||||
&delivery.HTTPTargetConfig{URL: ts.URL},
|
||||
&database.Event{},
|
||||
)
|
||||
|
||||
require.ErrorIs(t, err, io.ErrUnexpectedEOF)
|
||||
assert.Empty(t, body)
|
||||
}
|
||||
|
||||
// The event's stored inbound headers carry the same Content-Type the
|
||||
// receiver saved as the event's ContentType, so a delivery could send
|
||||
// it twice. It must go out exactly once, with a Content-Type configured
|
||||
@@ -1362,34 +1317,6 @@ func TestApplyRequestHeaders_SendsOneContentType(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// Stored inbound headers that do not decode forward nothing, not the
|
||||
// part of them that happened to decode.
|
||||
func TestApplyRequestHeaders_UndecodableInboundForwardsNothing(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
req, err := http.NewRequestWithContext(
|
||||
context.Background(),
|
||||
http.MethodPost,
|
||||
"https://target.example.com/hook",
|
||||
http.NoBody,
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
names := delivery.ExportApplyRequestHeaders(
|
||||
req,
|
||||
&database.Event{
|
||||
Headers: `{"X-Custom":["value1"],"X-Broken":"not a list"}`,
|
||||
},
|
||||
&delivery.HTTPTargetConfig{},
|
||||
"webhooker/dev",
|
||||
)
|
||||
|
||||
assert.Empty(t, names)
|
||||
assert.Empty(t, req.Header.Get("X-Custom"))
|
||||
}
|
||||
|
||||
func TestProcessDelivery_RoutesToCorrectHandler(
|
||||
t *testing.T,
|
||||
) {
|
||||
|
||||
@@ -376,97 +376,3 @@ func TestFailedResultWriteLeavesDeliveryRecoverable(
|
||||
database.DeliveryStatusPending,
|
||||
)
|
||||
}
|
||||
|
||||
// TestFailedResultWriteWithRetriesLeavesDeliveryRecoverable is the same
|
||||
// rule for a target with retries: whatever the receiver answered, the
|
||||
// delivery stays pending and no retry is scheduled. The circuit breaker
|
||||
// still learns the answer, because it describes the target's health,
|
||||
// not the database's.
|
||||
func TestFailedResultWriteWithRetriesLeavesDeliveryRecoverable(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
// The "send succeeded" case starts with the breaker tripped open,
|
||||
// so the delivery goes out as its probe and only a recorded
|
||||
// success closes it again.
|
||||
tests := []struct {
|
||||
name string
|
||||
answer int
|
||||
tripped bool
|
||||
wantBreaker delivery.CircuitState
|
||||
}{
|
||||
{"send succeeded", http.StatusOK, true, delivery.CircuitClosed},
|
||||
{"send failed", http.StatusBadGateway, false, delivery.CircuitOpen},
|
||||
}
|
||||
|
||||
for _, tc := range tests {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
s := newISetup(t)
|
||||
targetID := uuid.New().String()
|
||||
|
||||
ts := httptest.NewServer(http.HandlerFunc(
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.WriteHeader(tc.answer)
|
||||
},
|
||||
))
|
||||
defer ts.Close()
|
||||
|
||||
event := iSeedEvent(
|
||||
t, s.WebhookDB, s.WebhookID, `{"unwritable":true}`,
|
||||
)
|
||||
|
||||
d := iSeedDelivery(
|
||||
t, s.WebhookDB, event.ID, targetID,
|
||||
database.DeliveryStatusPending,
|
||||
)
|
||||
|
||||
require.NoError(
|
||||
t,
|
||||
s.WebhookDB.Exec("drop table delivery_results").Error,
|
||||
)
|
||||
|
||||
// A single failure opens this breaker, and with no
|
||||
// cooldown an open breaker lets the next delivery
|
||||
// through as a probe.
|
||||
cb := delivery.NewTestCircuitBreaker(1, 0)
|
||||
if tc.tripped {
|
||||
cb.RecordFailure()
|
||||
}
|
||||
|
||||
s.Engine.ExportSetCircuitBreaker(targetID, cb)
|
||||
|
||||
full := &database.Delivery{
|
||||
EventID: event.ID,
|
||||
TargetID: targetID,
|
||||
Status: database.DeliveryStatusPending,
|
||||
Event: event,
|
||||
Target: database.Target{
|
||||
Name: "unwritable",
|
||||
Type: database.TargetTypeHTTP,
|
||||
Config: iHTTPConfig(ts.URL),
|
||||
MaxRetries: 3,
|
||||
},
|
||||
}
|
||||
full.ID = d.ID
|
||||
|
||||
sched := &recordingScheduler{}
|
||||
|
||||
s.Engine.ExportDeliverHTTPWithScheduler(
|
||||
context.Background(), s.WebhookDB, full,
|
||||
&delivery.Task{
|
||||
DeliveryID: d.ID,
|
||||
TargetID: targetID,
|
||||
AttemptNum: 1,
|
||||
},
|
||||
sched,
|
||||
)
|
||||
|
||||
iAssertStatus(t, s.WebhookDB, d.ID, database.DeliveryStatusPending)
|
||||
assert.Empty(t, sched.delays, "no retry may be scheduled")
|
||||
assert.Equal(t, tc.wantBreaker, cb.State())
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
@@ -97,7 +97,7 @@ func targetConfigFields(
|
||||
) []ConfigField {
|
||||
switch t.Type {
|
||||
case database.TargetTypeSlack:
|
||||
return slackConfigFields(t)
|
||||
return slackConfigFields(t.Config)
|
||||
case database.TargetTypeHTTP:
|
||||
return httpConfigFields(t)
|
||||
case database.TargetTypeDatabase:
|
||||
@@ -119,11 +119,10 @@ func unavailableConfigFields() []ConfigField {
|
||||
}}
|
||||
}
|
||||
|
||||
// slackConfigFields describes a Slack target: its masked
|
||||
// webhook URL and its retry count. Only the masked URL is
|
||||
// shown; the full URL is the credential.
|
||||
func slackConfigFields(t *database.Target) []ConfigField {
|
||||
cfg, err := parseSlackConfig(t.Config)
|
||||
// slackConfigFields describes a Slack target. Only the masked
|
||||
// webhook URL is shown; the full URL is the credential.
|
||||
func slackConfigFields(configJSON string) []ConfigField {
|
||||
cfg, err := parseSlackConfig(configJSON)
|
||||
if err != nil {
|
||||
return unavailableConfigFields()
|
||||
}
|
||||
@@ -131,7 +130,7 @@ func slackConfigFields(t *database.Target) []ConfigField {
|
||||
return []ConfigField{{
|
||||
Label: "Webhook URL",
|
||||
Value: cfg.MaskedWebhookURL(),
|
||||
}, maxRetriesField(t)}
|
||||
}}
|
||||
}
|
||||
|
||||
// httpConfigFields describes an HTTP target: its destination
|
||||
@@ -171,7 +170,21 @@ func httpConfigFields(t *database.Target) []ConfigField {
|
||||
})
|
||||
}
|
||||
|
||||
fields = append(fields, maxRetriesField(t))
|
||||
return append(fields, retryFields(t)...)
|
||||
}
|
||||
|
||||
// retryFields describes a target's retry settings, which live
|
||||
// on the target row rather than in its configuration blob.
|
||||
func retryFields(t *database.Target) []ConfigField {
|
||||
retries := strconv.Itoa(t.MaxRetries)
|
||||
if t.MaxRetries == 0 {
|
||||
retries += " (fire-and-forget)"
|
||||
}
|
||||
|
||||
fields := []ConfigField{{
|
||||
Label: "Max Retries",
|
||||
Value: retries,
|
||||
}}
|
||||
|
||||
if t.MaxQueueSize > 0 {
|
||||
fields = append(fields, ConfigField{
|
||||
@@ -183,20 +196,6 @@ func httpConfigFields(t *database.Target) []ConfigField {
|
||||
return fields
|
||||
}
|
||||
|
||||
// maxRetriesField describes a target's retry count, which lives
|
||||
// on the target row rather than in its configuration blob.
|
||||
func maxRetriesField(t *database.Target) ConfigField {
|
||||
retries := strconv.Itoa(t.MaxRetries)
|
||||
if t.MaxRetries == 0 {
|
||||
retries += " (fire-and-forget)"
|
||||
}
|
||||
|
||||
return ConfigField{
|
||||
Label: "Max Retries",
|
||||
Value: retries,
|
||||
}
|
||||
}
|
||||
|
||||
// databaseConfigFields describes an archive target. Its
|
||||
// configuration is optional, and an absent or empty expiry
|
||||
// means the archive is kept forever. An expiry that is set
|
||||
|
||||
@@ -32,7 +32,6 @@ const (
|
||||
viewMaskedOrigin = viewExampleOrigin + "/..."
|
||||
viewUnavailable = "(unavailable)"
|
||||
viewExpiryNever = "never"
|
||||
viewMaxRetries = "Max Retries"
|
||||
)
|
||||
|
||||
func TestMaskedWebhookURL(t *testing.T) {
|
||||
@@ -158,7 +157,9 @@ func TestNewTargetViews_DeletedTarget(t *testing.T) {
|
||||
t, slackTargetName+" (deleted)", view.DisplayName(),
|
||||
)
|
||||
assert.Equal(
|
||||
t, viewFor(t, slackTarget()).Config, view.Config,
|
||||
t,
|
||||
map[string]string{"Webhook URL": slackMaskedURL},
|
||||
fieldMap(view.Config),
|
||||
)
|
||||
}
|
||||
|
||||
@@ -188,32 +189,7 @@ func TestNewTargetViews_Slack(t *testing.T) {
|
||||
|
||||
assert.Equal(
|
||||
t,
|
||||
map[string]string{
|
||||
"Webhook URL": slackMaskedURL,
|
||||
viewMaxRetries: "0 (fire-and-forget)",
|
||||
},
|
||||
fieldMap(view.Config),
|
||||
)
|
||||
}
|
||||
|
||||
// TestNewTargetViews_SlackRetries proves a Slack target shows
|
||||
// its retry count the same way an HTTP target does, and no
|
||||
// queue size even when one is stored: delivery never reads it.
|
||||
func TestNewTargetViews_SlackRetries(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
target := slackTarget()
|
||||
target.MaxRetries = 2
|
||||
target.MaxQueueSize = 100
|
||||
|
||||
view := viewFor(t, target)
|
||||
|
||||
assert.Equal(
|
||||
t,
|
||||
map[string]string{
|
||||
"Webhook URL": slackMaskedURL,
|
||||
viewMaxRetries: "2",
|
||||
},
|
||||
map[string]string{"Webhook URL": slackMaskedURL},
|
||||
fieldMap(view.Config),
|
||||
)
|
||||
}
|
||||
@@ -238,7 +214,7 @@ func TestNewTargetViews_HTTP(t *testing.T) {
|
||||
"Destination URL": viewMaskedOrigin,
|
||||
"Timeout": "30s",
|
||||
"Headers": "1 configured",
|
||||
viewMaxRetries: "5",
|
||||
"Max Retries": "5",
|
||||
"Max Queue Size": "100",
|
||||
},
|
||||
fields,
|
||||
@@ -262,7 +238,7 @@ func TestNewTargetViews_HTTPFireAndForget(t *testing.T) {
|
||||
t,
|
||||
map[string]string{
|
||||
"Destination URL": viewMaskedOrigin,
|
||||
viewMaxRetries: "0 (fire-and-forget)",
|
||||
"Max Retries": "0 (fire-and-forget)",
|
||||
},
|
||||
fieldMap(view.Config),
|
||||
)
|
||||
|
||||
@@ -3,6 +3,7 @@ package delivery
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"sync"
|
||||
"time"
|
||||
@@ -276,9 +277,10 @@ func (t *databaseTarget) releaseSweepWriter(
|
||||
}
|
||||
|
||||
// newWriter builds the writer for a database target's archive. The
|
||||
// file is the one ArchivePath gives for the webhook and the target as
|
||||
// the main database names them now; from then on only rename changes
|
||||
// the name the writer uses. It does not touch the archive file.
|
||||
// file lives beside the webhook's event database in the data
|
||||
// directory and is named for the webhook and the target as the main
|
||||
// database has them now; from then on only rename changes the name
|
||||
// the writer uses. It does not touch the archive file.
|
||||
func (t *databaseTarget) newWriter(
|
||||
targetID string,
|
||||
) (*archiveWriter, error) {
|
||||
@@ -297,10 +299,12 @@ func (t *databaseTarget) newWriter(
|
||||
)
|
||||
}
|
||||
|
||||
w := newArchiveWriter(
|
||||
ArchivePath(t.eng.dbManager, &target.Webhook, &target),
|
||||
t.eng.log,
|
||||
dir := filepath.Dir(t.eng.dbManager.DBPath(target.WebhookID))
|
||||
name := ArchiveFileName(
|
||||
target.Webhook.Name, target.Name, target.ID,
|
||||
)
|
||||
|
||||
w := newArchiveWriter(filepath.Join(dir, name), t.eng.log)
|
||||
w.webhookID = target.WebhookID
|
||||
|
||||
return w, nil
|
||||
|
||||
@@ -515,47 +515,6 @@ func (w *archiveWriter) prune(expiry time.Duration) {
|
||||
}
|
||||
}
|
||||
|
||||
// ArchiveFileInfo is what the metadata of a database target's archive
|
||||
// file says about it.
|
||||
type ArchiveFileInfo struct {
|
||||
// Size is the bytes on disk of the file and its -wal together.
|
||||
Size int64
|
||||
|
||||
// Written is when the file or its -wal was last modified, whichever
|
||||
// is later: a write lands in the -wal first.
|
||||
Written time.Time
|
||||
}
|
||||
|
||||
// StatArchive reads the metadata of the archive file at path and of
|
||||
// its -wal, without opening the archive. With no file at path, which is
|
||||
// so before the first write and after the operator moved it away, the
|
||||
// error wraps fs.ErrNotExist.
|
||||
func StatArchive(path string) (ArchiveFileInfo, error) {
|
||||
file, err := os.Stat(path)
|
||||
if err != nil {
|
||||
return ArchiveFileInfo{}, err
|
||||
}
|
||||
|
||||
info := ArchiveFileInfo{Size: file.Size(), Written: file.ModTime()}
|
||||
|
||||
wal, err := os.Stat(path + "-wal")
|
||||
if errors.Is(err, fs.ErrNotExist) {
|
||||
return info, nil
|
||||
}
|
||||
|
||||
if err != nil {
|
||||
return ArchiveFileInfo{}, err
|
||||
}
|
||||
|
||||
info.Size += wal.Size()
|
||||
|
||||
if wal.ModTime().After(info.Written) {
|
||||
info.Written = wal.ModTime()
|
||||
}
|
||||
|
||||
return info, nil
|
||||
}
|
||||
|
||||
// fileExists reports whether a path currently exists.
|
||||
func fileExists(path string) bool {
|
||||
_, err := os.Stat(path)
|
||||
|
||||
@@ -1,275 +0,0 @@
|
||||
package delivery
|
||||
|
||||
import (
|
||||
"compress/gzip"
|
||||
"context"
|
||||
"database/sql"
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"io"
|
||||
"log/slog"
|
||||
"path/filepath"
|
||||
"time"
|
||||
"unicode/utf8"
|
||||
|
||||
"gorm.io/driver/sqlite"
|
||||
"gorm.io/gorm"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/gormlog"
|
||||
)
|
||||
|
||||
// archiveTableQuery counts the archive's table: 0 when the archive
|
||||
// writer has created the file but not yet the table in it.
|
||||
const archiveTableQuery = "SELECT count(*) FROM sqlite_master " +
|
||||
"WHERE type = 'table' AND name = 'archived_events'"
|
||||
|
||||
// ArchivePath returns where a database target's archive file is: in
|
||||
// the data directory, beside the webhook's event database, under the
|
||||
// name ArchiveFileName gives it.
|
||||
func ArchivePath(
|
||||
dbMgr *database.WebhookDBManager,
|
||||
webhook *database.Webhook,
|
||||
target *database.Target,
|
||||
) string {
|
||||
return filepath.Join(
|
||||
filepath.Dir(dbMgr.DBPath(webhook.ID)),
|
||||
ArchiveFileName(webhook.Name, target.Name, target.ID),
|
||||
)
|
||||
}
|
||||
|
||||
// ArchiveExportFileName returns the name a database target's archive
|
||||
// downloads under:
|
||||
// archive-WEBHOOKNAME-TARGETNAME-YYYYMMDDTHHMMSSZ.json.gz, the names
|
||||
// made safe as in ArchiveFileName and the time in UTC.
|
||||
func ArchiveExportFileName(
|
||||
webhookName, targetName string, at time.Time,
|
||||
) string {
|
||||
return "archive-" + archiveNamePart(webhookName) + "-" +
|
||||
archiveNamePart(targetName) + "-" +
|
||||
at.UTC().Format("20060102T150405Z") + ".json.gz"
|
||||
}
|
||||
|
||||
// ArchiveExport is a database target's archive opened for download.
|
||||
// It reads the file on its own connection, inside one read-only
|
||||
// transaction, so it writes out the archive as it stood when
|
||||
// OpenArchiveExport returned.
|
||||
//
|
||||
// Archives are in WAL mode, where a reader works from a snapshot and
|
||||
// never blocks a writer: archive writes go on while an export is open,
|
||||
// and the export does not see them. SQLite cannot checkpoint the -wal
|
||||
// past an open snapshot, so the -wal grows until the export is closed.
|
||||
type ArchiveExport struct {
|
||||
db *sql.DB
|
||||
tx *gorm.DB
|
||||
|
||||
// empty is true when there is nothing to read: no file, or a file
|
||||
// without the archive's table yet.
|
||||
empty bool
|
||||
}
|
||||
|
||||
// exportedName is how an export names its webhook and its target.
|
||||
type exportedName struct {
|
||||
ID string `json:"id"`
|
||||
Name string `json:"name"`
|
||||
}
|
||||
|
||||
// OpenArchiveExport opens the archive file at path for export and
|
||||
// takes the snapshot the export reads. It never creates the file: with
|
||||
// no file at path, the export has no rows.
|
||||
//
|
||||
// Once it has returned, the file is open, so a rename or a move of it
|
||||
// does not affect the export, which reads the same file under its new
|
||||
// name.
|
||||
//
|
||||
// The transaction lasts as long as ctx does, so ctx must last for the
|
||||
// whole export.
|
||||
func OpenArchiveExport(
|
||||
ctx context.Context, path string, log *slog.Logger,
|
||||
) (*ArchiveExport, error) {
|
||||
if !fileExists(path) {
|
||||
return &ArchiveExport{empty: true}, nil
|
||||
}
|
||||
|
||||
db, err := database.OpenSQLite(path, archiveModeExisting)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("opening archive %s: %w", path, err)
|
||||
}
|
||||
|
||||
gdb, err := gorm.Open(
|
||||
sqlite.Dialector{Conn: db}, &gorm.Config{
|
||||
// Never leave this at GORM's default. See
|
||||
// internal/gormlog.
|
||||
Logger: gormlog.New(log),
|
||||
},
|
||||
)
|
||||
if err != nil {
|
||||
_ = db.Close()
|
||||
|
||||
return nil, fmt.Errorf("opening archive %s: %w", path, err)
|
||||
}
|
||||
|
||||
// ReadOnly makes the driver begin a deferred transaction in place
|
||||
// of the BEGIN IMMEDIATE the connection string asks for, so the
|
||||
// export never takes the archive's write lock.
|
||||
tx := gdb.WithContext(ctx).Begin(&sql.TxOptions{ReadOnly: true})
|
||||
if tx.Error != nil {
|
||||
_ = db.Close()
|
||||
|
||||
return nil, fmt.Errorf("reading archive %s: %w", path, tx.Error)
|
||||
}
|
||||
|
||||
// The transaction's first read is what takes the snapshot.
|
||||
var tables int
|
||||
|
||||
err = tx.Raw(archiveTableQuery).Row().Scan(&tables)
|
||||
if err != nil {
|
||||
_ = tx.Rollback()
|
||||
_ = db.Close()
|
||||
|
||||
return nil, fmt.Errorf("reading archive %s: %w", path, err)
|
||||
}
|
||||
|
||||
return &ArchiveExport{db: db, tx: tx, empty: tables == 0}, nil
|
||||
}
|
||||
|
||||
// WriteGzipJSON writes the export to w as one gzipped JSON object:
|
||||
// webhook and target, each an id and a name; exported_at; and
|
||||
// archived_events, one object per archived row, keyed by column name.
|
||||
// A body that is not valid UTF-8 cannot be a JSON string, so it is
|
||||
// written in base64, with "body_encoding": "base64" beside it.
|
||||
//
|
||||
// Each row is written out before the next is read, so neither the
|
||||
// archive nor its JSON is ever held in memory whole. After an error
|
||||
// the gzip stream is left unfinished, so what was written does not
|
||||
// decompress as a whole file.
|
||||
func (x *ArchiveExport) WriteGzipJSON(
|
||||
ctx context.Context,
|
||||
w io.Writer,
|
||||
webhook *database.Webhook,
|
||||
target *database.Target,
|
||||
exportedAt time.Time,
|
||||
) error {
|
||||
head, err := json.Marshal(map[string]any{
|
||||
"webhook": exportedName{ID: webhook.ID, Name: webhook.Name},
|
||||
"target": exportedName{ID: target.ID, Name: target.Name},
|
||||
"exported_at": exportedAt.UTC(),
|
||||
})
|
||||
if err != nil {
|
||||
return fmt.Errorf("encoding archive export: %w", err)
|
||||
}
|
||||
|
||||
zw := gzip.NewWriter(w)
|
||||
|
||||
err = x.writeJSON(ctx, zw, head)
|
||||
if err != nil {
|
||||
return fmt.Errorf("writing archive export: %w", err)
|
||||
}
|
||||
|
||||
return zw.Close()
|
||||
}
|
||||
|
||||
// Close ends the export's transaction and closes its connection.
|
||||
func (x *ArchiveExport) Close() error {
|
||||
if x.db == nil {
|
||||
return nil
|
||||
}
|
||||
|
||||
_ = x.tx.Rollback()
|
||||
|
||||
return x.db.Close()
|
||||
}
|
||||
|
||||
// writeJSON writes head with archived_events added as its last key,
|
||||
// the rows going into it one at a time.
|
||||
func (x *ArchiveExport) writeJSON(
|
||||
ctx context.Context, w io.Writer, head []byte,
|
||||
) error {
|
||||
// head goes out without its closing brace, so that
|
||||
// archived_events can follow it.
|
||||
_, err := w.Write(head[:len(head)-1])
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
_, err = io.WriteString(w, `,"archived_events":[`)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
err = x.writeRows(ctx, w)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
_, err = io.WriteString(w, "\n]}\n")
|
||||
|
||||
return err
|
||||
}
|
||||
|
||||
// writeRows writes each archived row to w, oldest first, one per line,
|
||||
// separated by commas.
|
||||
func (x *ArchiveExport) writeRows(ctx context.Context, w io.Writer) error {
|
||||
if x.empty {
|
||||
return nil
|
||||
}
|
||||
|
||||
rows, err := x.tx.WithContext(ctx).
|
||||
Model(&archivedEvent{}).Order("id").Rows()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
defer func() { _ = rows.Close() }()
|
||||
|
||||
for sep := "\n"; rows.Next(); sep = ",\n" {
|
||||
var ev archivedEvent
|
||||
|
||||
err = x.tx.ScanRows(rows, &ev)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
_, err = io.WriteString(w, sep)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
err = writeRow(w, &ev)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
|
||||
return rows.Err()
|
||||
}
|
||||
|
||||
// writeRow writes an archived row to w as a JSON object keyed by
|
||||
// column name, its body in base64 when it is not valid UTF-8.
|
||||
func writeRow(w io.Writer, ev *archivedEvent) error {
|
||||
row := map[string]any{
|
||||
"id": ev.ID,
|
||||
"event_id": ev.EventID,
|
||||
"webhook_id": ev.WebhookID,
|
||||
"entrypoint_id": ev.EntrypointID,
|
||||
"method": ev.Method,
|
||||
"headers": ev.Headers,
|
||||
"body": ev.Body,
|
||||
"content_type": ev.ContentType,
|
||||
"archived_at": ev.ArchivedAt.UTC(),
|
||||
}
|
||||
|
||||
if !utf8.ValidString(ev.Body) {
|
||||
row["body"] = base64.StdEncoding.EncodeToString([]byte(ev.Body))
|
||||
row["body_encoding"] = "base64"
|
||||
}
|
||||
|
||||
line, err := json.Marshal(row)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
_, err = w.Write(line)
|
||||
|
||||
return err
|
||||
}
|
||||
@@ -1,412 +0,0 @@
|
||||
package delivery_test
|
||||
|
||||
import (
|
||||
"bufio"
|
||||
"bytes"
|
||||
"compress/gzip"
|
||||
"crypto/rand"
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"io"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"runtime"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/delivery"
|
||||
)
|
||||
|
||||
// The webhook and the target the export tests' archives belong to.
|
||||
const (
|
||||
exportWebhookID = "wh-export"
|
||||
exportWebhookName = "Orders (EU)"
|
||||
exportTargetID = "tgt-export"
|
||||
exportTargetName = "Long-term archive"
|
||||
)
|
||||
|
||||
const (
|
||||
// binaryBody is a body that is not valid UTF-8.
|
||||
binaryBody = "\xff\xfe\x00\x01binary\x80"
|
||||
|
||||
// openedEventID is the event the snapshot tests archive before
|
||||
// they open the export.
|
||||
openedEventID = "opened"
|
||||
)
|
||||
|
||||
// writeExportTo writes export to w as the archive of the export tests'
|
||||
// webhook and target, exported at 2026-10-02T12:03:04Z.
|
||||
func writeExportTo(
|
||||
t *testing.T, export *delivery.ArchiveExport, w io.Writer,
|
||||
) error {
|
||||
t.Helper()
|
||||
|
||||
return export.WriteGzipJSON(
|
||||
t.Context(), w,
|
||||
&database.Webhook{
|
||||
BaseModel: database.BaseModel{ID: exportWebhookID},
|
||||
Name: exportWebhookName,
|
||||
},
|
||||
&database.Target{
|
||||
BaseModel: database.BaseModel{ID: exportTargetID},
|
||||
Name: exportTargetName,
|
||||
},
|
||||
time.Date(2026, 10, 2, 12, 3, 4, 0, time.UTC),
|
||||
)
|
||||
}
|
||||
|
||||
// exportArchive runs a whole export of the archive at path and returns
|
||||
// its JSON, decompressed and parsed.
|
||||
func exportArchive(t *testing.T, path string) map[string]any {
|
||||
t.Helper()
|
||||
|
||||
export, err := delivery.OpenArchiveExport(
|
||||
t.Context(), path, archiveTestLogger(),
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
defer func() { require.NoError(t, export.Close()) }()
|
||||
|
||||
return writeExport(t, export)
|
||||
}
|
||||
|
||||
// writeExport writes an opened export and returns its JSON,
|
||||
// decompressed and parsed. Reading to the end makes the gzip reader
|
||||
// check that the stream was finished.
|
||||
func writeExport(
|
||||
t *testing.T, export *delivery.ArchiveExport,
|
||||
) map[string]any {
|
||||
t.Helper()
|
||||
|
||||
var buf bytes.Buffer
|
||||
|
||||
require.NoError(t, writeExportTo(t, export, &buf))
|
||||
|
||||
zr, err := gzip.NewReader(&buf)
|
||||
require.NoError(t, err)
|
||||
|
||||
raw, err := io.ReadAll(zr)
|
||||
require.NoError(t, err)
|
||||
|
||||
var got map[string]any
|
||||
|
||||
require.NoError(t, json.Unmarshal(raw, &got))
|
||||
|
||||
return got
|
||||
}
|
||||
|
||||
// exportedEvents returns an export's archived_events.
|
||||
func exportedEvents(t *testing.T, got map[string]any) []map[string]any {
|
||||
t.Helper()
|
||||
|
||||
list, ok := got["archived_events"].([]any)
|
||||
require.True(t, ok, "archived_events must be an array: %v", got)
|
||||
|
||||
events := make([]map[string]any, len(list))
|
||||
|
||||
for i, v := range list {
|
||||
events[i], ok = v.(map[string]any)
|
||||
require.True(t, ok, "an archived event must be an object: %v", v)
|
||||
}
|
||||
|
||||
return events
|
||||
}
|
||||
|
||||
// exportedEventIDs returns the event_id of each of an export's
|
||||
// archived_events.
|
||||
func exportedEventIDs(t *testing.T, got map[string]any) []string {
|
||||
t.Helper()
|
||||
|
||||
events := exportedEvents(t, got)
|
||||
ids := make([]string, 0, len(events))
|
||||
|
||||
for _, ev := range events {
|
||||
ids = append(ids, fmt.Sprint(ev["event_id"]))
|
||||
}
|
||||
|
||||
return ids
|
||||
}
|
||||
|
||||
// TestArchiveExport_MatchesStoredRows proves an export holds the
|
||||
// webhook, the target, the time, and every column of every stored
|
||||
// row: a body that is valid UTF-8 as a string, and one that is not in
|
||||
// base64, marked as such.
|
||||
func TestArchiveExport_MatchesStoredRows(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
path := filepath.Join(t.TempDir(), "archive.db")
|
||||
w := delivery.NewExportArchiveWriter(path, archiveTestLogger(), 0)
|
||||
bodies := []string{`{"order":1}`, "plain text", "", binaryBody}
|
||||
|
||||
for i, body := range bodies {
|
||||
require.NoError(t, w.Write(delivery.ExportArchivedEvent{
|
||||
EventID: fmt.Sprintf("ev-%d", i),
|
||||
WebhookID: exportWebhookID,
|
||||
EntrypointID: "ep-1",
|
||||
Method: "POST",
|
||||
Headers: `{"X-Test":["yes"]}`,
|
||||
Body: body,
|
||||
ContentType: testContentType,
|
||||
}, 0))
|
||||
}
|
||||
|
||||
var stored []delivery.ExportArchivedEvent
|
||||
|
||||
require.NoError(t, openArchiveDBForRead(t, path).
|
||||
Order("id").Find(&stored).Error)
|
||||
|
||||
got := exportArchive(t, path)
|
||||
|
||||
assert.Equal(t,
|
||||
map[string]any{"id": exportWebhookID, "name": exportWebhookName},
|
||||
got["webhook"],
|
||||
)
|
||||
assert.Equal(t,
|
||||
map[string]any{"id": exportTargetID, "name": exportTargetName},
|
||||
got["target"],
|
||||
)
|
||||
assert.Equal(t, "2026-10-02T12:03:04Z", got["exported_at"])
|
||||
|
||||
events := exportedEvents(t, got)
|
||||
require.Len(t, events, len(bodies))
|
||||
|
||||
for i, row := range stored {
|
||||
assertExportedRow(t, row, events[i])
|
||||
}
|
||||
}
|
||||
|
||||
// assertExportedRow checks that ev, from an export, holds every column
|
||||
// of the stored row.
|
||||
func assertExportedRow(
|
||||
t *testing.T, row delivery.ExportArchivedEvent, ev map[string]any,
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
archivedAt, err := time.Parse(
|
||||
time.RFC3339Nano, fmt.Sprint(ev["archived_at"]),
|
||||
)
|
||||
require.NoError(t, err)
|
||||
assert.True(t, archivedAt.Equal(row.ArchivedAt))
|
||||
|
||||
assert.EqualValues(t, row.ID, ev["id"])
|
||||
assert.Equal(t, row.EventID, ev["event_id"])
|
||||
assert.Equal(t, row.WebhookID, ev["webhook_id"])
|
||||
assert.Equal(t, row.EntrypointID, ev["entrypoint_id"])
|
||||
assert.Equal(t, row.Method, ev["method"])
|
||||
assert.Equal(t, row.Headers, ev["headers"])
|
||||
assert.Equal(t, row.ContentType, ev["content_type"])
|
||||
|
||||
if row.Body != binaryBody {
|
||||
assert.Equal(t, row.Body, ev["body"])
|
||||
assert.Len(t, ev, 9, "the nine columns and nothing else: %v", ev)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
body, err := base64.StdEncoding.DecodeString(fmt.Sprint(ev["body"]))
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, binaryBody, string(body))
|
||||
assert.Equal(t, "base64", ev["body_encoding"])
|
||||
assert.Len(t, ev, 10, "the nine columns and body_encoding: %v", ev)
|
||||
}
|
||||
|
||||
// TestArchiveExport_Empty proves an archive with nothing in it exports
|
||||
// as an empty archived_events: no file, which the export must not
|
||||
// create; a file the archive writer has not yet put its table in; and
|
||||
// a table with no rows.
|
||||
func TestArchiveExport_Empty(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
dir := t.TempDir()
|
||||
missing := filepath.Join(dir, "missing.db")
|
||||
noTable := filepath.Join(dir, "no-table.db")
|
||||
noRows := filepath.Join(dir, "no-rows.db")
|
||||
|
||||
require.NoError(t, os.WriteFile(noTable, nil, 0o600))
|
||||
require.NoError(t,
|
||||
delivery.NewExportArchiveWriter(noRows, archiveTestLogger(), 0).
|
||||
Open(0),
|
||||
)
|
||||
|
||||
for _, path := range []string{missing, noTable, noRows} {
|
||||
assert.Empty(t, exportedEvents(t, exportArchive(t, path)), path)
|
||||
}
|
||||
|
||||
for _, suffix := range archiveFileSuffixes() {
|
||||
assert.NoFileExists(t, missing+suffix)
|
||||
}
|
||||
}
|
||||
|
||||
// TestArchiveExport_ReadsOneSnapshot proves an export writes the
|
||||
// archive as it was when it was opened, and holds up no archive
|
||||
// write: a row written while the export is open is stored, and is not
|
||||
// in the export. A write held up for the whole busy timeout would
|
||||
// fail.
|
||||
func TestArchiveExport_ReadsOneSnapshot(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
path := filepath.Join(t.TempDir(), "archive.db")
|
||||
w := delivery.NewExportArchiveWriter(path, archiveTestLogger(), 0)
|
||||
|
||||
require.NoError(t, w.Write(delivery.ExportArchivedEvent{EventID: openedEventID}, 0))
|
||||
|
||||
export, err := delivery.OpenArchiveExport(
|
||||
t.Context(), path, archiveTestLogger(),
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
defer func() { require.NoError(t, export.Close()) }()
|
||||
|
||||
require.NoError(t, w.Write(delivery.ExportArchivedEvent{EventID: "during"}, 0))
|
||||
|
||||
assert.Equal(t,
|
||||
[]string{openedEventID}, exportedEventIDs(t, writeExport(t, export)),
|
||||
)
|
||||
|
||||
var stored int64
|
||||
|
||||
require.NoError(t, openArchiveDBForRead(t, path).
|
||||
Model(&delivery.ExportArchivedEvent{}).Count(&stored).Error)
|
||||
assert.Equal(t, int64(2), stored)
|
||||
}
|
||||
|
||||
// TestArchiveExport_SurvivesRename proves that renaming the archive
|
||||
// while an export of it is open, as renaming its webhook or target
|
||||
// does, leaves the export reading the same file.
|
||||
func TestArchiveExport_SurvivesRename(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
path := filepath.Join(t.TempDir(), "archive-old.db")
|
||||
w := delivery.NewExportArchiveWriter(path, archiveTestLogger(), 0)
|
||||
|
||||
require.NoError(t, w.Write(delivery.ExportArchivedEvent{EventID: openedEventID}, 0))
|
||||
|
||||
export, err := delivery.OpenArchiveExport(
|
||||
t.Context(), path, archiveTestLogger(),
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
defer func() { require.NoError(t, export.Close()) }()
|
||||
|
||||
require.NoError(t, w.Rename("archive-new.db"))
|
||||
require.NoError(t, w.Write(delivery.ExportArchivedEvent{EventID: "after"}, 0))
|
||||
require.NoFileExists(t, path)
|
||||
|
||||
assert.Equal(t,
|
||||
[]string{openedEventID}, exportedEventIDs(t, writeExport(t, export)),
|
||||
)
|
||||
}
|
||||
|
||||
// heapPeak is an io.Writer that discards what it is given and records
|
||||
// the largest heap it saw at a write. It collects garbage before each
|
||||
// reading, so the heap it reads is what is still held.
|
||||
type heapPeak struct {
|
||||
max uint64
|
||||
}
|
||||
|
||||
func (p *heapPeak) Write(b []byte) (int, error) {
|
||||
var m runtime.MemStats
|
||||
|
||||
runtime.GC()
|
||||
runtime.ReadMemStats(&m)
|
||||
p.max = max(p.max, m.HeapAlloc)
|
||||
|
||||
return len(b), nil
|
||||
}
|
||||
|
||||
// exportHeapGrowth exports an archive of rows random bodies, each
|
||||
// bodySize bytes of base64, and returns how far the heap rose above
|
||||
// where it stood when the export began, at its highest.
|
||||
func exportHeapGrowth(t *testing.T, rows, bodySize int) uint64 {
|
||||
t.Helper()
|
||||
|
||||
path := filepath.Join(t.TempDir(), "archive.db")
|
||||
w := delivery.NewExportArchiveWriter(path, archiveTestLogger(), 0)
|
||||
|
||||
// Base64 makes four characters of every three bytes.
|
||||
random := make([]byte, bodySize/4*3)
|
||||
|
||||
for range rows {
|
||||
_, _ = rand.Read(random)
|
||||
|
||||
require.NoError(t, w.Write(delivery.ExportArchivedEvent{
|
||||
Body: base64.StdEncoding.EncodeToString(random),
|
||||
}, 0))
|
||||
}
|
||||
|
||||
export, err := delivery.OpenArchiveExport(
|
||||
t.Context(), path, archiveTestLogger(),
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
defer func() { require.NoError(t, export.Close()) }()
|
||||
|
||||
runtime.GC()
|
||||
|
||||
var start runtime.MemStats
|
||||
|
||||
runtime.ReadMemStats(&start)
|
||||
|
||||
// Through a buffer, the heap is read once per 8 KiB of output
|
||||
// rather than at each of gzip's small writes, which takes far
|
||||
// longer.
|
||||
peak := &heapPeak{max: start.HeapAlloc}
|
||||
buffered := bufio.NewWriterSize(peak, 8<<10)
|
||||
|
||||
require.NoError(t, writeExportTo(t, export, buffered))
|
||||
require.NoError(t, buffered.Flush())
|
||||
|
||||
return peak.max - start.HeapAlloc
|
||||
}
|
||||
|
||||
// TestArchiveExport_Streams proves an export holds neither the archive
|
||||
// nor its output in memory whole: exporting 384 KiB more of archive
|
||||
// raises the heap's peak by less than half of that. The export's own
|
||||
// memory, mostly gzip's compressor, is the same for both archives, so
|
||||
// it cancels out. The bodies are random bytes in base64, which gzip
|
||||
// shrinks by only a quarter, so an export that read every row before
|
||||
// writing, or built the JSON or the gzipped file before writing it,
|
||||
// would raise the peak by at least three quarters of the difference.
|
||||
//
|
||||
// The smaller archive has two rows so that its export, too, writes
|
||||
// out more than the 8 KiB buffer in exportHeapGrowth before it ends:
|
||||
// the heap must be read while the export's own memory is held.
|
||||
//
|
||||
//nolint:paralleltest // It measures the heap, which tests share.
|
||||
func TestArchiveExport_Streams(t *testing.T) {
|
||||
const (
|
||||
bodySize = 16 << 10
|
||||
smallRows = 2
|
||||
largeRows = smallRows + 24
|
||||
limit = (largeRows - smallRows) * bodySize / 2
|
||||
)
|
||||
|
||||
small := exportHeapGrowth(t, smallRows, bodySize)
|
||||
large := exportHeapGrowth(t, largeRows, bodySize)
|
||||
|
||||
assert.Less(t, large, small+limit,
|
||||
"the heap rose by %d for %d rows and by %d for %d rows",
|
||||
small, smallRows, large, largeRows,
|
||||
)
|
||||
}
|
||||
|
||||
// TestArchiveExportFileName proves the download is named for the
|
||||
// webhook and the target, with the names made safe as for the archive
|
||||
// file, and the export time in UTC.
|
||||
func TestArchiveExportFileName(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cest := time.FixedZone("CEST", int((2 * time.Hour).Seconds()))
|
||||
|
||||
assert.Equal(t,
|
||||
"archive-orders-eu-long-term-archive-20261002T120304Z.json.gz",
|
||||
delivery.ArchiveExportFileName(
|
||||
exportWebhookName, exportTargetName,
|
||||
time.Date(2026, 10, 2, 14, 3, 4, 0, cest),
|
||||
),
|
||||
)
|
||||
}
|
||||
@@ -3,7 +3,6 @@ package delivery_test
|
||||
import (
|
||||
"database/sql"
|
||||
"fmt"
|
||||
"io/fs"
|
||||
"log/slog"
|
||||
"os"
|
||||
"path/filepath"
|
||||
@@ -18,7 +17,6 @@ import (
|
||||
_ "modernc.org/sqlite" // Pure Go SQLite driver.
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/delivery"
|
||||
"sneak.berlin/go/webhooker/internal/gormlog"
|
||||
)
|
||||
|
||||
func archiveTestLogger() *slog.Logger {
|
||||
@@ -44,8 +42,7 @@ func openArchiveDBForRead(
|
||||
t.Cleanup(func() { _ = sqlDB.Close() })
|
||||
|
||||
gdb, err := gorm.Open(
|
||||
sqlite.Dialector{Conn: sqlDB},
|
||||
&gorm.Config{Logger: gormlog.New(slog.New(slog.DiscardHandler))},
|
||||
sqlite.Dialector{Conn: sqlDB}, &gorm.Config{},
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
@@ -184,49 +181,6 @@ func TestArchiveWriter_RecreatesAfterRemoval(
|
||||
assert.Equal(t, "b", got[0].EventID)
|
||||
}
|
||||
|
||||
// TestStatArchive proves StatArchive finds no file before the first
|
||||
// write; after a write still held in the -wal, counts the -wal in the
|
||||
// size and takes its later time as the last write; and finds no file
|
||||
// again once the file has been moved away.
|
||||
func TestStatArchive(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
path := filepath.Join(t.TempDir(), "archive-wh.db")
|
||||
|
||||
_, err := delivery.StatArchive(path)
|
||||
require.ErrorIs(t, err, fs.ErrNotExist)
|
||||
|
||||
// With the clock stopped, the reopen debounce never passes, so
|
||||
// the handle stays open after the write.
|
||||
stopped := time.Now()
|
||||
w := delivery.NewExportArchiveWriter(path, archiveTestLogger(), 0)
|
||||
w.SetNow(func() time.Time { return stopped })
|
||||
|
||||
require.NoError(t, w.Write(delivery.ExportArchivedEvent{EventID: "a"}, 0))
|
||||
|
||||
written := time.Date(2026, 1, 2, 3, 4, 5, 0, time.UTC)
|
||||
earlier := written.Add(-time.Hour)
|
||||
require.NoError(t, os.Chtimes(path, earlier, earlier))
|
||||
require.NoError(t, os.Chtimes(path+"-wal", written, written))
|
||||
|
||||
file, err := os.Stat(path)
|
||||
require.NoError(t, err)
|
||||
|
||||
wal, err := os.Stat(path + "-wal")
|
||||
require.NoError(t, err)
|
||||
require.Positive(t, wal.Size())
|
||||
|
||||
got, err := delivery.StatArchive(path)
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, file.Size()+wal.Size(), got.Size)
|
||||
assert.True(t, written.Equal(got.Written), got.Written)
|
||||
|
||||
removeArchiveFiles(t, path)
|
||||
|
||||
_, err = delivery.StatArchive(path)
|
||||
require.ErrorIs(t, err, fs.ErrNotExist)
|
||||
}
|
||||
|
||||
func TestArchiveWriter_ReopenDebounce(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
@@ -573,8 +573,6 @@ func TestRecoverPending_TargetDeleted(t *testing.T) {
|
||||
|
||||
s := newISetup(t)
|
||||
|
||||
iCreateWebhook(t, s.MainDB, s.WebhookID, "pending-recovery")
|
||||
|
||||
deliveryID := tSeedDeletedTarget(
|
||||
t, s, "gone-while-pending", "http://example.com/hook",
|
||||
database.DeliveryStatusPending,
|
||||
@@ -614,8 +612,6 @@ func TestRecoverPending_TargetDeleted_LeavesAnOwnedDeliveryAlone(
|
||||
|
||||
s := newISetup(t)
|
||||
|
||||
iCreateWebhook(t, s.MainDB, s.WebhookID, "owned-recovery")
|
||||
|
||||
deliveryID := tSeedDeletedTarget(
|
||||
t, s, "gone-but-owned", "http://example.com/hook",
|
||||
database.DeliveryStatusPending,
|
||||
|
||||
@@ -179,27 +179,6 @@ func TestDoHTTPRequest_TransportErrorMasksURL(t *testing.T) {
|
||||
)
|
||||
}
|
||||
|
||||
// TestDoHTTPRequest_UnparsableURLIsMasked is the same for an HTTP
|
||||
// target URL that no request can be built from.
|
||||
func TestDoHTTPRequest_UnparsableURLIsMasked(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
e := testEngine(t, 1)
|
||||
|
||||
statusCode, _, _, reqErr := e.ExportDoHTTPRequest(
|
||||
context.TODO(),
|
||||
&delivery.HTTPTargetConfig{
|
||||
URL: "https://hooks.example.com" + maskSecretPath + "\n",
|
||||
},
|
||||
&database.Event{},
|
||||
)
|
||||
require.Error(t, reqErr)
|
||||
assert.Zero(t, statusCode)
|
||||
|
||||
assertNoCredential(t, reqErr.Error())
|
||||
assert.Contains(t, reqErr.Error(), "invalid control character")
|
||||
}
|
||||
|
||||
// TestValidateTargetURL_UnparsableURLIsMasked proves the SSRF
|
||||
// validator's error does not carry the submitted URL, which
|
||||
// the handler both logs and shows.
|
||||
|
||||
@@ -117,8 +117,8 @@ func readFirstBootSecrets(
|
||||
}
|
||||
|
||||
// bootAtDebug starts and stops the real application graph against
|
||||
// dataDir with DEBUG=true and nothing else set, and returns everything
|
||||
// it wrote to standard output.
|
||||
// dataDir with DEBUG=true, and returns everything it wrote to standard
|
||||
// output.
|
||||
//
|
||||
// config.New reads DEBUG from the environment exactly as the binary
|
||||
// does, internal/logger builds the handler it builds in production,
|
||||
@@ -128,7 +128,6 @@ func readFirstBootSecrets(
|
||||
func bootAtDebug(t *testing.T, dataDir string) string {
|
||||
t.Helper()
|
||||
|
||||
config.ClearEnvForTest(t)
|
||||
t.Setenv("DEBUG", "true")
|
||||
t.Setenv("DATA_DIR", dataDir)
|
||||
|
||||
|
||||
@@ -111,9 +111,9 @@ func (l *Logger) LogMode(gormlogger.LogLevel) gormlogger.Interface {
|
||||
//
|
||||
// One GORM path does not consult this: (*gorm.DB).Scan records the
|
||||
// statement through gorm's own traceRecorder, which does not implement
|
||||
// this interface. No production code path calls it; only tests do, and
|
||||
// what a test binds is fixture data. scan_guard_test.go fails if a
|
||||
// non-test file calls it.
|
||||
// this interface. No production code path calls it; its one caller is
|
||||
// internal/database/database_test.go:91, whose SELECT 1 binds nothing.
|
||||
// scan_guard_test.go fails if a non-test file calls it.
|
||||
// (*gorm.DB).Pluck, Row and Raw all run through the normal callback
|
||||
// processor and are filtered.
|
||||
func (l *Logger) ParamsFilter(
|
||||
|
||||
@@ -14,16 +14,18 @@ import (
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
// isRowProducer reports whether name is GORM's Row or database/sql's
|
||||
// QueryRow or QueryRowContext, which return a *sql.Row whose Scan is
|
||||
// database/sql's and not (*gorm.DB).Scan. GORM's Rows is not listed:
|
||||
// it also returns an error, so Scan is never called on its result
|
||||
// directly. It matches the method name only and resolves no types, so
|
||||
// a repo-local method with one of these names that returns *gorm.DB
|
||||
// gets past it: Scan on that method's result is not reported.
|
||||
// minNonTestFiles guards the walk below against passing because it
|
||||
// found nothing to look at. The tree held 60 non-test .go files when
|
||||
// this was written.
|
||||
const minNonTestFiles = 40
|
||||
|
||||
// isRowProducer reports whether name is a method that returns a
|
||||
// database/sql row handle. GORM's Row and Rows return *sql.Row and
|
||||
// *sql.Rows, so Scan on the result of one of them is database/sql's
|
||||
// Scan and never (*gorm.DB).Scan.
|
||||
func isRowProducer(name string) bool {
|
||||
switch name {
|
||||
case "Row", "QueryRow", "QueryRowContext":
|
||||
case "Row", "Rows", "QueryRow", "QueryRowContext":
|
||||
return true
|
||||
default:
|
||||
return false
|
||||
@@ -48,14 +50,9 @@ func receiverIsRowHandle(x ast.Expr) bool {
|
||||
}
|
||||
|
||||
// unguardedScans returns the position of every Scan call in file whose
|
||||
// receiver is not a call to a row producer. It fails closed: any other
|
||||
// receiver — a local variable, a struct field, a call to any other
|
||||
// method — is reported rather than assumed safe.
|
||||
//
|
||||
// It sees only calls written x.Scan(...). A method value, f := db.Scan
|
||||
// followed by f(&v), is out of scope: Scan is never the called
|
||||
// expression there, and nobody writes a query that way by accident,
|
||||
// which is the mistake this check exists to catch.
|
||||
// receiver is not a row handle. It fails closed: a receiver it cannot
|
||||
// resolve syntactically — a local variable, a struct field — is
|
||||
// reported rather than assumed safe.
|
||||
func unguardedScans(
|
||||
fset *token.FileSet, file *ast.File,
|
||||
) []token.Position {
|
||||
@@ -114,15 +111,15 @@ func skipDir(name string) bool {
|
||||
}
|
||||
}
|
||||
|
||||
// walkNonTestGo parses every non-test .go file under root. It returns
|
||||
// the directories, relative to root, it parsed a file in, along with
|
||||
// every unguarded Scan it found.
|
||||
func walkNonTestGo(t *testing.T, root string) (map[string]bool, []string) {
|
||||
// walkNonTestGo parses every non-test .go file under root and returns
|
||||
// how many it parsed along with every unguarded Scan it found.
|
||||
func walkNonTestGo(t *testing.T, root string) (int, []string) {
|
||||
t.Helper()
|
||||
|
||||
walked := map[string]bool{}
|
||||
|
||||
var hits []string
|
||||
var (
|
||||
parsed int
|
||||
hits []string
|
||||
)
|
||||
|
||||
fset := token.NewFileSet()
|
||||
|
||||
@@ -150,12 +147,7 @@ func walkNonTestGo(t *testing.T, root string) (map[string]bool, []string) {
|
||||
return err
|
||||
}
|
||||
|
||||
dir, err := filepath.Rel(root, filepath.Dir(path))
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
walked[dir] = true
|
||||
parsed++
|
||||
|
||||
for _, pos := range unguardedScans(fset, file) {
|
||||
hits = append(hits, relPosition(root, pos))
|
||||
@@ -165,7 +157,7 @@ func walkNonTestGo(t *testing.T, root string) (map[string]bool, []string) {
|
||||
},
|
||||
))
|
||||
|
||||
return walked, hits
|
||||
return parsed, hits
|
||||
}
|
||||
|
||||
// isNonTestGo reports whether a file name is Go source this check
|
||||
@@ -197,39 +189,19 @@ func relPosition(root string, pos token.Position) string {
|
||||
// logged with its values interpolated. The package comment states the
|
||||
// limit; this fails when someone adds a call site anyway.
|
||||
//
|
||||
// Test files are not governed: what a test binds is fixture data.
|
||||
// The current tree has one caller, internal/database/database_test.go,
|
||||
// which this check does not govern: it is test-only and its SELECT 1
|
||||
// binds nothing.
|
||||
func TestGormScanIsNeverCalledOutsideTests(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
root := moduleRoot(t)
|
||||
walked, offenders := walkNonTestGo(t, root)
|
||||
|
||||
// The module's packages are static, templates, and every directory
|
||||
// directly under cmd and internal. Each holds non-test code, so one
|
||||
// the walk parsed nothing in was skipped, and a Scan there would
|
||||
// pass unseen.
|
||||
packages := []string{"static", "templates"}
|
||||
|
||||
for _, parent := range []string{"cmd", "internal"} {
|
||||
entries, err := os.ReadDir(filepath.Join(root, parent))
|
||||
require.NoError(t, err)
|
||||
|
||||
for _, entry := range entries {
|
||||
if !entry.IsDir() {
|
||||
continue
|
||||
}
|
||||
|
||||
packages = append(packages, filepath.Join(parent, entry.Name()))
|
||||
}
|
||||
}
|
||||
|
||||
for _, dir := range packages {
|
||||
require.True(
|
||||
t, walked[dir],
|
||||
"the walk parsed no non-test .go file in %s", dir,
|
||||
)
|
||||
}
|
||||
parsed, offenders := walkNonTestGo(t, moduleRoot(t))
|
||||
|
||||
require.GreaterOrEqual(
|
||||
t, parsed, minNonTestFiles,
|
||||
"parsed %d non-test .go files, so this check found "+
|
||||
"nothing to look at", parsed,
|
||||
)
|
||||
require.Empty(
|
||||
t, offenders,
|
||||
"Scan called on a receiver this check cannot show is a "+
|
||||
@@ -250,51 +222,18 @@ type scanGuardCase struct {
|
||||
want int
|
||||
}
|
||||
|
||||
// scanGuardCases covers each receiver form unguardedScans names, plus
|
||||
// each row producer isRowProducer lets through. Each body is valid Go
|
||||
// inside plantedFile.
|
||||
func scanGuardCases() []scanGuardCase {
|
||||
return []scanGuardCase{
|
||||
{"local variable", "q := gdb.Raw(\"SELECT 1\")\n\tq.Scan(&v)", 1},
|
||||
{"struct field", `s.db.Scan(&v)`, 1},
|
||||
{"gorm chain", `gdb.Raw("SELECT 1").Scan(&v)`, 1},
|
||||
{
|
||||
"sql rows in a variable",
|
||||
"rows, _ := gdb.Raw(\"SELECT 1\").Rows()\n\trows.Scan(&v)",
|
||||
1,
|
||||
},
|
||||
{"gorm Row", `gdb.Raw("SELECT 1").Row().Scan(&v)`, 0},
|
||||
{"sql QueryRow", `sqlDB.QueryRow("SELECT 1").Scan(&v)`, 0},
|
||||
{
|
||||
"sql QueryRowContext",
|
||||
`sqlDB.QueryRowContext(ctx, "SELECT 1").Scan(&v)`,
|
||||
0,
|
||||
},
|
||||
{"gorm chain", `db.DB().Raw("SELECT 1").Scan(&v)`, 1},
|
||||
{"gorm receiver", `gdb.Scan(&v)`, 1},
|
||||
{"gorm via variable", "q := gdb.Raw(\"x\")\nq.Scan(&v)", 1},
|
||||
{"gorm model chain", `gdb.Model(&x).Scan(&v)`, 1},
|
||||
{"sql row", `gdb.Raw("SELECT 1").Row().Scan(&v)`, 0},
|
||||
{"sql rows", `gdb.Raw("SELECT 1").Rows().Scan(&v)`, 0},
|
||||
{"unrelated call", `gdb.Find(&v)`, 0},
|
||||
}
|
||||
}
|
||||
|
||||
// plantedFile wraps one case body in a function that declares every
|
||||
// name the bodies use, so each body is the Go it stands for. The result
|
||||
// is parsed, never compiled.
|
||||
const plantedFile = `package p
|
||||
|
||||
import (
|
||||
"context"
|
||||
"database/sql"
|
||||
|
||||
"gorm.io/gorm"
|
||||
)
|
||||
|
||||
type store struct{ db *gorm.DB }
|
||||
|
||||
func f(ctx context.Context, gdb *gorm.DB, sqlDB *sql.DB, s store) {
|
||||
var v int
|
||||
|
||||
%s
|
||||
}
|
||||
`
|
||||
|
||||
// TestScanGuard_ReportsPlantedCalls proves the check fires. Without it
|
||||
// a detector that matched nothing would satisfy the walk above no
|
||||
// matter what the tree contained.
|
||||
@@ -306,7 +245,9 @@ func TestScanGuard_ReportsPlantedCalls(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
fset := token.NewFileSet()
|
||||
src := fmt.Sprintf(plantedFile, tc.body)
|
||||
src := fmt.Sprintf(
|
||||
"package p\n\nfunc f() {\n\t%s\n}\n", tc.body,
|
||||
)
|
||||
|
||||
file, err := parser.ParseFile(
|
||||
fset, tc.name+".go", src, 0,
|
||||
|
||||
@@ -1,95 +0,0 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"net/url"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/go-chi/chi"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"gorm.io/gorm"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
)
|
||||
|
||||
// TestHandleEntrypointToggle_DoesNotUndoAnEdit proves that a toggle
|
||||
// which loaded the entrypoint before an edit of its description was
|
||||
// saved does not write the old description back over the edit. The
|
||||
// edit is submitted from a callback on the toggle's own read of the
|
||||
// entrypoint, so it is saved after that read and before the toggle
|
||||
// writes.
|
||||
func TestHandleEntrypointToggle_DoesNotUndoAnEdit(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSourceTest(t)
|
||||
wh := seedWebhookWithRetention(t, env.db, 30)
|
||||
ep := seedEntrypoint(t, env.db, wh.ID)
|
||||
require.True(t, ep.Active)
|
||||
|
||||
router := chi.NewRouter()
|
||||
router.Post(
|
||||
"/hook/{sourceID}/entrypoints/{entrypointID}/edit",
|
||||
env.handlers.HandleEntrypointEdit(),
|
||||
)
|
||||
router.Post(
|
||||
"/hook/{sourceID}/entrypoints/{entrypointID}/toggle",
|
||||
env.handlers.HandleEntrypointToggle(),
|
||||
)
|
||||
|
||||
// post submits one of the entrypoint's forms as the test user and
|
||||
// returns the response's status code.
|
||||
post := func(action string, form url.Values) int {
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(), http.MethodPost,
|
||||
"/hook/"+wh.ID+"/entrypoints/"+ep.ID+"/"+action,
|
||||
strings.NewReader(form.Encode()),
|
||||
)
|
||||
req.Header.Set(
|
||||
"Content-Type", "application/x-www-form-urlencoded",
|
||||
)
|
||||
|
||||
for _, c := range env.cookies {
|
||||
req.AddCookie(c)
|
||||
}
|
||||
|
||||
w := httptest.NewRecorder()
|
||||
router.ServeHTTP(w, req)
|
||||
|
||||
return w.Code
|
||||
}
|
||||
|
||||
var (
|
||||
edited bool
|
||||
editCode int
|
||||
)
|
||||
|
||||
require.NoError(t, env.db.DB().Callback().Query().
|
||||
After("gorm:query").
|
||||
Register("test:edit_after_toggle_read", func(tx *gorm.DB) {
|
||||
// Only the first read of an entrypoint, the toggle's,
|
||||
// submits the edit.
|
||||
if tx.Statement.Table != "entrypoints" || edited {
|
||||
return
|
||||
}
|
||||
|
||||
edited = true
|
||||
editCode = post(
|
||||
"edit", url.Values{"description": {"Billing sender"}},
|
||||
)
|
||||
}),
|
||||
)
|
||||
|
||||
require.Equal(t, http.StatusSeeOther, post("toggle", nil))
|
||||
require.Equal(t, http.StatusSeeOther, editCode)
|
||||
|
||||
var stored database.Entrypoint
|
||||
|
||||
require.NoError(
|
||||
t, env.db.DB().First(&stored, "id = ?", ep.ID).Error,
|
||||
)
|
||||
assert.False(t, stored.Active)
|
||||
assert.Equal(t, "Billing sender", stored.Description)
|
||||
}
|
||||
@@ -1,11 +1,6 @@
|
||||
package handlers
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"time"
|
||||
|
||||
"github.com/dustin/go-humanize"
|
||||
"gorm.io/gorm"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
)
|
||||
|
||||
@@ -16,21 +11,6 @@ type EntrypointView struct {
|
||||
Path string
|
||||
Description string
|
||||
Active bool
|
||||
|
||||
// Events is how many events arrived on the entrypoint's URL within
|
||||
// the webhook's retention period. LastEvent is when the newest
|
||||
// event ever to arrive on it did, relative, and LastEventUTC the
|
||||
// full time; both are empty when none ever did.
|
||||
Events int64
|
||||
LastEvent string
|
||||
LastEventUTC string
|
||||
}
|
||||
|
||||
// entrypointEvents is one entrypoint's count read by
|
||||
// addEntrypointEvents.
|
||||
type entrypointEvents struct {
|
||||
EntrypointID string
|
||||
Events int64
|
||||
}
|
||||
|
||||
// NewEntrypointViews projects entrypoints for rendering.
|
||||
@@ -52,60 +32,3 @@ func NewEntrypointViews(
|
||||
|
||||
return views
|
||||
}
|
||||
|
||||
// addEntrypointEvents fills in each view's event figures from the
|
||||
// webhook's event database: when the last event arrived on its URL,
|
||||
// from its EntrypointTotals row, and how many events arrived on it
|
||||
// since the webhook's retention cutoff, counted in one query over the
|
||||
// events' entrypoint_id index. Resubmitted copies did not arrive on
|
||||
// the URL and are left out of both.
|
||||
func addEntrypointEvents(
|
||||
webhookDB *gorm.DB,
|
||||
webhook *database.Webhook,
|
||||
views []EntrypointView,
|
||||
now time.Time,
|
||||
) error {
|
||||
ids := make([]string, len(views))
|
||||
byID := make(map[string]*EntrypointView, len(views))
|
||||
|
||||
for i := range views {
|
||||
ids[i] = views[i].ID
|
||||
byID[views[i].ID] = &views[i]
|
||||
}
|
||||
|
||||
var totals []database.EntrypointTotals
|
||||
|
||||
err := webhookDB.Where("entrypoint_id IN ?", ids).Find(&totals).Error
|
||||
if err != nil {
|
||||
return fmt.Errorf("reading entrypoint totals: %w", err)
|
||||
}
|
||||
|
||||
query := webhookDB.Model(&database.Event{}).
|
||||
Select("entrypoint_id, count(*) AS events").
|
||||
Where("entrypoint_id IN ? AND resubmitted_from_id IS NULL", ids)
|
||||
|
||||
cutoff, finite := webhook.RetentionCutoff(now)
|
||||
if finite {
|
||||
query = query.Where("created_at >= ?", cutoff)
|
||||
}
|
||||
|
||||
var counts []entrypointEvents
|
||||
|
||||
err = query.Group("entrypoint_id").Find(&counts).Error
|
||||
if err != nil {
|
||||
return fmt.Errorf("counting events by entrypoint: %w", err)
|
||||
}
|
||||
|
||||
for _, row := range totals {
|
||||
view := byID[row.EntrypointID]
|
||||
view.LastEvent = humanize.Time(row.LastEventAt)
|
||||
view.LastEventUTC =
|
||||
row.LastEventAt.UTC().Format(time.DateTime) + " UTC"
|
||||
}
|
||||
|
||||
for _, row := range counts {
|
||||
byID[row.EntrypointID].Events = row.Events
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -1,197 +0,0 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
"strconv"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/google/uuid"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"gorm.io/gorm/clause"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/handlers"
|
||||
"sneak.berlin/go/webhooker/internal/logger"
|
||||
"sneak.berlin/go/webhooker/internal/session"
|
||||
)
|
||||
|
||||
// entrypointRow returns the part of a rendered webhook page from an
|
||||
// entrypoint's URL to the next entrypoint's, which holds its figures.
|
||||
func entrypointRow(t *testing.T, page, entrypointID string) string {
|
||||
t.Helper()
|
||||
|
||||
_, row, found := strings.Cut(page, `id="entrypoint-url-`+entrypointID+`"`)
|
||||
require.True(t, found)
|
||||
|
||||
row, _, _ = strings.Cut(row, `id="entrypoint-url-`)
|
||||
|
||||
return row
|
||||
}
|
||||
|
||||
// lastEventShown matches an entrypoint row's last event arriving at at.
|
||||
func lastEventShown(at time.Time) string {
|
||||
return `Last Event:</span>\s*<span title="` +
|
||||
at.UTC().Format(time.DateTime) + ` UTC">[^<]+</span>`
|
||||
}
|
||||
|
||||
// eventsShown matches an entrypoint row's count of n events.
|
||||
func eventsShown(n int) string {
|
||||
return `Events Within Retention:</span>\s*<span>` +
|
||||
strconv.Itoa(n) + `</span>`
|
||||
}
|
||||
|
||||
// TestHandleSourceDetail_ShowsEntrypointEvents proves each entrypoint
|
||||
// on the webhook page shows its own figures: how many events arrived
|
||||
// through it within the webhook's retention period, leaving out one
|
||||
// older than that, and when the newest arrived, or "never" for an
|
||||
// entrypoint with none.
|
||||
func TestHandleSourceDetail_ShowsEntrypointEvents(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
sess *session.Session
|
||||
db *database.Database
|
||||
dbMgr *database.WebhookDBManager
|
||||
)
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &dbMgr)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
wh := &database.Webhook{
|
||||
UserID: deleteTestUserID, Name: "figures", RetentionDays: 7,
|
||||
}
|
||||
require.NoError(t, db.DB().Omit(clause.Associations).Create(wh).Error)
|
||||
|
||||
webhookDB, err := dbMgr.GetDB(wh.ID)
|
||||
require.NoError(t, err)
|
||||
|
||||
entrypoint := func() *database.Entrypoint {
|
||||
ep := &database.Entrypoint{
|
||||
WebhookID: wh.ID, Path: uuid.New().String(), Active: true,
|
||||
}
|
||||
require.NoError(t,
|
||||
db.DB().Omit(clause.Associations).Create(ep).Error)
|
||||
|
||||
return ep
|
||||
}
|
||||
|
||||
// event stores an event that arrived on ep's URL age ago and
|
||||
// records it as ep's last event, as the receiver does.
|
||||
event := func(ep *database.Entrypoint, age time.Duration) time.Time {
|
||||
e := &database.Event{
|
||||
WebhookID: wh.ID,
|
||||
EntrypointID: ep.ID,
|
||||
Method: http.MethodPost,
|
||||
}
|
||||
e.CreatedAt = time.Now().Add(-age)
|
||||
require.NoError(t,
|
||||
webhookDB.Omit(clause.Associations).Create(e).Error)
|
||||
require.NoError(t, database.AddEntrypointTotals(webhookDB,
|
||||
database.EntrypointTotals{
|
||||
EntrypointID: ep.ID, LastEventAt: e.CreatedAt,
|
||||
}))
|
||||
|
||||
return e.CreatedAt
|
||||
}
|
||||
|
||||
busy, quiet, unused := entrypoint(), entrypoint(), entrypoint()
|
||||
|
||||
event(busy, 8*24*time.Hour) // older than the 7 days kept
|
||||
event(busy, 3*time.Hour)
|
||||
busyLast := event(busy, time.Hour)
|
||||
quietLast := event(quiet, 2*24*time.Hour)
|
||||
|
||||
body := renderSourceDetailPage(t, h, sess, wh.ID)
|
||||
|
||||
assert.Regexp(t, lastEventShown(busyLast), entrypointRow(t, body, busy.ID))
|
||||
assert.Regexp(t, eventsShown(2), entrypointRow(t, body, busy.ID))
|
||||
assert.Regexp(t, lastEventShown(quietLast), entrypointRow(t, body, quiet.ID))
|
||||
assert.Regexp(t, eventsShown(1), entrypointRow(t, body, quiet.ID))
|
||||
assert.Regexp(t, `Last Event:</span>\s*<span>never</span>`,
|
||||
entrypointRow(t, body, unused.ID))
|
||||
assert.Regexp(t, eventsShown(0), entrypointRow(t, body, unused.ID))
|
||||
}
|
||||
|
||||
// TestHandleSourceDetail_EntrypointLastEventSurvivesRetention checks
|
||||
// that once retention has removed every event that arrived on an
|
||||
// entrypoint's URL, the entrypoint still shows when the last one
|
||||
// arrived rather than "never".
|
||||
func TestHandleSourceDetail_EntrypointLastEventSurvivesRetention(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
sess *session.Session
|
||||
db *database.Database
|
||||
dbMgr *database.WebhookDBManager
|
||||
log *logger.Logger
|
||||
)
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &dbMgr, &log)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
wh := &database.Webhook{
|
||||
UserID: deleteTestUserID, Name: "swept", RetentionDays: 1,
|
||||
}
|
||||
require.NoError(t, db.DB().Omit(clause.Associations).Create(wh).Error)
|
||||
|
||||
ep := seedEntrypoint(t, db, wh.ID)
|
||||
webhookDB, events := receiveEvents(t, h, dbMgr, wh.ID, ep.Path, 1)
|
||||
arrived := events[0].CreatedAt
|
||||
|
||||
statsAge(t, webhookDB, events[0].ID, time.Now().Add(-50*time.Hour))
|
||||
statsPrune(t, db, dbMgr, log, webhookDB)
|
||||
require.Empty(t, listEvents(t, webhookDB))
|
||||
|
||||
row := entrypointRow(t, renderSourceDetailPage(t, h, sess, wh.ID), ep.ID)
|
||||
assert.Regexp(t, lastEventShown(arrived), row)
|
||||
assert.Regexp(t, eventsShown(0), row)
|
||||
}
|
||||
|
||||
// TestHandleSourceDetail_ResubmitLeavesEntrypointFigures checks that a
|
||||
// resubmitted copy, which did not arrive on the entrypoint's URL,
|
||||
// changes neither the entrypoint's last event nor its count.
|
||||
func TestHandleSourceDetail_ResubmitLeavesEntrypointFigures(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
sess *session.Session
|
||||
db *database.Database
|
||||
dbMgr *database.WebhookDBManager
|
||||
)
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &dbMgr)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
wh := seedWebhook(t, db)
|
||||
ep := seedEntrypoint(t, db, wh.ID)
|
||||
webhookDB, events := receiveEvents(t, h, dbMgr, wh.ID, ep.Path, 1)
|
||||
arrived := events[0].CreatedAt
|
||||
|
||||
require.Equal(t, http.StatusSeeOther,
|
||||
postResubmit(t, h, sess, wh.ID, events[0].ID).Code)
|
||||
require.Len(t, listEvents(t, webhookDB), 2)
|
||||
|
||||
var totals database.EntrypointTotals
|
||||
|
||||
require.NoError(t, webhookDB.Take(&totals).Error)
|
||||
assert.True(t, arrived.Equal(totals.LastEventAt))
|
||||
|
||||
row := entrypointRow(t, renderSourceDetailPage(t, h, sess, wh.ID), ep.ID)
|
||||
assert.Regexp(t, lastEventShown(arrived), row)
|
||||
assert.Regexp(t, eventsShown(1), row)
|
||||
}
|
||||
@@ -15,19 +15,16 @@ import (
|
||||
// eventBodyQuery reads one event's stored body as bytes. The cast
|
||||
// to blob is what makes the driver hand back the stored bytes
|
||||
// rather than a string conversion, so Content-Length taken from
|
||||
// the result matches what goes on the wire. The retention reaper
|
||||
// deletes event rows outright, so a reaped event is simply gone
|
||||
// and the query finds no row. The deleted_at predicate repeats
|
||||
// the soft-delete scope GORM adds to its own queries, which Raw
|
||||
// bypasses; nothing soft-deletes an event, so today it excludes
|
||||
// nothing.
|
||||
// the result matches what goes on the wire. The soft-delete
|
||||
// predicate is spelled out because Raw bypasses GORM's default
|
||||
// scope, and it is what stops a reaped event still being
|
||||
// downloadable.
|
||||
const eventBodyQuery = "SELECT cast(body as blob) " +
|
||||
"FROM events WHERE id = ? AND webhook_id = ? AND deleted_at IS NULL"
|
||||
|
||||
// HandleEventBodyDownload serves one event's stored body byte
|
||||
// for byte, which the pages do not: they show it as escaped
|
||||
// text, cut at maxRenderedBodyBytes in the lists of events, and
|
||||
// leave a binary one out.
|
||||
// HandleEventBodyDownload serves one event's stored body in
|
||||
// full, which the event log page cannot: it caps each rendered
|
||||
// body at maxRenderedBodyBytes.
|
||||
//
|
||||
// The bytes are attacker-supplied — anyone who can reach the
|
||||
// public receiver chooses them — and this route hands them back
|
||||
|
||||
@@ -405,11 +405,10 @@ func TestHandleEventBodyDownload_UnknownEvent404s(t *testing.T) {
|
||||
// route. The body is read in one query before any header is
|
||||
// written, so a reaped event cannot produce a partial download:
|
||||
// it is a clean 404 with no Content-Length and no
|
||||
// Content-Disposition. The reaper deletes event rows outright,
|
||||
// which is the "hard deleted" case. The "soft deleted" case
|
||||
// covers a row no code produces today: it only pins the query's
|
||||
// own deleted_at predicate, the soft-delete condition Raw would
|
||||
// otherwise skip.
|
||||
// Content-Disposition. Both removals the codebase performs are
|
||||
// covered — the reaper hard-deletes, and a soft-deleted row is
|
||||
// excluded by the query's own deleted_at predicate rather than
|
||||
// by GORM's default scope, which Raw bypasses.
|
||||
func TestHandleEventBodyDownload_ReapedEvent404s(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
@@ -1,168 +0,0 @@
|
||||
package handlers
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"io"
|
||||
"unicode"
|
||||
"unicode/utf8"
|
||||
)
|
||||
|
||||
// maxRenderedBodyBytes is the most of one event's body that the
|
||||
// recent events on a webhook's page and the event log show; a larger
|
||||
// body is cut there and shown whole only on the event's own page.
|
||||
// Bodies come from the unauthenticated receiver under its 1 MB cap,
|
||||
// and renderTemplate buffers a whole page before writing it, so a list
|
||||
// of events cannot show every body whole.
|
||||
const maxRenderedBodyBytes = 32 << 10
|
||||
|
||||
// maxInlineBodyLines is the most lines a body is shown at its full
|
||||
// height with. A body with more lines, or larger than
|
||||
// maxRenderedBodyBytes, is shown in a box of fixed height that
|
||||
// scrolls, so that it does not make the page huge.
|
||||
const maxInlineBodyLines = 200
|
||||
|
||||
// maxIndentDepth is how deeply a JSON body's objects and arrays may
|
||||
// nest for it to be indented at all; a deeper one is shown as received.
|
||||
// Each level indents every line inside it two more spaces, so 10 KB of
|
||||
// nested brackets would indent to some 50 MB; within this depth a body
|
||||
// grows at most 35 times.
|
||||
const maxIndentDepth = 16
|
||||
|
||||
// A JSON body is shown pretty-printed only when that makes it at most
|
||||
// maxIndentGrowth times its size plus indentAllowance bytes, and
|
||||
// otherwise as received, so that indenting does not undo
|
||||
// maxRenderedBodyBytes. The allowance keeps a small nested body
|
||||
// pretty-printed.
|
||||
const (
|
||||
maxIndentGrowth = 4
|
||||
indentAllowance = 1 << 10
|
||||
)
|
||||
|
||||
// jsonIndent is the indent of a pretty-printed JSON body.
|
||||
const jsonIndent = " "
|
||||
|
||||
// BodyView is an event's body as the pages show it. newBodyView
|
||||
// decides it and templates/event_body.html shows it, the same way in
|
||||
// the recent events on a webhook's page, in the event log and on the
|
||||
// event's own page.
|
||||
type BodyView struct {
|
||||
// EventURL is the event's own page. The stored body downloads
|
||||
// from EventURL/body.
|
||||
EventURL string
|
||||
|
||||
// Text is the body as shown, pretty-printed when it is JSON.
|
||||
Text string
|
||||
|
||||
// Size is the stored body's size in bytes, and ShownBytes how
|
||||
// many of them Text holds when Cut.
|
||||
Size int64
|
||||
ShownBytes int
|
||||
|
||||
// Cut reports that Text is only the start of the body.
|
||||
Cut bool
|
||||
|
||||
// Binary reports a body that is not text. It is not shown.
|
||||
Binary bool
|
||||
|
||||
// Scroll reports a body to show in a box that scrolls.
|
||||
Scroll bool
|
||||
}
|
||||
|
||||
// newBodyView decides how to show an event's body. body is the
|
||||
// stored body, or its first maxRenderedBodyBytes when only those were
|
||||
// read, and size is the stored body's size.
|
||||
func newBodyView(eventURL string, body []byte, size int64) BodyView {
|
||||
v := BodyView{EventURL: eventURL, Size: size}
|
||||
|
||||
if size > int64(len(body)) {
|
||||
v.Cut = true
|
||||
body = trimPartialRune(body)
|
||||
v.ShownBytes = len(body)
|
||||
}
|
||||
|
||||
// html/template shows invalid UTF-8 as replacement characters,
|
||||
// and a browser shows a control character other than tab, line
|
||||
// feed and carriage return as a box or not at all, so a body
|
||||
// holding either is not text.
|
||||
isControl := func(r rune) bool {
|
||||
return unicode.IsControl(r) && r != '\t' && r != '\n' && r != '\r'
|
||||
}
|
||||
|
||||
if !utf8.Valid(body) || bytes.IndexFunc(body, isControl) >= 0 {
|
||||
v.Binary = true
|
||||
|
||||
return v
|
||||
}
|
||||
|
||||
// A cut JSON document is no longer valid JSON.
|
||||
if !v.Cut {
|
||||
body = indentJSON(body)
|
||||
}
|
||||
|
||||
// The page shows a carriage return, a line feed, or the two
|
||||
// together as one line break. A final one ends the last line
|
||||
// rather than starting another.
|
||||
text := bytes.TrimSuffix(body, []byte("\n"))
|
||||
text = bytes.TrimSuffix(text, []byte("\r"))
|
||||
breaks := bytes.Count(text, []byte("\n")) + bytes.Count(text, []byte("\r")) -
|
||||
bytes.Count(text, []byte("\r\n"))
|
||||
lines := breaks + 1
|
||||
|
||||
v.Text = string(body)
|
||||
v.Scroll = lines > maxInlineBodyLines || size > maxRenderedBodyBytes
|
||||
|
||||
return v
|
||||
}
|
||||
|
||||
// indentJSON returns body pretty-printed when it is a JSON document,
|
||||
// and unchanged when it is not, nests deeper than maxIndentDepth, or
|
||||
// would grow past maxIndentGrowth times its size plus indentAllowance
|
||||
// bytes.
|
||||
func indentJSON(body []byte) []byte {
|
||||
if !json.Valid(body) || !indentFits(body) {
|
||||
return body
|
||||
}
|
||||
|
||||
var out bytes.Buffer
|
||||
|
||||
err := json.Indent(&out, body, "", jsonIndent)
|
||||
if err != nil || out.Len() > maxIndentGrowth*len(body)+indentAllowance {
|
||||
return body
|
||||
}
|
||||
|
||||
return out.Bytes()
|
||||
}
|
||||
|
||||
// indentFits reports whether the objects and arrays of the JSON
|
||||
// document body nest at most maxIndentDepth deep.
|
||||
func indentFits(body []byte) bool {
|
||||
depth := 0
|
||||
|
||||
dec := json.NewDecoder(bytes.NewReader(body))
|
||||
|
||||
// A number too large for a float64 is still valid JSON.
|
||||
dec.UseNumber()
|
||||
|
||||
for {
|
||||
tok, err := dec.Token()
|
||||
if errors.Is(err, io.EOF) {
|
||||
return true
|
||||
}
|
||||
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
|
||||
switch tok {
|
||||
case json.Delim('{'), json.Delim('['):
|
||||
depth++
|
||||
if depth > maxIndentDepth {
|
||||
return false
|
||||
}
|
||||
case json.Delim('}'), json.Delim(']'):
|
||||
depth--
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,176 +0,0 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"sneak.berlin/go/webhooker/internal/handlers"
|
||||
)
|
||||
|
||||
// bodyView is how the pages would show body, stored whole.
|
||||
func bodyView(body string) handlers.BodyView {
|
||||
return handlers.NewBodyViewForTest([]byte(body), int64(len(body)))
|
||||
}
|
||||
|
||||
// lines is n lines of text, without a newline after the last.
|
||||
func lines(n int) string {
|
||||
return strings.TrimSuffix(strings.Repeat("line\n", n), "\n")
|
||||
}
|
||||
|
||||
// TestNewBodyView_FormatsValidJSON proves a JSON body is shown
|
||||
// pretty-printed, whatever its content type, with its keys in
|
||||
// the order they arrived.
|
||||
func TestNewBodyView_FormatsValidJSON(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
v := bodyView(`{"b":1,"a":[true,null,"x"],"c":{}}`)
|
||||
|
||||
assert.Equal(t, []string{
|
||||
`{`,
|
||||
` "b": 1,`,
|
||||
` "a": [`,
|
||||
` true,`,
|
||||
` null,`,
|
||||
` "x"`,
|
||||
` ],`,
|
||||
` "c": {}`,
|
||||
`}`,
|
||||
}, strings.Split(v.Text, "\n"))
|
||||
assert.False(t, v.Scroll)
|
||||
}
|
||||
|
||||
// TestNewBodyView_FormatsNestedJSON proves a small document with a
|
||||
// few levels of nesting is pretty-printed.
|
||||
func TestNewBodyView_FormatsNestedJSON(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
v := bodyView(`{"data":[[1,2,3],[4,5,6]]}`)
|
||||
|
||||
assert.Equal(t, []string{
|
||||
`{`,
|
||||
` "data": [`,
|
||||
` [`,
|
||||
` 1,`,
|
||||
` 2,`,
|
||||
` 3`,
|
||||
` ],`,
|
||||
` [`,
|
||||
` 4,`,
|
||||
` 5,`,
|
||||
` 6`,
|
||||
` ]`,
|
||||
` ]`,
|
||||
`}`,
|
||||
}, strings.Split(v.Text, "\n"))
|
||||
}
|
||||
|
||||
// TestNewBodyView_InvalidJSONAsReceived proves a body that is not
|
||||
// a JSON document is shown exactly as it arrived.
|
||||
func TestNewBodyView_InvalidJSONAsReceived(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
for _, body := range []string{
|
||||
`{"a":1,`,
|
||||
`{"a":1} {"b":2}`,
|
||||
"plain text\n indented",
|
||||
} {
|
||||
assert.Equal(t, body, bodyView(body).Text)
|
||||
}
|
||||
}
|
||||
|
||||
// TestNewBodyView_DeepJSONAsReceived proves a JSON body nested
|
||||
// more than 16 levels deep is shown as it arrived. 10 KB of nested
|
||||
// arrays would indent to some 50 MB.
|
||||
func TestNewBodyView_DeepJSONAsReceived(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
nested := func(depth int) string {
|
||||
return strings.Repeat("[", depth) + "1" + strings.Repeat("]", depth)
|
||||
}
|
||||
|
||||
assert.NotEqual(t, nested(16), bodyView(nested(16)).Text)
|
||||
assert.Equal(t, nested(17), bodyView(nested(17)).Text)
|
||||
|
||||
body := strings.Repeat("[", 5000) + strings.Repeat("]", 5000)
|
||||
|
||||
assert.Equal(t, body, bodyView(body).Text)
|
||||
}
|
||||
|
||||
// TestNewBodyView_GrowingJSONAsReceived proves a JSON body that
|
||||
// pretty-printing would make more than four times its size plus 1 KiB
|
||||
// is shown as it arrived, however shallow: each short element eight
|
||||
// levels deep gets a line indented sixteen spaces.
|
||||
func TestNewBodyView_GrowingJSONAsReceived(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
numbers := func(n int) string {
|
||||
return strings.Repeat("[", 8) +
|
||||
strings.TrimSuffix(strings.Repeat("1,", n), ",") +
|
||||
strings.Repeat("]", 8)
|
||||
}
|
||||
|
||||
assert.NotEqual(t, numbers(10), bodyView(numbers(10)).Text)
|
||||
assert.Equal(t, numbers(1000), bodyView(numbers(1000)).Text)
|
||||
}
|
||||
|
||||
// TestNewBodyView_ScrollsPast200Lines proves a body is shown at
|
||||
// its full height up to 200 lines and in the scrolling box past
|
||||
// them, counting the lines after formatting.
|
||||
func TestNewBodyView_ScrollsPast200Lines(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
assert.False(t, bodyView(lines(200)).Scroll)
|
||||
assert.True(t, bodyView(lines(201)).Scroll)
|
||||
|
||||
// A final newline ends the last line rather than starting another.
|
||||
assert.False(t, bodyView(lines(200)+"\n").Scroll)
|
||||
assert.True(t, bodyView(lines(201)+"\n").Scroll)
|
||||
|
||||
// The page shows a carriage return, a line feed, or the two
|
||||
// together as one line break.
|
||||
assert.True(t, bodyView(strings.Repeat("line\r", 400)).Scroll)
|
||||
assert.False(t, bodyView(strings.Repeat("line\r\n", 200)).Scroll)
|
||||
|
||||
// One line as received, 201 once formatted: the brackets and
|
||||
// 199 elements.
|
||||
numbers := "[" + strings.TrimSuffix(strings.Repeat("1,", 199), ",") + "]"
|
||||
|
||||
assert.NotContains(t, numbers, "\n")
|
||||
assert.True(t, bodyView(numbers).Scroll)
|
||||
}
|
||||
|
||||
// TestNewBodyView_LargeBodyScrolls proves a body larger than the
|
||||
// cap of the lists of events is shown in the scrolling box
|
||||
// however few lines it has, on the event's own page as in the
|
||||
// lists.
|
||||
func TestNewBodyView_LargeBodyScrolls(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
assert.False(t, bodyView(strings.Repeat("x", bodyCap)).Scroll)
|
||||
assert.True(t, bodyView(strings.Repeat("x", bodyCap+1)).Scroll)
|
||||
}
|
||||
|
||||
// TestNewBodyView_BinaryNotShown proves a body that is not text
|
||||
// is never shown: one that is not valid UTF-8, or that holds a
|
||||
// control character other than tab, line feed and carriage return.
|
||||
func TestNewBodyView_BinaryNotShown(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
for _, body := range []string{
|
||||
"\xff\xfe\xfd",
|
||||
"a\x00b",
|
||||
// A small protobuf message: valid UTF-8, but control bytes.
|
||||
"\x08\x01\x12\x03abc",
|
||||
"\x1b[31mred\x1b[0m",
|
||||
"a\x7fb",
|
||||
} {
|
||||
v := bodyView(body)
|
||||
|
||||
assert.True(t, v.Binary, "%q", body)
|
||||
assert.Empty(t, v.Text)
|
||||
}
|
||||
|
||||
assert.False(t, bodyView("snow "+snowman).Binary)
|
||||
assert.False(t, bodyView("a\tb\r\nc\n").Binary)
|
||||
}
|
||||
@@ -1,74 +0,0 @@
|
||||
package handlers
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
|
||||
"github.com/go-chi/chi"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
)
|
||||
|
||||
// HandleEventDetail shows one event on its own page: its details,
|
||||
// its whole body and every delivery of it. The page reads the
|
||||
// event's body whole, which the receiver caps at 1 MB.
|
||||
func (h *Handlers) HandleEventDetail() http.HandlerFunc {
|
||||
return func(w http.ResponseWriter, r *http.Request) {
|
||||
webhook, ok := h.ownedWebhook(w, r)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
|
||||
if !h.dbMgr.DBExists(webhook.ID) {
|
||||
h.renderError(w, r, http.StatusNotFound)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
webhookDB, err := h.dbMgr.GetDB(webhook.ID)
|
||||
if err != nil {
|
||||
h.serverError(w, r, "failed to get webhook database", err)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
var rows []eventLogRow
|
||||
|
||||
err = webhookDB.Model(&database.Event{}).
|
||||
Select(eventColumns).
|
||||
Where(
|
||||
"id = ? AND webhook_id = ?",
|
||||
chi.URLParam(r, "eventID"), webhook.ID,
|
||||
).
|
||||
Limit(1).
|
||||
Find(&rows).Error
|
||||
if err != nil {
|
||||
h.serverError(w, r, "failed to load event", err)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
if len(rows) == 0 {
|
||||
h.renderError(w, r, http.StatusNotFound)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
targets, err := h.loadTargetMap(webhook.ID)
|
||||
if err != nil {
|
||||
h.serverError(w, r, "failed to load targets", err)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
views, ok := h.eventLogViews(
|
||||
w, r, webhookDB, webhook.ID, rows, targets,
|
||||
)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
|
||||
h.renderTemplate(w, r, "event_detail.html", map[string]any{
|
||||
tmplKeyWebhook: &webhook,
|
||||
"Event": views[0],
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -1,152 +0,0 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strconv"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/go-chi/chi"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"gorm.io/gorm/clause"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/handlers"
|
||||
"sneak.berlin/go/webhooker/internal/session"
|
||||
)
|
||||
|
||||
// serveEventPage runs the real event page handler as the test user
|
||||
// for the given webhook and event ids.
|
||||
func serveEventPage(
|
||||
t *testing.T,
|
||||
h *handlers.Handlers,
|
||||
sess *session.Session,
|
||||
webhookID, eventID string,
|
||||
) *httptest.ResponseRecorder {
|
||||
t.Helper()
|
||||
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(),
|
||||
http.MethodGet,
|
||||
"/hook/"+webhookID+"/events/"+eventID,
|
||||
nil,
|
||||
)
|
||||
|
||||
for _, c := range authenticatedCookies(
|
||||
t, sess, deleteTestUserID, deleteTestUsername,
|
||||
) {
|
||||
req.AddCookie(c)
|
||||
}
|
||||
|
||||
rctx := chi.NewRouteContext()
|
||||
rctx.URLParams.Add(paramSourceID, webhookID)
|
||||
rctx.URLParams.Add(paramEventID, eventID)
|
||||
|
||||
req = req.WithContext(
|
||||
context.WithValue(req.Context(), chi.RouteCtxKey, rctx),
|
||||
)
|
||||
|
||||
w := httptest.NewRecorder()
|
||||
h.HandleEventDetail().ServeHTTP(w, req)
|
||||
|
||||
return w
|
||||
}
|
||||
|
||||
// TestHandleEventDetail_ShowsEventWholeWithDeliveries proves the
|
||||
// event's page shows its details, its whole body even past the cap
|
||||
// of the lists of events, pretty-printed and in the scrolling box,
|
||||
// and each delivery with its status and attempts.
|
||||
func TestHandleEventDetail_ShowsEventWholeWithDeliveries(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
f := newRecentEventsFixture(t)
|
||||
target := seedTarget(t, f.db, f.webhook.ID, database.TargetTypeHTTP)
|
||||
|
||||
const sentinel = "TAIL-SENTINEL-5b2e"
|
||||
|
||||
body := `{"pad":"` + strings.Repeat("x", 2*bodyCap) +
|
||||
`","tail":"` + sentinel + `"}`
|
||||
event := f.event(t, contentTypeJSON, body, time.Now())
|
||||
f.attempt(t, f.delivery(
|
||||
t, event, target.ID, database.DeliveryStatusFailed,
|
||||
), http.StatusBadGateway, time.Second)
|
||||
|
||||
w := serveEventPage(t, f.h, f.sess, f.webhook.ID, event.ID)
|
||||
require.Equal(t, http.StatusOK, w.Code)
|
||||
|
||||
page := w.Body.String()
|
||||
|
||||
assert.Contains(t, page, event.ID)
|
||||
assert.Contains(t, page, contentTypeJSON)
|
||||
assert.Contains(t, page, strconv.Itoa(len(body))+" bytes")
|
||||
assert.Contains(t, page, "{\n "pad": "xxx")
|
||||
assert.Contains(t, page, ""tail": ""+sentinel+""\n}")
|
||||
assert.Contains(t, page, `style="max-height: 32rem; overflow-y: auto"`)
|
||||
assert.NotContains(t, page, "Showing the first")
|
||||
assert.Contains(t, page, target.Name)
|
||||
assert.Contains(t, page, ">failed</span>")
|
||||
assert.Contains(t, page, "Status: 502")
|
||||
}
|
||||
|
||||
// TestHandleEventDetail_ResubmitLinks proves a resubmitted copy's
|
||||
// page links to its original's page, and the original's page says
|
||||
// it was resubmitted.
|
||||
func TestHandleEventDetail_ResubmitLinks(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
f := newRecentEventsFixture(t)
|
||||
original := f.event(t, contentTypeJSON, "{}", time.Now())
|
||||
|
||||
cp := &database.Event{
|
||||
WebhookID: f.webhook.ID,
|
||||
Method: http.MethodPost,
|
||||
Body: "{}",
|
||||
ContentType: contentTypeJSON,
|
||||
ResubmittedFromID: &original.ID,
|
||||
}
|
||||
require.NoError(t, f.webhookDB.Omit(clause.Associations).Create(cp).Error)
|
||||
|
||||
w := serveEventPage(t, f.h, f.sess, f.webhook.ID, cp.ID)
|
||||
require.Equal(t, http.StatusOK, w.Code)
|
||||
assert.Contains(
|
||||
t, w.Body.String(),
|
||||
`href="/hook/`+f.webhook.ID+`/events/`+original.ID+`"`,
|
||||
)
|
||||
|
||||
w = serveEventPage(t, f.h, f.sess, f.webhook.ID, original.ID)
|
||||
require.Equal(t, http.StatusOK, w.Code)
|
||||
assert.Contains(t, w.Body.String(), "as 1 new event<")
|
||||
}
|
||||
|
||||
// TestHandleEventDetail_UnknownEventNotFound proves the page is a
|
||||
// 404 for an event that does not exist and for one that belongs to
|
||||
// another webhook.
|
||||
func TestHandleEventDetail_UnknownEventNotFound(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
sess *session.Session
|
||||
db *database.Database
|
||||
dbMgr *database.WebhookDBManager
|
||||
)
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &dbMgr)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
mine := seedWebhook(t, db)
|
||||
theirs := seedWebhook(t, db)
|
||||
|
||||
seedEventWithBody(t, dbMgr, mine.ID, "{}")
|
||||
elsewhere := seedEventWithBody(t, dbMgr, theirs.ID, "{}")
|
||||
|
||||
for _, id := range []string{"no-such-event", elsewhere.ID} {
|
||||
w := serveEventPage(t, h, sess, mine.ID, id)
|
||||
assert.Equal(t, http.StatusNotFound, w.Code, id)
|
||||
}
|
||||
}
|
||||
@@ -5,6 +5,14 @@ import (
|
||||
"unicode/utf8"
|
||||
)
|
||||
|
||||
// maxRenderedBodyBytes caps how many bytes of a stored event
|
||||
// body reach the event log page. Bodies come from the
|
||||
// unauthenticated receiver under the 1 MB ingest cap and
|
||||
// renderTemplate buffers a whole page before writing it, so
|
||||
// an uncapped page of paginationPerPage events is tens of
|
||||
// megabytes of resident memory per concurrent viewer.
|
||||
const maxRenderedBodyBytes = 8192
|
||||
|
||||
// eventLogColumns is the event log's projection. The casts to
|
||||
// blob are load-bearing: they make substr and length count
|
||||
// bytes rather than characters, so the cap bounds the page in
|
||||
@@ -16,23 +24,27 @@ const eventLogColumns = "id, created_at, method, content_type, " +
|
||||
"substr(cast(body as blob), 1, ?) AS body, " +
|
||||
"length(cast(body as blob)) AS body_bytes"
|
||||
|
||||
// eventColumns is eventLogColumns for the event's own page, which
|
||||
// shows the whole body.
|
||||
const eventColumns = "id, created_at, method, content_type, " +
|
||||
"resubmitted_from_id, " +
|
||||
"cast(body as blob) AS body, " +
|
||||
"length(cast(body as blob)) AS body_bytes"
|
||||
|
||||
// EventLogView is the display-safe projection of an event for
|
||||
// the event log page and the event's own page, alongside
|
||||
// DeliveryView and TargetView.
|
||||
// the event log page, alongside DeliveryView and TargetView.
|
||||
// It carries a capped body plus the true stored size, so the
|
||||
// page can mark a body as truncated without ever holding the
|
||||
// whole thing.
|
||||
type EventLogView struct {
|
||||
ID string
|
||||
CreatedAt time.Time
|
||||
Method string
|
||||
ContentType string
|
||||
|
||||
Body BodyView
|
||||
// Body holds at most maxRenderedBodyBytes bytes of the
|
||||
// stored body.
|
||||
Body string
|
||||
|
||||
// BodyBytes is the true size of the stored body.
|
||||
BodyBytes int64
|
||||
|
||||
// BodyTruncated reports that the stored body was larger
|
||||
// than the cap, so the page owes the reader a marker.
|
||||
BodyTruncated bool
|
||||
|
||||
// ResubmittedFromID names the event this one was copied
|
||||
// from, empty for an event that arrived on the receiver.
|
||||
@@ -53,10 +65,16 @@ func (v EventLogView) ResubmittedFrom() bool {
|
||||
return v.ResubmittedFromID != ""
|
||||
}
|
||||
|
||||
// eventLogRow is one row of the event log projection, or of
|
||||
// eventColumns. In the event log its body column arrives
|
||||
// already cut to the cap by SQLite, with the true size beside
|
||||
// it.
|
||||
// BodyShownBytes is how many body bytes the page is actually
|
||||
// rendering, which the truncation marker reports beside the
|
||||
// true size.
|
||||
func (v EventLogView) BodyShownBytes() int {
|
||||
return len(v.Body)
|
||||
}
|
||||
|
||||
// eventLogRow is one row of the event log projection. Its
|
||||
// body column arrives already cut to the cap by SQLite, with
|
||||
// the true size beside it.
|
||||
type eventLogRow struct {
|
||||
ID string
|
||||
CreatedAt time.Time
|
||||
@@ -67,22 +85,31 @@ type eventLogRow struct {
|
||||
BodyBytes int64
|
||||
}
|
||||
|
||||
// view projects a loaded row of the webhook's events for
|
||||
// rendering.
|
||||
func (r *eventLogRow) view(webhookID string) EventLogView {
|
||||
// view projects a loaded row for rendering.
|
||||
func (r *eventLogRow) view() EventLogView {
|
||||
body := r.Body
|
||||
truncated := r.BodyBytes > int64(len(body))
|
||||
|
||||
// Only a cut body can have been left mid-sequence by
|
||||
// this query. A whole body is passed through exactly as
|
||||
// stored, however malformed.
|
||||
if truncated {
|
||||
body = trimPartialRune(body)
|
||||
}
|
||||
|
||||
var from string
|
||||
if r.ResubmittedFromID != nil {
|
||||
from = *r.ResubmittedFromID
|
||||
}
|
||||
|
||||
return EventLogView{
|
||||
ID: r.ID,
|
||||
CreatedAt: r.CreatedAt,
|
||||
Method: r.Method,
|
||||
ContentType: r.ContentType,
|
||||
Body: newBodyView(
|
||||
"/hook/"+webhookID+"/events/"+r.ID, r.Body, r.BodyBytes,
|
||||
),
|
||||
ID: r.ID,
|
||||
CreatedAt: r.CreatedAt,
|
||||
Method: r.Method,
|
||||
ContentType: r.ContentType,
|
||||
Body: string(body),
|
||||
BodyBytes: r.BodyBytes,
|
||||
BodyTruncated: truncated,
|
||||
ResubmittedFromID: from,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -16,7 +16,7 @@ import (
|
||||
"sneak.berlin/go/webhooker/internal/session"
|
||||
)
|
||||
|
||||
// bodyCap is the number of body bytes the lists of events are
|
||||
// bodyCap is the number of body bytes the event log page is
|
||||
// allowed to render for one event.
|
||||
const bodyCap = handlers.MaxRenderedBodyBytesForTest
|
||||
|
||||
@@ -85,7 +85,7 @@ func seedAndProject(
|
||||
|
||||
// TestHandleSourceLogs_BoundsOversizeBody proves the rendered
|
||||
// page is bounded by the cap rather than by the stored payload:
|
||||
// the body here is 16 times the cap, and the ingest path would
|
||||
// the body here is 64 times the cap, and the ingest path would
|
||||
// accept twice as much again.
|
||||
func TestHandleSourceLogs_BoundsOversizeBody(t *testing.T) {
|
||||
t.Parallel()
|
||||
@@ -123,7 +123,7 @@ func TestHandleSourceLogs_BoundsOversizeBody(t *testing.T) {
|
||||
// The marker states the true stored size, not the cut one.
|
||||
assert.Contains(
|
||||
t, page,
|
||||
"Showing the first "+strconv.Itoa(bodyCap)+
|
||||
"showing "+strconv.Itoa(bodyCap)+
|
||||
" of "+strconv.Itoa(storedBytes)+" bytes",
|
||||
)
|
||||
}
|
||||
@@ -152,35 +152,34 @@ func TestHandleSourceLogs_SmallBodyRendersWhole(t *testing.T) {
|
||||
page := renderSourceLogsPage(t, h, sess, wh.ID)
|
||||
|
||||
assert.Contains(t, page, ""kept"")
|
||||
assert.NotContains(t, page, "Showing the first")
|
||||
assert.NotContains(t, page, "Body truncated for display")
|
||||
}
|
||||
|
||||
// TestEventLogView_CutMidRune proves a multi-byte rune severed
|
||||
// by the byte-wise cut is dropped rather than surfaced as a
|
||||
// mojibake tail, which would also make the text look binary.
|
||||
// mojibake tail.
|
||||
func TestEventLogView_CutMidRune(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
body := strings.Repeat(snowman, bodyCap)
|
||||
body := strings.Repeat(snowman, 4096)
|
||||
view := seedAndProject(t, body)
|
||||
|
||||
// bodyCap bytes hold bodyCap/3 whole snowmen and two bytes
|
||||
// of the next one; those two are dropped.
|
||||
whole := bodyCap / len(snowman)
|
||||
|
||||
assert.True(t, view.Body.Cut)
|
||||
assert.False(t, view.Body.Binary)
|
||||
assert.Equal(t, int64(len(body)), view.Body.Size)
|
||||
assert.Equal(t, strings.Repeat(snowman, whole), view.Body.Text)
|
||||
assert.True(t, utf8.ValidString(view.Body.Text))
|
||||
assert.Equal(t, len(view.Body.Text), view.Body.ShownBytes)
|
||||
assert.LessOrEqual(t, view.Body.ShownBytes, bodyCap)
|
||||
assert.True(t, view.BodyTruncated)
|
||||
assert.Equal(t, int64(len(body)), view.BodyBytes)
|
||||
assert.Equal(t, strings.Repeat(snowman, whole), view.Body)
|
||||
assert.True(t, utf8.ValidString(view.Body))
|
||||
assert.LessOrEqual(t, len(view.Body), bodyCap)
|
||||
}
|
||||
|
||||
// TestEventLogView_BinaryBodyNotShown proves a body that is not
|
||||
// text is left out rather than shown as replacement characters,
|
||||
// whether it is cut or not.
|
||||
func TestEventLogView_BinaryBodyNotShown(t *testing.T) {
|
||||
// TestEventLogView_BinaryBodyLeftAsStored proves a binary
|
||||
// payload is passed through byte for byte. Its tail is invalid
|
||||
// UTF-8 however the cut falls, so repairing it would misreport
|
||||
// what the sender delivered.
|
||||
func TestEventLogView_BinaryBodyLeftAsStored(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
raw := make([]byte, bodyCap+808)
|
||||
@@ -189,21 +188,12 @@ func TestEventLogView_BinaryBodyNotShown(t *testing.T) {
|
||||
raw[i] = 0x80 | byte(i%0x40)
|
||||
}
|
||||
|
||||
for name, body := range map[string][]byte{
|
||||
"cut": raw,
|
||||
"whole": raw[:2048],
|
||||
"NUL": []byte("text\x00text"),
|
||||
} {
|
||||
t.Run(name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
view := seedAndProject(t, string(raw))
|
||||
|
||||
view := seedAndProject(t, string(body))
|
||||
|
||||
assert.True(t, view.Body.Binary)
|
||||
assert.Empty(t, view.Body.Text)
|
||||
assert.Equal(t, int64(len(body)), view.Body.Size)
|
||||
})
|
||||
}
|
||||
assert.True(t, view.BodyTruncated)
|
||||
assert.Equal(t, int64(len(raw)), view.BodyBytes)
|
||||
assert.Equal(t, string(raw[:bodyCap]), view.Body)
|
||||
assert.False(t, utf8.ValidString(view.Body))
|
||||
}
|
||||
|
||||
// TestTrimPartialRune covers the distinction the cut repair
|
||||
|
||||
@@ -145,9 +145,8 @@ func (h *Handlers) resubmitEvent(
|
||||
// per-webhook database files — a sibling webhook's event is not in the
|
||||
// database being queried at all — and is there so the scoping survives
|
||||
// any future change that puts more than one webhook's events in one
|
||||
// file. A reaped event is not found because the retention reaper
|
||||
// deletes its row outright rather than marking it deleted; see
|
||||
// deleteEvents in internal/database/retention.go.
|
||||
// file. Going through Model applies GORM's soft-delete scope, which is
|
||||
// what stops a reaped event being resubmitted.
|
||||
func loadResubmitSource(
|
||||
webhookDB *gorm.DB,
|
||||
webhookID, eventID string,
|
||||
|
||||
@@ -19,16 +19,10 @@ func (s *Handlers) SetLogForTest(log *slog.Logger) {
|
||||
s.log = log
|
||||
}
|
||||
|
||||
// MaxRenderedBodyBytesForTest exposes the body cap of the lists
|
||||
// of events to the handlers_test package.
|
||||
// MaxRenderedBodyBytesForTest exposes the event log's body cap
|
||||
// to the handlers_test package.
|
||||
const MaxRenderedBodyBytesForTest = maxRenderedBodyBytes
|
||||
|
||||
// NewBodyViewForTest exposes newBodyView for use in the
|
||||
// handlers_test package.
|
||||
func NewBodyViewForTest(body []byte, size int64) BodyView {
|
||||
return newBodyView("/hook/w/events/e", body, size)
|
||||
}
|
||||
|
||||
// MaxRenderedResponseBytesForTest exposes the event log's
|
||||
// delivery response cap to the handlers_test package.
|
||||
const MaxRenderedResponseBytesForTest = maxRenderedResponseBytes
|
||||
@@ -42,15 +36,6 @@ const MaxRenderedAttemptsForTest = maxRenderedAttempts
|
||||
// the handlers enforce rather than a number copied beside it.
|
||||
const MaxTargetRetriesForTest = maxTargetRetries
|
||||
|
||||
// EventDBLeftMsgForTest and SidecarLeftMsgForTest expose the two
|
||||
// messages the webhook delete handler logs when a file of the event
|
||||
// database is left on disk, so a test checking that one is absent
|
||||
// checks for the handler's own wording.
|
||||
const (
|
||||
EventDBLeftMsgForTest = eventDBLeftMsg
|
||||
SidecarLeftMsgForTest = sidecarLeftMsg
|
||||
)
|
||||
|
||||
// PageOrFirstForTest exposes pageOrFirst for use in the handlers_test
|
||||
// package.
|
||||
func PageOrFirstForTest(s string) int {
|
||||
@@ -143,20 +128,22 @@ func (s *Handlers) RenderTemplateForTest(
|
||||
// BuildSlackTargetConfigForTest exposes
|
||||
// buildSlackTargetConfig for use in the handlers_test package.
|
||||
func (s *Handlers) BuildSlackTargetConfigForTest(
|
||||
ctx context.Context,
|
||||
w http.ResponseWriter,
|
||||
r *http.Request,
|
||||
targetURL string,
|
||||
) (string, string, error) {
|
||||
return s.buildSlackTargetConfig(ctx, targetURL)
|
||||
) (string, error) {
|
||||
return s.buildSlackTargetConfig(w, r, targetURL)
|
||||
}
|
||||
|
||||
// BuildHTTPTargetConfigForTest exposes buildHTTPTargetConfig
|
||||
// for use in the handlers_test package, taking the form fields
|
||||
// an HTTP target's configuration is built from.
|
||||
func (s *Handlers) BuildHTTPTargetConfigForTest(
|
||||
ctx context.Context,
|
||||
w http.ResponseWriter,
|
||||
r *http.Request,
|
||||
targetURL, headers, timeout string,
|
||||
) (string, string, error) {
|
||||
return s.buildHTTPTargetConfig(ctx, targetFormInput{
|
||||
) (string, error) {
|
||||
return s.buildHTTPTargetConfig(w, r, targetFormInput{
|
||||
URL: targetURL,
|
||||
Headers: headers,
|
||||
Timeout: timeout,
|
||||
@@ -166,8 +153,9 @@ func (s *Handlers) BuildHTTPTargetConfigForTest(
|
||||
// BuildDatabaseTargetConfigForTest exposes
|
||||
// buildDatabaseTargetConfig for use in the handlers_test
|
||||
// package.
|
||||
func BuildDatabaseTargetConfigForTest(
|
||||
func (s *Handlers) BuildDatabaseTargetConfigForTest(
|
||||
w http.ResponseWriter,
|
||||
expiry string,
|
||||
) (string, string, error) {
|
||||
return buildDatabaseTargetConfig(expiry)
|
||||
) (string, error) {
|
||||
return s.buildDatabaseTargetConfig(w, newRequestForTest(), expiry)
|
||||
}
|
||||
|
||||
@@ -97,8 +97,7 @@ type Handlers struct {
|
||||
// names through the archive rename, the save and any move back.
|
||||
// Interleaved, one could rename an archive between another's
|
||||
// rename and save, leaving the file named for one edit and the
|
||||
// stored names from the other. An archive download holds it while
|
||||
// it reads the stored names and opens the file they give.
|
||||
// stored names from the other.
|
||||
renameMu sync.Mutex
|
||||
|
||||
// dummyVerifications counts the equivalent-cost verifications
|
||||
@@ -150,23 +149,16 @@ func New(
|
||||
|
||||
// Parse all page templates once at startup
|
||||
s.templates = map[string]*template.Template{
|
||||
"login.html": parsePageTemplate("login.html"),
|
||||
"profile.html": parsePageTemplate("profile.html"),
|
||||
"settings.html": parsePageTemplate("settings.html"),
|
||||
"sources_list.html": parsePageTemplate("sources_list.html"),
|
||||
"sources_new.html": parsePageTemplate("sources_new.html"),
|
||||
"source_detail.html": parsePageTemplate(
|
||||
"source_detail.html", "webhook_stats.html", "event_body.html",
|
||||
),
|
||||
"source_edit.html": parsePageTemplate("source_edit.html"),
|
||||
"source_logs.html": parsePageTemplate(
|
||||
"source_logs.html", "event_body.html", "delivery_attempts.html",
|
||||
),
|
||||
"event_detail.html": parsePageTemplate(
|
||||
"event_detail.html", "event_body.html", "delivery_attempts.html",
|
||||
),
|
||||
"target_edit.html": parsePageTemplate("target_edit.html"),
|
||||
"error.html": parsePageTemplate("error.html"),
|
||||
"login.html": parsePageTemplate("login.html"),
|
||||
"profile.html": parsePageTemplate("profile.html"),
|
||||
"settings.html": parsePageTemplate("settings.html"),
|
||||
"sources_list.html": parsePageTemplate("sources_list.html"),
|
||||
"sources_new.html": parsePageTemplate("sources_new.html"),
|
||||
"source_detail.html": parsePageTemplate("source_detail.html", "webhook_stats.html"),
|
||||
"source_edit.html": parsePageTemplate("source_edit.html"),
|
||||
"source_logs.html": parsePageTemplate("source_logs.html"),
|
||||
"target_edit.html": parsePageTemplate("target_edit.html"),
|
||||
"error.html": parsePageTemplate("error.html"),
|
||||
}
|
||||
|
||||
lc.Append(fx.Hook{
|
||||
@@ -393,7 +385,7 @@ func (s *Handlers) pageData(
|
||||
// partial body and the status before a mid-render error can be
|
||||
// reported, leaving no way to serve a 500. Buffering makes a page's
|
||||
// rendered size resident memory per concurrent viewer, so every page
|
||||
// owes it a bound: the lists of events cap each stored body at
|
||||
// owes it a bound: the event log caps each stored body at
|
||||
// maxRenderedBodyBytes for exactly this reason.
|
||||
func (s *Handlers) executeTemplate(
|
||||
w http.ResponseWriter,
|
||||
|
||||
@@ -314,12 +314,16 @@ func TestBuildSlackTargetConfig_AcceptsPublicURL(t *testing.T) {
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
cfg, errMsg, err := h.BuildSlackTargetConfigForTest(
|
||||
t.Context(), "http://93.184.216.34/services/T00/B00/xxx",
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(), http.MethodPost, "/", nil)
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
cfg, err := h.BuildSlackTargetConfigForTest(
|
||||
w, req, "http://93.184.216.34/services/T00/B00/xxx",
|
||||
)
|
||||
|
||||
require.NoError(t, err)
|
||||
assert.Empty(t, errMsg)
|
||||
assert.Equal(t, http.StatusOK, w.Code)
|
||||
assert.Contains(t, cfg, "webhookUrl")
|
||||
}
|
||||
|
||||
@@ -333,13 +337,17 @@ func TestBuildSlackTargetConfig_RejectsReservedURL(t *testing.T) {
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
cfg, errMsg, err := h.BuildSlackTargetConfigForTest(
|
||||
t.Context(), "http://169.254.169.254/latest/meta-data/",
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(), http.MethodPost, "/", nil)
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
cfg, err := h.BuildSlackTargetConfigForTest(
|
||||
w, req, "http://169.254.169.254/latest/meta-data/",
|
||||
)
|
||||
|
||||
require.NoError(t, err)
|
||||
assert.Contains(t, errMsg, "Invalid target URL")
|
||||
require.Error(t, err)
|
||||
assert.Empty(t, cfg)
|
||||
assert.Equal(t, http.StatusBadRequest, w.Code)
|
||||
}
|
||||
|
||||
func TestRenderTemplate(t *testing.T) {
|
||||
@@ -436,22 +444,29 @@ func TestRenderTemplateMidRenderErrorSendsNoPartialBody(t *testing.T) {
|
||||
func TestBuildDatabaseTargetConfig_Valid(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var h *handlers.Handlers
|
||||
|
||||
app := newTestApp(t, &h)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
// Empty expiry: the keep-forever default, empty config.
|
||||
cfg, errMsg, err := handlers.BuildDatabaseTargetConfigForTest("")
|
||||
w := httptest.NewRecorder()
|
||||
cfg, err := h.BuildDatabaseTargetConfigForTest(w, "")
|
||||
require.NoError(t, err)
|
||||
assert.Empty(t, errMsg)
|
||||
assert.Empty(t, cfg)
|
||||
|
||||
// Explicit never is stored as config.
|
||||
cfg, errMsg, err = handlers.BuildDatabaseTargetConfigForTest("never")
|
||||
w = httptest.NewRecorder()
|
||||
cfg, err = h.BuildDatabaseTargetConfigForTest(w, "never")
|
||||
require.NoError(t, err)
|
||||
assert.Empty(t, errMsg)
|
||||
assert.JSONEq(t, `{"expiry":"never"}`, cfg)
|
||||
|
||||
// A positive duration is stored as config.
|
||||
cfg, errMsg, err = handlers.BuildDatabaseTargetConfigForTest("720h")
|
||||
w = httptest.NewRecorder()
|
||||
cfg, err = h.BuildDatabaseTargetConfigForTest(w, "720h")
|
||||
require.NoError(t, err)
|
||||
assert.Empty(t, errMsg)
|
||||
assert.JSONEq(t, `{"expiry":"720h"}`, cfg)
|
||||
}
|
||||
|
||||
@@ -460,14 +475,22 @@ func TestBuildDatabaseTargetConfig_RejectsBadExpiry(
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
for _, bad := range []string{"nonsense", "7d", "-5h"} {
|
||||
cfg, errMsg, err := handlers.BuildDatabaseTargetConfigForTest(bad)
|
||||
var h *handlers.Handlers
|
||||
|
||||
require.NoError(t, err)
|
||||
assert.Contains(
|
||||
t, errMsg, "Invalid archive expiry",
|
||||
"expiry %q should be refused", bad,
|
||||
)
|
||||
app := newTestApp(t, &h)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
for _, bad := range []string{"nonsense", "7d", "-5h"} {
|
||||
w := httptest.NewRecorder()
|
||||
cfg, err := h.BuildDatabaseTargetConfigForTest(w, bad)
|
||||
|
||||
require.Error(t, err, "expiry %q", bad)
|
||||
assert.Empty(t, cfg)
|
||||
assert.Equal(
|
||||
t, http.StatusBadRequest, w.Code,
|
||||
"expiry %q should be rejected with 400", bad,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -20,7 +20,6 @@ const (
|
||||
webhookSaved noticeCode = "webhook-saved"
|
||||
webhookDeleted noticeCode = "webhook-deleted"
|
||||
entrypointAdded noticeCode = "entrypoint-added"
|
||||
entrypointSaved noticeCode = "entrypoint-saved"
|
||||
entrypointDeleted noticeCode = "entrypoint-deleted"
|
||||
entrypointActivated noticeCode = "entrypoint-activated"
|
||||
entrypointDeactivated noticeCode = "entrypoint-deactivated"
|
||||
@@ -49,7 +48,6 @@ func noticeFor(r *http.Request) *notice {
|
||||
webhookSaved: {Text: "Webhook saved."},
|
||||
webhookDeleted: {Text: "Webhook deleted."},
|
||||
entrypointAdded: {Text: "Entrypoint added."},
|
||||
entrypointSaved: {Text: "Entrypoint description saved."},
|
||||
entrypointDeleted: {Text: "Entrypoint deleted."},
|
||||
entrypointActivated: {Text: "Entrypoint activated."},
|
||||
entrypointDeactivated: {Text: "Entrypoint deactivated."},
|
||||
|
||||
@@ -12,12 +12,11 @@ import (
|
||||
)
|
||||
|
||||
// recentEventColumns is the recent events list's projection. It
|
||||
// reads the body cut to maxRenderedBodyBytes, as eventLogColumns
|
||||
// does, and its size from body_bytes, recorded when the event was
|
||||
// leaves out the body, for the reason maxRenderedBodyBytes gives,
|
||||
// and reads its size from body_bytes, recorded when the event was
|
||||
// stored.
|
||||
const recentEventColumns = "id, created_at, method, content_type, " +
|
||||
"resubmitted_from_id, body_bytes, " +
|
||||
"substr(cast(body as blob), 1, ?) AS body"
|
||||
"resubmitted_from_id, body_bytes"
|
||||
|
||||
// recentAttemptColumns is the part of a recorded attempt the list
|
||||
// uses. The event log's deliveryResultColumns also reads response
|
||||
@@ -51,9 +50,6 @@ type RecentEventView struct {
|
||||
// unless the webhook has exactly one HTTP target.
|
||||
Status string
|
||||
StatusClass string
|
||||
|
||||
// Body is what the row shows when it is expanded.
|
||||
Body BodyView
|
||||
}
|
||||
|
||||
// recentEventRow is one row of recentEventColumns.
|
||||
@@ -64,7 +60,6 @@ type recentEventRow struct {
|
||||
ContentType string
|
||||
ResubmittedFromID *string
|
||||
BodyBytes uint64
|
||||
Body []byte
|
||||
}
|
||||
|
||||
// recentAttemptRow is one row of recentAttemptColumns. CreatedAt is
|
||||
@@ -105,7 +100,7 @@ func loadRecentEvents(
|
||||
var rows []recentEventRow
|
||||
|
||||
err := webhookDB.Model(&database.Event{}).
|
||||
Select(recentEventColumns, maxRenderedBodyBytes).
|
||||
Select(recentEventColumns).
|
||||
Where("webhook_id = ?", webhookID).
|
||||
Order("created_at DESC").
|
||||
Limit(recentEventLimit).
|
||||
@@ -150,7 +145,7 @@ func loadRecentEvents(
|
||||
views := make([]RecentEventView, len(rows))
|
||||
for i := range rows {
|
||||
views[i] = rows[i].view(
|
||||
webhookID, byEvent[rows[i].ID], attempts, statusTargetID,
|
||||
byEvent[rows[i].ID], attempts, statusTargetID,
|
||||
)
|
||||
}
|
||||
|
||||
@@ -187,20 +182,14 @@ func loadRecentAttempts(
|
||||
return byDelivery, nil
|
||||
}
|
||||
|
||||
// view projects a loaded row of the webhook's events for
|
||||
// rendering. deliveries is the event's deliveries, oldest first,
|
||||
// and attempts their recorded attempts keyed by delivery ID.
|
||||
// view projects a loaded row for rendering. deliveries is the
|
||||
// event's deliveries, oldest first, and attempts their recorded
|
||||
// attempts keyed by delivery ID.
|
||||
func (r *recentEventRow) view(
|
||||
webhookID string,
|
||||
deliveries []database.Delivery,
|
||||
attempts map[string][]recentAttemptRow,
|
||||
statusTargetID string,
|
||||
) RecentEventView {
|
||||
//nolint:gosec // body_bytes is at most the receiver's 1 MB cap
|
||||
body := newBodyView(
|
||||
"/hook/"+webhookID+"/events/"+r.ID, r.Body, int64(r.BodyBytes),
|
||||
)
|
||||
|
||||
v := RecentEventView{
|
||||
Method: r.Method,
|
||||
ContentType: r.ContentType,
|
||||
@@ -208,7 +197,6 @@ func (r *recentEventRow) view(
|
||||
ReceivedUTC: r.CreatedAt.UTC().Format(time.DateTime) + " UTC",
|
||||
Size: humanize.Bytes(r.BodyBytes),
|
||||
ProcessingTime: processingTime(deliveries, attempts),
|
||||
Body: body,
|
||||
}
|
||||
|
||||
if r.ResubmittedFromID != nil {
|
||||
|
||||
@@ -5,7 +5,6 @@ import (
|
||||
"fmt"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strconv"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
@@ -302,73 +301,6 @@ func TestHandleSourceDetail_NoStatusWithoutSingleHTTPTarget(
|
||||
}
|
||||
}
|
||||
|
||||
// TestHandleSourceDetail_RecentEventsLinkAndExpand proves each row
|
||||
// links to its event's own page and expands to show its body, and
|
||||
// that only the newest row starts expanded.
|
||||
func TestHandleSourceDetail_RecentEventsLinkAndExpand(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
f := newRecentEventsFixture(t)
|
||||
now := time.Now()
|
||||
|
||||
older := f.event(
|
||||
t, contentTypeJSON, `{"which":"older"}`, now.Add(-time.Minute),
|
||||
)
|
||||
newer := f.event(t, contentTypeJSON, `{"which":"newer"}`, now)
|
||||
|
||||
body := f.render(t)
|
||||
|
||||
for _, e := range []*database.Event{older, newer} {
|
||||
assert.Contains(
|
||||
t, body, `href="/hook/`+f.webhook.ID+`/events/`+e.ID+`"`,
|
||||
)
|
||||
}
|
||||
|
||||
assert.Equal(t, 2, strings.Count(body, `<div x-show="open" x-cloak class="mt-3">`))
|
||||
assert.Equal(t, 1, strings.Count(body, " data-open>"))
|
||||
|
||||
open := strings.Index(body, " data-open>")
|
||||
newerBody := strings.Index(body, ""which": "newer"")
|
||||
olderBody := strings.Index(body, ""which": "older"")
|
||||
|
||||
assert.Less(t, open, newerBody, "the newest row is not the open one")
|
||||
assert.Less(t, newerBody, olderBody)
|
||||
}
|
||||
|
||||
// TestHandleSourceDetail_RecentEventBodyCut proves a body up to
|
||||
// the cap is shown whole and pretty-printed, and a larger one only
|
||||
// its first bodyCap bytes, as received, with links to the whole
|
||||
// body on the event's page and to the download.
|
||||
func TestHandleSourceDetail_RecentEventBodyCut(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
f := newRecentEventsFixture(t)
|
||||
now := time.Now()
|
||||
|
||||
// A JSON document of n bytes.
|
||||
document := func(n int) string {
|
||||
return `{"pad":"` + strings.Repeat("x", n-len(`{"pad":""}`)) + `"}`
|
||||
}
|
||||
|
||||
whole := f.event(
|
||||
t, contentTypeJSON, document(bodyCap), now.Add(-time.Minute),
|
||||
)
|
||||
cut := f.event(t, contentTypeJSON, document(bodyCap+1), now)
|
||||
|
||||
body := f.render(t)
|
||||
eventURL := `href="/hook/` + f.webhook.ID + `/events/`
|
||||
|
||||
assert.Equal(t, 1, strings.Count(body, "{\n "pad": "))
|
||||
assert.Contains(t, body, "{"pad":"xxx")
|
||||
assert.Contains(
|
||||
t, body,
|
||||
"Showing the first "+strconv.Itoa(bodyCap)+" of "+
|
||||
strconv.Itoa(bodyCap+1)+" bytes, unformatted.",
|
||||
)
|
||||
assert.Contains(t, body, eventURL+cut.ID+`/body"`)
|
||||
assert.NotContains(t, body, eventURL+whole.ID+`/body"`)
|
||||
}
|
||||
|
||||
// TestHandleWebhook_RecordsBodySize proves the receiver records the
|
||||
// body's size in bytes, not characters, with the event it stores.
|
||||
func TestHandleWebhook_RecordsBodySize(t *testing.T) {
|
||||
|
||||
@@ -77,8 +77,7 @@ func settingRows(cfg *config.Config) []settingRow {
|
||||
{
|
||||
"RETENTION_SWEEP_INTERVAL",
|
||||
"How often the retention reaper and archive sweeper run " +
|
||||
"(Go duration, must be positive). A value that does " +
|
||||
"not parse, or is zero or negative, fails startup",
|
||||
"(Go duration, must be positive)",
|
||||
cfg.RetentionSweepInterval.String(),
|
||||
},
|
||||
{
|
||||
|
||||
@@ -1,207 +0,0 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"html"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"net/url"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"gorm.io/gorm"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
)
|
||||
|
||||
// submitCreateForm posts the new webhook form and returns the
|
||||
// recorder.
|
||||
func submitCreateForm(
|
||||
env *sourceTestEnv, form url.Values,
|
||||
) *httptest.ResponseRecorder {
|
||||
req := formRequest("/hooks/new", env.cookies, form, nil)
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
env.handlers.HandleSourceCreateSubmit().ServeHTTP(w, req)
|
||||
|
||||
return w
|
||||
}
|
||||
|
||||
// assertNothingCreated checks that the main database holds no webhook,
|
||||
// entrypoint or target.
|
||||
func assertNothingCreated(t *testing.T, db *database.Database) {
|
||||
t.Helper()
|
||||
|
||||
for _, model := range []any{
|
||||
&database.Webhook{}, &database.Entrypoint{}, &database.Target{},
|
||||
} {
|
||||
var count int64
|
||||
|
||||
require.NoError(t, db.DB().Model(model).Count(&count).Error)
|
||||
assert.Zerof(t, count, "%T rows were created", model)
|
||||
}
|
||||
}
|
||||
|
||||
// TestHandleSourceCreateSubmit_CreatesRequestedTargets submits the new
|
||||
// webhook form with the HTTP target URL filled in or empty, and with
|
||||
// the archive checkbox off or on with each pruning choice. The webhook
|
||||
// gets an HTTP target only for a URL and a database target only for a
|
||||
// checked archive. The pruning choice is always submitted, as the
|
||||
// browser submits it while it is hidden, and is ignored when archive
|
||||
// is off.
|
||||
func TestHandleSourceCreateSubmit_CreatesRequestedTargets(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSourceTest(t)
|
||||
|
||||
// Each value the archive pruning choice submits, after an empty
|
||||
// one that stands for the archive checkbox left off.
|
||||
expiries := []string{
|
||||
"", "never", "1h", "12h", "24h", "720h", "2160h", "8760h",
|
||||
}
|
||||
|
||||
for _, httpURL := range []string{"", editOriginalURL} {
|
||||
for _, expiry := range expiries {
|
||||
name := "url=" + httpURL + " archive=" + expiry
|
||||
|
||||
t.Run(name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
form := url.Values{}
|
||||
form.Set("name", name)
|
||||
form.Set("http_url", httpURL)
|
||||
form.Set("archive_expiry", "720h")
|
||||
|
||||
if expiry != "" {
|
||||
form.Set("archive", "on")
|
||||
form.Set("archive_expiry", expiry)
|
||||
}
|
||||
|
||||
w := submitCreateForm(env, form)
|
||||
require.Equal(t, http.StatusSeeOther, w.Code, w.Body.String())
|
||||
|
||||
var webhook database.Webhook
|
||||
|
||||
require.NoError(t, env.db.DB().
|
||||
Where("name = ?", name).First(&webhook).Error)
|
||||
|
||||
byType := map[database.TargetType]database.Target{}
|
||||
for _, target := range targetsForWebhook(t, env.db, webhook.ID) {
|
||||
byType[target.Type] = target
|
||||
}
|
||||
|
||||
wantCount := 0
|
||||
|
||||
if httpURL != "" {
|
||||
wantCount++
|
||||
|
||||
assert.Equal(t, "HTTP", byType[database.TargetTypeHTTP].Name)
|
||||
assert.JSONEq(t, `{"url":"`+httpURL+`"}`,
|
||||
byType[database.TargetTypeHTTP].Config)
|
||||
}
|
||||
|
||||
if expiry != "" {
|
||||
wantCount++
|
||||
|
||||
assert.Equal(t, "Archive",
|
||||
byType[database.TargetTypeDatabase].Name)
|
||||
assert.JSONEq(t, `{"expiry":"`+expiry+`"}`,
|
||||
byType[database.TargetTypeDatabase].Config)
|
||||
}
|
||||
|
||||
assert.Len(t, byType, wantCount)
|
||||
})
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// TestHandleSourceCreateSubmit_RefusedFormKeepsEveryValue refuses the
|
||||
// new webhook form for an invalid HTTP target URL and for an invalid
|
||||
// retention, each with archive on. Nothing is created, and the form
|
||||
// comes back with the reason and every value entered: name,
|
||||
// description, retention, URL, the checked archive box and the pruning
|
||||
// choice.
|
||||
func TestHandleSourceCreateSubmit_RefusedFormKeepsEveryValue(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
const badURL = "Invalid target URL"
|
||||
|
||||
cases := []struct {
|
||||
name string
|
||||
retention string
|
||||
httpURL string
|
||||
reason string
|
||||
}{
|
||||
{"blocked url", "7", editBlockedURL, badURL},
|
||||
{"unsupported scheme", "7", "ftp://93.184.216.34/hook", badURL},
|
||||
{"bad retention", "-5", editOriginalURL, "Retention must be"},
|
||||
}
|
||||
|
||||
for _, tc := range cases {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSourceTest(t)
|
||||
|
||||
form := url.Values{}
|
||||
form.Set("name", "kept name")
|
||||
form.Set("description", "kept description")
|
||||
form.Set("retention_days", tc.retention)
|
||||
form.Set("http_url", tc.httpURL)
|
||||
form.Set("archive", "on")
|
||||
form.Set("archive_expiry", "2160h")
|
||||
|
||||
w := submitCreateForm(env, form)
|
||||
require.Equal(t, http.StatusBadRequest, w.Code)
|
||||
|
||||
page := w.Body.String()
|
||||
assert.Contains(t, page, tc.reason)
|
||||
assert.Contains(t, page, `value="kept name"`)
|
||||
assert.Contains(t, page, `>kept description</textarea>`)
|
||||
assert.Contains(t, page, `value="`+tc.retention+`"`)
|
||||
assert.Contains(t, page,
|
||||
`value="`+html.EscapeString(tc.httpURL)+`"`)
|
||||
assert.Contains(t, page, `name="archive" value="on" checked`)
|
||||
assert.Contains(t, page, `x-data="collapsible" data-open`)
|
||||
assert.Contains(t, page, `<option value="2160h" selected>`)
|
||||
|
||||
assertNothingCreated(t, env.db)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// errInjectedTargetCreate is the failure a test makes the insert of a
|
||||
// target report.
|
||||
var errInjectedTargetCreate = errors.New("injected target create failure")
|
||||
|
||||
// TestHandleSourceCreateSubmit_FailedTargetInsertCreatesNothing makes
|
||||
// inserting a target fail after the webhook and its entrypoint were
|
||||
// inserted, and checks that neither is left behind.
|
||||
func TestHandleSourceCreateSubmit_FailedTargetInsertCreatesNothing(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSourceTest(t)
|
||||
|
||||
require.NoError(t, env.db.DB().Callback().Create().
|
||||
Before("gorm:create").
|
||||
Register("test:fail_target_create", func(tx *gorm.DB) {
|
||||
if tx.Statement.Table == "targets" {
|
||||
_ = tx.AddError(errInjectedTargetCreate)
|
||||
}
|
||||
}),
|
||||
)
|
||||
|
||||
form := url.Values{}
|
||||
form.Set("name", "rolled back")
|
||||
form.Set("archive", "on")
|
||||
form.Set("archive_expiry", "never")
|
||||
|
||||
w := submitCreateForm(env, form)
|
||||
require.Equal(t, http.StatusInternalServerError, w.Code)
|
||||
|
||||
assertNothingCreated(t, env.db)
|
||||
}
|
||||
@@ -1,10 +1,8 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"errors"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"os"
|
||||
@@ -86,13 +84,12 @@ var errInjectedDelete = errors.New("injected delete failure")
|
||||
// save of an existing row.
|
||||
var errInjectedSave = errors.New("injected save failure")
|
||||
|
||||
// seedEntrypoint inserts an active entrypoint for a webhook and
|
||||
// returns it.
|
||||
// seedEntrypoint inserts an entrypoint for a webhook.
|
||||
func seedEntrypoint(
|
||||
t *testing.T,
|
||||
db *database.Database,
|
||||
webhookID string,
|
||||
) *database.Entrypoint {
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
ep := &database.Entrypoint{
|
||||
@@ -105,8 +102,6 @@ func seedEntrypoint(
|
||||
t,
|
||||
db.DB().Omit(clause.Associations).Create(ep).Error,
|
||||
)
|
||||
|
||||
return ep
|
||||
}
|
||||
|
||||
// countRows counts the live (not soft-deleted) rows of a model
|
||||
@@ -471,121 +466,6 @@ func TestHandleSourceDelete_RemovesConfigAndEventDatabase(
|
||||
)
|
||||
}
|
||||
|
||||
// TestHandleSourceDelete_LeftoverSidecar proves that when the event
|
||||
// database file is removed but a sidecar beside it is not, the
|
||||
// operator is told the events are gone, never that the event
|
||||
// database file is still there.
|
||||
func TestHandleSourceDelete_LeftoverSidecar(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
sess *session.Session
|
||||
db *database.Database
|
||||
mgr *database.WebhookDBManager
|
||||
)
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &mgr)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
logs := new(bytes.Buffer)
|
||||
h.SetLogForTest(slog.New(slog.NewTextHandler(logs, nil)))
|
||||
|
||||
wh := seedWebhook(t, db)
|
||||
|
||||
require.NoError(t, mgr.CreateDB(wh.ID))
|
||||
// Closing removes the sidecars, so the -wal below is the only
|
||||
// one there.
|
||||
require.NoError(t, mgr.CloseAll())
|
||||
|
||||
// A non-empty directory in the -wal file's place, which
|
||||
// os.Remove cannot remove whoever runs the test.
|
||||
eventDBPath := mgr.DBPath(wh.ID)
|
||||
require.NoError(t, os.MkdirAll(
|
||||
filepath.Join(eventDBPath+"-wal", "keep"), 0o700,
|
||||
))
|
||||
|
||||
cookies := authenticatedCookies(
|
||||
t, sess, deleteTestUserID, deleteTestUsername,
|
||||
)
|
||||
|
||||
req := postRequest(
|
||||
"/hook/"+wh.ID+"/delete",
|
||||
cookies,
|
||||
map[string]string{paramSourceID: wh.ID},
|
||||
)
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
h.HandleSourceDelete().ServeHTTP(w, req)
|
||||
|
||||
assert.Equal(t, http.StatusInternalServerError, w.Code)
|
||||
assert.NoFileExists(t, eventDBPath)
|
||||
assert.Contains(t, logs.String(), "its events are gone")
|
||||
assert.Contains(t, logs.String(), eventDBPath+"-wal")
|
||||
assert.NotContains(
|
||||
t, logs.String(), handlers.EventDBLeftMsgForTest,
|
||||
"the events are gone, so the operator must not be told "+
|
||||
"the event database file survived",
|
||||
)
|
||||
}
|
||||
|
||||
// TestHandleSourceDelete_LeftoverDatabaseFile proves that when the
|
||||
// event database file itself cannot be removed, the operator is told
|
||||
// it is still on disk, never that its events are gone.
|
||||
func TestHandleSourceDelete_LeftoverDatabaseFile(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
sess *session.Session
|
||||
db *database.Database
|
||||
mgr *database.WebhookDBManager
|
||||
)
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &mgr)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
logs := new(bytes.Buffer)
|
||||
h.SetLogForTest(slog.New(slog.NewTextHandler(logs, nil)))
|
||||
|
||||
wh := seedWebhook(t, db)
|
||||
|
||||
// A non-empty directory in the database file's place, which
|
||||
// os.Remove cannot remove whoever runs the test.
|
||||
eventDBPath := mgr.DBPath(wh.ID)
|
||||
require.NoError(t, os.MkdirAll(
|
||||
filepath.Join(eventDBPath, "keep"), 0o700,
|
||||
))
|
||||
|
||||
cookies := authenticatedCookies(
|
||||
t, sess, deleteTestUserID, deleteTestUsername,
|
||||
)
|
||||
|
||||
req := postRequest(
|
||||
"/hook/"+wh.ID+"/delete",
|
||||
cookies,
|
||||
map[string]string{paramSourceID: wh.ID},
|
||||
)
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
h.HandleSourceDelete().ServeHTTP(w, req)
|
||||
|
||||
assert.Equal(t, http.StatusInternalServerError, w.Code)
|
||||
assert.Contains(
|
||||
t, logs.String(), "event database file is still on disk",
|
||||
)
|
||||
assert.Contains(t, logs.String(), eventDBPath)
|
||||
assert.NotContains(
|
||||
t, logs.String(), handlers.SidecarLeftMsgForTest,
|
||||
"the database file is still on disk, so the operator must "+
|
||||
"not be told its events are gone",
|
||||
)
|
||||
}
|
||||
|
||||
// TestHandleTargetDelete_EvictsThatTarget proves that deleting a
|
||||
// database target releases that target's archive writer and no
|
||||
// other: the webhook's other database target keeps its own.
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -191,7 +191,6 @@ func storedRetentionDays(
|
||||
type sourceTestEnv struct {
|
||||
handlers *handlers.Handlers
|
||||
db *database.Database
|
||||
dbMgr *database.WebhookDBManager
|
||||
archives *recordingArchives
|
||||
cookies []*http.Cookie
|
||||
}
|
||||
@@ -205,11 +204,9 @@ func setupSourceTest(t *testing.T) *sourceTestEnv {
|
||||
|
||||
var db *database.Database
|
||||
|
||||
var dbMgr *database.WebhookDBManager
|
||||
|
||||
var archives *recordingArchives
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &dbMgr, &archives)
|
||||
app := newTestApp(t, &h, &sess, &db, &archives)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
@@ -217,7 +214,6 @@ func setupSourceTest(t *testing.T) *sourceTestEnv {
|
||||
return &sourceTestEnv{
|
||||
handlers: h,
|
||||
db: db,
|
||||
dbMgr: dbMgr,
|
||||
archives: archives,
|
||||
cookies: authenticatedCookies(
|
||||
t, sess, sourceTestUserID, "sourceuser",
|
||||
@@ -372,42 +368,31 @@ func TestHandleSourceCreateSubmit_OverflowingRetentionIsRejected(
|
||||
// boundary between "too large to represent" and "retain forever": the
|
||||
// sentinel is above MaxFiniteRetentionDays, but it is the value the
|
||||
// edit form pre-fills, so it must be accepted rather than rejected as
|
||||
// out of range. A value above the sentinel is stored as the sentinel.
|
||||
// out of range.
|
||||
func TestHandleSourceCreateSubmit_SentinelIsAcceptedAsForever(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
for _, days := range []int{
|
||||
env := setupSourceTest(t)
|
||||
sentinel := strconv.Itoa(database.RetentionForeverDays)
|
||||
|
||||
w := submitCreate(t, env.handlers, env.cookies, "forever", &sentinel)
|
||||
require.Equal(t, http.StatusSeeOther, w.Code)
|
||||
|
||||
wh := onlyWebhook(t, env.db)
|
||||
assert.Equal(
|
||||
t,
|
||||
database.RetentionForeverDays,
|
||||
database.RetentionForeverDays + 1,
|
||||
} {
|
||||
raw := strconv.Itoa(days)
|
||||
|
||||
t.Run(raw, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSourceTest(t)
|
||||
|
||||
w := submitCreate(t, env.handlers, env.cookies, "forever", &raw)
|
||||
require.Equal(t, http.StatusSeeOther, w.Code)
|
||||
|
||||
wh := onlyWebhook(t, env.db)
|
||||
assert.Equal(
|
||||
t,
|
||||
database.RetentionForeverDays,
|
||||
storedRetentionDays(t, env.db, wh.ID),
|
||||
)
|
||||
})
|
||||
}
|
||||
storedRetentionDays(t, env.db, wh.ID),
|
||||
)
|
||||
}
|
||||
|
||||
// TestHandleSourceCreateSubmit_RejectedFormKeepsUserInput checks that a
|
||||
// validation failure hands the user's typing back, matching what the
|
||||
// edit form already does. Losing a long description to a mistyped
|
||||
// retention value is the kind of thing that makes people give up on a
|
||||
// form. Both values carry HTML-special characters, which must come
|
||||
// back escaped rather than as markup.
|
||||
// form.
|
||||
func TestHandleSourceCreateSubmit_RejectedFormKeepsUserInput(
|
||||
t *testing.T,
|
||||
) {
|
||||
@@ -416,8 +401,8 @@ func TestHandleSourceCreateSubmit_RejectedFormKeepsUserInput(
|
||||
env := setupSourceTest(t)
|
||||
|
||||
const (
|
||||
name = `kept"><b>name`
|
||||
description = `a </textarea> worth not losing`
|
||||
name = "kept-name"
|
||||
description = "a description worth not losing"
|
||||
)
|
||||
|
||||
form := url.Values{}
|
||||
@@ -434,10 +419,8 @@ func TestHandleSourceCreateSubmit_RejectedFormKeepsUserInput(
|
||||
|
||||
body := w.Body.String()
|
||||
|
||||
assert.Contains(t, body, `value="kept"><b>name"`)
|
||||
assert.Contains(t, body, `a </textarea> worth not losing`)
|
||||
assert.NotContains(t, body, name)
|
||||
assert.NotContains(t, body, description)
|
||||
assert.Contains(t, body, `value="`+name+`"`)
|
||||
assert.Contains(t, body, description)
|
||||
}
|
||||
|
||||
// submitEdit posts the webhook edit form for the given webhook.
|
||||
|
||||
@@ -1,154 +0,0 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"html"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
)
|
||||
|
||||
// TestHandleTargetCreate_EveryType adds a target of each type. Each
|
||||
// submission carries a url: only the http and slack types store one.
|
||||
func TestHandleTargetCreate_EveryType(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSourceTest(t)
|
||||
|
||||
// fields is the rest of each submission, as a query string.
|
||||
cases := []struct {
|
||||
targetType database.TargetType
|
||||
fields string
|
||||
wantConfig string
|
||||
wantRetries int
|
||||
}{
|
||||
{
|
||||
database.TargetTypeHTTP, "timeout=12&max_retries=3",
|
||||
`{"url":"` + editOriginalURL + `","timeout":12}`, 3,
|
||||
},
|
||||
{
|
||||
database.TargetTypeSlack, "max_retries=4",
|
||||
`{"webhookUrl":"` + editOriginalURL + `"}`, 4,
|
||||
},
|
||||
{
|
||||
database.TargetTypeDatabase, "expiry=720h",
|
||||
`{"expiry":"720h"}`, 0,
|
||||
},
|
||||
{database.TargetTypeLog, "", "", 0},
|
||||
}
|
||||
|
||||
for _, tc := range cases {
|
||||
t.Run(string(tc.targetType), func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
webhook := seedWebhookWithRetention(t, env.db, 30)
|
||||
|
||||
form, err := url.ParseQuery(tc.fields)
|
||||
require.NoError(t, err)
|
||||
form.Set("name", "every-type")
|
||||
form.Set("type", string(tc.targetType))
|
||||
form.Set("url", editOriginalURL)
|
||||
|
||||
w := serveTarget(
|
||||
env, http.MethodPost,
|
||||
"/hook/"+webhook.ID+"/targets", form,
|
||||
)
|
||||
require.Equal(t, http.StatusSeeOther, w.Code, w.Body.String())
|
||||
|
||||
targets := targetsForWebhook(t, env.db, webhook.ID)
|
||||
require.Len(t, targets, 1)
|
||||
assert.Equal(t, tc.targetType, targets[0].Type)
|
||||
assert.Equal(t, tc.wantRetries, targets[0].MaxRetries)
|
||||
|
||||
if tc.wantConfig == "" {
|
||||
assert.Empty(t, targets[0].Config)
|
||||
} else {
|
||||
assert.JSONEq(t, tc.wantConfig, targets[0].Config)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// TestHandleTargetCreate_RefusedFormComesBack refuses a target of each
|
||||
// type and checks that the webhook page comes back with the add target
|
||||
// form open on that type, the values entered, and the reason.
|
||||
func TestHandleTargetCreate_RefusedFormComesBack(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSourceTest(t)
|
||||
|
||||
// fields is what the operator typed, as a query string.
|
||||
cases := []struct {
|
||||
targetType database.TargetType
|
||||
fields string
|
||||
reason string
|
||||
}{
|
||||
{
|
||||
database.TargetTypeHTTP,
|
||||
"name=private&url=" + editBlockedURL +
|
||||
"&timeout=12&max_retries=3",
|
||||
"Invalid target URL",
|
||||
},
|
||||
{
|
||||
database.TargetTypeSlack, "name=no-url&max_retries=4",
|
||||
"Webhook URL is required for Slack targets",
|
||||
},
|
||||
{
|
||||
database.TargetTypeDatabase, "name=archive&expiry=7d",
|
||||
"Invalid archive expiry",
|
||||
},
|
||||
{database.TargetTypeLog, "name=", "Name is required"},
|
||||
}
|
||||
|
||||
for _, tc := range cases {
|
||||
t.Run(string(tc.targetType), func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
webhook := seedWebhookWithRetention(t, env.db, 30)
|
||||
|
||||
typed, err := url.ParseQuery(tc.fields)
|
||||
require.NoError(t, err)
|
||||
|
||||
form := url.Values{}
|
||||
form.Set("type", string(tc.targetType))
|
||||
|
||||
for field := range typed {
|
||||
form.Set(field, typed.Get(field))
|
||||
}
|
||||
|
||||
w := serveTarget(
|
||||
env, http.MethodPost,
|
||||
"/hook/"+webhook.ID+"/targets", form,
|
||||
)
|
||||
assert.Equal(t, http.StatusBadRequest, w.Code)
|
||||
|
||||
page := w.Body.String()
|
||||
assert.Contains(
|
||||
t, page, `data-type="`+string(tc.targetType)+`"`,
|
||||
)
|
||||
assert.Contains(t, page, html.EscapeString(tc.reason))
|
||||
|
||||
// Each value comes back in a data attribute of the targets
|
||||
// section named after its field (max_retries as
|
||||
// data-max-retries), except url, which comes back in
|
||||
// data-destination; templates/source_detail.html says why.
|
||||
for field := range typed {
|
||||
attr := "data-" + strings.ReplaceAll(field, "_", "-")
|
||||
if field == "url" {
|
||||
attr = "data-destination"
|
||||
}
|
||||
|
||||
assert.Contains(
|
||||
t, page, attr+`="`+
|
||||
html.EscapeString(typed.Get(field))+`"`,
|
||||
)
|
||||
}
|
||||
|
||||
assert.Empty(t, targetsForWebhook(t, env.db, webhook.ID))
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -1,121 +0,0 @@
|
||||
package handlers
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"net/http"
|
||||
"time"
|
||||
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/delivery"
|
||||
)
|
||||
|
||||
// downloadWriteTimeout is how long one write of a download may wait
|
||||
// for a client that has stopped reading.
|
||||
const downloadWriteTimeout = 60 * time.Second
|
||||
|
||||
// HandleTargetDownload serves a database target's archive as one
|
||||
// gzipped JSON file, named for the webhook, the target and the time;
|
||||
// see delivery.ArchiveExport.WriteGzipJSON for what it holds. Other
|
||||
// target types have no archive and are a 404.
|
||||
//
|
||||
// A download runs for as long as the client keeps reading: it reads
|
||||
// under a context the request limit does not cancel, and gives each
|
||||
// write its own deadline in place of the server's write timeout. It
|
||||
// stops when a write fails.
|
||||
func (h *Handlers) HandleTargetDownload() http.HandlerFunc {
|
||||
return func(w http.ResponseWriter, r *http.Request) {
|
||||
ctx := context.WithoutCancel(r.Context())
|
||||
|
||||
webhook, target, export, ok := h.openTargetArchive(ctx, w, r)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
|
||||
defer func() { _ = export.Close() }()
|
||||
|
||||
now := time.Now()
|
||||
|
||||
w.Header().Set("Content-Type", "application/gzip")
|
||||
w.Header().Set(
|
||||
"Content-Disposition",
|
||||
`attachment; filename="`+delivery.ArchiveExportFileName(
|
||||
webhook.Name, target.Name, now,
|
||||
)+`"`,
|
||||
)
|
||||
|
||||
err := export.WriteGzipJSON(
|
||||
ctx,
|
||||
downloadWriter{w: w, rc: http.NewResponseController(w)},
|
||||
&webhook, target, now,
|
||||
)
|
||||
if err != nil {
|
||||
h.log.Error(
|
||||
"failed to export archive",
|
||||
"target_id", target.ID,
|
||||
"error", err,
|
||||
)
|
||||
|
||||
// The 200 has gone out. Aborting the connection is what
|
||||
// tells the client the file is incomplete.
|
||||
panic(http.ErrAbortHandler)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// downloadWriter writes a download to the client, giving each write
|
||||
// downloadWriteTimeout to finish.
|
||||
type downloadWriter struct {
|
||||
w http.ResponseWriter
|
||||
rc *http.ResponseController
|
||||
}
|
||||
|
||||
func (d downloadWriter) Write(b []byte) (int, error) {
|
||||
// A writer that has no write deadline, such as a test's recorder,
|
||||
// answers http.ErrNotSupported and needs none extended.
|
||||
err := d.rc.SetWriteDeadline(time.Now().Add(downloadWriteTimeout))
|
||||
if err != nil && !errors.Is(err, http.ErrNotSupported) {
|
||||
return 0, err
|
||||
}
|
||||
|
||||
return d.w.Write(b)
|
||||
}
|
||||
|
||||
// openTargetArchive opens the archive of the request's database target
|
||||
// for export, with its reads under ctx. It reports false once it has
|
||||
// written the response.
|
||||
//
|
||||
// It holds renameMu, which every archive rename runs under, while it
|
||||
// reads the stored names and opens the file, so the file it opens is
|
||||
// the one those names give. It lets go before the export is streamed:
|
||||
// once the file is open, a rename does not affect the export.
|
||||
func (h *Handlers) openTargetArchive(
|
||||
ctx context.Context,
|
||||
w http.ResponseWriter,
|
||||
r *http.Request,
|
||||
) (database.Webhook, *database.Target, *delivery.ArchiveExport, bool) {
|
||||
h.renameMu.Lock()
|
||||
defer h.renameMu.Unlock()
|
||||
|
||||
webhook, target, ok := h.ownedTarget(w, r)
|
||||
if !ok {
|
||||
return database.Webhook{}, nil, nil, false
|
||||
}
|
||||
|
||||
if target.Type != database.TargetTypeDatabase {
|
||||
h.renderError(w, r, http.StatusNotFound)
|
||||
|
||||
return database.Webhook{}, nil, nil, false
|
||||
}
|
||||
|
||||
export, err := delivery.OpenArchiveExport(
|
||||
ctx, delivery.ArchivePath(h.dbMgr, &webhook, target), h.log,
|
||||
)
|
||||
if err != nil {
|
||||
h.serverError(w, r, "failed to open archive for export", err)
|
||||
|
||||
return database.Webhook{}, nil, nil, false
|
||||
}
|
||||
|
||||
return webhook, target, export, true
|
||||
}
|
||||
@@ -1,379 +0,0 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"compress/gzip"
|
||||
"context"
|
||||
"crypto/rand"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"io"
|
||||
"log/slog"
|
||||
"net"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"net/url"
|
||||
"sync"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"sneak.berlin/go/webhooker/internal/config"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/delivery"
|
||||
"sneak.berlin/go/webhooker/internal/middleware"
|
||||
)
|
||||
|
||||
// errClientGone is the write failure of a client that has gone away.
|
||||
var errClientGone = errors.New("client gone")
|
||||
|
||||
// downloadPath is the archive download route of a target.
|
||||
func downloadPath(webhookID, targetID string) string {
|
||||
return "/hook/" + webhookID + "/targets/" + targetID + "/download"
|
||||
}
|
||||
|
||||
// renameTarget submits the edit form renaming a target to Renamed.
|
||||
func renameTarget(
|
||||
env *sourceTestEnv, webhookID, targetID string,
|
||||
) *httptest.ResponseRecorder {
|
||||
form := url.Values{}
|
||||
form.Set("name", "Renamed")
|
||||
|
||||
return submitTargetEdit(env, webhookID, targetID, form)
|
||||
}
|
||||
|
||||
// TestHandleTargetDownload proves a database target's archive
|
||||
// downloads as a gzipped JSON attachment named for the webhook, the
|
||||
// target and the time, here with no archive file yet, so with no
|
||||
// rows; and that a target of another type has no download.
|
||||
func TestHandleTargetDownload(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSourceTest(t)
|
||||
wh := seedWebhookWithRetention(t, env.db, 7)
|
||||
archive := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
|
||||
logTarget := seedTarget(t, env.db, wh.ID, database.TargetTypeLog)
|
||||
|
||||
w := serveTarget(
|
||||
env, http.MethodGet, downloadPath(wh.ID, archive.ID), nil,
|
||||
)
|
||||
require.Equal(t, http.StatusOK, w.Code, w.Body.String())
|
||||
assert.Equal(t, "application/gzip", w.Header().Get("Content-Type"))
|
||||
assert.Regexp(t,
|
||||
`^attachment; filename="archive-seeded-t-database-`+
|
||||
`\d{8}T\d{6}Z\.json\.gz"$`,
|
||||
w.Header().Get("Content-Disposition"),
|
||||
)
|
||||
|
||||
zr, err := gzip.NewReader(w.Body)
|
||||
require.NoError(t, err)
|
||||
|
||||
var got map[string]json.RawMessage
|
||||
|
||||
require.NoError(t, json.NewDecoder(zr).Decode(&got))
|
||||
assert.JSONEq(t,
|
||||
`{"id":"`+archive.ID+`","name":"t-database"}`,
|
||||
string(got["target"]),
|
||||
)
|
||||
assert.JSONEq(t, `[]`, string(got["archived_events"]))
|
||||
|
||||
w = serveTarget(
|
||||
env, http.MethodGet, downloadPath(wh.ID, logTarget.ID), nil,
|
||||
)
|
||||
assert.Equal(t, http.StatusNotFound, w.Code)
|
||||
}
|
||||
|
||||
// TestHandleTargetDownload_WaitsForRename proves a download reads the
|
||||
// target's names and opens its archive under the lock a rename holds:
|
||||
// started while an edit is renaming the archive, it waits, and is
|
||||
// named for the target's new name.
|
||||
func TestHandleTargetDownload_WaitsForRename(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSourceTest(t)
|
||||
wh := seedWebhookWithRetention(t, env.db, 7)
|
||||
archive := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
|
||||
|
||||
renaming, release := env.archives.BlockNextRename()
|
||||
edited := make(chan *httptest.ResponseRecorder, 1)
|
||||
|
||||
go func() {
|
||||
edited <- renameTarget(env, wh.ID, archive.ID)
|
||||
}()
|
||||
|
||||
<-renaming
|
||||
|
||||
downloaded := make(chan *httptest.ResponseRecorder, 1)
|
||||
|
||||
go func() {
|
||||
downloaded <- serveTarget(
|
||||
env, http.MethodGet, downloadPath(wh.ID, archive.ID), nil,
|
||||
)
|
||||
}()
|
||||
|
||||
select {
|
||||
case <-downloaded:
|
||||
release()
|
||||
t.Fatal("the download did not wait for the rename")
|
||||
case <-time.After(100 * time.Millisecond):
|
||||
}
|
||||
|
||||
release()
|
||||
require.Equal(t, http.StatusSeeOther, (<-edited).Code)
|
||||
|
||||
w := <-downloaded
|
||||
require.Equal(t, http.StatusOK, w.Code)
|
||||
assert.Contains(t,
|
||||
w.Header().Get("Content-Disposition"), "archive-seeded-renamed-",
|
||||
)
|
||||
}
|
||||
|
||||
// stalledWriter is a response writer whose first write waits until
|
||||
// resume is closed, closing writing when it starts to wait.
|
||||
type stalledWriter struct {
|
||||
*httptest.ResponseRecorder
|
||||
|
||||
once sync.Once
|
||||
writing chan struct{}
|
||||
resume chan struct{}
|
||||
}
|
||||
|
||||
func (s *stalledWriter) Write(b []byte) (int, error) {
|
||||
s.once.Do(func() {
|
||||
close(s.writing)
|
||||
<-s.resume
|
||||
})
|
||||
|
||||
return s.ResponseRecorder.Write(b)
|
||||
}
|
||||
|
||||
// TestHandleTargetDownload_StreamsWithoutTheLock proves a download
|
||||
// lets go of the rename lock once its archive is open: while the
|
||||
// download is stalled writing, an edit can still rename the target.
|
||||
func TestHandleTargetDownload_StreamsWithoutTheLock(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSourceTest(t)
|
||||
wh := seedWebhookWithRetention(t, env.db, 7)
|
||||
archive := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
|
||||
|
||||
req := httptest.NewRequestWithContext(
|
||||
t.Context(), http.MethodGet, downloadPath(wh.ID, archive.ID), nil,
|
||||
)
|
||||
for _, c := range env.cookies {
|
||||
req.AddCookie(c)
|
||||
}
|
||||
|
||||
sw := &stalledWriter{
|
||||
ResponseRecorder: httptest.NewRecorder(),
|
||||
writing: make(chan struct{}),
|
||||
resume: make(chan struct{}),
|
||||
}
|
||||
downloaded := make(chan struct{})
|
||||
|
||||
go func() {
|
||||
targetRouter(env).ServeHTTP(sw, req)
|
||||
close(downloaded)
|
||||
}()
|
||||
|
||||
<-sw.writing
|
||||
|
||||
edited := make(chan *httptest.ResponseRecorder, 1)
|
||||
|
||||
go func() {
|
||||
edited <- renameTarget(env, wh.ID, archive.ID)
|
||||
}()
|
||||
|
||||
select {
|
||||
case w := <-edited:
|
||||
assert.Equal(t, http.StatusSeeOther, w.Code)
|
||||
case <-time.After(10 * time.Second):
|
||||
t.Error("the rename waited for the download")
|
||||
}
|
||||
|
||||
close(sw.resume)
|
||||
<-downloaded
|
||||
assert.Equal(t, http.StatusOK, sw.Code)
|
||||
}
|
||||
|
||||
// seedArchive writes rows to the archive file at path, each with a
|
||||
// body of bodySize random bytes, which do not compress. Its table has
|
||||
// only the columns the test fills; an export writes the others empty.
|
||||
func seedArchive(t *testing.T, path string, rows, bodySize int) {
|
||||
t.Helper()
|
||||
|
||||
db, err := database.OpenSQLite(path, database.SQLiteModeCreate)
|
||||
require.NoError(t, err)
|
||||
|
||||
defer func() { require.NoError(t, db.Close()) }()
|
||||
|
||||
_, err = db.ExecContext(t.Context(),
|
||||
"CREATE TABLE archived_events (id INTEGER PRIMARY KEY, body TEXT)",
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
body := make([]byte, bodySize)
|
||||
|
||||
for range rows {
|
||||
_, _ = rand.Read(body)
|
||||
|
||||
_, err = db.ExecContext(t.Context(),
|
||||
"INSERT INTO archived_events (body) VALUES (?)", string(body),
|
||||
)
|
||||
require.NoError(t, err)
|
||||
}
|
||||
}
|
||||
|
||||
// limitedServer serves the target routes as the server does, behind the
|
||||
// access log, whose lines it returns, and the request limit, here
|
||||
// limit, which is also its write timeout. Each connection's send buffer
|
||||
// is a few KiB, so a larger response is still being written while its
|
||||
// client is not reading.
|
||||
func limitedServer(
|
||||
t *testing.T, env *sourceTestEnv, limit time.Duration,
|
||||
) (*httptest.Server, *bytes.Buffer) {
|
||||
t.Helper()
|
||||
|
||||
const sendBuffer = 4 << 10
|
||||
|
||||
logBuf := new(bytes.Buffer)
|
||||
mw := middleware.NewForTest(
|
||||
slog.New(slog.NewJSONHandler(logBuf, nil)),
|
||||
&config.Config{Environment: config.EnvironmentDev},
|
||||
nil,
|
||||
)
|
||||
|
||||
srv := httptest.NewUnstartedServer(
|
||||
mw.Logging()(mw.Timeout(limit)(targetRouter(env))),
|
||||
)
|
||||
srv.Config.WriteTimeout = limit
|
||||
srv.Config.ConnContext = func(
|
||||
ctx context.Context, c net.Conn,
|
||||
) context.Context {
|
||||
tcp, ok := c.(*net.TCPConn)
|
||||
if assert.True(t, ok) {
|
||||
assert.NoError(t, tcp.SetWriteBuffer(sendBuffer))
|
||||
}
|
||||
|
||||
return ctx
|
||||
}
|
||||
srv.Start()
|
||||
t.Cleanup(srv.Close)
|
||||
|
||||
return srv, logBuf
|
||||
}
|
||||
|
||||
// TestHandleTargetDownload_OutlastsTheRequestLimit proves a download
|
||||
// runs for as long as the client keeps reading, and is logged as the
|
||||
// 200 it was. Behind a request limit and a server write timeout of a
|
||||
// tenth of a second, the client stops reading once the response has
|
||||
// started, waits three times as long, and still gets the whole file.
|
||||
// The archive is larger than the connection holds, so the download is
|
||||
// still being written while the client waits.
|
||||
func TestHandleTargetDownload_OutlastsTheRequestLimit(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
const (
|
||||
limit = 100 * time.Millisecond
|
||||
rows = 8
|
||||
bodySize = 64 << 10
|
||||
)
|
||||
|
||||
env := setupSourceTest(t)
|
||||
wh := seedWebhookWithRetention(t, env.db, 7)
|
||||
archive := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
|
||||
seedArchive(
|
||||
t, delivery.ArchivePath(env.dbMgr, &wh, archive), rows, bodySize,
|
||||
)
|
||||
|
||||
srv, accessLog := limitedServer(t, env, limit)
|
||||
|
||||
req, err := http.NewRequestWithContext(
|
||||
t.Context(), http.MethodGet,
|
||||
srv.URL+downloadPath(wh.ID, archive.ID), nil,
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
for _, c := range env.cookies {
|
||||
req.AddCookie(c)
|
||||
}
|
||||
|
||||
resp, err := srv.Client().Do(req)
|
||||
require.NoError(t, err)
|
||||
|
||||
defer func() { _ = resp.Body.Close() }()
|
||||
|
||||
require.Equal(t, http.StatusOK, resp.StatusCode)
|
||||
|
||||
time.Sleep(3 * limit)
|
||||
|
||||
zr, err := gzip.NewReader(resp.Body)
|
||||
require.NoError(t, err)
|
||||
|
||||
var (
|
||||
got map[string]json.RawMessage
|
||||
events []json.RawMessage
|
||||
)
|
||||
|
||||
require.NoError(t, json.NewDecoder(zr).Decode(&got))
|
||||
require.NoError(t, json.Unmarshal(got["archived_events"], &events))
|
||||
assert.Len(t, events, rows)
|
||||
|
||||
// Reading to the end makes the gzip reader check that the file was
|
||||
// finished.
|
||||
_, err = io.ReadAll(zr)
|
||||
require.NoError(t, err)
|
||||
|
||||
// Close waits for the handler, so the access log line is written.
|
||||
srv.Close()
|
||||
|
||||
var access map[string]any
|
||||
|
||||
require.NoError(t, json.Unmarshal(accessLog.Bytes(), &access))
|
||||
assert.EqualValues(t, http.StatusOK, access["status"])
|
||||
assert.GreaterOrEqual(t,
|
||||
access["latency_ms"], float64(limit.Milliseconds()),
|
||||
"the download must outlast the request limit",
|
||||
)
|
||||
}
|
||||
|
||||
// brokenWriter is a response writer whose writes fail once the
|
||||
// response has started, as they do when the client goes away.
|
||||
type brokenWriter struct {
|
||||
*httptest.ResponseRecorder
|
||||
}
|
||||
|
||||
func (b brokenWriter) Write(p []byte) (int, error) {
|
||||
if b.Body.Len() > 0 {
|
||||
return 0, errClientGone
|
||||
}
|
||||
|
||||
return b.ResponseRecorder.Write(p)
|
||||
}
|
||||
|
||||
// TestHandleTargetDownload_AbortsWhenItFails proves a download that
|
||||
// fails after its response has started aborts the connection, so the
|
||||
// client sees a failed download rather than a file that looks
|
||||
// complete and does not decompress.
|
||||
func TestHandleTargetDownload_AbortsWhenItFails(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := setupSourceTest(t)
|
||||
wh := seedWebhookWithRetention(t, env.db, 7)
|
||||
archive := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
|
||||
|
||||
req := httptest.NewRequestWithContext(
|
||||
t.Context(), http.MethodGet, downloadPath(wh.ID, archive.ID), nil,
|
||||
)
|
||||
for _, c := range env.cookies {
|
||||
req.AddCookie(c)
|
||||
}
|
||||
|
||||
w := brokenWriter{ResponseRecorder: httptest.NewRecorder()}
|
||||
|
||||
assert.PanicsWithValue(t, http.ErrAbortHandler, func() {
|
||||
targetRouter(env).ServeHTTP(w, req)
|
||||
})
|
||||
assert.Equal(t, http.StatusOK, w.Code)
|
||||
}
|
||||
@@ -120,23 +120,18 @@ func (h *Handlers) applyTargetEdit(
|
||||
) {
|
||||
name := r.PostFormValue("name")
|
||||
if name == "" {
|
||||
http.Error(w, "Name is required", http.StatusBadRequest)
|
||||
http.Error(
|
||||
w, "Name is required", http.StatusBadRequest,
|
||||
)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
configJSON, errMsg, err := h.buildTargetConfig(
|
||||
r.Context(), target.Type, targetFormInputFrom(r),
|
||||
configJSON, err := h.buildTargetConfig(
|
||||
w, r, target.Type, targetFormInputFrom(r),
|
||||
)
|
||||
if err != nil {
|
||||
h.serverError(w, r, "failed to encode target config", err)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
if errMsg != "" {
|
||||
http.Error(w, errMsg, http.StatusBadRequest)
|
||||
|
||||
// buildTargetConfig has already written the response.
|
||||
return
|
||||
}
|
||||
|
||||
|
||||
@@ -37,18 +37,14 @@ const (
|
||||
editAuthHeader = "Authorization: Bearer " + editBearerSecret
|
||||
)
|
||||
|
||||
// targetRouter mounts the target create, edit and download routes on
|
||||
// a chi router so the handlers see the URL parameters they read.
|
||||
// targetRouter mounts the target create and edit routes on a chi
|
||||
// router so the handlers see the URL parameters they read.
|
||||
func targetRouter(env *sourceTestEnv) *chi.Mux {
|
||||
router := chi.NewRouter()
|
||||
router.Post(
|
||||
"/hook/{sourceID}/targets",
|
||||
env.handlers.HandleTargetCreate(),
|
||||
)
|
||||
router.Get(
|
||||
"/hook/{sourceID}/targets/{targetID}/download",
|
||||
env.handlers.HandleTargetDownload(),
|
||||
)
|
||||
router.Get(
|
||||
"/hook/{sourceID}/targets/{targetID}/edit",
|
||||
env.handlers.HandleTargetEdit(),
|
||||
|
||||
@@ -1,180 +0,0 @@
|
||||
package handlers
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"io/fs"
|
||||
"path/filepath"
|
||||
"time"
|
||||
|
||||
"github.com/dustin/go-humanize"
|
||||
"gorm.io/gorm"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/delivery"
|
||||
)
|
||||
|
||||
// TargetRowView is one row of the target list on a webhook's page.
|
||||
type TargetRowView struct {
|
||||
delivery.TargetView
|
||||
|
||||
// Deliveries counts the target's delivered and failed deliveries,
|
||||
// and is nil when the webhook's event database could not be read.
|
||||
Deliveries *TargetDeliveries
|
||||
|
||||
// Archive is a database target's archive file, and nil for a target
|
||||
// of any other type.
|
||||
Archive *ArchiveFileView
|
||||
}
|
||||
|
||||
// TargetDeliveries is how many of a target's deliveries became
|
||||
// delivered and how many failed: in total, which retention does not
|
||||
// reduce, and in the last 24 hours. Deliveries still pending or
|
||||
// retrying count in neither.
|
||||
type TargetDeliveries struct {
|
||||
Delivered int64
|
||||
Failed int64
|
||||
|
||||
DeliveredLast24Hours int64
|
||||
FailedLast24Hours int64
|
||||
}
|
||||
|
||||
// ArchiveFileView is what a database target's row shows about its
|
||||
// archive file.
|
||||
type ArchiveFileView struct {
|
||||
Name string
|
||||
|
||||
// Note stands in for the size and the last write when there are
|
||||
// none to show, and is empty when there are.
|
||||
Note string
|
||||
|
||||
// Size is the size on disk. Written is how long ago the file was
|
||||
// last written, and WrittenUTC the full time the page shows on
|
||||
// hover.
|
||||
Size string
|
||||
Written string
|
||||
WrittenUTC string
|
||||
}
|
||||
|
||||
// targetRows projects a webhook's targets for the target list on its
|
||||
// page.
|
||||
func (h *Handlers) targetRows(
|
||||
webhook *database.Webhook, targets []database.Target,
|
||||
) []TargetRowView {
|
||||
views := delivery.NewTargetViews(targets)
|
||||
rows := make([]TargetRowView, len(views))
|
||||
|
||||
deliveries, err := h.loadTargetDeliveries(webhook.ID)
|
||||
if err != nil {
|
||||
h.log.Error(
|
||||
"failed to read target delivery counts",
|
||||
"webhook_id", webhook.ID,
|
||||
"error", err,
|
||||
)
|
||||
}
|
||||
|
||||
// NewTargetViews returns one view per target, in order.
|
||||
for i := range views {
|
||||
rows[i].TargetView = views[i]
|
||||
|
||||
if err == nil {
|
||||
counts := deliveries[targets[i].ID]
|
||||
rows[i].Deliveries = &counts
|
||||
}
|
||||
|
||||
if targets[i].Type == database.TargetTypeDatabase {
|
||||
rows[i].Archive = h.archiveFileView(webhook, &targets[i])
|
||||
}
|
||||
}
|
||||
|
||||
return rows
|
||||
}
|
||||
|
||||
// loadTargetDeliveries reads the delivery counts of a webhook's targets
|
||||
// from its event database, keyed by target. A target with no deliveries
|
||||
// is left out, and so is every target when the event database does not
|
||||
// exist yet, since opening it would create it.
|
||||
func (h *Handlers) loadTargetDeliveries(
|
||||
webhookID string,
|
||||
) (map[string]TargetDeliveries, error) {
|
||||
if !h.dbMgr.DBExists(webhookID) {
|
||||
return map[string]TargetDeliveries{}, nil
|
||||
}
|
||||
|
||||
webhookDB, err := h.dbMgr.GetDB(webhookID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
return readTargetDeliveries(webhookDB, time.Now())
|
||||
}
|
||||
|
||||
// readTargetDeliveries counts each target's deliveries that became
|
||||
// delivered and those that failed: in total from the targets' running
|
||||
// totals, and in the 24 hours before now from the deliveries' status
|
||||
// index. Each is one query for all the targets, and neither reads every
|
||||
// stored delivery.
|
||||
func readTargetDeliveries(
|
||||
db *gorm.DB, now time.Time,
|
||||
) (map[string]TargetDeliveries, error) {
|
||||
var totals []database.TargetTotals
|
||||
|
||||
err := db.Find(&totals).Error
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("reading target totals: %w", err)
|
||||
}
|
||||
|
||||
lastDay, err := finishedByTarget(db, now.Add(-longWindow))
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
byTarget := make(map[string]TargetDeliveries, len(totals))
|
||||
|
||||
for _, total := range totals {
|
||||
byTarget[total.TargetID] = TargetDeliveries{
|
||||
Delivered: total.Delivered,
|
||||
Failed: total.Failed,
|
||||
}
|
||||
}
|
||||
|
||||
for _, finished := range lastDay {
|
||||
counts := byTarget[finished.TargetID]
|
||||
counts.DeliveredLast24Hours = finished.Delivered
|
||||
counts.FailedLast24Hours = finished.Failed
|
||||
byTarget[finished.TargetID] = counts
|
||||
}
|
||||
|
||||
return byTarget, nil
|
||||
}
|
||||
|
||||
// archiveFileView describes a database target's archive file from the
|
||||
// file's metadata alone; the archive is never opened. The file is found
|
||||
// by the name the archive writer uses, so it follows a rename of the
|
||||
// webhook or the target.
|
||||
func (h *Handlers) archiveFileView(
|
||||
webhook *database.Webhook, target *database.Target,
|
||||
) *ArchiveFileView {
|
||||
path := delivery.ArchivePath(h.dbMgr, webhook, target)
|
||||
view := &ArchiveFileView{Name: filepath.Base(path)}
|
||||
|
||||
file, err := delivery.StatArchive(path)
|
||||
|
||||
switch {
|
||||
case errors.Is(err, fs.ErrNotExist):
|
||||
view.Note = "not created yet"
|
||||
case err != nil:
|
||||
h.log.Error(
|
||||
"failed to read archive file metadata",
|
||||
"target_id", target.ID,
|
||||
"error", err,
|
||||
)
|
||||
|
||||
view.Note = "could not be read"
|
||||
default:
|
||||
view.Size = humanize.Bytes(uint64(file.Size)) //nolint:gosec // never negative
|
||||
view.Written = humanize.Time(file.Written)
|
||||
view.WrittenUTC = file.Written.UTC().Format(time.DateTime) + " UTC"
|
||||
}
|
||||
|
||||
return view
|
||||
}
|
||||
@@ -1,174 +0,0 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"os"
|
||||
"path/filepath"
|
||||
"regexp"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/delivery"
|
||||
"sneak.berlin/go/webhooker/internal/handlers"
|
||||
"sneak.berlin/go/webhooker/internal/logger"
|
||||
"sneak.berlin/go/webhooker/internal/session"
|
||||
)
|
||||
|
||||
// TestHandleSourceDetail_ShowsArchiveFile proves a database target's
|
||||
// row names its archive file and says "not created yet" before the
|
||||
// first write, adds the file's size and last write once it has one row,
|
||||
// and says "not created yet" again once the file has been moved away.
|
||||
// A target of another type shows no archive file.
|
||||
func TestHandleSourceDetail_ShowsArchiveFile(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
sess *session.Session
|
||||
db *database.Database
|
||||
dbMgr *database.WebhookDBManager
|
||||
)
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &dbMgr)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
wh := seedWebhook(t, db)
|
||||
archive := seedTarget(t, db, wh.ID, database.TargetTypeDatabase)
|
||||
seedTarget(t, db, wh.ID, database.TargetTypeLog)
|
||||
|
||||
path := delivery.ArchivePath(dbMgr, wh, archive)
|
||||
|
||||
body := renderSourceDetailPage(t, h, sess, wh.ID)
|
||||
assert.Equal(t, 1, strings.Count(body, "Archive File:"))
|
||||
assert.Contains(t, body, filepath.Base(path))
|
||||
assert.Contains(t, body, "not created yet")
|
||||
assert.NotContains(t, body, "Archive Size:")
|
||||
|
||||
seedArchive(t, path, 1, 100)
|
||||
|
||||
file, err := os.Stat(path)
|
||||
require.NoError(t, err)
|
||||
|
||||
body = renderSourceDetailPage(t, h, sess, wh.ID)
|
||||
assert.Contains(t, body, filepath.Base(path))
|
||||
assert.NotContains(t, body, "not created yet")
|
||||
assert.Regexp(t,
|
||||
`Archive Size:</span>\s*<span>[1-9][0-9.]* [kM]?B</span>`, body,
|
||||
)
|
||||
assert.Contains(t, body,
|
||||
`title="`+file.ModTime().UTC().Format(time.DateTime)+` UTC"`,
|
||||
)
|
||||
|
||||
require.NoError(t, os.Rename(path, filepath.Join(t.TempDir(), "moved.db")))
|
||||
|
||||
body = renderSourceDetailPage(t, h, sess, wh.ID)
|
||||
assert.Contains(t, body, filepath.Base(path))
|
||||
assert.Contains(t, body, "not created yet")
|
||||
assert.NotContains(t, body, "Archive Size:")
|
||||
}
|
||||
|
||||
// targetList returns the text of the targets section in a rendered
|
||||
// webhook page, from its heading to the next heading, with the markup
|
||||
// taken out and each run of space made one space. Each target's row
|
||||
// then reads as its name, type, state and buttons, followed by the
|
||||
// lines below them.
|
||||
func targetList(t *testing.T, page string) string {
|
||||
t.Helper()
|
||||
|
||||
_, list, found := strings.Cut(page, ">Targets</h2>")
|
||||
require.True(t, found, "the page has no targets section")
|
||||
|
||||
list, _, _ = strings.Cut(list, "<h2")
|
||||
list = regexp.MustCompile(`<[^>]*>`).ReplaceAllString(list, " ")
|
||||
|
||||
return strings.Join(strings.Fields(list), " ")
|
||||
}
|
||||
|
||||
// TestHandleSourceDetail_ShowsTargetDeliveries checks each target row's
|
||||
// delivered and failed deliveries, in total and in the last 24 hours,
|
||||
// for the history seedStatsHistory builds, before and after the real
|
||||
// retention reaper removes the oldest event. The http target has one
|
||||
// delivered, one of them in the last 24 hours, and three failed, one of
|
||||
// them in the last 24 hours and one of them the oldest event's, which
|
||||
// retention removes without changing the total. The active log target
|
||||
// has two failed, both in the last 24 hours, and its pending and
|
||||
// retrying deliveries count in neither. The four inactive log targets
|
||||
// have none.
|
||||
func TestHandleSourceDetail_ShowsTargetDeliveries(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
sess *session.Session
|
||||
db *database.Database
|
||||
dbMgr *database.WebhookDBManager
|
||||
log *logger.Logger
|
||||
)
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &dbMgr, &log)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
hist := seedStatsHistory(t, h, sess, db, dbMgr)
|
||||
|
||||
const (
|
||||
httpRow = "Delivered: 1 in total, 1 in the last 24 hours " +
|
||||
"Failed: 3 in total, 1 in the last 24 hours"
|
||||
activeLogRow = "t-log log Active Edit Deactivate Delete " +
|
||||
"Delivered: 0 in total, 0 in the last 24 hours " +
|
||||
"Failed: 2 in total, 2 in the last 24 hours"
|
||||
inactiveLogRow = "t-log log Inactive Edit Activate Delete " +
|
||||
"Delivered: 0 in total, 0 in the last 24 hours " +
|
||||
"Failed: 0 in total, 0 in the last 24 hours"
|
||||
)
|
||||
|
||||
list := targetList(t, renderSourceDetailPage(t, h, sess, hist.webhook.ID))
|
||||
assert.Equal(t, 1, strings.Count(list, httpRow))
|
||||
assert.Equal(t, 1, strings.Count(list, activeLogRow))
|
||||
assert.Equal(t, 4, strings.Count(list, inactiveLogRow))
|
||||
|
||||
statsPrune(t, db, dbMgr, log, hist.webhookDB)
|
||||
|
||||
list = targetList(t, renderSourceDetailPage(t, h, sess, hist.webhook.ID))
|
||||
assert.Equal(t, 1, strings.Count(list, httpRow))
|
||||
assert.Equal(t, 1, strings.Count(list, activeLogRow))
|
||||
assert.Equal(t, 4, strings.Count(list, inactiveLogRow))
|
||||
}
|
||||
|
||||
// TestHandleSourceDetail_TargetDeliveriesUnreadable checks that when the
|
||||
// webhook's event database cannot be read, each target's row says so
|
||||
// instead of showing zeros.
|
||||
func TestHandleSourceDetail_TargetDeliveriesUnreadable(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
sess *session.Session
|
||||
db *database.Database
|
||||
dbMgr *database.WebhookDBManager
|
||||
)
|
||||
|
||||
app := newTestApp(t, &h, &sess, &db, &dbMgr)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
wh := seedWebhook(t, db)
|
||||
seedTarget(t, db, wh.ID, database.TargetTypeLog)
|
||||
|
||||
webhookDB, err := dbMgr.GetDB(wh.ID)
|
||||
require.NoError(t, err)
|
||||
require.NoError(t,
|
||||
webhookDB.Migrator().DropTable(&database.TargetTotals{}))
|
||||
|
||||
list := targetList(t, renderSourceDetailPage(t, h, sess, wh.ID))
|
||||
assert.Contains(t, list, "t-log log Active Edit Deactivate Delete "+
|
||||
"The delivery counts could not be read.")
|
||||
assert.NotContains(t, list, "Delivered:")
|
||||
}
|
||||
@@ -1,7 +1,6 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"html"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"testing"
|
||||
@@ -44,16 +43,12 @@ func TestTargetRefusal_PrivateDestinationSaysHowToAllowIt(
|
||||
form.Set("type", string(targetType))
|
||||
form.Set("url", editBlockedURL)
|
||||
|
||||
// A refused add shows the webhook page again, where
|
||||
// the hint is HTML-escaped; a refused edit answers in
|
||||
// plain text.
|
||||
added := serveTarget(
|
||||
env, http.MethodPost, targetsPath, form,
|
||||
)
|
||||
assert.Equal(t, http.StatusBadRequest, added.Code)
|
||||
assert.Contains(
|
||||
t, added.Body.String(),
|
||||
html.EscapeString(privateRefusalHint),
|
||||
t, added.Body.String(), privateRefusalHint,
|
||||
)
|
||||
|
||||
form.Set("url", editOriginalURL)
|
||||
|
||||
@@ -90,14 +90,13 @@ func retriesErrorMessage(err error) string {
|
||||
", or 0 for fire-and-forget"
|
||||
}
|
||||
|
||||
// targetMaxRetries reads and validates max_retries from a target edit
|
||||
// targetMaxRetries reads and validates max_retries from a target form
|
||||
// submission, answering the request with a 400 and reporting false
|
||||
// when the value is set but invalid.
|
||||
//
|
||||
// It and the create path (newTarget) both use parseMaxRetries and
|
||||
// retriesErrorMessage, so the two cannot come to disagree about what a
|
||||
// valid retry count is. The wording matches the timeout control on
|
||||
// the same submission.
|
||||
// Both the create and the edit path go through here, so the two
|
||||
// cannot come to disagree about what a valid retry count is. The
|
||||
// wording matches the timeout control on the same submission.
|
||||
func targetMaxRetries(
|
||||
w http.ResponseWriter,
|
||||
r *http.Request,
|
||||
|
||||
@@ -82,9 +82,9 @@ func TestNavbarUsesWebhookTerminology(t *testing.T) {
|
||||
})
|
||||
|
||||
assert.Contains(t, body, "Retention: 14 days")
|
||||
assert.Contains(t, body, `class="btn-secondary">Webhooks</a>`)
|
||||
assert.Contains(t, body, `class="btn-text">Webhooks</a>`)
|
||||
assert.Contains(
|
||||
t, body, `class="btn-secondary w-full">Webhooks</a>`,
|
||||
t, body, `class="btn-text w-full text-left">Webhooks</a>`,
|
||||
)
|
||||
assert.Contains(
|
||||
t, body,
|
||||
@@ -163,7 +163,7 @@ func TestEventLogPageIsCalledFullEventLog(t *testing.T) {
|
||||
)
|
||||
assert.Contains(
|
||||
t, detailBody,
|
||||
`<a href="/hook/wh-1/events" class="btn-small">Full Event Log</a>`,
|
||||
`<a href="/hook/wh-1/events" class="btn-text text-sm">Full Event Log</a>`,
|
||||
"the link under recent events",
|
||||
)
|
||||
|
||||
@@ -196,6 +196,8 @@ func TestCreateFormRetentionCopyMatchesBehaviour(t *testing.T) {
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
body := renderPage(t, h, sess, "sources_new.html", map[string]any{
|
||||
"Name": "",
|
||||
"Description": "",
|
||||
"DefaultRetentionDays": database.DefaultRetentionDays,
|
||||
dataKeyError: "",
|
||||
})
|
||||
@@ -329,9 +331,8 @@ func TestEntrypointCopyButtonIsProgressiveEnhancement(t *testing.T) {
|
||||
assert.Contains(t, body, "https://hooks.example.com/h/abc123")
|
||||
assert.Contains(
|
||||
t, body,
|
||||
`<button type="button" hidden data-copy-target="entrypoint-url-ep-1"`,
|
||||
"the copy control must be a button, start hidden and be "+
|
||||
"revealed by script",
|
||||
`hidden data-copy-target="entrypoint-url-ep-1"`,
|
||||
"the button must start hidden and be revealed by script",
|
||||
)
|
||||
|
||||
// renderTemplate streams to the ResponseWriter, so an abort
|
||||
|
||||
@@ -11,7 +11,6 @@ import (
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/delivery"
|
||||
"sneak.berlin/go/webhooker/internal/logfield"
|
||||
"sneak.berlin/go/webhooker/internal/middleware"
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -58,8 +57,7 @@ func (h *Handlers) HandleWebhook() http.HandlerFunc {
|
||||
h.log.Info("webhook request received",
|
||||
"entrypoint_uuid", entrypointUUID,
|
||||
"method", r.Method,
|
||||
"remoteIP", middleware.RemoteIP(r),
|
||||
"clientIP", middleware.ClientIP(r),
|
||||
"remote_addr", r.RemoteAddr,
|
||||
)
|
||||
|
||||
if !entrypoint.Active {
|
||||
@@ -272,12 +270,10 @@ func requestEventSource(
|
||||
|
||||
// createAndFanOut writes the event and one pending delivery per target,
|
||||
// and adds them to the webhook's running totals, in a single
|
||||
// transaction, then hands the tasks to the delivery engine. Every
|
||||
// event is created here, received or resubmitted, so a resubmitted
|
||||
// event is retried, SSRF-guarded and circuit-broken exactly as a
|
||||
// received one is. Per-delivery replay is the one other path that
|
||||
// creates a delivery: it adds one to an existing event without
|
||||
// coming through here.
|
||||
// transaction, then hands the tasks to the delivery engine. It is the
|
||||
// only path by which an event and its deliveries are created, so a
|
||||
// resubmitted event is retried, SSRF-guarded and circuit-broken
|
||||
// exactly as a received one is.
|
||||
//
|
||||
// The tasks are returned as well as queued, so a caller can report how
|
||||
// many targets the event went to.
|
||||
@@ -326,19 +322,6 @@ func (h *Handlers) createAndFanOut(
|
||||
return nil, nil, err
|
||||
}
|
||||
|
||||
// A resubmitted copy did not arrive on its entrypoint's URL, so it
|
||||
// leaves the entrypoint's last event as it is.
|
||||
if src.ResubmittedFromID == nil {
|
||||
err = database.AddEntrypointTotals(tx, database.EntrypointTotals{
|
||||
EntrypointID: event.EntrypointID, LastEventAt: event.CreatedAt,
|
||||
})
|
||||
if err != nil {
|
||||
tx.Rollback()
|
||||
|
||||
return nil, nil, err
|
||||
}
|
||||
}
|
||||
|
||||
err = tx.Commit().Error
|
||||
if err != nil {
|
||||
return nil, nil, fmt.Errorf(
|
||||
|
||||
@@ -1,124 +0,0 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"encoding/json"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"net/netip"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/go-chi/chi"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"sneak.berlin/go/webhooker/internal/config"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
"sneak.berlin/go/webhooker/internal/handlers"
|
||||
"sneak.berlin/go/webhooker/internal/middleware"
|
||||
)
|
||||
|
||||
// TestHandleWebhook_LogsClientNextToThePeer checks that the
|
||||
// receiver's "webhook request received" line carries both addresses:
|
||||
// remoteIP, the connecting peer, and clientIP, the client the access
|
||||
// log attributes the request to.
|
||||
func TestHandleWebhook_LogsClientNextToThePeer(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
// untrustedPeer is outside the trusted 10.0.0.0/8, so its
|
||||
// X-Forwarded-For is ignored and it is the client.
|
||||
const untrustedPeer = "192.0.2.10"
|
||||
|
||||
cases := map[string]struct {
|
||||
peer string
|
||||
wantRemote string
|
||||
wantClient string
|
||||
}{
|
||||
"trusted proxy with a forwarded chain": {
|
||||
peer: "10.0.0.1:44444",
|
||||
wantRemote: "10.0.0.1",
|
||||
wantClient: "198.51.100.7",
|
||||
},
|
||||
"untrusted peer": {
|
||||
peer: untrustedPeer + ":5555",
|
||||
wantRemote: untrustedPeer,
|
||||
wantClient: untrustedPeer,
|
||||
},
|
||||
}
|
||||
|
||||
for name, tc := range cases {
|
||||
t.Run(name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var (
|
||||
h *handlers.Handlers
|
||||
mw *middleware.Middleware
|
||||
db *database.Database
|
||||
)
|
||||
|
||||
app := newTestAppWithConfig(t, &config.Config{
|
||||
DataDir: t.TempDir(),
|
||||
TrustedProxies: []netip.Prefix{
|
||||
netip.MustParsePrefix("10.0.0.0/8"),
|
||||
},
|
||||
}, &h, &mw, &db)
|
||||
app.RequireStart()
|
||||
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
buf := new(bytes.Buffer)
|
||||
h.SetLogForTest(slog.New(slog.NewJSONHandler(buf, nil)))
|
||||
|
||||
webhook := seedWebhook(t, db)
|
||||
seedEntrypoint(t, db, webhook.ID)
|
||||
|
||||
// Logging is what works the client address out, so the
|
||||
// request goes through it as it does in production.
|
||||
router := chi.NewRouter()
|
||||
router.Use(mw.Logging())
|
||||
router.Post("/h/{uuid}", h.HandleWebhook())
|
||||
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(), http.MethodPost,
|
||||
"/h/ep-"+webhook.ID, strings.NewReader("{}"),
|
||||
)
|
||||
req.RemoteAddr = tc.peer
|
||||
req.Header.Set("X-Forwarded-For", "198.51.100.7, 10.0.0.2")
|
||||
|
||||
w := httptest.NewRecorder()
|
||||
router.ServeHTTP(w, req)
|
||||
|
||||
require.Equal(t, http.StatusOK, w.Code)
|
||||
|
||||
line := receivedLine(t, buf)
|
||||
assert.Equal(t, tc.wantRemote, line["remoteIP"])
|
||||
assert.Equal(t, tc.wantClient, line["clientIP"])
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// receivedLine returns the one "webhook request received" line in the
|
||||
// captured JSON log.
|
||||
func receivedLine(t *testing.T, buf *bytes.Buffer) map[string]any {
|
||||
t.Helper()
|
||||
|
||||
var found []map[string]any
|
||||
|
||||
for line := range strings.SplitSeq(
|
||||
strings.TrimSpace(buf.String()), "\n",
|
||||
) {
|
||||
var entry map[string]any
|
||||
|
||||
require.NoError(t, json.Unmarshal([]byte(line), &entry))
|
||||
|
||||
if entry["msg"] == "webhook request received" {
|
||||
found = append(found, entry)
|
||||
}
|
||||
}
|
||||
|
||||
require.Len(t, found, 1)
|
||||
|
||||
return found[0]
|
||||
}
|
||||
@@ -5,7 +5,6 @@ import (
|
||||
"io"
|
||||
"log/slog"
|
||||
"strings"
|
||||
"sync"
|
||||
"testing"
|
||||
"unicode/utf8"
|
||||
|
||||
@@ -19,11 +18,15 @@ import (
|
||||
// width.
|
||||
const budget = 64
|
||||
|
||||
// batchRunes is how many consecutive code points the charge test logs
|
||||
// in one value from U+1000 up. Logging each of those on its own line
|
||||
// is too slow for the suite under the race detector; 4,096 at a time
|
||||
// is 271 batches, each logged on two lines, so 542 lines per handler.
|
||||
const batchRunes = 4096
|
||||
// sampleRunes is how many runes wide the values in the charge test
|
||||
// are. The handlers add a constant per field — a pair of quotes when
|
||||
// the value needs quoting — so the per-rune charge is only visible
|
||||
// once it is amortised over a run of them.
|
||||
const sampleRunes = 64
|
||||
|
||||
// quotingSlack is that constant: the pair of quotes a handler adds to
|
||||
// a value that needs them and omits from one that does not.
|
||||
const quotingSlack = 2
|
||||
|
||||
// newHandlers are the two handlers internal/logger can install. Time
|
||||
// is dropped so a line's width is a function of its value alone —
|
||||
@@ -63,48 +66,46 @@ func renderedWidth(
|
||||
return buf.Len()
|
||||
}
|
||||
|
||||
// emittedBytes is what a handler writes for the runes of s alone, in a
|
||||
// value that starts with prefix: the width of a line carrying prefix
|
||||
// and then s twice, less that of a line carrying prefix and s once.
|
||||
// Both values start the same way and hold the same runes, so the text
|
||||
// handler quotes both or neither, and the quotes cancel along with the
|
||||
// prefix and everything else on the line.
|
||||
func emittedBytes(
|
||||
newHandler func(io.Writer) slog.Handler,
|
||||
prefix, s string,
|
||||
) int {
|
||||
return renderedWidth(newHandler, prefix+s+s) -
|
||||
renderedWidth(newHandler, prefix+s)
|
||||
}
|
||||
// chargeTestRunes is the set of code points the charge test measures:
|
||||
// every rune in the first two planes' worth of the BMP that the
|
||||
// handlers are most likely to treat specially, the separators that
|
||||
// only slog's JSON handler escapes, and a stratified sample across
|
||||
// the rest of Unicode so the astral charge is exercised on more than
|
||||
// one hand-picked rune.
|
||||
func chargeTestRunes() []rune {
|
||||
const (
|
||||
denseCeiling = 0x800
|
||||
stride = 1021
|
||||
surrogateLo = 0xD800
|
||||
surrogateHi = 0xDFFF
|
||||
)
|
||||
|
||||
// firstUndercharged returns the first rune in s that the handler
|
||||
// writes in more bytes than EncodedBytes charges for it, and how many
|
||||
// runes in s are undercharged that way. It measures one rune per line,
|
||||
// in a value of that rune alone and again after a space, which makes
|
||||
// the text handler quote the value. The charge test calls it on the
|
||||
// code points below U+1000, and from there up only on a batch that has
|
||||
// already failed, to name the code points rather than just their range.
|
||||
func firstUndercharged(
|
||||
newHandler func(io.Writer) slog.Handler,
|
||||
s string,
|
||||
) (rune, int) {
|
||||
first, count := rune(-1), 0
|
||||
var runes []rune
|
||||
|
||||
for _, r := range s {
|
||||
charge := logfield.EncodedBytes(r)
|
||||
if emittedBytes(newHandler, "", string(r)) <= charge &&
|
||||
emittedBytes(newHandler, " ", string(r)) <= charge {
|
||||
continue
|
||||
keep := func(r rune) {
|
||||
if r >= surrogateLo && r <= surrogateHi {
|
||||
return
|
||||
}
|
||||
|
||||
if count == 0 {
|
||||
first = r
|
||||
}
|
||||
|
||||
count++
|
||||
runes = append(runes, r)
|
||||
}
|
||||
|
||||
return first, count
|
||||
for r := range rune(denseCeiling) {
|
||||
keep(r)
|
||||
}
|
||||
|
||||
for _, r := range []rune{
|
||||
0x2028, 0x2029, 0x200B, 0x4E00, 0xE000, 0xFFFD,
|
||||
0x1000C, 0x1F600, 0xE0001, 0x10FFFF,
|
||||
} {
|
||||
keep(r)
|
||||
}
|
||||
|
||||
for r := rune(denseCeiling); r <= utf8.MaxRune; r += stride {
|
||||
keep(r)
|
||||
}
|
||||
|
||||
return runes
|
||||
}
|
||||
|
||||
// TestEncodedBytes_ChargesAtLeastWhatTheHandlersEmit is the property
|
||||
@@ -113,93 +114,33 @@ func firstUndercharged(
|
||||
// how a stated ceiling becomes false without any test noticing, so
|
||||
// the charge is measured against what the handlers actually write
|
||||
// rather than against the escaping rules as read.
|
||||
//
|
||||
// Every code point below U+1000 is checked on its own, for both
|
||||
// handlers. That range holds the quote, the backslash and the control
|
||||
// characters the handlers escape, next to code points each handler
|
||||
// writes in fewer bytes than their charge, which in a sum would cover
|
||||
// a neighbour charged too little. Each is measured in a value of it
|
||||
// alone and again in one the text handler quotes, because that handler
|
||||
// writes U+007F as one raw byte in a value it leaves bare but as \x7f,
|
||||
// four bytes, in one it quotes.
|
||||
//
|
||||
// From U+1000 up the text handler writes every code point in exactly
|
||||
// its charge, so the rest of Unicode is checked batchRunes at a time:
|
||||
// each batch's summed charge must cover what the handler writes for
|
||||
// the whole batch. The sums there can miss the JSON handler alone
|
||||
// writing one code point in more bytes than its charge, when it writes
|
||||
// others in the same batch in fewer.
|
||||
func TestEncodedBytes_ChargesAtLeastWhatTheHandlersEmit(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var below strings.Builder
|
||||
for r := range rune(0x1000) {
|
||||
below.WriteRune(r)
|
||||
}
|
||||
|
||||
var batches []string
|
||||
|
||||
for lo := rune(0x1000); lo <= utf8.MaxRune; lo += batchRunes {
|
||||
var batch strings.Builder
|
||||
|
||||
for r := lo; r < lo+batchRunes; r++ {
|
||||
// Surrogate halves are not runes a string can carry.
|
||||
if utf8.ValidRune(r) {
|
||||
batch.WriteRune(r)
|
||||
}
|
||||
}
|
||||
|
||||
batches = append(batches, batch.String())
|
||||
}
|
||||
|
||||
// What EncodedBytes charges for each batch. Under -race -cover this
|
||||
// takes longer than logging the batches, so it is worked out once,
|
||||
// by whichever handler finishes logging first, while the other is
|
||||
// still logging.
|
||||
charged := sync.OnceValue(func() []int {
|
||||
costs := make([]int, len(batches))
|
||||
|
||||
for i, batch := range batches {
|
||||
for _, r := range batch {
|
||||
costs[i] += logfield.EncodedBytes(r)
|
||||
}
|
||||
}
|
||||
|
||||
return costs
|
||||
})
|
||||
|
||||
for name, newHandler := range newHandlers() {
|
||||
t.Run(name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
if first, count := firstUndercharged(newHandler, below.String()); count > 0 {
|
||||
t.Errorf(
|
||||
"%d code points below U+1000 cost more than "+
|
||||
"EncodedBytes charges, the first U+%04X",
|
||||
count, first,
|
||||
// 'a' is a printable ASCII rune, charged exactly one
|
||||
// byte, so it is the zero point the other runes are
|
||||
// measured against.
|
||||
base := renderedWidth(
|
||||
newHandler, strings.Repeat("a", sampleRunes),
|
||||
)
|
||||
|
||||
for _, r := range chargeTestRunes() {
|
||||
got := renderedWidth(
|
||||
newHandler,
|
||||
strings.Repeat(string(r), sampleRunes),
|
||||
)
|
||||
}
|
||||
charged := sampleRunes *
|
||||
(logfield.EncodedBytes(r) - 1)
|
||||
|
||||
emitted := make([]int, len(batches))
|
||||
for i, batch := range batches {
|
||||
emitted[i] = emittedBytes(newHandler, "", batch)
|
||||
}
|
||||
|
||||
for i, cost := range charged() {
|
||||
if emitted[i] <= cost {
|
||||
continue
|
||||
}
|
||||
|
||||
lo := rune(0x1000 + i*batchRunes)
|
||||
first, count := firstUndercharged(
|
||||
newHandler, batches[i],
|
||||
)
|
||||
t.Errorf(
|
||||
"U+%04X to U+%04X emit %d bytes but are "+
|
||||
"charged %d; %d of them cost more than "+
|
||||
"EncodedBytes charges, the first U+%04X",
|
||||
lo, lo+batchRunes-1, emitted[i], cost,
|
||||
count, first,
|
||||
require.LessOrEqual(
|
||||
t, got-base, charged+quotingSlack,
|
||||
"U+%04X costs more on the line than "+
|
||||
"EncodedBytes charges for it",
|
||||
r,
|
||||
)
|
||||
}
|
||||
})
|
||||
|
||||
@@ -9,7 +9,6 @@ import (
|
||||
"time"
|
||||
|
||||
"go.uber.org/fx"
|
||||
"go.uber.org/fx/fxevent"
|
||||
"sneak.berlin/go/webhooker/internal/globals"
|
||||
)
|
||||
|
||||
@@ -107,40 +106,3 @@ func (l *Logger) Identify() {
|
||||
func (l *Logger) Writer() io.Writer {
|
||||
return os.Stdout
|
||||
}
|
||||
|
||||
// FxLogger writes fx's own events through a slog logger: how the
|
||||
// dependency graph was built at DEBUG, since it repeats on every
|
||||
// start; the start and stop hooks, the start itself and the signal
|
||||
// that stops the service at INFO; every failure at ERROR.
|
||||
//
|
||||
// The formatting is fx's own fxevent.SlogLogger. That logger takes a
|
||||
// single level for every event that is not a failure, so FxLogger
|
||||
// holds one at each level and picks between them.
|
||||
type FxLogger struct {
|
||||
graph *fxevent.SlogLogger
|
||||
lifecycle *fxevent.SlogLogger
|
||||
}
|
||||
|
||||
// NewFxLogger returns an FxLogger that writes through log.
|
||||
func NewFxLogger(log *slog.Logger) *FxLogger {
|
||||
graph := &fxevent.SlogLogger{Logger: log}
|
||||
graph.UseLogLevel(slog.LevelDebug)
|
||||
|
||||
lifecycle := &fxevent.SlogLogger{Logger: log}
|
||||
lifecycle.UseLogLevel(slog.LevelInfo)
|
||||
|
||||
return &FxLogger{graph: graph, lifecycle: lifecycle}
|
||||
}
|
||||
|
||||
// LogEvent implements fxevent.Logger.
|
||||
func (f *FxLogger) LogEvent(event fxevent.Event) {
|
||||
switch event.(type) {
|
||||
case *fxevent.Supplied, *fxevent.Provided, *fxevent.Replaced,
|
||||
*fxevent.Decorated, *fxevent.BeforeRun, *fxevent.Run,
|
||||
*fxevent.Invoking, *fxevent.Invoked,
|
||||
*fxevent.LoggerInitialized:
|
||||
f.graph.LogEvent(event)
|
||||
default:
|
||||
f.lifecycle.LogEvent(event)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,23 +1,13 @@
|
||||
package logger_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"log/slog"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"go.uber.org/fx"
|
||||
"go.uber.org/fx/fxevent"
|
||||
"go.uber.org/fx/fxtest"
|
||||
"sneak.berlin/go/webhooker/internal/globals"
|
||||
"sneak.berlin/go/webhooker/internal/logger"
|
||||
)
|
||||
|
||||
var errStopHook = errors.New("stop hook failed on purpose")
|
||||
|
||||
func testGlobals() *globals.Globals {
|
||||
return &globals.Globals{
|
||||
Appname: "test-app",
|
||||
@@ -67,47 +57,3 @@ func TestEnableDebugLogging(t *testing.T) {
|
||||
// Test debug logging
|
||||
l.Get().Debug("debug message", "test", true)
|
||||
}
|
||||
|
||||
// TestFxLogger_Levels starts and stops an fx app that reports its own
|
||||
// events through NewFxLogger, as cmd/webhooker does, and reads back
|
||||
// what reached the handler: the graph at DEBUG, the start at INFO and
|
||||
// a failed stop hook at ERROR, each as a structured record.
|
||||
func TestFxLogger_Levels(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var out bytes.Buffer
|
||||
|
||||
log := slog.New(slog.NewJSONHandler(
|
||||
&out, &slog.HandlerOptions{Level: slog.LevelDebug},
|
||||
))
|
||||
|
||||
app := fx.New(
|
||||
fx.WithLogger(func() fxevent.Logger {
|
||||
return logger.NewFxLogger(log)
|
||||
}),
|
||||
fx.Invoke(func(lc fx.Lifecycle) {
|
||||
lc.Append(fx.StopHook(func() error { return errStopHook }))
|
||||
}),
|
||||
)
|
||||
|
||||
require.NoError(t, app.Start(t.Context()))
|
||||
require.ErrorIs(t, app.Stop(t.Context()), errStopHook)
|
||||
|
||||
levels := map[string]string{}
|
||||
|
||||
decoder := json.NewDecoder(&out)
|
||||
for decoder.More() {
|
||||
var record struct {
|
||||
Level string `json:"level"`
|
||||
Msg string `json:"msg"`
|
||||
}
|
||||
|
||||
require.NoError(t, decoder.Decode(&record))
|
||||
|
||||
levels[record.Msg] = record.Level
|
||||
}
|
||||
|
||||
assert.Equal(t, "DEBUG", levels["provided"])
|
||||
assert.Equal(t, "INFO", levels["started"])
|
||||
assert.Equal(t, "ERROR", levels["OnStop hook failed"])
|
||||
}
|
||||
|
||||
@@ -63,12 +63,6 @@ const (
|
||||
// capturingMiddleware returns a Middleware whose logger writes JSON
|
||||
// lines into the returned buffer, so the access log can be asserted
|
||||
// on directly.
|
||||
//
|
||||
// It trusts 192.0.2.1, the peer address httptest.NewRequestWithContext
|
||||
// gives a request, as a proxy, the way a deployment trusts its reverse
|
||||
// proxy: a request built that way and carrying X-Forwarded-For is
|
||||
// logged with the client that header names as clientIP, and one
|
||||
// without it with the peer.
|
||||
func capturingMiddleware(t *testing.T) (*middleware.Middleware, *bytes.Buffer) {
|
||||
t.Helper()
|
||||
|
||||
@@ -78,10 +72,7 @@ func capturingMiddleware(t *testing.T) (*middleware.Middleware, *bytes.Buffer) {
|
||||
&slog.HandlerOptions{Level: slog.LevelInfo},
|
||||
))
|
||||
|
||||
cfg := &config.Config{
|
||||
Environment: config.EnvironmentDev,
|
||||
TrustedProxies: trustedProxies("192.0.2.1/32"),
|
||||
}
|
||||
cfg := &config.Config{Environment: config.EnvironmentDev}
|
||||
|
||||
return middleware.NewForTest(log, cfg, nil), buf
|
||||
}
|
||||
@@ -90,7 +81,7 @@ func capturingMiddleware(t *testing.T) (*middleware.Middleware, *bytes.Buffer) {
|
||||
// internal/logger can select: slog's text handler, which
|
||||
// internal/logger/logger.go installs when stderr is a tty. It escapes
|
||||
// differently from the JSON one, so the line bound has to be asserted
|
||||
// against both. It trusts the same peer.
|
||||
// against both.
|
||||
func capturingTextMiddleware(
|
||||
t *testing.T,
|
||||
) (*middleware.Middleware, *bytes.Buffer) {
|
||||
@@ -102,10 +93,7 @@ func capturingTextMiddleware(
|
||||
&slog.HandlerOptions{Level: slog.LevelInfo},
|
||||
))
|
||||
|
||||
cfg := &config.Config{
|
||||
Environment: config.EnvironmentDev,
|
||||
TrustedProxies: trustedProxies("192.0.2.1/32"),
|
||||
}
|
||||
cfg := &config.Config{Environment: config.EnvironmentDev}
|
||||
|
||||
return middleware.NewForTest(log, cfg, nil), buf
|
||||
}
|
||||
@@ -346,12 +334,11 @@ func oversizedHeaders(value string) map[string]string {
|
||||
// sizeCase is one way of pointing 8 KB of client-chosen text at the
|
||||
// access log.
|
||||
type sizeCase struct {
|
||||
target string
|
||||
headers map[string]string
|
||||
wantStatus int
|
||||
wantURL string
|
||||
wantClientIP string
|
||||
bound int
|
||||
target string
|
||||
headers map[string]string
|
||||
wantStatus int
|
||||
wantURL string
|
||||
bound int
|
||||
}
|
||||
|
||||
// lineSizeCases enumerates every part of a request that reaches the
|
||||
@@ -388,7 +375,8 @@ func lineSizeCases() map[string]sizeCase {
|
||||
}
|
||||
|
||||
// The url field on a 5xx keeps the concrete path, so it reaches its
|
||||
// own budget on the same line as the three header fields.
|
||||
// own budget on the same line as the three header fields. That is
|
||||
// the widest access log line the service can be made to write.
|
||||
longPath := "/boom/" + strings.Repeat("x", oversizedSegmentBytes)
|
||||
wantLongURL := longPath[:maxFieldBytes] + truncationSuffix
|
||||
|
||||
@@ -432,29 +420,6 @@ func lineSizeCases() map[string]sizeCase {
|
||||
}
|
||||
}
|
||||
|
||||
// From a trusted proxy, clientIP is read out of X-Forwarded-For,
|
||||
// which the client writes. What bounds the field is that only one
|
||||
// address from the header is written, and it is written parsed, with
|
||||
// no zone. An IPv6 address with all eight groups at four digits is
|
||||
// the longest such address; here it carries an 8 KB zone, which must
|
||||
// not reach the line. It goes on the 5xx line with all three header
|
||||
// fields at their budget.
|
||||
const longestIPv6 = "ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff"
|
||||
|
||||
forwarded := oversizedHeaders(oversizedValue("h"))
|
||||
forwarded[headerXFF] = oversizedValue("h") + ", " +
|
||||
longestIPv6 + "%" + oversizedValue("h")
|
||||
|
||||
cases["oversized X-Forwarded-For from a trusted proxy "+
|
||||
"with a 5xx concrete url"] = sizeCase{
|
||||
target: longPath,
|
||||
headers: forwarded,
|
||||
wantStatus: http.StatusInternalServerError,
|
||||
wantURL: wantLongURL,
|
||||
wantClientIP: longestIPv6,
|
||||
bound: maxCappedLineBytes,
|
||||
}
|
||||
|
||||
return cases
|
||||
}
|
||||
|
||||
@@ -495,14 +460,6 @@ func TestAccessLog_LineSizeDoesNotTrackInputSize(t *testing.T) {
|
||||
require.Len(t, entries, 1)
|
||||
assert.Equal(t, tc.wantURL, entries[0]["url"])
|
||||
|
||||
// Set only by the X-Forwarded-For case, where it proves
|
||||
// the header was read rather than ignored.
|
||||
if tc.wantClientIP != "" {
|
||||
assert.Equal(
|
||||
t, tc.wantClientIP, entries[0]["clientIP"],
|
||||
)
|
||||
}
|
||||
|
||||
// The markers sit at the far end of the client-chosen
|
||||
// text, so their absence is what proves the redaction and
|
||||
// the truncation actually ran.
|
||||
@@ -691,8 +648,7 @@ func TestAccessLog_RetainsEveryOtherField(t *testing.T) {
|
||||
|
||||
for _, key := range []string{
|
||||
"request_start", "method", "url", "useragent", "request_id",
|
||||
"referer", "proto", "remoteIP", "clientIP", "status",
|
||||
"latency_ms",
|
||||
"referer", "proto", "remoteIP", "status", "latency_ms",
|
||||
} {
|
||||
assert.Contains(t, entries[0], key)
|
||||
}
|
||||
|
||||
@@ -1,200 +0,0 @@
|
||||
package middleware_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"sneak.berlin/go/webhooker/internal/config"
|
||||
"sneak.berlin/go/webhooker/internal/middleware"
|
||||
)
|
||||
|
||||
const (
|
||||
// forwardedChain is the X-Forwarded-For a request arrives with:
|
||||
// the client, then a second proxy inside trustedProxyCIDR that the
|
||||
// request passed through before reaching trustedPeer.
|
||||
forwardedChain = clientIPv4 + ", 10.0.0.2"
|
||||
|
||||
// untrustedPeer is a peer outside trustedProxyCIDR, so its
|
||||
// X-Forwarded-For is ignored and the peer is the client.
|
||||
untrustedPeer = "192.0.2.10:5555"
|
||||
|
||||
// oneRequestPerMinute is the receiver limit these tests install:
|
||||
// the second request on a path is rejected, and the aggregate
|
||||
// limit is ReceiverAggregateMultiplierConst.
|
||||
oneRequestPerMinute = 1
|
||||
)
|
||||
|
||||
// clientLogSite is one log line that names the client. build wraps the
|
||||
// middleware that writes it around a handler, and requests is how many
|
||||
// identical requests it takes before the line is written.
|
||||
type clientLogSite struct {
|
||||
build func(m *middleware.Middleware) http.Handler
|
||||
requests int
|
||||
}
|
||||
|
||||
// clientLogSites maps the message of each line that names the client
|
||||
// to the way to make it be written.
|
||||
func clientLogSites() map[string]clientLogSite {
|
||||
served := func(*middleware.Middleware) http.Handler {
|
||||
return okHandler()
|
||||
}
|
||||
|
||||
receiver := func(m *middleware.Middleware) http.Handler {
|
||||
return m.ReceiverRateLimit()(okHandler())
|
||||
}
|
||||
|
||||
login := func(m *middleware.Middleware) http.Handler {
|
||||
return http.HandlerFunc(
|
||||
func(w http.ResponseWriter, r *http.Request) {
|
||||
m.RecordLoginFailure(r, "someone")
|
||||
w.WriteHeader(http.StatusUnauthorized)
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
csrf := func(m *middleware.Middleware) http.Handler {
|
||||
return m.CSRF(http.HandlerFunc(forbidden))(okHandler())
|
||||
}
|
||||
|
||||
passwordChange := func(m *middleware.Middleware) http.Handler {
|
||||
return m.PasswordChangeRateLimit()(okHandler())
|
||||
}
|
||||
|
||||
replay := func(m *middleware.Middleware) http.Handler {
|
||||
return m.ReplayRateLimit()(okHandler())
|
||||
}
|
||||
|
||||
resubmit := func(m *middleware.Middleware) http.Handler {
|
||||
return m.ResubmitRateLimit()(okHandler())
|
||||
}
|
||||
|
||||
return map[string]clientLogSite{
|
||||
"http request": {
|
||||
build: served,
|
||||
requests: 1,
|
||||
},
|
||||
"webhook receiver rate limit exceeded": {
|
||||
build: receiver,
|
||||
requests: oneRequestPerMinute + 1,
|
||||
},
|
||||
// The aggregate limit sits in front of the per-entrypoint
|
||||
// one, so the requests that one rejects count towards it.
|
||||
"webhook receiver aggregate rate limit exceeded": {
|
||||
build: receiver,
|
||||
requests: middleware.ReceiverAggregateMultiplierConst*
|
||||
oneRequestPerMinute + 1,
|
||||
},
|
||||
"login failure limit exceeded": {
|
||||
build: login,
|
||||
requests: middleware.LoginRateLimitConst + 1,
|
||||
},
|
||||
"csrf: token validation failed": {
|
||||
build: csrf,
|
||||
requests: 1,
|
||||
},
|
||||
"password change rate limit exceeded": {
|
||||
build: passwordChange,
|
||||
requests: middleware.PasswordChangeRateLimitConst + 1,
|
||||
},
|
||||
"delivery replay rate limit exceeded": {
|
||||
build: replay,
|
||||
requests: middleware.ReplayRateLimitConst + 1,
|
||||
},
|
||||
"event resubmit rate limit exceeded": {
|
||||
build: resubmit,
|
||||
requests: middleware.ResubmitRateLimitConst + 1,
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
// clientLogLines sends the site's requests from peer, each carrying
|
||||
// forwardedChain, through Logging and then the site, as production
|
||||
// does, and returns the logged lines whose message is msg.
|
||||
func clientLogLines(
|
||||
t *testing.T, site clientLogSite, msg, peer string,
|
||||
) []map[string]any {
|
||||
t.Helper()
|
||||
|
||||
buf := new(bytes.Buffer)
|
||||
log := slog.New(slog.NewJSONHandler(
|
||||
buf,
|
||||
&slog.HandlerOptions{Level: slog.LevelDebug},
|
||||
))
|
||||
|
||||
cfg := &config.Config{
|
||||
Environment: config.EnvironmentDev,
|
||||
ReceiverRateLimit: oneRequestPerMinute,
|
||||
TrustedProxies: trustedProxies(trustedProxyCIDR),
|
||||
}
|
||||
|
||||
m := middleware.NewForTest(
|
||||
log, cfg, newTestSessionManager(cfg, log, nil),
|
||||
)
|
||||
handler := m.Logging()(site.build(m))
|
||||
|
||||
for range site.requests {
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(), http.MethodPost, "/h/x", nil,
|
||||
)
|
||||
req.RemoteAddr = peer
|
||||
req.Header.Set(headerXFF, forwardedChain)
|
||||
|
||||
handler.ServeHTTP(httptest.NewRecorder(), req)
|
||||
}
|
||||
|
||||
var lines []map[string]any
|
||||
|
||||
for _, entry := range accessLogEntries(t, buf) {
|
||||
if entry["msg"] == msg {
|
||||
lines = append(lines, entry)
|
||||
}
|
||||
}
|
||||
|
||||
return lines
|
||||
}
|
||||
|
||||
// TestClientIP_LoggedNextToThePeer checks that every line that names
|
||||
// the client carries both addresses: remoteIP, the connecting peer,
|
||||
// and clientIP, the client the rate limiters key on.
|
||||
func TestClientIP_LoggedNextToThePeer(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cases := map[string]struct {
|
||||
peer string
|
||||
wantRemote string
|
||||
wantClient string
|
||||
}{
|
||||
"trusted proxy with a forwarded chain": {
|
||||
peer: trustedPeer,
|
||||
wantRemote: "10.0.0.1",
|
||||
wantClient: clientIPv4,
|
||||
},
|
||||
"untrusted peer": {
|
||||
peer: untrustedPeer,
|
||||
wantRemote: "192.0.2.10",
|
||||
wantClient: "192.0.2.10",
|
||||
},
|
||||
}
|
||||
|
||||
for msg, site := range clientLogSites() {
|
||||
for name, tc := range cases {
|
||||
t.Run(msg+"/"+name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
lines := clientLogLines(t, site, msg, tc.peer)
|
||||
require.NotEmpty(t, lines, "%q was never logged", msg)
|
||||
|
||||
for _, line := range lines {
|
||||
assert.Equal(t, tc.wantRemote, line["remoteIP"])
|
||||
assert.Equal(t, tc.wantClient, line["clientIP"])
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -45,10 +45,10 @@ func (m *Middleware) CSRF(
|
||||
// unauthenticated client: a POST with no token to
|
||||
// /hook/<any length of any text>/edit lands here. The
|
||||
// method and path are capped against the same budgets as
|
||||
// the access log. remoteIP and clientIP are the same
|
||||
// addresses the access log carries, and
|
||||
// the access log. remote_addr is set by net/http from the
|
||||
// accepted connection rather than by the client, and
|
||||
// csrf.FailureReason returns one of gorilla/csrf's own
|
||||
// fixed error values, so none of them is client-sized.
|
||||
// fixed error values, so neither is client-sized.
|
||||
m.log.Warn("csrf: token validation failed",
|
||||
"method", logfield.Truncate(
|
||||
r.Method, maxLogMethodBytes,
|
||||
@@ -56,8 +56,7 @@ func (m *Middleware) CSRF(
|
||||
"path", logfield.Truncate(
|
||||
r.URL.Path, logfield.MaxBytes,
|
||||
),
|
||||
"remoteIP", RemoteIP(r),
|
||||
"clientIP", ClientIP(r),
|
||||
"remote_addr", r.RemoteAddr,
|
||||
"reason", csrf.FailureReason(r),
|
||||
)
|
||||
forbidden.ServeHTTP(w, r)
|
||||
|
||||
@@ -132,12 +132,6 @@ func (g *LoginGuard) TrackedKeysForTest() (int, int) {
|
||||
// passwordChangeRateLimit constant.
|
||||
const PasswordChangeRateLimitConst = passwordChangeRateLimit
|
||||
|
||||
// ReplayRateLimitConst exposes the replayRateLimit constant.
|
||||
const ReplayRateLimitConst = replayRateLimit
|
||||
|
||||
// ResubmitRateLimitConst exposes the resubmitRateLimit constant.
|
||||
const ResubmitRateLimitConst = resubmitRateLimit
|
||||
|
||||
// ReceiverAggregateMultiplierConst exposes the
|
||||
// receiverAggregateMultiplier constant.
|
||||
const ReceiverAggregateMultiplierConst = receiverAggregateMultiplier
|
||||
|
||||
@@ -385,8 +385,6 @@ func (m *Middleware) RecordLoginFailure(
|
||||
"path", logfield.Truncate(
|
||||
r.URL.Path, logfield.MaxBytes,
|
||||
),
|
||||
"remoteIP", RemoteIP(r),
|
||||
"clientIP", ClientIP(r),
|
||||
)
|
||||
}
|
||||
|
||||
|
||||
@@ -3,7 +3,6 @@
|
||||
package middleware
|
||||
|
||||
import (
|
||||
"context"
|
||||
"log/slog"
|
||||
"net"
|
||||
"net/http"
|
||||
@@ -70,19 +69,18 @@ const (
|
||||
// url, useragent, referer 3*(512+11) = 1569
|
||||
// request_id 128+11 = 139
|
||||
// method 32+11 = 43
|
||||
// fixed portion = 405
|
||||
// fixed portion = 336
|
||||
// ----
|
||||
// 2156
|
||||
// 2087
|
||||
//
|
||||
// The 512 is logfield.MaxBytes; the 11 is the truncation marker,
|
||||
// charged on top of each budget rather than inside it.
|
||||
//
|
||||
// The fixed portion is the JSON punctuation, the field names, the
|
||||
// level and the message, both timestamps at their longest, remoteIP
|
||||
// and clientIP each charged as an IPv6 address with a zone, a
|
||||
// three-digit status and a full-width int64 latency. Stated at 2560
|
||||
// so the figure carries headroom rather than sitting on the
|
||||
// arithmetic.
|
||||
// level and the message, both timestamps at their longest, an IPv6
|
||||
// remoteIP with a zone, a three-digit status and a full-width int64
|
||||
// latency. Stated at 2560 so the figure carries headroom rather
|
||||
// than sitting on the arithmetic.
|
||||
//
|
||||
// The tty text handler in internal/logger is covered by the same
|
||||
// figure. logfield.EncodedBytes charges every rune at least what
|
||||
@@ -90,8 +88,8 @@ const (
|
||||
// bytes strconv.Quote spends on a non-printable rune at or above
|
||||
// U+10000, which is four more than the JSON handler ever spends —
|
||||
// so each budget bounds the encoded field under either handler.
|
||||
// The text handler's fixed portion is 351, the smaller of the two,
|
||||
// which puts its worst case at 2102.
|
||||
// The text handler's fixed portion is 286, the smaller of the two,
|
||||
// which puts its worst case at 2037.
|
||||
//
|
||||
// It is also the ceiling on every OTHER line this service writes
|
||||
// THROUGH SLOG that carries text an UNAUTHENTICATED client
|
||||
@@ -217,28 +215,6 @@ func ipFromHostPort(hp string) string {
|
||||
return h
|
||||
}
|
||||
|
||||
// RemoteIP returns the address of the connecting peer, without its
|
||||
// port. Behind a reverse proxy it is the proxy. Every log line that
|
||||
// names the client logs it as remoteIP, next to clientIP.
|
||||
func RemoteIP(r *http.Request) string {
|
||||
return ipFromHostPort(r.RemoteAddr)
|
||||
}
|
||||
|
||||
// clientIPKey is the request context key under which Logging stores
|
||||
// the value ClientIP returns.
|
||||
type clientIPKey struct{}
|
||||
|
||||
// ClientIP returns the address the request is attributed to, which
|
||||
// Logging works out once per request with clientAddr in ratelimit.go
|
||||
// and logs as clientIP. The other lines that name the client read it
|
||||
// from here, so all of them agree. It is empty for a request Logging
|
||||
// has not seen.
|
||||
func ClientIP(r *http.Request) string {
|
||||
ip, _ := r.Context().Value(clientIPKey{}).(string)
|
||||
|
||||
return ip
|
||||
}
|
||||
|
||||
type loggingResponseWriter struct {
|
||||
http.ResponseWriter
|
||||
|
||||
@@ -340,13 +316,6 @@ func (s *Middleware) Logging() func(http.Handler) http.Handler {
|
||||
lrw := newLoggingResponseWriter(w)
|
||||
ctx := r.Context()
|
||||
|
||||
// When RemoteAddr is not an address, the peer's own
|
||||
// text is all the request can be attributed to.
|
||||
clientIP := RemoteIP(r)
|
||||
if addr, ok := s.clientAddr(r); ok {
|
||||
clientIP = addr.String()
|
||||
}
|
||||
|
||||
defer func() {
|
||||
latency := time.Since(start)
|
||||
requestID := ""
|
||||
@@ -381,16 +350,13 @@ func (s *Middleware) Logging() func(http.Handler) http.Handler {
|
||||
r.Referer(), logfield.MaxBytes,
|
||||
),
|
||||
"proto", r.Proto,
|
||||
"remoteIP", RemoteIP(r),
|
||||
"clientIP", clientIP,
|
||||
"remoteIP", ipFromHostPort(r.RemoteAddr),
|
||||
"status", lrw.statusCode,
|
||||
"latency_ms", latency.Milliseconds(),
|
||||
)
|
||||
}()
|
||||
|
||||
next.ServeHTTP(lrw, r.WithContext(
|
||||
context.WithValue(ctx, clientIPKey{}, clientIP),
|
||||
))
|
||||
next.ServeHTTP(lrw, r)
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -600,10 +566,7 @@ func bodyLimitedMethod(method string) bool {
|
||||
}
|
||||
|
||||
// MaxBodySize returns middleware that limits the size of
|
||||
// POST/PUT/PATCH request bodies to maxBytes. A request with any other
|
||||
// method passes through uncapped, deliberately: no route behind it
|
||||
// reads a body on GET, HEAD or DELETE. A handler that starts to needs
|
||||
// its method added to bodyLimitedMethod first. It must be registered
|
||||
// POST/PUT/PATCH request bodies to maxBytes. It must be registered
|
||||
// before any middleware that parses the body — notably CSRF, which
|
||||
// calls r.PostFormValue — so that form parsing happens under this
|
||||
// cap rather than net/http's 10 MB default.
|
||||
|
||||
@@ -730,8 +730,10 @@ func TestNoCache_SetsHeaders(t *testing.T) {
|
||||
|
||||
const testBodyLimit int64 = 64
|
||||
|
||||
// maxBodySizeResult is what runMaxBodySize's sentinel handler saw,
|
||||
// together with the response.
|
||||
// maxBodySizeHandler wraps a sentinel handler in MaxBodySize with
|
||||
// testBodyLimit. The sentinel records whether it ran and how much of
|
||||
// the body it managed to read, so tests can distinguish "never
|
||||
// reached" from "reached but truncated".
|
||||
type maxBodySizeResult struct {
|
||||
called bool
|
||||
read int
|
||||
@@ -739,10 +741,6 @@ type maxBodySizeResult struct {
|
||||
response *httptest.ResponseRecorder
|
||||
}
|
||||
|
||||
// runMaxBodySize wraps a sentinel handler in MaxBodySize with
|
||||
// testBodyLimit and serves req through it. The sentinel records
|
||||
// whether it ran and how much of the body it managed to read, so
|
||||
// tests can distinguish "never reached" from "reached but truncated".
|
||||
func runMaxBodySize(
|
||||
t *testing.T,
|
||||
req *http.Request,
|
||||
|
||||
@@ -202,61 +202,44 @@ func (m *Middleware) forwardedClientAddr(
|
||||
}
|
||||
|
||||
// rateLimitKey is the client identity every rate limiter in this
|
||||
// package buckets on: the address clientAddr attributes the request
|
||||
// to, reduced to a bucket by bucketKey — full address for IPv4, /64
|
||||
// prefix for IPv6.
|
||||
// package buckets on. Forwarded headers are honoured only when the
|
||||
// direct peer (RemoteAddr) is inside the configured trusted-proxy
|
||||
// set; otherwise the peer address itself is the key. Without that
|
||||
// gate any client could mint a fresh bucket per request, or starve
|
||||
// another client's bucket, by picking an X-Forwarded-For value —
|
||||
// which makes every limit here decorative against a deliberate
|
||||
// attacker.
|
||||
//
|
||||
// The address that identifies the client is then reduced to a bucket
|
||||
// by bucketKey: full address for IPv4, /64 prefix for IPv6.
|
||||
func (m *Middleware) rateLimitKey(r *http.Request) (string, error) {
|
||||
return m.clientKey(r), nil
|
||||
}
|
||||
|
||||
// clientKey computes the bucket key described on rateLimitKey.
|
||||
func (m *Middleware) clientKey(r *http.Request) string {
|
||||
addr, ok := m.clientAddr(r)
|
||||
if !ok {
|
||||
peer, err := netip.ParseAddr(ipFromHostPort(r.RemoteAddr))
|
||||
if err != nil {
|
||||
// Not an address we can reason about; key on the raw
|
||||
// value, the most specific identity left. Distinct
|
||||
// RemoteAddr values stay in distinct buckets, so this
|
||||
// path cannot silently collapse unrelated clients
|
||||
// together. On a Unix-socket listener every peer
|
||||
// carries the same RemoteAddr and so shares one bucket,
|
||||
// which is the fail-closed direction. An empty RemoteAddr
|
||||
// is a different case, which net/http never produces for
|
||||
// a TCP listener and only a hand-built request carries,
|
||||
// but it fails closed the same way: every such request
|
||||
// shares the one bucket keyed on the empty string.
|
||||
// which is the fail-closed direction.
|
||||
return r.RemoteAddr
|
||||
}
|
||||
|
||||
return bucketKey(addr)
|
||||
}
|
||||
|
||||
// clientAddr is the address a request is attributed to. The rate
|
||||
// limiters key on it and the logs name it as clientIP.
|
||||
//
|
||||
// Forwarded headers are honoured only when the direct peer
|
||||
// (RemoteAddr) is inside the configured trusted-proxy set; otherwise
|
||||
// the peer address itself is the client. Without that gate any client
|
||||
// could mint a fresh bucket per request, or starve another client's
|
||||
// bucket, by picking an X-Forwarded-For value — which makes every
|
||||
// limit here decorative against a deliberate attacker.
|
||||
//
|
||||
// ok is false when RemoteAddr is not an address at all.
|
||||
func (m *Middleware) clientAddr(r *http.Request) (netip.Addr, bool) {
|
||||
peer, err := netip.ParseAddr(ipFromHostPort(r.RemoteAddr))
|
||||
if err != nil {
|
||||
return netip.Addr{}, false
|
||||
}
|
||||
|
||||
peer = normalizeAddr(peer)
|
||||
if !m.isTrustedProxy(peer) {
|
||||
return peer, true
|
||||
return bucketKey(peer)
|
||||
}
|
||||
|
||||
if addr, ok := m.forwardedClientAddr(r); ok {
|
||||
return addr, true
|
||||
return bucketKey(addr)
|
||||
}
|
||||
|
||||
return peer, true
|
||||
return bucketKey(peer)
|
||||
}
|
||||
|
||||
// tooManyRequests returns the 429 handler used by the
|
||||
@@ -279,8 +262,6 @@ func (m *Middleware) tooManyRequests(
|
||||
"path", logfield.Truncate(
|
||||
r.URL.Path, logfield.MaxBytes,
|
||||
),
|
||||
"remoteIP", RemoteIP(r),
|
||||
"clientIP", ClientIP(r),
|
||||
)
|
||||
http.Error(w, responseMessage, http.StatusTooManyRequests)
|
||||
}
|
||||
@@ -305,12 +286,8 @@ func (m *Middleware) tooManyRequests(
|
||||
func (m *Middleware) floodTooManyRequests(
|
||||
logMessage, responseMessage string,
|
||||
) http.HandlerFunc {
|
||||
return func(w http.ResponseWriter, r *http.Request) {
|
||||
m.log.Debug(
|
||||
logMessage,
|
||||
"remoteIP", RemoteIP(r),
|
||||
"clientIP", ClientIP(r),
|
||||
)
|
||||
return func(w http.ResponseWriter, _ *http.Request) {
|
||||
m.log.Debug(logMessage)
|
||||
http.Error(w, responseMessage, http.StatusTooManyRequests)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1012,23 +1012,6 @@ func TestRateLimitKey_UnparseablePeerKeepsDistinctBuckets(
|
||||
)
|
||||
}
|
||||
|
||||
// TestRateLimitKey_EmptyPeerSharesOneBucket pins what the fallback
|
||||
// does with an empty RemoteAddr: it keys on the empty string, so every
|
||||
// such request shares one bucket. That is the fail-closed direction
|
||||
// and is kept on purpose; only a hand-built request carries an empty
|
||||
// RemoteAddr.
|
||||
func TestRateLimitKey_EmptyPeerSharesOneBucket(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
m := rateLimitMiddleware(t, &config.Config{})
|
||||
|
||||
assert.Empty(
|
||||
t, clientKeyFor(t, m, ""),
|
||||
"every peer with an empty RemoteAddr must key on the "+
|
||||
"empty string and so share one bucket",
|
||||
)
|
||||
}
|
||||
|
||||
// TestPostRateLimit_IPv6SharesBucketWithinSlash64 is the behavioural
|
||||
// half, and the regression test for the bypass itself: a client that
|
||||
// rotates source addresses inside its own routed /64 must stay in one
|
||||
|
||||
@@ -1,71 +0,0 @@
|
||||
package middleware
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"net/http"
|
||||
"time"
|
||||
)
|
||||
|
||||
// Timeout returns middleware that gives each request limit to finish:
|
||||
// it cancels the request's context once limit has passed, and answers
|
||||
// 504 when the handler then returns without having started its
|
||||
// response.
|
||||
//
|
||||
// It replaces chi's middleware.Timeout, which writes that 504 even
|
||||
// after the handler has sent its own status. A download that outlasts
|
||||
// the limit has already sent its 200 and the whole file, so the late
|
||||
// 504 changes nothing for the client: the access log and the metrics
|
||||
// would record it in place of the 200, and net/http would complain of
|
||||
// a superfluous WriteHeader.
|
||||
func (s *Middleware) Timeout(
|
||||
limit time.Duration,
|
||||
) func(http.Handler) http.Handler {
|
||||
return func(next http.Handler) http.Handler {
|
||||
return http.HandlerFunc(func(
|
||||
w http.ResponseWriter,
|
||||
r *http.Request,
|
||||
) {
|
||||
ctx, cancel := context.WithTimeout(r.Context(), limit)
|
||||
defer cancel()
|
||||
|
||||
tw := &timeoutResponseWriter{ResponseWriter: w}
|
||||
|
||||
next.ServeHTTP(tw, r.WithContext(ctx))
|
||||
|
||||
if !tw.started &&
|
||||
errors.Is(ctx.Err(), context.DeadlineExceeded) {
|
||||
w.WriteHeader(http.StatusGatewayTimeout)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// timeoutResponseWriter records whether the handler has started its
|
||||
// response.
|
||||
type timeoutResponseWriter struct {
|
||||
http.ResponseWriter
|
||||
|
||||
started bool
|
||||
}
|
||||
|
||||
func (w *timeoutResponseWriter) WriteHeader(code int) {
|
||||
w.started = true
|
||||
|
||||
w.ResponseWriter.WriteHeader(code)
|
||||
}
|
||||
|
||||
func (w *timeoutResponseWriter) Write(b []byte) (int, error) {
|
||||
// A Write without a WriteHeader starts the response too: net/http
|
||||
// sends 200 in front of it.
|
||||
w.started = true
|
||||
|
||||
//nolint:wrapcheck // Pass the writer's own error through unchanged.
|
||||
return w.ResponseWriter.Write(b)
|
||||
}
|
||||
|
||||
// Unwrap lets http.ResponseController reach the writer underneath, so
|
||||
// a handler can still set a write deadline through this wrapper.
|
||||
func (w *timeoutResponseWriter) Unwrap() http.ResponseWriter {
|
||||
return w.ResponseWriter
|
||||
}
|
||||
@@ -1,56 +0,0 @@
|
||||
package middleware_test
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
// TestTimeout proves the request limit answers 504 to a handler that
|
||||
// outlasts it without starting its response, and leaves a response the
|
||||
// handler has started with the status it sent. Both are what the
|
||||
// access log records.
|
||||
func TestTimeout(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
const limit = 10 * time.Millisecond
|
||||
|
||||
for _, tc := range []struct {
|
||||
name string
|
||||
sent int // the status the handler sends, or 0 for none
|
||||
want int
|
||||
}{
|
||||
{name: "not started", sent: 0, want: http.StatusGatewayTimeout},
|
||||
{name: "started", sent: http.StatusOK, want: http.StatusOK},
|
||||
} {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
m, buf := capturingMiddleware(t)
|
||||
handler := m.Logging()(m.Timeout(limit)(http.HandlerFunc(
|
||||
func(w http.ResponseWriter, r *http.Request) {
|
||||
if tc.sent != 0 {
|
||||
w.WriteHeader(tc.sent)
|
||||
}
|
||||
|
||||
<-r.Context().Done()
|
||||
},
|
||||
)))
|
||||
|
||||
w := httptest.NewRecorder()
|
||||
handler.ServeHTTP(w, httptest.NewRequestWithContext(
|
||||
t.Context(), http.MethodGet, "/", nil,
|
||||
))
|
||||
|
||||
assert.Equal(t, tc.want, w.Code)
|
||||
|
||||
entries := accessLogEntries(t, buf)
|
||||
require.Len(t, entries, 1)
|
||||
assert.EqualValues(t, tc.want, entries[0]["status"])
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -308,7 +308,7 @@ func checkDataDir(dir string) error {
|
||||
|
||||
dbPath := filepath.Join(dir, database.MainDBFileName)
|
||||
|
||||
dbInfo, err := os.Stat(dbPath)
|
||||
_, err = os.Stat(dbPath)
|
||||
|
||||
switch {
|
||||
case errors.Is(err, fs.ErrNotExist):
|
||||
@@ -319,15 +319,6 @@ func checkDataDir(dir string) error {
|
||||
)
|
||||
case err != nil:
|
||||
return fmt.Errorf("checking %s: %w", dbPath, err)
|
||||
case dbInfo.Size() == 0:
|
||||
// SQLite opens a zero-length file as an empty database, so
|
||||
// it holds no deployment either, and opening it would write
|
||||
// an empty schema into it.
|
||||
return fmt.Errorf(
|
||||
"%w: %s is zero-length. The admin account is created by "+
|
||||
"the first server start",
|
||||
ErrNoDatabase, dbPath,
|
||||
)
|
||||
}
|
||||
|
||||
return nil
|
||||
|
||||
@@ -377,33 +377,6 @@ func TestMissingDatabaseCreatesNothing(t *testing.T) {
|
||||
)
|
||||
}
|
||||
|
||||
// TestZeroLengthDatabaseCreatesNothing covers a webhooker.db left at
|
||||
// zero length, as a truncated copy leaves it. SQLite would open it as
|
||||
// an empty database, so it is refused like a missing one and left as
|
||||
// it is.
|
||||
func TestZeroLengthDatabaseCreatesNothing(t *testing.T) {
|
||||
dir := t.TempDir()
|
||||
t.Setenv("DATA_DIR", dir)
|
||||
|
||||
dbPath := filepath.Join(dir, database.MainDBFileName)
|
||||
require.NoError(
|
||||
t, os.WriteFile(dbPath, nil, database.SQLiteFilePerm),
|
||||
)
|
||||
|
||||
code, _, stderr := run(t, newPassword+"\n", operatorUser)
|
||||
|
||||
require.Equal(t, exitFailure, code)
|
||||
assert.Contains(t, stderr, dbPath)
|
||||
|
||||
entries, err := os.ReadDir(dir)
|
||||
require.NoError(t, err)
|
||||
assert.Len(t, entries, 1, "nothing may be created beside it")
|
||||
|
||||
info, err := os.Stat(dbPath)
|
||||
require.NoError(t, err)
|
||||
assert.Zero(t, info.Size(), "nothing may be written into it")
|
||||
}
|
||||
|
||||
// TestUnknownUserFails states the decision: resetpw changes an
|
||||
// existing account's password and never creates an account. A typo in
|
||||
// the username must say so rather than quietly adding a second user.
|
||||
|
||||
@@ -17,14 +17,10 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/chromedp/cdproto/browser"
|
||||
"github.com/chromedp/cdproto/dom"
|
||||
"github.com/chromedp/cdproto/input"
|
||||
"github.com/chromedp/cdproto/log"
|
||||
"github.com/chromedp/cdproto/network"
|
||||
"github.com/chromedp/cdproto/runtime"
|
||||
"github.com/chromedp/chromedp"
|
||||
"github.com/chromedp/chromedp/kb"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"gorm.io/gorm/clause"
|
||||
@@ -42,21 +38,12 @@ const (
|
||||
// the mobile menu button instead of the navigation links.
|
||||
phoneWidth = 390
|
||||
phoneHeight = 844
|
||||
|
||||
// A window short enough that the event log scrolls with its last
|
||||
// event expanded, and tall enough to show all of that event.
|
||||
shortWidth = 1024
|
||||
shortHeight = 450
|
||||
|
||||
// olderBody is the body of the event received before the newest.
|
||||
olderBody = "the older event"
|
||||
)
|
||||
|
||||
// TestAlpineRunsUnderTheSecurityPolicy loads the webhook page and the
|
||||
// event log in a headless browser, served by the real router and so
|
||||
// under the real Content-Security-Policy, and checks that the pages'
|
||||
// Alpine.js directives and the copy control work, and that a target's
|
||||
// row shows its delivery counts.
|
||||
// Alpine.js directives work.
|
||||
func TestAlpineRunsUnderTheSecurityPolicy(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
@@ -68,14 +55,6 @@ func TestAlpineRunsUnderTheSecurityPolicy(t *testing.T) {
|
||||
|
||||
userID, _ := env.seedUser(t, "browser", "browser-password")
|
||||
webhook := env.seedWebhook(t, userID)
|
||||
require.NoError(t, env.db.DB().Omit(clause.Associations).Create(
|
||||
&database.Entrypoint{
|
||||
WebhookID: webhook.ID,
|
||||
Path: "3c9e1f7a-5b2d-4e8a-9f6c-2a7d1e4b8c05",
|
||||
Active: true,
|
||||
},
|
||||
).Error)
|
||||
older := env.seedEvent(t, webhook.ID, olderBody)
|
||||
event := env.seedEvent(t, webhook.ID, `{"hello":"browser"}`)
|
||||
target := env.seedTarget(t, webhook.ID)
|
||||
dlv := env.seedFailedDelivery(t, webhook.ID, event.ID, target.ID)
|
||||
@@ -96,47 +75,9 @@ func TestAlpineRunsUnderTheSecurityPolicy(t *testing.T) {
|
||||
|
||||
page := srv.URL + "/hook/" + webhook.ID
|
||||
|
||||
checkAddEntrypoint(ctx, t, page)
|
||||
|
||||
// Each target type, with the fields its add target form submits, in
|
||||
// page order. Only http and slack have a url field.
|
||||
targetTypes := []struct {
|
||||
name string
|
||||
fields string
|
||||
values map[string]string
|
||||
}{
|
||||
{
|
||||
"http", "csrf_token name type url headers timeout max_retries",
|
||||
map[string]string{"url": publicTargetURL},
|
||||
},
|
||||
{
|
||||
"slack", "csrf_token name type url max_retries",
|
||||
map[string]string{"url": publicTargetURL},
|
||||
},
|
||||
{
|
||||
"database", "csrf_token name type expiry",
|
||||
map[string]string{"expiry": "720h"},
|
||||
},
|
||||
{"log", "csrf_token name type", nil},
|
||||
}
|
||||
|
||||
for _, tt := range targetTypes {
|
||||
checkAddTarget(
|
||||
ctx, t, page, tt.name, strings.Fields(tt.fields), tt.values,
|
||||
)
|
||||
}
|
||||
|
||||
checkRefusedTarget(ctx, t, page)
|
||||
checkTargetDeliveries(ctx, t, page, target.Name,
|
||||
"0 in total, 0 in the last 24 hours",
|
||||
"1 in total, 1 in the last 24 hours")
|
||||
checkCopy(ctx, t, page)
|
||||
checkEntrypointEdit(ctx, t, page, page+"/events")
|
||||
checkRecentEvents(ctx, t, page)
|
||||
checkArchiveChoice(ctx, t, srv.URL+"/hooks/new", page)
|
||||
checkNewWebhookTargets(ctx, t, env, srv.URL+"/hooks/new")
|
||||
checkRefusedNewWebhook(ctx, t, srv.URL+"/hooks/new")
|
||||
checkEventLog(ctx, t, page+"/events", event.ID, older.ID, target.Name)
|
||||
checkAddForms(ctx, t, page)
|
||||
checkTargetType(ctx, t, page+"/events")
|
||||
checkEventLog(ctx, t, page+"/events", event.ID, target.Name)
|
||||
checkMobileMenu(ctx, t, page)
|
||||
|
||||
assert.Empty(t, problems(), "the browser reported problems")
|
||||
@@ -277,395 +218,128 @@ func click(ctx context.Context, t *testing.T, xpath string) {
|
||||
))
|
||||
}
|
||||
|
||||
// checkAddEntrypoint loads a webhook page and checks that the add
|
||||
// entrypoint form stays hidden until the Add button beside its heading
|
||||
// is clicked. The click looks for a button element there, so it also
|
||||
// checks that Add is one.
|
||||
func checkAddEntrypoint(ctx context.Context, t *testing.T, url string) {
|
||||
t.Helper()
|
||||
|
||||
form := `form[action$="/entrypoints"]`
|
||||
|
||||
require.NoError(t, chromedp.Run(ctx, loadPage(url)))
|
||||
|
||||
assert.True(t, hidden(ctx, form),
|
||||
"the add entrypoint form shows before Add is clicked")
|
||||
|
||||
click(ctx, t, `//h2[text()="Entrypoints"]/following-sibling::button`)
|
||||
|
||||
assert.True(t, shown(ctx, form),
|
||||
"the add entrypoint form stays hidden when Add is clicked")
|
||||
}
|
||||
|
||||
// publicTargetURL is a destination the server accepts for an http or
|
||||
// slack target. It is a literal public address, so accepting it needs
|
||||
// no DNS.
|
||||
const publicTargetURL = "https://93.184.216.34/hook"
|
||||
|
||||
// The parts of the targets section's add target form the checks below
|
||||
// find and click. Add is the button beside the Targets heading; each
|
||||
// Cancel is found from the button beside it, since both are on the
|
||||
// page at once.
|
||||
const (
|
||||
addTarget = `//h2[text()="Targets"]/following-sibling::button`
|
||||
typeSelect = `//select[@aria-label="Target type"]`
|
||||
nextButton = `//button[text()="Next"]`
|
||||
cancelChoice = nextButton + `/following-sibling::button[text()="Cancel"]`
|
||||
saveButton = `//form[contains(@action, "/targets")]//button[text()="Save"]`
|
||||
cancelFields = saveButton + `/following-sibling::button[text()="Cancel"]`
|
||||
targetName = `form[action$="/targets"] input[name="name"]`
|
||||
submittedKeys = `[...new FormData(
|
||||
document.querySelector('form[action$="/targets"]')).keys()]`
|
||||
)
|
||||
|
||||
// checkAddTarget loads a webhook page and walks the add target form for
|
||||
// one target type. The form shows nothing until Add is clicked; Add
|
||||
// shows only the type choice; Cancel there closes it; Next shows the
|
||||
// type's own fields in place of the choice, and the form then submits
|
||||
// exactly fields, so a field another type uses, such as url, is absent;
|
||||
// Cancel closes it again. It then adds a target of the type, filling in
|
||||
// values, and checks that the section lists it with that type.
|
||||
func checkAddTarget(
|
||||
ctx context.Context,
|
||||
t *testing.T,
|
||||
url, targetType string,
|
||||
fields []string,
|
||||
values map[string]string,
|
||||
) {
|
||||
// checkAddForms loads a webhook page and checks that each section's add
|
||||
// form stays hidden until the Add button beside its heading is clicked.
|
||||
func checkAddForms(ctx context.Context, t *testing.T, url string) {
|
||||
t.Helper()
|
||||
|
||||
require.NoError(t, chromedp.Run(ctx, loadPage(url)))
|
||||
|
||||
assert.Truef(t, hidden(ctx, typeSelect),
|
||||
"%s: the type choice shows before Add is clicked", targetType)
|
||||
assert.Truef(t, hidden(ctx, targetName),
|
||||
"%s: the fields show before Add is clicked", targetType)
|
||||
|
||||
click(ctx, t, addTarget)
|
||||
assert.Truef(t, shown(ctx, typeSelect),
|
||||
"%s: Add does not show the type choice", targetType)
|
||||
assert.Truef(t, hidden(ctx, targetName),
|
||||
"%s: Add shows the fields before Next", targetType)
|
||||
|
||||
click(ctx, t, cancelChoice)
|
||||
assert.Truef(t, hidden(ctx, typeSelect),
|
||||
"%s: Cancel does not close the type choice", targetType)
|
||||
|
||||
chooseTargetType(ctx, t, targetType)
|
||||
|
||||
var submitted []string
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx, chromedp.Evaluate(submittedKeys, &submitted),
|
||||
))
|
||||
assert.Equalf(t, fields, submitted,
|
||||
"%s: the form does not submit exactly the type's fields", targetType)
|
||||
|
||||
click(ctx, t, cancelFields)
|
||||
assert.Truef(t, hidden(ctx, targetName),
|
||||
"%s: Cancel does not close the fields", targetType)
|
||||
assert.Truef(t, shown(ctx, addTarget),
|
||||
"%s: Add does not come back after Cancel", targetType)
|
||||
|
||||
name := "added-" + targetType
|
||||
|
||||
chooseTargetType(ctx, t, targetType)
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx, chromedp.SetValue(targetName, name, chromedp.ByQuery),
|
||||
))
|
||||
|
||||
for field, value := range values {
|
||||
require.NoError(t, chromedp.Run(ctx, chromedp.SetValue(
|
||||
`form[action$="/targets"] [name="`+field+`"]`, value,
|
||||
chromedp.ByQuery,
|
||||
)))
|
||||
sections := []struct{ heading, form string }{
|
||||
{"Entrypoints", `form[action$="/entrypoints"]`},
|
||||
{"Targets", `form[action$="/targets"]`},
|
||||
}
|
||||
|
||||
click(ctx, t, saveButton)
|
||||
assert.Truef(t, shown(ctx, `//span[text()="`+name+
|
||||
`"]/following-sibling::div/span[text()="`+targetType+`"]`),
|
||||
"%s: the added target is not listed with its type", targetType)
|
||||
for _, s := range sections {
|
||||
assert.Truef(
|
||||
t, hidden(ctx, s.form),
|
||||
"%s: the add form shows before Add is clicked", s.heading,
|
||||
)
|
||||
|
||||
click(ctx, t, `//h2[text()="`+s.heading+
|
||||
`"]/following-sibling::button`)
|
||||
|
||||
assert.Truef(
|
||||
t, shown(ctx, s.form),
|
||||
"%s: the add form stays hidden when Add is clicked", s.heading,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// chooseTargetType clicks Add, picks targetType and clicks Next, and
|
||||
// checks that the type's fields then show in place of the type choice.
|
||||
func chooseTargetType(ctx context.Context, t *testing.T, targetType string) {
|
||||
t.Helper()
|
||||
|
||||
click(ctx, t, addTarget)
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx, chromedp.SetValue(typeSelect, targetType, chromedp.BySearch),
|
||||
))
|
||||
click(ctx, t, nextButton)
|
||||
|
||||
assert.Truef(t, shown(ctx, targetName),
|
||||
"%s: Next does not show the fields", targetType)
|
||||
assert.Truef(t, hidden(ctx, typeSelect),
|
||||
"%s: Next leaves the type choice showing", targetType)
|
||||
assert.Truef(t, hidden(ctx, addTarget),
|
||||
"%s: Add still shows while the form is open", targetType)
|
||||
}
|
||||
|
||||
// checkRefusedTarget submits an http target the server refuses, a
|
||||
// loopback destination, and checks that the page comes back with the
|
||||
// form open on the http fields, the values entered and the reason, and
|
||||
// that after Cancel the next Add starts with an empty form and no
|
||||
// reason.
|
||||
func checkRefusedTarget(ctx context.Context, t *testing.T, url string) {
|
||||
// checkTargetType chooses Slack in the open add target form and checks
|
||||
// what the form would then submit: one url field, the Slack one, and
|
||||
// not the HTTP url, headers or timeout, which are hidden and disabled.
|
||||
//
|
||||
// It then opens the page at elsewhere and goes back. The browser loads
|
||||
// the webhook page again and restores the form as it was left, Slack
|
||||
// chosen, without a change event; the form must again show and submit
|
||||
// Slack's fields, not the HTTP ones.
|
||||
func checkTargetType(ctx context.Context, t *testing.T, elsewhere string) {
|
||||
t.Helper()
|
||||
|
||||
const (
|
||||
refusedURL = "http://127.0.0.1/hook"
|
||||
urlField = `form[action$="/targets"] input[name="url"]`
|
||||
reason = `//div[@class="alert-error"]`
|
||||
chooseSlack = `(() => {
|
||||
const type = document.querySelector('select[name="type"]');
|
||||
type.value = "slack";
|
||||
type.dispatchEvent(new Event("change"));
|
||||
})()`
|
||||
chosen = `document.querySelector('select[name="type"]').value`
|
||||
howLoaded = `performance.getEntriesByType("navigation")[0].type`
|
||||
submitted = `[...new FormData(
|
||||
document.querySelector('form[action$="/targets"]')).keys()]`
|
||||
slackURL = `input[placeholder^="https://hooks.slack.com/"]`
|
||||
httpURL = `input[placeholder="https://example.com/webhook"]`
|
||||
)
|
||||
|
||||
require.NoError(t, chromedp.Run(ctx, loadPage(url)))
|
||||
slackFields := strings.Fields("csrf_token name type max_retries url")
|
||||
|
||||
chooseTargetType(ctx, t, "http")
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
chromedp.SetValue(targetName, "refused", chromedp.ByQuery),
|
||||
chromedp.SetValue(urlField, refusedURL, chromedp.ByQuery),
|
||||
))
|
||||
|
||||
click(ctx, t, saveButton)
|
||||
|
||||
assert.True(t, shown(ctx, reason),
|
||||
"a refused target does not show the reason")
|
||||
|
||||
var name, typed string
|
||||
var fields []string
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
chromedp.Value(targetName, &name, chromedp.ByQuery),
|
||||
chromedp.Value(urlField, &typed, chromedp.ByQuery),
|
||||
chromedp.Evaluate(chooseSlack, nil),
|
||||
chromedp.Evaluate(submitted, &fields),
|
||||
))
|
||||
|
||||
assert.Equal(t, "refused", name,
|
||||
"a refused target does not keep the name entered")
|
||||
assert.Equal(t, refusedURL, typed,
|
||||
"a refused target does not keep the url entered")
|
||||
assert.True(t, shown(ctx, targetName),
|
||||
"a refused target does not come back with the form open")
|
||||
assert.True(t, hidden(ctx, typeSelect),
|
||||
"a refused target comes back on the type choice")
|
||||
|
||||
click(ctx, t, cancelFields)
|
||||
chooseTargetType(ctx, t, "http")
|
||||
|
||||
assert.True(t, hidden(ctx, reason),
|
||||
"after Cancel, the next Add still shows the reason")
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
chromedp.Value(targetName, &name, chromedp.ByQuery),
|
||||
chromedp.Value(urlField, &typed, chromedp.ByQuery),
|
||||
))
|
||||
|
||||
assert.Empty(t, name, "after Cancel, the next Add keeps the name entered")
|
||||
assert.Empty(t, typed, "after Cancel, the next Add keeps the url entered")
|
||||
}
|
||||
|
||||
// checkTargetDeliveries loads a webhook page and checks that the row of
|
||||
// the target named name shows delivered and failed beside its
|
||||
// "Delivered:" and "Failed:" labels.
|
||||
func checkTargetDeliveries(
|
||||
ctx context.Context, t *testing.T, url, name, delivered, failed string,
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
row := `//span[text()="` + name + `"]/ancestor::div[@class="p-4"][1]`
|
||||
figure := func(label, value string) string {
|
||||
return row + `//span[text()="` + label +
|
||||
`"]/following-sibling::span[text()="` + value + `"]`
|
||||
}
|
||||
|
||||
require.NoError(t, chromedp.Run(ctx, loadPage(url)))
|
||||
|
||||
assert.Truef(t, shown(ctx, figure("Delivered:", delivered)),
|
||||
"the row of %s does not show %q delivered", name, delivered)
|
||||
assert.Truef(t, shown(ctx, figure("Failed:", failed)),
|
||||
"the row of %s does not show %q failed", name, failed)
|
||||
}
|
||||
|
||||
// checkCopy loads a webhook page and checks that the Copy control beside
|
||||
// its entrypoint's URL is a button, and that clicking it copies the URL
|
||||
// and says so: the button reads "Copied" only once the copy succeeded.
|
||||
func checkCopy(ctx context.Context, t *testing.T, url string) {
|
||||
t.Helper()
|
||||
|
||||
copyButton := `//button[@data-copy-target]`
|
||||
|
||||
// A browser lets the page in its active tab write to the clipboard
|
||||
// on a click. A headless browser refuses unless told to allow it.
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
browser.SetPermission(
|
||||
&browser.PermissionDescriptor{Name: "clipboard-write"},
|
||||
browser.PermissionSettingGranted,
|
||||
),
|
||||
loadPage(url),
|
||||
))
|
||||
|
||||
click(ctx, t, copyButton)
|
||||
|
||||
assert.True(t, shown(ctx, copyButton+`[text()="Copied"]`),
|
||||
`clicking Copy does not show "Copied"`)
|
||||
}
|
||||
|
||||
// checkEntrypointEdit loads a webhook page whose entrypoint has no
|
||||
// description, and checks that Edit shows the edit form in place of
|
||||
// the description and hides until the form closes, so the form always
|
||||
// opens on the saved description; that Cancel hides it and drops what
|
||||
// was typed; that after typing, opening the page at elsewhere and going
|
||||
// back, Edit again opens the form on the saved description; and that
|
||||
// Save changes the description the page shows.
|
||||
func checkEntrypointEdit(
|
||||
ctx context.Context, t *testing.T, url, elsewhere string,
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
// Cancel and Save are found inside the edit form, since the add
|
||||
// target form has buttons of the same names.
|
||||
const (
|
||||
editForm = `form[action$="/edit"]`
|
||||
input = editForm + ` input[name="description"]`
|
||||
cancelEdit = `//form[contains(@action, "/edit")]/button[text()="Cancel"]`
|
||||
saveEdit = `//form[contains(@action, "/edit")]/button[text()="Save"]`
|
||||
description = `//span[text()="Entrypoint"]`
|
||||
edit = `//button[text()="Edit"]`
|
||||
assert.Equal(
|
||||
t, slackFields, fields,
|
||||
"with Slack chosen, the HTTP fields must not be submitted",
|
||||
)
|
||||
|
||||
require.NoError(t, chromedp.Run(ctx, loadPage(url)))
|
||||
|
||||
assert.True(t, hidden(ctx, editForm),
|
||||
"the edit form shows before Edit is clicked")
|
||||
|
||||
click(ctx, t, edit)
|
||||
assert.True(t, shown(ctx, editForm),
|
||||
"clicking Edit does not show the edit form")
|
||||
assert.True(t, hidden(ctx, description),
|
||||
"the description stays shown beside the edit form")
|
||||
assert.True(t, hidden(ctx, edit),
|
||||
"Edit stays shown while the edit form is open")
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx, chromedp.SendKeys(input, "draft", chromedp.ByQuery),
|
||||
))
|
||||
click(ctx, t, cancelEdit)
|
||||
assert.True(t, hidden(ctx, editForm),
|
||||
"clicking Cancel does not hide the edit form")
|
||||
assert.True(t, shown(ctx, description),
|
||||
"clicking Cancel does not show the description again")
|
||||
assert.True(t, shown(ctx, edit),
|
||||
"clicking Cancel does not show Edit again")
|
||||
|
||||
var typed string
|
||||
|
||||
click(ctx, t, edit)
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx, chromedp.Value(input, &typed, chromedp.ByQuery),
|
||||
))
|
||||
assert.Empty(t, typed, "Cancel keeps what was typed")
|
||||
|
||||
var loaded string
|
||||
var loaded, restored string
|
||||
|
||||
// Going back waits for the load event, after which the browser has
|
||||
// restored the form.
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
chromedp.SendKeys(input, "draft", chromedp.ByQuery),
|
||||
loadPage(elsewhere),
|
||||
chromedp.NavigateBack(),
|
||||
chromedp.WaitNotPresent("[x-cloak]", chromedp.ByQuery),
|
||||
chromedp.Evaluate(
|
||||
`performance.getEntriesByType("navigation")[0].type`, &loaded,
|
||||
),
|
||||
chromedp.Evaluate(howLoaded, &loaded),
|
||||
chromedp.Evaluate(chosen, &restored),
|
||||
))
|
||||
|
||||
// A page the browser kept in memory and showed again as it was
|
||||
// would prove nothing here.
|
||||
require.Equal(
|
||||
t, "back_forward", loaded,
|
||||
"going back, the browser did not load the page again",
|
||||
)
|
||||
require.Equal(
|
||||
t, "slack", restored,
|
||||
"going back, the browser did not restore the chosen type",
|
||||
)
|
||||
|
||||
click(ctx, t, edit)
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx, chromedp.Value(input, &typed, chromedp.ByQuery),
|
||||
))
|
||||
assert.Empty(t, typed, "going back puts what was typed back in the form")
|
||||
click(ctx, t, `//h2[text()="Targets"]/following-sibling::button`)
|
||||
|
||||
assert.True(t, shown(ctx, slackURL),
|
||||
"going back with Slack chosen, the Slack fields are not shown")
|
||||
assert.True(t, hidden(ctx, httpURL),
|
||||
"going back with Slack chosen, the HTTP fields are shown")
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx, chromedp.SendKeys(input, "Billing sender", chromedp.ByQuery),
|
||||
ctx, chromedp.Evaluate(submitted, &fields),
|
||||
))
|
||||
click(ctx, t, saveEdit)
|
||||
|
||||
assert.True(t, shown(ctx, `//span[text()="Billing sender"]`),
|
||||
"saving the edit form does not change the description")
|
||||
assert.Equal(
|
||||
t, slackFields, fields,
|
||||
"going back with Slack chosen, the HTTP fields must not be submitted",
|
||||
)
|
||||
}
|
||||
|
||||
// checkRecentEvents loads a webhook page and checks that of its recent
|
||||
// events only the newest starts expanded, showing its body, that
|
||||
// clicking the older one's row expands it and clicking again collapses
|
||||
// it, and that clicking the newest one's row collapses it. It then
|
||||
// follows the newest one's Open link to the event's own page, which
|
||||
// shows the body.
|
||||
func checkRecentEvents(ctx context.Context, t *testing.T, url string) {
|
||||
t.Helper()
|
||||
|
||||
// The newest event's body is pretty-printed JSON. Each row's
|
||||
// toggle is the button in the element that holds its state.
|
||||
newest := `//pre[contains(., '"hello": "browser"')]`
|
||||
older := `//pre[text()="` + olderBody + `"]`
|
||||
toggle := `/ancestor::div[@x-data][1]//button`
|
||||
|
||||
require.NoError(t, chromedp.Run(ctx, loadPage(url)))
|
||||
|
||||
assert.True(t, shown(ctx, newest), "the newest event starts collapsed")
|
||||
assert.True(t, hidden(ctx, older), "an older event starts expanded")
|
||||
|
||||
click(ctx, t, older+toggle)
|
||||
assert.True(t, shown(ctx, older), "clicking an event does not expand it")
|
||||
|
||||
click(ctx, t, older+toggle)
|
||||
assert.True(t, hidden(ctx, older),
|
||||
"clicking an event again does not collapse it")
|
||||
|
||||
click(ctx, t, newest+toggle)
|
||||
assert.True(t, hidden(ctx, newest),
|
||||
"clicking the newest event does not collapse it")
|
||||
|
||||
require.NoError(t, chromedp.Run(ctx, loadPage(url)))
|
||||
click(ctx, t, newest+`/ancestor::div[@x-data][1]//a[text()="Open"]`)
|
||||
|
||||
assert.True(t, shown(ctx, `//h2[text()="Body"]`),
|
||||
"Open does not lead to the event's own page")
|
||||
assert.True(t, shown(ctx, newest),
|
||||
"the event's own page does not show its body")
|
||||
}
|
||||
|
||||
// checkEventLog loads the event log and checks an event's row. Clicking
|
||||
// its ID expands the event, and in there clicking its delivery shows the
|
||||
// delivery's attempts and clicking again hides them. Clicking the row's
|
||||
// caret collapses the event, clicking it again expands it, and clicking
|
||||
// the ID again collapses it. While the event is expanded the row says so
|
||||
// and its caret is turned up, and while it is collapsed neither. It then
|
||||
// runs checkEventSelection on the log's last event, lastEventID, and
|
||||
// checkEventKeyboard on eventID.
|
||||
// checkEventLog loads the event log and checks that clicking an event's
|
||||
// row expands it, that in there clicking its delivery shows the
|
||||
// delivery's attempts and clicking again hides them, and that clicking
|
||||
// the event's row again collapses it.
|
||||
func checkEventLog(
|
||||
ctx context.Context,
|
||||
t *testing.T,
|
||||
url, eventID, lastEventID, targetName string,
|
||||
ctx context.Context, t *testing.T, url, eventID, targetName string,
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
// The event's row shows its ID and ends with its caret, which turns
|
||||
// up with Tailwind's rotate-180 class, and its Resubmit form is in
|
||||
// the part that expands. The delivery's row there shows the target's
|
||||
// name.
|
||||
id := `//span[text()="` + eventID + `"]`
|
||||
row := id + `/ancestor::div[@role="button"]`
|
||||
caret := row + `//*[local-name()="svg"]`
|
||||
caretUp := caret + `[contains(@class, "rotate-180")]`
|
||||
caretDown := caret + `[not(contains(@class, "rotate-180"))]`
|
||||
expanded := `form[action$="/` + eventID + `/resubmit"]`
|
||||
// The event's row shows its ID, and its Resubmit form is in the part
|
||||
// that expands. The delivery's row there shows the target's name.
|
||||
eventRow := `//span[text()="` + eventID + `"]`
|
||||
expanded := `form[action$="/resubmit"]`
|
||||
deliveryRow := `//span[text()="` + targetName + `"]`
|
||||
attempt := `//span[text()="Attempt 1"]`
|
||||
|
||||
@@ -673,13 +347,8 @@ func checkEventLog(
|
||||
|
||||
assert.True(t, hidden(ctx, expanded), "the event starts expanded")
|
||||
|
||||
click(ctx, t, id)
|
||||
assert.True(t, shown(ctx, expanded),
|
||||
"clicking the event's ID does not expand it")
|
||||
assert.True(t, shown(ctx, row+`[@aria-expanded="true"]`),
|
||||
"the expanded event's row does not say it is expanded")
|
||||
assert.True(t, shown(ctx, caretUp),
|
||||
"the expanded event's caret does not turn up")
|
||||
click(ctx, t, eventRow)
|
||||
assert.True(t, shown(ctx, expanded), "clicking the event does not expand it")
|
||||
|
||||
assert.True(t, hidden(ctx, attempt), "the delivery's attempts start shown")
|
||||
|
||||
@@ -691,362 +360,9 @@ func checkEventLog(
|
||||
assert.True(t, hidden(ctx, attempt),
|
||||
"clicking the delivery again does not hide its attempts")
|
||||
|
||||
click(ctx, t, caret)
|
||||
click(ctx, t, eventRow)
|
||||
assert.True(t, hidden(ctx, expanded),
|
||||
"clicking the caret does not collapse the event")
|
||||
assert.True(t, shown(ctx, row+`[@aria-expanded="false"]`),
|
||||
"the collapsed event's row does not say it is collapsed")
|
||||
assert.True(t, shown(ctx, caretDown),
|
||||
"the collapsed event's caret stays turned up")
|
||||
|
||||
click(ctx, t, caret)
|
||||
assert.True(t, shown(ctx, expanded),
|
||||
"clicking the caret again does not expand the event")
|
||||
|
||||
click(ctx, t, id)
|
||||
assert.True(t, hidden(ctx, expanded),
|
||||
"clicking the event's ID again does not collapse it")
|
||||
|
||||
checkEventSelection(ctx, t, url, lastEventID)
|
||||
checkEventKeyboard(ctx, t, url, eventID)
|
||||
}
|
||||
|
||||
// checkEventSelection loads the event log in a short window and checks
|
||||
// that selecting the ID of its last event, eventID, with the mouse leaves
|
||||
// the event as it was: dragging over the ID leaves it collapsed, the
|
||||
// caret's next click still expands it, and with the page then scrolled to
|
||||
// its end, a triple-click on the ID leaves it expanded and selects that
|
||||
// ID. Had the triple-click's first click collapsed the event, the page
|
||||
// would have got shorter and moved under the pointer.
|
||||
func checkEventSelection(
|
||||
ctx context.Context, t *testing.T, url, eventID string,
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
id := `//span[text()="` + eventID + `"]`
|
||||
row := id + `/ancestor::div[@role="button"]`
|
||||
caret := row + `//*[local-name()="svg"]`
|
||||
expanded := `form[action$="/` + eventID + `/resubmit"]`
|
||||
|
||||
var (
|
||||
selected, state string
|
||||
hasState bool
|
||||
scrolled float64
|
||||
)
|
||||
|
||||
// A single click toggles the event half a second later, so this waits
|
||||
// a second before reading the selection and whether it is expanded.
|
||||
read := chromedp.Tasks{
|
||||
chromedp.Sleep(time.Second),
|
||||
chromedp.Evaluate(`window.getSelection().toString()`, &selected),
|
||||
chromedp.AttributeValue(
|
||||
row, "aria-expanded", &state, &hasState, chromedp.BySearch,
|
||||
),
|
||||
}
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx, chromedp.EmulateViewport(shortWidth, shortHeight), loadPage(url),
|
||||
))
|
||||
|
||||
selectText(ctx, t, id)
|
||||
require.NoError(t, chromedp.Run(ctx, read))
|
||||
assert.Equal(t, eventID, selected, "the event's ID cannot be selected")
|
||||
require.True(t, hasState, "the event's row does not say if it is expanded")
|
||||
assert.Equal(t, "false", state, "selecting the event's ID expands it")
|
||||
|
||||
// The caret's click also clears the selection, so the triple-click's
|
||||
// first click finds nothing selected, as a person's would.
|
||||
click(ctx, t, caret)
|
||||
assert.True(t, shown(ctx, expanded),
|
||||
"clicking the caret after selecting the ID does not expand the event")
|
||||
|
||||
require.NoError(t, chromedp.Run(ctx, chromedp.Evaluate(
|
||||
`window.scrollTo(0, document.body.scrollHeight); window.scrollY`,
|
||||
&scrolled,
|
||||
)))
|
||||
require.Positive(t, scrolled, "the event log does not scroll")
|
||||
|
||||
tripleClick(ctx, t, id)
|
||||
require.NoError(t, chromedp.Run(ctx, read))
|
||||
assert.Contains(t, selected, eventID,
|
||||
"a triple-click does not select the event's ID")
|
||||
assert.Equal(t, "true", state,
|
||||
"a triple-click selecting the event's ID collapses it")
|
||||
}
|
||||
|
||||
// checkEventKeyboard loads the event log and checks that Tab from the
|
||||
// page's Back link reaches the event's row, the first after it, and that
|
||||
// Enter then expands the event and Space collapses it.
|
||||
func checkEventKeyboard(
|
||||
ctx context.Context, t *testing.T, url, eventID string,
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
back := `//a[contains(text(), "Back to")]`
|
||||
expanded := `form[action$="/` + eventID + `/resubmit"]`
|
||||
|
||||
var focused string
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
loadPage(url),
|
||||
chromedp.Focus(back, chromedp.BySearch),
|
||||
chromedp.KeyEvent(kb.Tab),
|
||||
chromedp.Evaluate(`document.activeElement.textContent`, &focused),
|
||||
))
|
||||
require.Contains(t, focused, eventID,
|
||||
"Tab from the Back link does not reach the event's row")
|
||||
|
||||
require.NoError(t, chromedp.Run(ctx, chromedp.KeyEvent(kb.Enter)))
|
||||
assert.True(t, shown(ctx, expanded), "Enter does not expand the event")
|
||||
|
||||
require.NoError(t, chromedp.Run(ctx, chromedp.KeyEvent(" ")))
|
||||
assert.True(t, hidden(ctx, expanded), "Space does not collapse the event")
|
||||
}
|
||||
|
||||
// selectText selects the text of the element matching an XPath
|
||||
// expression as a person does with the mouse: pressing the button at the
|
||||
// text's start, moving to its end and releasing it there.
|
||||
func selectText(ctx context.Context, t *testing.T, xpath string) {
|
||||
t.Helper()
|
||||
|
||||
var box *dom.BoxModel
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx, chromedp.Dimensions(xpath, &box, chromedp.BySearch),
|
||||
))
|
||||
|
||||
// The content box's corners, clockwise from its top left.
|
||||
left, right := box.Content[0]+1, box.Content[2]-1
|
||||
middle := (box.Content[1] + box.Content[5]) / 2
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
input.DispatchMouseEvent(input.MousePressed, left, middle).
|
||||
WithButton(input.Left).WithButtons(1).WithClickCount(1),
|
||||
input.DispatchMouseEvent(input.MouseMoved, right, middle).
|
||||
WithButton(input.Left).WithButtons(1),
|
||||
input.DispatchMouseEvent(input.MouseReleased, right, middle).
|
||||
WithButton(input.Left).WithClickCount(1),
|
||||
))
|
||||
}
|
||||
|
||||
// tripleClick clicks three times in a row in the middle of the element
|
||||
// matching an XPath expression, as a person does to select a whole line
|
||||
// of text. The browser selects a word on the second click and the whole
|
||||
// paragraph on the third.
|
||||
func tripleClick(ctx context.Context, t *testing.T, xpath string) {
|
||||
t.Helper()
|
||||
|
||||
var box *dom.BoxModel
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx, chromedp.Dimensions(xpath, &box, chromedp.BySearch),
|
||||
))
|
||||
|
||||
// The content box's corners, clockwise from its top left.
|
||||
x := (box.Content[0] + box.Content[2]) / 2
|
||||
y := (box.Content[1] + box.Content[5]) / 2
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
chromedp.MouseClickXY(x, y, chromedp.ClickCount(1)),
|
||||
chromedp.MouseClickXY(x, y, chromedp.ClickCount(2)),
|
||||
chromedp.MouseClickXY(x, y, chromedp.ClickCount(3)),
|
||||
))
|
||||
}
|
||||
|
||||
// The parts of the new webhook page the checks below find and click.
|
||||
const (
|
||||
archiveBox = `//input[@name="archive"]`
|
||||
archiveIsOn = `document.querySelector('input[name="archive"]').checked`
|
||||
pruningChoice = `//select[@name="archive_expiry"]`
|
||||
createButton = `//button[text()="Create Webhook"]`
|
||||
)
|
||||
|
||||
// checkArchiveChoice loads the new webhook page and checks that the
|
||||
// archive pruning choice stays hidden until the archive box is checked
|
||||
// and hides again when it is unchecked; and that after checking it,
|
||||
// opening the page at elsewhere and going back, the page again shows
|
||||
// the box unchecked and the choice hidden.
|
||||
func checkArchiveChoice(
|
||||
ctx context.Context, t *testing.T, url, elsewhere string,
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
require.NoError(t, chromedp.Run(ctx, loadPage(url)))
|
||||
|
||||
assert.True(t, hidden(ctx, pruningChoice),
|
||||
"the pruning choice shows before archive is checked")
|
||||
|
||||
click(ctx, t, archiveBox)
|
||||
assert.True(t, shown(ctx, pruningChoice),
|
||||
"checking archive does not show the pruning choice")
|
||||
|
||||
click(ctx, t, archiveBox)
|
||||
assert.True(t, hidden(ctx, pruningChoice),
|
||||
"unchecking archive does not hide the pruning choice")
|
||||
|
||||
var (
|
||||
loaded string
|
||||
checked bool
|
||||
)
|
||||
|
||||
click(ctx, t, archiveBox)
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
loadPage(elsewhere),
|
||||
chromedp.NavigateBack(),
|
||||
chromedp.WaitNotPresent("[x-cloak]", chromedp.ByQuery),
|
||||
chromedp.Evaluate(
|
||||
`performance.getEntriesByType("navigation")[0].type`, &loaded,
|
||||
),
|
||||
chromedp.Evaluate(archiveIsOn, &checked),
|
||||
))
|
||||
require.Equal(
|
||||
t, "back_forward", loaded,
|
||||
"going back, the browser did not load the page again",
|
||||
)
|
||||
|
||||
assert.False(t, checked, "going back leaves archive checked")
|
||||
assert.True(t, hidden(ctx, pruningChoice),
|
||||
"going back shows the pruning choice")
|
||||
}
|
||||
|
||||
// checkNewWebhookTargets submits the new webhook page with the HTTP
|
||||
// target URL filled in or empty, and with archive left off or checked
|
||||
// with each pruning choice, and checks that each webhook is created
|
||||
// with exactly the targets asked for.
|
||||
func checkNewWebhookTargets(
|
||||
ctx context.Context, t *testing.T, env *testEnv, url string,
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
// Each value the pruning choice submits, after an empty one that
|
||||
// stands for archive left off.
|
||||
expiries := []string{
|
||||
"", "never", "1h", "12h", "24h", "720h", "2160h", "8760h",
|
||||
}
|
||||
|
||||
for _, httpURL := range []string{"", publicTargetURL} {
|
||||
for _, expiry := range expiries {
|
||||
name := "url=" + httpURL + " archive=" + expiry
|
||||
want := map[database.TargetType]string{}
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
loadPage(url),
|
||||
chromedp.SetValue("#name", name, chromedp.ByQuery),
|
||||
))
|
||||
|
||||
if httpURL != "" {
|
||||
require.NoError(t, chromedp.Run(ctx, chromedp.SetValue(
|
||||
"#http_url", httpURL, chromedp.ByQuery,
|
||||
)))
|
||||
|
||||
want[database.TargetTypeHTTP] = `{"url":"` + httpURL + `"}`
|
||||
}
|
||||
|
||||
if expiry != "" {
|
||||
// The choice showing moves Create down, so it is
|
||||
// waited for before Create is clicked.
|
||||
click(ctx, t, archiveBox)
|
||||
require.Truef(t, shown(ctx, pruningChoice),
|
||||
"%s: checking archive does not show the pruning choice",
|
||||
name)
|
||||
require.NoError(t, chromedp.Run(ctx, chromedp.SetValue(
|
||||
pruningChoice, expiry, chromedp.BySearch,
|
||||
)))
|
||||
|
||||
want[database.TargetTypeDatabase] = `{"expiry":"` + expiry + `"}`
|
||||
}
|
||||
|
||||
click(ctx, t, createButton)
|
||||
require.Truef(t, shown(ctx, `//h1[text()="`+name+`"]`),
|
||||
"%s: the new webhook's page does not open", name)
|
||||
|
||||
assert.Equalf(t, want, targetConfigs(t, env, name),
|
||||
"%s: the webhook does not have the targets asked for", name)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// targetConfigs reads the targets of the webhook named name, and
|
||||
// returns each one's stored configuration by its type.
|
||||
func targetConfigs(
|
||||
t *testing.T, env *testEnv, name string,
|
||||
) map[database.TargetType]string {
|
||||
t.Helper()
|
||||
|
||||
var (
|
||||
webhook database.Webhook
|
||||
targets []database.Target
|
||||
)
|
||||
|
||||
require.NoError(t, env.db.DB().
|
||||
Where("name = ?", name).First(&webhook).Error)
|
||||
require.NoError(t, env.db.DB().
|
||||
Where("webhook_id = ?", webhook.ID).Find(&targets).Error)
|
||||
|
||||
configs := map[database.TargetType]string{}
|
||||
for _, target := range targets {
|
||||
configs[target.Type] = target.Config
|
||||
}
|
||||
|
||||
return configs
|
||||
}
|
||||
|
||||
// checkRefusedNewWebhook submits the new webhook page with archive
|
||||
// checked and an HTTP target URL the server refuses, a loopback
|
||||
// destination, and checks that the page comes back with the reason and
|
||||
// every value entered, archive still checked and its pruning choice
|
||||
// showing.
|
||||
func checkRefusedNewWebhook(ctx context.Context, t *testing.T, url string) {
|
||||
t.Helper()
|
||||
|
||||
const refusedURL = "http://127.0.0.1/hook"
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
loadPage(url),
|
||||
chromedp.SetValue("#name", "refused", chromedp.ByQuery),
|
||||
chromedp.SetValue("#description", "kept", chromedp.ByQuery),
|
||||
chromedp.SetValue("#retention_days", "7", chromedp.ByQuery),
|
||||
chromedp.SetValue("#http_url", refusedURL, chromedp.ByQuery),
|
||||
))
|
||||
click(ctx, t, archiveBox)
|
||||
require.True(t, shown(ctx, pruningChoice),
|
||||
"checking archive does not show the pruning choice")
|
||||
require.NoError(t, chromedp.Run(ctx, chromedp.SetValue(
|
||||
pruningChoice, "2160h", chromedp.BySearch,
|
||||
)))
|
||||
click(ctx, t, createButton)
|
||||
|
||||
assert.True(t, shown(ctx, `//div[@class="alert-error"]`),
|
||||
"a refused webhook does not show the reason")
|
||||
|
||||
var (
|
||||
name, description, retention, typed, expiry string
|
||||
checked bool
|
||||
)
|
||||
|
||||
require.NoError(t, chromedp.Run(
|
||||
ctx,
|
||||
chromedp.Value("#name", &name, chromedp.ByQuery),
|
||||
chromedp.Value("#description", &description, chromedp.ByQuery),
|
||||
chromedp.Value("#retention_days", &retention, chromedp.ByQuery),
|
||||
chromedp.Value("#http_url", &typed, chromedp.ByQuery),
|
||||
chromedp.Value("#archive_expiry", &expiry, chromedp.ByQuery),
|
||||
chromedp.Evaluate(archiveIsOn, &checked),
|
||||
))
|
||||
|
||||
assert.Equal(t, "refused", name, "the name entered is lost")
|
||||
assert.Equal(t, "kept", description, "the description entered is lost")
|
||||
assert.Equal(t, "7", retention, "the retention entered is lost")
|
||||
assert.Equal(t, refusedURL, typed, "the url entered is lost")
|
||||
assert.True(t, checked, "archive is no longer checked")
|
||||
assert.True(t, shown(ctx, pruningChoice), "the pruning choice is hidden")
|
||||
assert.Equal(t, "2160h", expiry, "the pruning chosen is lost")
|
||||
"clicking the event again does not collapse it")
|
||||
}
|
||||
|
||||
// checkMobileMenu loads a page in a phone-sized window and checks that
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user