Author SHA1 Message Date
clawbot ff0018cf43 Add a statistics pane to the webhook page (closes #368)
check / check (push) Failing after 2m53s
Each webhook's event database keeps running totals: one row for its
events, and one row per target for that target's deliveries, delivered
and failed, each with what retention removed. Every write to them
shares the transaction of the rows it counts. Deliveries get a
finished_at column; it and target_id end the status index, so each
target's deliveries finished in a window come from one index-range
query grouped by target. Retention deletes 1000 expired events per
transaction. The pane is its own template, its figures in tables.

The schema changes in place with nothing back-filled, so an existing
database must be recreated.

Model: opus-5-5
2026-10-01 21:05:05 +00:00
130 changed files with 2063 additions and 7676 deletions
+4 -10
View File
@@ -1,20 +1,14 @@
# .git is sent so the build can derive the version it stamps into the binary
# (script/version). Its config, which can hold a remote URL carrying a
# credential and which `git describe` does not need, is left out of a
# directory context. A context sent as a tar is not filtered by this file, so
# it carries .git/config unless its sender leaves it out.
.git/config
# No tracked file may be listed here: git in the build would see it as
# deleted and mark the version -dirty.
#
# .ci-fingerprint is deliberately NOT excluded: it is the CI cache barrier # .ci-fingerprint is deliberately NOT excluded: it is the CI cache barrier
# that keeps the check stages from replaying a cached pass. See the lint # that keeps the check stages from replaying a cached pass. See the lint
# stage of the Dockerfile. # stage of the Dockerfile.
.git/
bin/ bin/
# Extracted from 3p/ by `make assets` inside the build; a host copy is not # Extracted from 3p/ by `make assets` inside the build; a host copy is not
# needed. The tarball in 3p/ must stay in the context. # needed. The tarball in 3p/ must stay in the context.
static/js/alpine.min.js static/js/alpine.min.js
*.md
LICENSE
.editorconfig
.env .env
.env.* .env.*
*.db *.db
+13 -7
View File
@@ -12,8 +12,9 @@ jobs:
- name: Checkout - name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 2024-10-23 uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 2024-10-23
with: with:
# The superseded-status step needs history to walk ancestors (it # The fingerprint step below needs history to find the last commit
# aborts on a shallow clone). # that touched the Docker build context, and the superseded-status
# step needs it to walk ancestors (it aborts on a shallow clone).
fetch-depth: 0 fetch-depth: 0
- name: Mark superseded run statuses - name: Mark superseded run statuses
@@ -27,11 +28,16 @@ jobs:
run: script/ci-mark-superseded run: script/ci-mark-superseded
- name: Fingerprint the build context - name: Fingerprint the build context
# Writes the hash of the commit being checked into the context, which # `.dockerignore` keeps docs out of the build context, so a docs-only
# invalidates the `COPY . .` layer of both check stages: a commit # commit legitimately replays the whole image from cache and stays
# that was never linted, format-checked, tested and built cannot # cheap. Every other commit writes a new fingerprint into the context,
# report success from cache. # which invalidates the `COPY . .` layer of both check stages: a
run: git rev-parse HEAD > .ci-fingerprint # commit that was never linted, formatted-checked, tested and built
# cannot report success from cache.
run: |
set -eu
fp="$(git log -1 --format=%H -- . ':!*.md' ':!LICENSE' ':!.editorconfig')"
printf '%s\n' "${fp:-$GITHUB_SHA}" > .ci-fingerprint
- name: Build Docker image (runs make check) - name: Build Docker image (runs make check)
run: script/cibuild run: script/cibuild
+9 -22
View File
@@ -12,8 +12,8 @@ WORKDIR /src
COPY go.mod go.sum ./ COPY go.mod go.sum ./
RUN go mod download RUN go mod download
# Copy source code. In CI the context also carries .ci-fingerprint, which # Copy source code. In CI the context also carries .ci-fingerprint, whose
# holds the hash of the commit being checked (see # value changes with every commit that touches the build context (see
# .gitea/workflows/check.yml). That invalidates this layer, so the checks # .gitea/workflows/check.yml). That invalidates this layer, so the checks
# below cannot report success by replaying a cached pass. Do not add it to # below cannot report success by replaying a cached pass. Do not add it to
# .dockerignore. # .dockerignore.
@@ -38,13 +38,8 @@ FROM golang:1.26.1-bookworm@sha256:4465644228bc2857a954b092167e12aa59c006a349228
COPY --from=lint /src/go.sum /dev/null COPY --from=lint /src/go.sum /dev/null
# jq is a runtime dependency of script/ci-mark-superseded, which the test # jq is a runtime dependency of script/ci-mark-superseded, which the test
# suite executes. git is what script/version derives the version with. # suite executes.
RUN apt-get update && apt-get install -y --no-install-recommends make curl ca-certificates jq git && rm -rf /var/lib/apt/lists/* RUN apt-get update && apt-get install -y --no-install-recommends make curl ca-certificates jq && rm -rf /var/lib/apt/lists/*
# A build context sent as a tar archive keeps its files' owners, and git
# refuses to read a checkout owned by another user. Trust this one
# whoever owns it.
RUN git config --system --add safe.directory /build
WORKDIR /build WORKDIR /build
@@ -60,22 +55,14 @@ COPY . .
# from its tarball in 3p/. # from its tarball in 3p/.
RUN make test RUN make test
# Version stamped into the binary: the VERSION build arg when one is # Version stamped into the binary. .dockerignore excludes .git/, so
# given, otherwise what script/version derives from the .git the build # nothing in this stage can derive it: script/docker resolves it on the
# context carries, so any `docker build .` of a clone stamps its commit. # host and passes it in. The default is what a bare `docker build .`
# With neither, as from a source tarball, it is "unknown". # with no --build-arg gets, and it names no tag the tree may not be at.
# #
# Declared here, below the test step, so a changed version does not # Declared here, below the test step, so a changed version does not
# invalidate its cached layer. # invalidate its cached layer.
ARG VERSION ARG VERSION=unknown
# A context that carries .git must not stamp "unknown": that means git is
# missing here or could not read the checkout, and the image could not be
# traced back to its commit.
RUN if [ -d .git ] && [ "$(make version VERSION="$VERSION")" = unknown ]; then \
echo "version is unknown although the build context carries .git" >&2; \
exit 1; \
fi
RUN make build VERSION="$VERSION" RUN make build VERSION="$VERSION"
+4 -4
View File
@@ -4,12 +4,12 @@
.DEFAULT_GOAL := check .DEFAULT_GOAL := check
# Version stamped into the binary. Derived from git by script/version; # Version stamped into the binary. Derived from git by script/version;
# override it (`make build VERSION=v1.2.3`) to stamp a given value, which is # override it (`make build VERSION=v1.2.3`) where git metadata is
# how the Dockerfile passes its build arg in. # unavailable, which is how the Dockerfile passes its build arg in.
VERSION ?= $(shell script/version) VERSION ?= $(shell script/version)
# An empty override (`make build VERSION=`, or the Dockerfile's `make build # An empty override (`make build VERSION=`, or a `--build-arg VERSION=`
# VERSION="$VERSION"` when no VERSION build arg was given) means unset, # landing on the Dockerfile's `make build VERSION="$VERSION"`) means unset,
# exactly as it does in script/version -- stamping "" would leave the binary # exactly as it does in script/version -- stamping "" would leave the binary
# reporting no version and the footer back on its "dev" fallback. `override` # reporting no version and the footer back on its "dev" fallback. `override`
# is required: a plain assignment loses to the command-line definition it # is required: a plain assignment loses to the command-line definition it
+229 -327
View File
@@ -7,7 +7,7 @@ services, durably stores them, and delivers them to configured targets
with retry support, logging, and observability. Category: infrastructure with retry support, logging, and observability. Category: infrastructure
/ web service. License: MIT. / web service. License: MIT.
Each entrypoint is a version 4 UUID served at `/h/{uuid}`, and Each entrypoint is a version 4 UUID served at `/webhook/{uuid}`, and
that UUID is the entrypoint's only credential. webhooker does not use that UUID is the entrypoint's only credential. webhooker does not use
shared secrets, HMAC signatures or token headers on the receiver, and shared secrets, HMAC signatures or token headers on the receiver, and
will not add them — read will not add them — read
@@ -135,20 +135,16 @@ TTY detection, and security headers are always applied.
| `BIND_ADDRESS` | IP address the HTTP listener binds. Loopback by default, so the cleartext listener is not published on every interface. The Docker image ships `0.0.0.0` instead. See [Bind address](#bind-address) | `127.0.0.1` (image: `0.0.0.0`) | | `BIND_ADDRESS` | IP address the HTTP listener binds. Loopback by default, so the cleartext listener is not published on every interface. The Docker image ships `0.0.0.0` instead. See [Bind address](#bind-address) | `127.0.0.1` (image: `0.0.0.0`) |
| `DATA_DIR` | Directory for all SQLite databases | `/var/lib/webhooker` | | `DATA_DIR` | Directory for all SQLite databases | `/var/lib/webhooker` |
| `DEBUG` | Enable debug logging | `false` | | `DEBUG` | Enable debug logging | `false` |
| `MAINTENANCE_MODE` | Report `maintenanceMode: true` in the healthcheck JSON. It does not change how any request is served — no maintenance page exists | `false` |
| `METRICS_USERNAME` | Basic auth username for `/metrics`. Must be set together with `METRICS_PASSWORD`; one without the other fails startup | `""` | | `METRICS_USERNAME` | Basic auth username for `/metrics`. Must be set together with `METRICS_PASSWORD`; one without the other fails startup | `""` |
| `METRICS_PASSWORD` | Basic auth password for `/metrics`. Must be set together with `METRICS_USERNAME`; one without the other fails startup | `""` | | `METRICS_PASSWORD` | Basic auth password for `/metrics`. Must be set together with `METRICS_USERNAME`; one without the other fails startup | `""` |
| `SENTRY_DSN` | Sentry error reporting DSN. Unset leaves error reporting off; a value the Sentry SDK cannot parse fails startup rather than serving with reporting silently off | `""` | | `SENTRY_DSN` | Sentry error reporting DSN. Unset leaves error reporting off; a value the Sentry SDK cannot parse fails startup rather than serving with reporting silently off | `""` |
| `RETENTION_SWEEP_INTERVAL` | How often the retention reaper and archive sweeper run (Go duration, must be positive) | `1h` | | `RETENTION_SWEEP_INTERVAL` | How often the retention reaper and archive sweeper run (Go duration, must be positive) | `1h` |
| `SESSION_IDLE_TIMEOUT` | Idle session timeout (Go duration) | `24h` | | `SESSION_IDLE_TIMEOUT` | Idle session timeout (Go duration) | `24h` |
| `RECEIVER_RATE_LIMIT` | Receiver requests/minute per IP per entrypoint (10x that per IP across the route) | `120` | | `RECEIVER_RATE_LIMIT` | Receiver requests/minute per IP per entrypoint (10x that per IP across the route) | `120` |
| `TRUSTED_PROXIES` | CIDRs whose forwarded headers are trusted. A set value replaces the default. If any client can reach webhooker, or the proxy in front of it, from an RFC 1918 source address, set it to the proxy's address alone. See [Trusted proxies](#trusted-proxies) | `10.0.0.0/8,172.16.0.0/12,192.168.0.0/16` (RFC 1918) | | `TRUSTED_PROXIES` | CIDRs whose forwarded headers are trusted (unset: all clients behind a proxy share one rate-limit bucket; a correct login password is never throttled either way) | `""` (none) |
| `ALLOWED_EGRESS_CIDRS` | CIDRs that delivery targets may reach despite the SSRF blocklist. Read [Allowing egress to your own network](#allowing-egress-to-your-own-network) before setting it | `""` (none) | | `ALLOWED_EGRESS_CIDRS` | CIDRs that delivery targets may reach despite the SSRF blocklist. Read [Allowing egress to your own network](#allowing-egress-to-your-own-network) before setting it | `""` (none) |
The Settings page of the web UI (`/settings`, behind the login) lists
every one of these with the value the running server loaded. It is
read-only, and it shows `METRICS_PASSWORD` and `SENTRY_DSN` only as
set or not set, never their values.
#### Allowing egress to your own network #### Allowing egress to your own network
By default every delivery target must resolve to a public address. The By default every delivery target must resolve to a public address. The
@@ -161,22 +157,6 @@ public cloud metadata addresses: currently only `168.63.129.16`, Azure's
WireServer, which serves an Azure VM its credentials. Because it is a WireServer, which serves an Azure VM its credentials. Because it is a
public address, listing it in `ALLOWED_EGRESS_CIDRS` reopens it. public address, listing it in `ALLOWED_EGRESS_CIDRS` reopens it.
That is all the default blocklist covers: the IPv4 private and reserved
ranges; of IPv6, only loopback (`::1`), the unspecified address (`::`),
unique local addresses (`fc00::/7`), link-local addresses (`fe80::/10`),
multicast (`ff00::/8`) and documentation space (`2001:db8::/32`); and
certain public addresses. A public address belongs on the default
blocklist only if it hands credentials, user data or bootstrap material
to whatever can reach it, without the caller presenting anything. A
provider's other public addresses are not refused. IBM Cloud, for
example, serves its package mirrors, time servers and object storage on
`161.26.0.0/16`, and the private endpoints of its own cloud services on
`166.8.0.0/14`. Neither range hands out credentials that way: the token
service among those endpoints issues a token only in exchange for
something the caller presents, such as an API key. Reaching these
services can be a legitimate delivery, and every cloud has some, so a
partial list would promise coverage it does not give.
That default is also inconvenient for the thing webhooker is mostly That default is also inconvenient for the thing webhooker is mostly
for: taking a public webhook and forwarding it to something on your own for: taking a public webhook and forwarding it to something on your own
network. A container on the same Docker network, a box on `10.x`, a network. A container on the same Docker network, a box on `10.x`, a
@@ -215,16 +195,16 @@ Two things this setting cannot do:
the list is always an allowlist; an empty list (the default) means the list is always an allowlist; an empty list (the default) means
every private and reserved range stays refused. Note that every private and reserved range stays refused. Note that
`0.0.0.0/0` gets you most of the way there anyway, per above. `0.0.0.0/0` gets you most of the way there anyway, per above.
- **It cannot open link-local, the unspecified addresses, or a cloud - **It cannot open link-local, or a cloud metadata endpoint at a
metadata endpoint at a non-public address that discloses credentials non-public address that discloses credentials or user data.** An
or user data.** A metadata address is on the list below when it is not address is on the list below when it is not a public address and both
a public address and both of these hold: the provider fixes it, so it of these hold: the provider fixes it, so it cannot collide with
cannot collide with anything you run; and reaching it hands out anything you run; and reaching it hands out credentials, user data or
credentials, user data or bootstrap material. Those stay blocked no bootstrap material. Those stay blocked no matter what you list,
matter what you list, including when you list them outright or list a including when you list them outright or list a supernet such as
supernet such as `0.0.0.0/0`, `::/0`, `fd00::/8` or `100.64.0.0/10`. `0.0.0.0/0`, `::/0`, `fd00::/8` or `100.64.0.0/10`. Treat this as best
Treat this as best effort rather than a guarantee — it is a effort rather than a guarantee — it is a hand-maintained list and the
hand-maintained list and the caveat below the table applies: caveat below the table applies:
| Blocked unconditionally | What it is | | Blocked unconditionally | What it is |
| ----------------------- | ---------- | | ----------------------- | ---------- |
@@ -238,25 +218,14 @@ Two things this setting cannot do:
| `fd00:a9fe:a9fe::1/128` | Linode/Akamai metadata over IPv6 | | `fd00:a9fe:a9fe::1/128` | Linode/Akamai metadata over IPv6 |
| `100.100.100.200/32` | Alibaba Cloud metadata, inside CGNAT | | `100.100.100.200/32` | Alibaba Cloud metadata, inside CGNAT |
| `192.0.0.192/32` | Oracle Cloud Classic metadata | | `192.0.0.192/32` | Oracle Cloud Classic metadata |
| `0.0.0.0/32` | IPv4 unspecified address, which reaches this host's loopback on Linux |
| `::/128` | IPv6 unspecified address, which reaches this host's loopback on Linux |
| `::a9fe:a9fe/128` | `169.254.169.254` as an IPv4-compatible IPv6 address | | `::a9fe:a9fe/128` | `169.254.169.254` as an IPv4-compatible IPv6 address |
| `64:ff9b::a9fe:a9fe/128` | `169.254.169.254` behind the NAT64 well-known prefix | | `64:ff9b::a9fe:a9fe/128` | `169.254.169.254` behind the NAT64 well-known prefix |
The IPv4-mapped form `::ffff:169.254.169.254` is covered by the The IPv4-mapped form `::ffff:169.254.169.254` is covered by the
`169.254.0.0/16` entry. Reaching any of these but the two unspecified `169.254.0.0/16` entry. Reaching any of these is credential or
addresses is credential or user-data theft rather than delivery to an user-data theft rather than delivery to an internal service. Every
internal service. Every entry outside the two link-local blocks is a entry outside the two link-local blocks is a single address, so
single address, so blocking it costs you nothing else on the network blocking it costs you nothing else on the network around it.
around it.
The unspecified addresses `0.0.0.0` and `::` hand out nothing
themselves, but no host can have either, and on Linux a connection to
one reaches this host's own loopback. They are listed so that an
allowlist reaches loopback only through an entry that covers a loopback
address, such as `127.0.0.0/8`, `::1` or `0.0.0.0/0`, never through one
that covers only `0.0.0.0` or `::`; `0.0.0.0/8`, for example, does not
open loopback.
The six ULA entries, all inside `fd00::/8`, are why this matters in The six ULA entries, all inside `fd00::/8`, are why this matters in
practice: `fd00::/8` is an ordinary block to allowlist for your own practice: `fd00::/8` is an ordinary block to allowlist for your own
@@ -405,37 +374,41 @@ unlocked.
`TRUSTED_PROXIES` is a comma-separated list of CIDR blocks (a bare `TRUSTED_PROXIES` is a comma-separated list of CIDR blocks (a bare
address such as `192.168.1.7` is accepted and treated as a single address such as `192.168.1.7` is accepted and treated as a single
host), for example `192.168.1.7, 2001:db8::5`. It decides whose host), for example `192.168.1.7, 2001:db8::5`. It decides whose
`X-Forwarded-For` header the rate limiters believe, so it should cover `X-Forwarded-For` header the rate limiters believe, so it should name
the addresses of your reverse proxies. the addresses of your reverse proxies and nothing else.
`X-Forwarded-For` is honoured **only** when the connecting peer is `X-Forwarded-For` is honoured **only** when the connecting peer is
inside one of these blocks; for every other peer the client identity is inside one of these blocks; for every other peer the client identity is
the connection's own address and the header is ignored. Unset (or the connection's own address and the header is ignored. The default is
empty), the list is the RFC 1918 private ranges: `10.0.0.0/8`, the empty list, which trusts nobody — anything else would let any
`172.16.0.0/12` and `192.168.0.0/16`. A set value replaces the default client pick its own rate limit bucket, minting a fresh one per request
entirely. A set but unparseable value aborts startup. or draining someone else's. Set it to the address of your reverse
proxy, and to nothing wider. A set but unparseable value aborts
startup.
If any client can reach webhooker, or the proxy in front of it, from an That default is safe against forged headers, but leaving it unset in
RFC 1918 source address (directly, or through anything that can production has a cost you must know about. Production runs behind a
rewrite source addresses, such as NAT or a published container port), TLS-terminating reverse proxy, so with `TRUSTED_PROXIES` unset every
set `TRUSTED_PROXIES` to the proxy's address alone, or every rate request keys on the proxy's own address and all clients share a single
limit, the webhook receiver's included, can be bypassed by those bucket per limit. The receiver limits become service-wide ceilings,
clients. The address to set is the `remoteIP` field of the and the login endpoint's failure counting collapses onto one key, so a
`http request` log line for a request that came through the proxy. stranger's wrong passwords throttle every other client's wrong
passwords.
Behind a proxy the list does not cover, every request keys on the
proxy's own address and all clients share a single bucket per limit.
The receiver limits become service-wide ceilings, and the login
endpoint's failure counting collapses onto one key, so a stranger's
wrong passwords throttle every other client's wrong passwords. Set
`TRUSTED_PROXIES` to that proxy's address to restore per-client
buckets.
What it cannot do is lock the operator out. The login endpoint What it cannot do is lock the operator out. The login endpoint
verifies credentials **before** it consults any limit and charges only verifies credentials **before** it consults any limit and charges only
failures, so a correct password is never throttled no matter how full failures, so a correct password is never throttled no matter how full
the bucket is. See [Rate Limiting](#rate-limiting). the bucket is. See [Rate Limiting](#rate-limiting).
The remedy is to set `TRUSTED_PROXIES` to your reverse proxy's
address, which restores per-client buckets. webhooker logs a warning
at startup whenever `TRUSTED_PROXIES` is empty, in every environment,
because behind a proxy every client shares one bucket in `dev` and
`prod` alike. The warning is informational when nothing proxies to the
process: with no proxy in front, the peer address is the client's own
and the buckets are already per-client. See
[Rate Limiting](#rate-limiting) for what each limit shares.
`X-Real-IP` and `True-Client-IP` are **never** read, from any peer. `X-Real-IP` and `True-Client-IP` are **never** read, from any peer.
Reverse proxies append to `X-Forwarded-For` but forward other client Reverse proxies append to `X-Forwarded-For` but forward other client
headers verbatim, so a single-valued header is client-controlled even headers verbatim, so a single-valued header is client-controlled even
@@ -451,10 +424,20 @@ instead, since past such an entry the chain is not the shape assumed
here. The peer address is likewise used when the header is absent or here. The peer address is likewise used when the header is absent or
every hop in it is a trusted proxy. every hop in it is a trusted proxy.
Your proxy must therefore **append** the peer address to Two operator requirements follow:
`X-Forwarded-For` (nginx `$proxy_add_x_forwarded_for`, HAProxy
`option forwardfor`, Caddy and AWS ALB by default), and must append a - Your proxy must **append** the peer address to `X-Forwarded-For`
bare address with no port. (nginx `$proxy_add_x_forwarded_for`, HAProxy `option forwardfor`,
Caddy and AWS ALB by default), and must append a bare address with
no port.
- List proxy hosts **only**. Any address inside `TRUSTED_PROXIES`
chooses its own rate-limit key: its `X-Forwarded-For` is walked, so
it can name a different address on every request to get a fresh
bucket each time, or name another client's address to drain that
client's bucket. Never list a block that also covers clients — a
broad `10.0.0.0/8` on a network where clients live in the same range
makes all three limits, including the unauthenticated webhook
receiver, silently bypassable by every client in the block.
#### Sessions #### Sessions
@@ -514,8 +497,8 @@ no report is being sent — which is why it aborts rather than starting
with reporting off. Leaving it unset is not a mistake and not affected: with reporting off. Leaving it unset is not a mistake and not affected:
error reporting is simply off and startup is normal. error reporting is simply off and startup is normal.
The boolean variable `DEBUG` accepts exactly the spellings Go's Boolean variables (`DEBUG`, `MAINTENANCE_MODE`) accept exactly the
`strconv.ParseBool` accepts — `1`, `t`, `T`, `TRUE`, spellings Go's `strconv.ParseBool` accepts — `1`, `t`, `T`, `TRUE`,
`true`, `True`, `0`, `f`, `F`, `FALSE`, `false`, `False` — and nothing `true`, `True`, `0`, `f`, `F`, `FALSE`, `false`, `False` — and nothing
else. `yes`, `on`, and `off` are rejected rather than quietly treated else. `yes`, `on`, and `off` are rejected rather than quietly treated
as false. as false.
@@ -714,8 +697,7 @@ The app runs as a non-root user (`webhooker`, UID 1000), exposes port
The `/var/lib/webhooker` volume holds all SQLite databases: the main The `/var/lib/webhooker` volume holds all SQLite databases: the main
application database (`webhooker.db`), the per-webhook event databases application database (`webhooker.db`), the per-webhook event databases
(`events-{uuid}.db`), and any archive databases written by `database` (`events-{uuid}.db`), and any archive databases written by `database`
targets (`archive-{webhook_name}-{target_name}-{target_uuid}.db`). Mount targets (`archive-{uuid}.db`). Mount this as a persistent volume to
this as a persistent volume to
preserve data across container restarts. preserve data across container restarts.
**The container sets its data directory's owner and mode itself **The container sets its data directory's owner and mode itself
@@ -754,15 +736,10 @@ repository's `Dockerfile` and runs it. The app needs:
- **Volume:** one host directory mounted at `/var/lib/webhooker`. - **Volume:** one host directory mounted at `/var/lib/webhooker`.
- **Environment variables:** - **Environment variables:**
- `WEBHOOKER_ENVIRONMENT=prod` - `WEBHOOKER_ENVIRONMENT=prod`
- `TRUSTED_PROXIES`: unset, it is the RFC 1918 ranges. Set it to - `TRUSTED_PROXIES`: your reverse proxy's address on that Docker
your reverse proxy's address alone if that address is outside network. The `remoteIP` field of the `http request` log line for a
those ranges, or if any client can reach webhooker, or the proxy, request that came through the proxy shows it; the health check's
from an RFC 1918 source address (directly, or through anything own lines show `::1`. See [Trusted proxies](#trusted-proxies).
that can rewrite source addresses, such as NAT or a published
container port). The `remoteIP` field of the `http request` log
line for a request that came through the proxy shows that
address; the health check's own lines show `::1`. See
[Trusted proxies](#trusted-proxies).
- Leave `BIND_ADDRESS` and `DATA_DIR` unset: the image sets - Leave `BIND_ADDRESS` and `DATA_DIR` unset: the image sets
`BIND_ADDRESS` to `0.0.0.0`, and `DATA_DIR` defaults to `BIND_ADDRESS` to `0.0.0.0`, and `DATA_DIR` defaults to
`/var/lib/webhooker`. `/var/lib/webhooker`.
@@ -825,16 +802,12 @@ reports.
behind a proxy means the `X-Forwarded-Proto` header. The block below behind a proxy means the `X-Forwarded-Proto` header. The block below
sets it; without it every request is read as plaintext and cookies sets it; without it every request is read as plaintext and cookies
ship without `Secure`. See [Configuration](#configuration). ship without `Secure`. See [Configuration](#configuration).
3. **Make sure `TRUSTED_PROXIES` covers the proxy's address.** For a 3. **Set `TRUSTED_PROXIES` to the proxy's address.** Unset, every rate
proxy it does not cover, every rate limiter keys on the proxy, so limiter keys on the connecting peer, which behind a proxy is the
all clients share one bucket per limit. Unset, the list is the RFC proxy on every request: all clients collapse into one global bucket
1918 ranges, which do not cover a proxy that reaches the binary per limit and the receiver's per-IP limits become service-wide
itself over loopback (the binary bound to `127.0.0.1`). With the ceilings. See [Trusted proxies](#trusted-proxies). List the proxy
image, the address to check is the `remoteIP` field of the and nothing else.
`http request` log line for a request that came through the proxy.
If any client can reach webhooker, or the proxy, from an RFC 1918
source address, set the list to the proxy's address alone. See
[Trusted proxies](#trusted-proxies).
4. **Send `Host` as `$http_host`, not `$host`.** `$host` strips the 4. **Send `Host` as `$http_host`, not `$host`.** `$host` strips the
port. webhooker's Origin/Referer check compares against the host it port. webhooker's Origin/Referer check compares against the host it
was given, so on any port other than 443 `$host` makes every form was given, so on any port other than 443 `$host` makes every form
@@ -954,13 +927,13 @@ is both the simplest and the only complete rule:
encryption key), users, API keys, webhooks, entrypoints, targets. encryption key), users, API keys, webhooks, entrypoints, targets.
- `events-{webhook_uuid}.db` — **one per webhook**. Events, deliveries, - `events-{webhook_uuid}.db` — **one per webhook**. Events, deliveries,
delivery results. delivery results.
- `archive-{webhook_name}-{target_name}-{target_uuid}.db` — **one per - `archive-{webhook_uuid}.db` — **one per webhook that has a `database`
`database` target**. Archived events. The two names are made safe for target**. Archived events. Keyed on the webhook UUID, not the target
a file name, and the file is renamed when the webhook or the target is UUID: a webhook with several `database` targets still has exactly one
(see [Database Architecture](#database-architecture)). archive file.
`{webhook_uuid}` and `{target_uuid}` are UUID primary keys in their `{webhook_uuid}` is the webhook's UUID primary key in its canonical
canonical 36-character hyphenated form, so a real filename looks like 36-character hyphenated form, so a real filename looks like
`events-3f2a1c9e-....db`. The only other file is `webhooker.lock`, the `events-3f2a1c9e-....db`. The only other file is `webhooker.lock`, the
always-empty [single-instance lock](#single-instance-lock); it holds no always-empty [single-instance lock](#single-instance-lock); it holds no
state and is not part of the backup set — a copied one is stale and state and is not part of the backup set — a copied one is stale and
@@ -1034,8 +1007,8 @@ stopped copy.
Archive databases are the one exception the service is built for: the Archive databases are the one exception the service is built for: the
archive writer closes and reopens its handle around writes (debounced archive writer closes and reopens its handle around writes (debounced
to at most one reopen per second), so an operator can move an to at most one reopen per second), so an operator can move
`archive-….db` away for offline retention while the service runs, `archive-{uuid}.db` away for offline retention while the service runs,
and it is recreated on the next write. See and it is recreated on the next write. See
[Database Architecture](#database-architecture). That is a [Database Architecture](#database-architecture). That is a
move-the-file-away workflow, not a substitute for the backup procedures move-the-file-away workflow, not a substitute for the backup procedures
@@ -1053,7 +1026,7 @@ happens on the next write past the debounce window, when the connection
pool retires the idle connection (about a minute after the last write), pool retires the idle connection (about a minute after the last write),
or at the idle archive sweep — measured, the same file was a complete or at the idle archive sweep — measured, the same file was a complete
20 KB `.db` with no sidecars about a minute after its last write. A 20 KB `.db` with no sidecars about a minute after its last write. A
clean stop closes it too. So either move the `archive-….db` together clean stop closes it too. So either move `archive-{uuid}.db` together
with any `-wal`/`-shm` beside it, or wait until there are none. with any `-wal`/`-shm` beside it, or wait until there are none.
### Restore ### Restore
@@ -1150,29 +1123,13 @@ build itself.
| Uncommitted changes | the above with a `-dirty` suffix | | Uncommitted changes | the above with a `-dirty` suffix |
| No git metadata | `unknown` | | No git metadata | `unknown` |
The image derives it the same way, from the `.git` that the build `unknown` is what a source tarball or a `docker build .` with no
context carries, so any `docker build .` of a clone, with no build `--build-arg VERSION=...` reports. `.dockerignore` excludes `.git/`, so
arguments, stamps the commit it was built from; a shallow clone of one the build context carries no git metadata and the image cannot derive
branch has no tags and stamps the short SHA. `.dockerignore` must the version itself: `script/docker` (and so `make docker`) resolves it
therefore leave out neither `.git` nor any tracked file, which git in on the host and passes it in as the `VERSION` build arg. A build that
the build would see as deleted, marking the version `-dirty`. It does reports `unknown` is a build nobody told what it was; it is not a
leave `.git/config`, which can hold a remote URL carrying a credential failure, but it cannot be traced back to a commit.
and which `git describe` does not need, out of a directory context. A
context sent as a tar is not filtered by `.dockerignore`, so it carries
`.git/config` unless its sender leaves it out; for upaas, that is
https://git.eeqj.de/sneak/upaas/issues/274. git in the build
reads the checkout whoever owns its files, since a context sent as a tar
archive keeps the sender's owners and git otherwise refuses a checkout
owned by another user. A `VERSION` build arg (`--build-arg VERSION=...`)
takes precedence; `script/docker` (and so `make docker`) passes the one
`script/version` resolves on the host. The image build fails if its
context carries `.git` and the version still comes out `unknown`, which
means git is missing from the build or could not read the checkout.
`unknown` is what a source tarball, or a `docker build` with no `.git`
in its context and no `VERSION` build arg, reports. A build that reports
`unknown` is a build nobody told what it was; it is not a failure, but
it cannot be traced back to a commit.
`make version` prints what the current checkout would stamp, and `make version` prints what the current checkout would stamp, and
`make build VERSION=v1.2.3` overrides it. An empty override — from `make build VERSION=v1.2.3` overrides it. An empty override — from
@@ -1188,7 +1145,7 @@ commit still produce a byte-identical binary.
Treat a backup with the same care as the credentials inside it. Encrypt Treat a backup with the same care as the credentials inside it. Encrypt
backups at rest and restrict who can read them. backups at rest and restrict who can read them.
- `events-{uuid}.db` and `archive-….db` hold the **full payload - `events-{uuid}.db` and `archive-{uuid}.db` hold the **full payload
body and headers** of every event as received, including whatever the body and headers** of every event as received, including whatever the
sending service put in them — tokens, signatures, personal data. sending service put in them — tokens, signatures, personal data.
- Event databases written before - Event databases written before
@@ -1221,7 +1178,7 @@ backups at rest and restrict who can read them.
**The entrypoint UUID is the credential, and it is the only one.** **The entrypoint UUID is the credential, and it is the only one.**
webhooker mints a version 4 UUID per entrypoint and serves it at webhooker mints a version 4 UUID per entrypoint and serves it at
`/h/{uuid}`. Possession of that URL is the authentication: `/webhook/{uuid}`. Possession of that URL is the authentication:
anyone who holds it can submit events to the entrypoint, and the anyone who holds it can submit events to the entrypoint, and the
receiver verifies nothing else about the sender. receiver verifies nothing else about the sender.
@@ -1403,11 +1360,10 @@ It uses:
- **[go-chi/httprate](https://github.com/go-chi/httprate)** for - **[go-chi/httprate](https://github.com/go-chi/httprate)** for
sliding-window rate limiting of the password-change and webhook sliding-window rate limiting of the password-change and webhook
receiver endpoints. The bucket is per client IP only when receiver endpoints. The bucket is per client IP only when
`TRUSTED_PROXIES` covers the reverse proxy (by default it covers the `TRUSTED_PROXIES` names the reverse proxy; unset, every client
RFC 1918 private ranges); otherwise every client behind that proxy behind that proxy shares one bucket per limit. The login endpoint
shares one bucket per limit. The login endpoint counts failed counts failed attempts itself instead, so that a correct password is
attempts itself instead, so that a correct password is never never throttled (see [Rate Limiting](#rate-limiting))
throttled (see [Rate Limiting](#rate-limiting))
- **[Prometheus](https://prometheus.io)** for metrics, served at - **[Prometheus](https://prometheus.io)** for metrics, served at
`/metrics` behind basic auth `/metrics` behind basic auth
- **[Sentry](https://sentry.io)** for optional error reporting - **[Sentry](https://sentry.io)** for optional error reporting
@@ -1563,7 +1519,7 @@ the full request and creates an Event.
| -------------- | ------- | ----------- | | -------------- | ------- | ----------- |
| `id` | UUID | Primary key | | `id` | UUID | Primary key |
| `webhook_id` | UUID | Foreign key → Webhook | | `webhook_id` | UUID | Foreign key → Webhook |
| `path` | string | Unique bare UUID, generated at creation. The `/h/` prefix is route only and is not stored: the receiver matches this column against the raw `{uuid}` path segment. It is also the entrypoint's credential; see [The entrypoint URL is the authentication secret](#the-entrypoint-url-is-the-authentication-secret) | | `path` | string | Unique bare UUID, generated at creation. The `/webhook/` prefix is route only and is not stored: the receiver matches this column against the raw `{uuid}` path segment. It is also the entrypoint's credential; see [The entrypoint URL is the authentication secret](#the-entrypoint-url-is-the-authentication-secret) |
| `description` | string | Optional description | | `description` | string | Optional description |
| `active` | boolean | Whether this entrypoint accepts events (default: true) | | `active` | boolean | Whether this entrypoint accepts events (default: true) |
@@ -1606,9 +1562,8 @@ events should be forwarded.
is built on the same HTTP core as `http` and honours `max_retries` is built on the same HTTP core as `http` and honours `max_retries`
identically, circuit breaker included. See the Slack target section identically, circuit breaker included. See the Slack target section
under "Per-Webhook Event Databases" for the message format. under "Per-Webhook Event Databases" for the message format.
- **`database`** — Archive the full event as a row into the target's - **`database`** — Archive the full event as a row into a separate
own archive database per-webhook archive database (`archive-{webhookID}.db`) for long-term
(`archive-{webhook_name}-{target_name}-{target_uuid}.db`) for long-term
retention, with an optional creation-validated expiry (default: keep retention, with an optional creation-validated expiry (default: keep
forever). No external delivery and no retries; an archive write forever). No external delivery and no retries; an archive write
failure fails the delivery. See the database target section under failure fails the delivery. See the database target section under
@@ -1694,7 +1649,6 @@ data for auditing, for replay, and for resubmission.
| `headers` | JSON | Complete request headers | | `headers` | JSON | Complete request headers |
| `body` | text | Raw request body | | `body` | text | Raw request body |
| `content_type` | string | Content-Type header value | | `content_type` | string | Content-Type header value |
| `body_bytes` | integer | The body's size in bytes, recorded when the event is stored, on receipt and on resubmit |
| `resubmitted_from_id` | UUID | The event this one was copied from by a resubmit (nullable; empty for an event that arrived on the receiver). Not a foreign key: the source event can be reaped by retention while its copies remain | | `resubmitted_from_id` | UUID | The event this one was copied from by a resubmit (nullable; empty for an event that arrived on the receiver). Not a foreign key: the source event can be reaped by retention while its copies remain |
**Relations:** Belongs to Webhook. Belongs to Entrypoint. Has many **Relations:** Belongs to Webhook. Belongs to Entrypoint. Has many
@@ -1786,13 +1740,12 @@ retries) is individually logged for full observability.
#### EventTotals and TargetTotals #### EventTotals and TargetTotals
Running counts in each event database, read by the statistics pane at the Running counts in each event database, read by the statistics pane at the
top of the webhook page and by the webhook list. `EventTotals` is one row: top of the webhook page. `EventTotals` is one row:
| Field | Type | Description | | Field | Type | Description |
| ---------------- | --------- | ----------- | | ---------------- | ------- | ----------- |
| `events` | integer | Events ever stored, resubmitted copies included | | `events` | integer | Events ever stored, resubmitted copies included |
| `events_removed` | integer | Events retention has deleted | | `events_removed` | integer | Events retention has deleted |
| `last_event_at` | timestamp | When the newest event arrived (nullable; empty before the first); retention leaves it as it is |
`TargetTotals` is one row per target, created by the first delivery to it: `TargetTotals` is one row per target, created by the first delivery to it:
@@ -1809,23 +1762,13 @@ Each count changes in the transaction that writes or deletes the rows it
counts. The pane's lifetime events are `events`, and its lifetime counts. The pane's lifetime events are `events`, and its lifetime
deliveries and failures are `deliveries` and `failed` summed over the deliveries and failures are `deliveries` and `failed` summed over the
targets; each figure within retention is the same less what retention targets; each figure within retention is the same less what retention
removed, so neither needs the rows themselves. Its last event is removed, so neither needs the rows themselves. Its last-10-minutes and
`last_event_at`, written in the transaction that stores the event, so it
still shows once retention has removed every event. Its last-10-minutes and
last-24-hours figures are counted from the `events` and `deliveries` last-24-hours figures are counted from the `events` and `deliveries`
indexes over just that window, the deliveries in one query grouped by indexes over just that window, the deliveries in one query grouped by
target. Its failure percentage for a window is the deliveries that became target. Its failure percentage for a window is the deliveries that became
`failed` in it out of all that became `delivered` or `failed` in it, and `failed` in it out of all that became `delivered` or `failed` in it, and
a dash when none did. a dash when none did.
The webhook list at `/hooks` shows three of the pane's figures for each
webhook: its events within retention and its last event, both from
`EventTotals`, and its deliveries that failed in the last 24 hours,
counted with the pane's query. It opens each webhook's event database once
(the handle stays open) and runs those two reads there, so its cost grows
with the number of webhooks and, for each, with the deliveries that
finished in the last 24 hours, never with the events stored.
#### Event-tier indexes #### Event-tier indexes
These indexes on the per-webhook event databases are declared in the model These indexes on the per-webhook event databases are declared in the model
@@ -1833,28 +1776,26 @@ tags, so `AutoMigrate` creates them on a fresh database:
| Table | Columns | Serves | | Table | Columns | Serves |
| ------------------ | --------------------------- | ------ | | ------------------ | --------------------------- | ------ |
| `deliveries` | `status`, `deleted_at`, `finished_at`, `target_id` | Startup recovery, the retry and pending sweeps every 60 seconds and the queue-depth sampler every 30 seconds, which select deliveries by status, and the webhook page's statistics and the webhook list, which count each target's deliveries by status and when they finished | | `deliveries` | `status`, `deleted_at`, `finished_at`, `target_id` | Startup recovery, the retry and pending sweeps every 60 seconds and the queue-depth sampler every 30 seconds, which select deliveries by status, and the webhook page's statistics, which count each target's deliveries by status and when they finished |
| `deliveries` | `event_id`, `deleted_at` | The event log, which loads each event's deliveries, and retention, which counts and deletes the deliveries of expired events | | `deliveries` | `event_id`, `deleted_at` | The event log, which loads each event's deliveries, and retention, which counts and deletes the deliveries of expired events |
| `delivery_results` | `delivery_id`, `deleted_at` | The event log, which loads the attempts of a page's deliveries, and retention, which deletes the attempts of expired events | | `delivery_results` | `delivery_id`, `deleted_at` | The event log, which loads the attempts of a page's deliveries, and retention, which deletes the attempts of expired events |
| `events` | `deleted_at`, `created_at` | The webhook page's statistics, which count recent events | | `events` | `deleted_at`, `created_at` | The webhook page's statistics, which count recent events and find the newest |
| `events` | `created_at` | Retention, which selects expired events by age | | `events` | `created_at` | Retention, which selects expired events by age |
GORM's soft delete adds `deleted_at IS NULL` to these queries; retention GORM's soft delete adds `deleted_at IS NULL` to these queries; retention
leaves it out. SQLite keeps no statistics on these tables, and without them it leaves it out. SQLite keeps no statistics on these tables, and without them it
rates the `deleted_at` index, which every live row matches, above an index on rates the `deleted_at` index, which every live row matches, above an index on
a column matched against several values or compared with a range. So every a column matched against several values or compared with `<`. So every index
index but the last also covers `deleted_at`. It comes second, so that but the last also covers `deleted_at`. It comes second, so that retention can
retention can use the index without it, except in `events`, where the use the index without it, except in `events`, where `created_at` is compared
statistics compare `created_at` with a range (`>=`) and SQLite narrows by a with `<` and SQLite narrows by a `<` only on the last column it uses.
range only on the last column it uses.
#### Common Fields #### Common Fields
Every entity except `Setting`, `EventTotals` and `TargetTotals` includes Every entity except `Setting`, `EventTotals` and `TargetTotals` includes
these fields from `BaseModel`. `Setting` is a bare key-value row with no these fields from `BaseModel`. `Setting` is a bare key-value row with no
`id`, no timestamps and no soft delete, and the two totals tables hold `id`, no timestamps and no soft delete, and the two totals tables hold
counts, plus `last_event_at` in `event_totals`, keyed by a numeric `id` only counts, keyed by a numeric `id` and by `target_id`:
and by `target_id`:
| Field | Type | Description | | Field | Type | Description |
| ------------ | --------- | ----------- | | ------------ | --------- | ----------- |
@@ -1930,41 +1871,9 @@ The **database target type** builds on this architecture to provide
long-term archiving, separate from the per-webhook event database (which long-term archiving, separate from the per-webhook event database (which
may prune events under its own retention). Delivering to a database may prune events under its own retention). Delivering to a database
target writes the full event — body, headers, method, content type, and target writes the full event — body, headers, method, content type, and
webhook/entrypoint/event identifiers — as a row into the target's own webhook/entrypoint/event identifiers — as a row into a dedicated archive
archive database, `archive-{webhook_name}-{target_name}-{target_uuid}.db`, database, `archive-{webhookID}.db`, stored under the data directory
stored under the data directory beside the event database. Each beside the event database. After each write the archive handle is closed
`database` target has its own archive file, even when one webhook has
several.
Both names are made safe for a file name the same way: lowercased, ASCII
letters and digits kept, every other run of characters turned into a
single `-`, no `-` at either end, cut to 40 characters, and `unnamed`
when nothing is left. The target UUID keeps the file name unique. A
webhook named `Orders (EU)` with a target named `Long-term archive`
archives into `archive-orders-eu-long-term-archive-{target_uuid}.db`.
Renaming the webhook or the target renames the file, under the same
lock the archive writes and the archive sweeper take. Webhook edits,
target edits and target creation run one at a time, so no edit can
rename the file between another's rename and save, and the name on disk
matches the UI. A rename never replaces a file: if one already has
the new name, the edit is refused with an error naming that file, and
the stored name stays. If the archive is not there (the operator moved
it away), the rename is not an error, and the next write creates the
file under the new name.
The file is moved just before the new name is saved. If the process
stops between the two, the archive is left under the new name while the
UI still shows the old one, and the next delivery starts a second
archive under the name shown. To bring them back together, stop the
service before moving anything, and move each archive as its `.db`
together with any `-wal` and `-shm` beside it, since the `-wal` can hold
rows that are not yet in the `.db`. If no file has the name shown, move
the archive under the new name back to it. If a second archive already
has the name shown, move the archive under the new name out of the data
directory instead and keep it as you would any archive moved away. Then
start the service again.
After each write the archive handle is closed
and reopened, debounced to at most once per second, so an operator can and reopened, debounced to at most once per second, so an operator can
move the archive file away for offline archiving without stopping the move the archive file away for offline archiving without stopping the
service; a moved or removed archive file is recreated automatically on service; a moved or removed archive file is recreated automatically on
@@ -1975,33 +1884,35 @@ older than the expiry are pruned each time the archive is (re)opened. An
archive write failure is never silent success: the delivery records a archive write failure is never silent success: the delivery records a
failed attempt with the error and is marked failed. failed attempt with the error and is marked failed.
Because reopens only happen on writes, an archive whose target has Because reopens only happen on writes, an archive belonging to a webhook
stopped receiving events would never be pruned. A background **archive that has stopped receiving events would never be pruned. A background
sweeper** closes that gap: on the same interval as the event retention **archive sweeper** closes that gap: on the same interval as the event
reaper (`RETENTION_SWEEP_INTERVAL`) it prunes every archive whose retention reaper (`RETENTION_SWEEP_INTERVAL`) it prunes every archive
database target declares a positive expiry, whether or not the target whose database target declares a positive expiry, whether or not the
is still receiving traffic. The sweep never creates an archive — a webhook is still receiving traffic. The sweep never creates an archive —
target whose archive file does not yet exist is skipped, not initialised a webhook whose archive file does not yet exist is skipped, not
— it takes the same per-target lock the write path uses, so it can never initialised — it takes the same per-webhook lock the write path uses, so
interleave with a write, and it leaves the archive closed afterwards so it can never interleave with a write, and it leaves the archive closed
the move-the-file-away workflow keeps working. Archives with no expiry, afterwards so the move-the-file-away workflow keeps working. Archives
or the expiry `never`, are not touched by the sweep at all. with no expiry, or the expiry `never`, are not touched by the sweep at
all.
Because each `database` target has its own archive file, a target's Note that a webhook has one archive file but may carry more than one
`expiry` governs only its own archive. Two `database` targets on one `database` target, each with its own `expiry`. The shortest expiry
webhook with different expiries keep two archives, each pruned on its configured on any of them therefore governs the whole archive, and the
own schedule. sweep applies it whether or not the webhook is still receiving events.
Configure a single `database` target per webhook unless you intend that.
Deleting a webhook releases its archives: the delivery engine's cached Deleting a webhook releases its archive: the delivery engine's cached
archive writers are dropped and their file handles closed, so nothing archive writer is dropped and its file handle closed, so nothing lingers
lingers after the webhook is gone. The archive **files themselves are after the webhook is gone. The archive **file itself is deliberately
deliberately left on disk**. Unlike the event database — per-webhook left on disk**. Unlike the event database — per-webhook working storage
working storage that is hard-deleted with the webhook — an archive is that is hard-deleted with the webhook — an archive is long-term storage
long-term storage an operator may still want to keep or move away for an operator may still want to keep or move away for offline retention,
offline retention, and destroying it as a side effect of deleting a and destroying it as a side effect of deleting a webhook would be
webhook would be unrecoverable. Removing an `archive-….db` is the unrecoverable. Removing `archive-{webhookID}.db` is the operator's call.
operator's call. Deleting a `database` target releases its writer the Deleting a webhook's last `database` target releases the writer the same
same way, and for the same reason leaves its file alone. way, and for the same reason leaves the file alone.
The **Slack target type** sends webhook events as formatted messages to The **Slack target type** sends webhook events as formatted messages to
any Slack-compatible incoming webhook URL (works with Slack, Mattermost, any Slack-compatible incoming webhook URL (works with Slack, Mattermost,
@@ -2024,7 +1935,7 @@ runtime, though CGO is required at build time due to the transitive
``` ```
External Service External Service
│ │
│ POST /h/{uuid} │ POST /webhook/{uuid}
▼ ▼
┌─────────────┐ ┌──────────────┐ ┌──────────────┐ ┌─────────────┐ ┌──────────────┐ ┌──────────────┐
│ chi Router │────►│ Middleware │────►│ Webhook │ │ chi Router │────►│ Middleware │────►│ Webhook │
@@ -2250,7 +2161,7 @@ The middleware records three more on the same registry:
Two of those labels are written once per request from bytes the client Two of those labels are written once per request from bytes the client
chose, so both are bounded to something this service registers: chose, so both are bounded to something this service registers:
- `handler` is the chi route pattern — `/h/{uuid}`, never the - `handler` is the chi route pattern — `/webhook/{uuid}`, never the
concrete path. A request matching no route carries `(unmatched)`, concrete path. A request matching no route carries `(unmatched)`,
and no entrypoint UUID ever reaches a label. and no entrypoint UUID ever reaches a label.
- `method` is the request method when the router can route it, and - `method` is the request method when the router can route it, and
@@ -2280,7 +2191,7 @@ unpredictable rates, and blanket limits shared with other routes would
cause legitimate deliveries to be dropped. cause legitimate deliveries to be dropped.
The receiver instead has its own dedicated abuse limit, scoped to the The receiver instead has its own dedicated abuse limit, scoped to the
`/h/{uuid}` route only and keyed per client IP per request path `/webhook/{uuid}` route only and keyed per client IP per request path
(`httprate.KeyByEndpoint`): one misbehaving sender is throttled without (`httprate.KeyByEndpoint`): one misbehaving sender is throttled without
affecting other senders of the same entrypoint or the same sender's affecting other senders of the same entrypoint or the same sender's
other entrypoints. Keying on the path rather than on the entrypoint other entrypoints. Keying on the path rather than on the entrypoint
@@ -2317,7 +2228,7 @@ log spends. The access log is bounded by neither limit: every request
is recorded once at `INFO`, served or rejected alike. is recorded once at `INFO`, served or rejected alike.
What the access log does bound is the _content_ of those lines. A 3xx What the access log does bound is the _content_ of those lines. A 3xx
or 4xx response logs the chi route pattern — `/h/{uuid}`, or 4xx response logs the chi route pattern — `/webhook/{uuid}`,
`/user/{username}//`, or the literal `(unmatched)` when the request hit `/user/{username}//`, or the literal `(unmatched)` when the request hit
no route at all — in place of the concrete URL. Those are the outcomes no route at all — in place of the concrete URL. Those are the outcomes
an unauthenticated client can drive for free: 404 and 429 on any an unauthenticated client can drive for free: 404 and 429 on any
@@ -2351,12 +2262,12 @@ reduces the headers to a fixed allowlist — `Accept`, `Content-Length`,
The same hook rewrites the request URL. The SDK builds it as The same hook rewrites the request URL. The SDK builds it as
`scheme://host/path` from the concrete path, which on the receiver `scheme://host/path` from the concrete path, which on the receiver
route is `/h/<uuid>` in full — and that UUID is a write route is `/webhook/<uuid>` in full — and that UUID is a write
capability, not an identifier: anyone holding it can post events this capability, not an identifier: anyone holding it can post events this
service accepts and its targets then deliver. A tracker has its own service accepts and its targets then deliver. A tracker has its own
retention, access control and deletion policy, so the rule the access retention, access control and deletion policy, so the rule the access
log follows above does not carry across that boundary. What is sent is log follows above does not carry across that boundary. What is sent is
the chi route pattern instead: `http://host/h/{uuid}`. the chi route pattern instead: `http://host/webhook/{uuid}`.
The scheme and the host are kept, and everything else in the URL is The scheme and the host are kept, and everything else in the URL is
discarded rather than edited, so a future SDK version that starts discarded rather than edited, so a future SDK version that starts
@@ -2400,8 +2311,8 @@ fallback is never the concrete path. The path becomes the literal
rewrite cannot parse into a scheme is withheld whole. A transaction rewrite cannot parse into a scheme is withheld whole. A transaction
event additionally carries the SDK's own `METHOD /path` name, built event additionally carries the SDK's own `METHOD /path` name, built
from the concrete path as well; it is rewritten on the same terms, to from the concrete path as well; it is rewritten on the same terms, to
`POST /h/{uuid}` where the pattern is known and `POST /(redacted)` `POST /webhook/{uuid}` where the pattern is known and `POST
where it is not. /(redacted)` where it is not.
The headers are an allowlist for the same reason the rules above are The headers are an allowlist for the same reason the rules above are
unconditional: the SDK's own filter removes four names and passes unconditional: the SDK's own filter removes four names and passes
@@ -2536,7 +2447,7 @@ logger printed the fully interpolated SQL — parameters and all — to
standard output on every statement that returned an error, including a standard output on every statement that returned an error, including a
plain record-not-found, at a level no operator setting reached. Two of plain record-not-found, at a level no operator setting reached. Two of
this service's lookups miss by design on unauthenticated routes: the this service's lookups miss by design on unauthenticated routes: the
entrypoint lookup behind `/h/{uuid}` and the user lookup behind entrypoint lookup behind `/webhook/{uuid}` and the user lookup behind
the login form, whose path segment and submitted username the client the login form, whose path segment and submitted username the client
picks outright. Every picks outright. Every
`gorm.Open` in the service now installs the adapter in `gorm.Open` in the service now installs the adapter in
@@ -2664,44 +2575,47 @@ the tree is checked out: four checkouts have reported 3,959, 3,961,
client-supplied field was cut, and that the shipped chain's stack client-supplied field was cut, and that the shipped chain's stack
arrived uncut — never the numbers. arrived uncut — never the numbers.
Every limiter here — receiver, login, password change, delivery replay Every limiter here — receiver, login, and password change — identifies
and event resubmit — identifies the client the same way, through one the client the same way, through one shared key function: the
shared key function: the connection's own address, unless the peer is connection's own address, unless the peer is listed in
inside `TRUSTED_PROXIES`, in which case the forwarded client address is `TRUSTED_PROXIES`, in which case the forwarded client address is used
used instead. That address becomes a bucket by family: IPv4 keys on instead. That address becomes a bucket by family: IPv4 keys on the full
the full address, IPv6 on its `/64` prefix. A routed `/64` is the normal address, IPv6 on its `/64` prefix. A routed `/64` is the normal
residential and mobile IPv6 allocation, so keying IPv6 per address would residential and mobile IPv6 allocation, so keying IPv6 per address would
let one subscriber rotate source addresses and mint a fresh bucket per let one subscriber rotate source addresses and mint a fresh bucket per
request, evading these limits at the network layer without spoofing request, evading these limits at the network layer without spoofing
anything; the cost is that distinct clients inside one `/64` share a anything; the cost is that distinct clients inside one `/64` share a
bucket. IPv4-mapped addresses (`::ffff:1.2.3.4`) key as the IPv4 address bucket. IPv4-mapped addresses (`::ffff:1.2.3.4`) key as the IPv4 address
they carry. See [Trusted proxies](#trusted-proxies). When that variable they carry. See [Trusted proxies](#trusted-proxies). Deployed without that
does not cover the reverse proxy, a client behind it shares one bucket variable set, a client behind a reverse proxy shares one bucket with
with every other client behind the same proxy. Set `TRUSTED_PROXIES` to every other client behind the same proxy. Set `TRUSTED_PROXIES` to the
the proxy's address to get per-client limits back. What the shared bucket proxy's address to get per-client limits back. What the shared bucket
costs is not the same for every limiter, and the two cases pull in costs is not the same for every limiter, and the two cases pull in
opposite directions: opposite directions:
- For the **receiver** limits it costs throughput, which is the safe - For the **receiver** limits it costs throughput, which is the safe
direction to be wrong in: sharing can only make a limit bind sooner, direction to be wrong in: sharing can only make a limit bind sooner,
never let a sender past it. It matters more for the aggregate limit never let a sender past it. It matters more for the aggregate limit
than for the per-entrypoint one: with every request keyed on the than for the per-entrypoint one: with `TRUSTED_PROXIES` unset behind
proxy, the aggregate limit becomes a service-wide ceiling of 1200 the reverse proxy a production deployment is required to run behind,
requests per minute across all senders and all entrypoints, where the every request keys on the proxy, so the aggregate limit becomes a
per-entrypoint limit's capacity still grows with the number of service-wide ceiling of 1200 requests per minute across all senders
entrypoints. and all entrypoints, where the per-entrypoint limit's capacity still
grows with the number of entrypoints. Any deployment with more than a
handful of busy entrypoints must set `TRUSTED_PROXIES`.
- For the **login and password-change** limits it costs precision, not - For the **login and password-change** limits it costs precision, not
availability. Login failures from every client land in one counter, availability. Login failures from every client land in one counter,
so a stranger's wrong passwords make the operator's own wrong so a stranger's wrong passwords make the operator's own wrong
passwords answer `429` sooner; the operator's _correct_ password is passwords answer `429` sooner; the operator's _correct_ password is
never affected, because it is never counted. never affected, because it is never counted. Production deployments
should still set `TRUSTED_PROXIES`; webhooker warns at startup
whenever it is empty, in any environment.
#### The login endpoint #### The login endpoint
The login `POST` is the one endpoint with no pre-emptive limiter in The login `POST` is the one endpoint with no pre-emptive limiter in
front of it, and that is deliberate. A limiter that spends budget on front of it, and that is deliberate. A limiter that spends budget on
arrival is a lockout wherever clients share one bucket, as they do arrival is a lockout in this deployment shape: sharing one bucket, a
behind a reverse proxy that `TRUSTED_PROXIES` does not cover: a
stranger sending five POSTs a minute — about 0.08 requests per second, stranger sending five POSTs a minute — about 0.08 requests per second,
from anywhere — keeps it permanently full, and the operator has no from anywhere — keeps it permanently full, and the operator has no
second administrative path. So the handler inverts the order: second administrative path. So the handler inverts the order:
@@ -2798,10 +2712,8 @@ re-fills both verification slots on its first two requests. The
remedies are to block the source at the reverse proxy, or to remedies are to block the source at the reverse proxy, or to
rate-limit `POST /pages/login` there — the one place a limit can be rate-limit `POST /pages/login` there — the one place a limit can be
applied without reintroducing the lockout, because the proxy sees the applied without reintroducing the lockout, because the proxy sees the
real client address. `TRUSTED_PROXIES` does not stop the saturation. real client address. Setting `TRUSTED_PROXIES` does not stop the
The flood's source is in the proxy's access log: webhooker's own logs saturation, but it makes the source visible in the failure logs.
record the proxy's address, not the client's (see
[Deployment behind a reverse proxy](#deployment-behind-a-reverse-proxy)).
Finer-grained per-webhook rate limits (configured in the web UI and Finer-grained per-webhook rate limits (configured in the web UI and
enforced in the webhook handler) can layer on top of this env-level enforced in the webhook handler) can layer on top of this env-level
@@ -2813,49 +2725,44 @@ abuse limit later; they are tracked as future work.
| Method | Path | Description | | Method | Path | Description |
| ------ | --------------------------- | ----------- | | ------ | --------------------------- | ----------- |
| `GET` | `/` | Root redirect, 303 (authenticated → `/hooks`, unauthenticated → `/pages/login`) | | `GET` | `/` | Root redirect, 303 (authenticated → `/sources`, unauthenticated → `/pages/login`) |
| `GET` | `/.well-known/healthcheck` | Health check (JSON: `status`, `now`, `uptimeSeconds`, `uptimeHuman`, `version`, `appname`) | | `GET` | `/.well-known/healthcheck` | Health check (JSON: `status`, `now`, `uptimeSeconds`, `uptimeHuman`, `version`, `appname`, `maintenanceMode`) |
| `GET`, `HEAD` | `/s/*` | Static file serving (embedded CSS, JS). `GET` and `HEAD` only — `POST`, `PUT`, `PATCH`, `DELETE`, `OPTIONS`, `TRACE` and `CONNECT` are answered `405 Method Not Allowed` with `Allow: GET, HEAD`. Any other method (such as `PROPFIND`) is refused by chi before it reaches this route, and gets `405` without an `Allow` header. Pinned by `TestStaticServesOnlyGetAndHead` | | `GET`, `HEAD` | `/s/*` | Static file serving (embedded CSS, JS). `GET` and `HEAD` only — `POST`, `PUT`, `PATCH`, `DELETE`, `OPTIONS`, `TRACE` and `CONNECT` are answered `405 Method Not Allowed` with `Allow: GET, HEAD`. Any other method (such as `PROPFIND`) is refused by chi before it reaches this route, and gets `405` without an `Allow` header. Pinned by `TestStaticServesOnlyGetAndHead` |
| `POST` | `/h/{uuid}` | Webhook receiver endpoint. `POST` only — every other method is answered `405 Method Not Allowed` with `Allow: POST`. Rate limited (see [Rate Limiting](#rate-limiting)) | | `POST` | `/webhook/{uuid}` | Webhook receiver endpoint. `POST` only — every other method is answered `405 Method Not Allowed` with `Allow: POST`. Rate limited (see [Rate Limiting](#rate-limiting)) |
#### Authentication Endpoints #### Authentication Endpoints
| Method | Path | Description | | Method | Path | Description |
| ------ | --------------- | ----------- | | ------ | --------------- | ----------- |
| `GET` | `/pages/login` | Login page (not rate limited). Its `next` parameter names the page to return to after login; anything but a path on this site is replaced with `/` | | `GET` | `/pages/login` | Login page (not rate limited) |
| `POST` | `/pages/login` | Login form submission. On success, redirects to the form's `next` when it is a path on this site, otherwise to `/`. Credentials are verified before any limit is consulted, so a correct password is never throttled; 5 FAILED attempts per minute per bucket per submitted username, then `429`. `503` if no verification slot frees up within 5s, or immediately if 16 requests are already queued for one (see [Rate Limiting](#rate-limiting)) | | `POST` | `/pages/login` | Login form submission. Credentials are verified before any limit is consulted, so a correct password is never throttled; 5 FAILED attempts per minute per bucket per submitted username, then `429`. `503` if no verification slot frees up within 5s, or immediately if 16 requests are already queued for one (see [Rate Limiting](#rate-limiting)) |
| `POST` | `/pages/logout` | Logout (destroys session) | | `POST` | `/pages/logout` | Logout (destroys session) |
#### Authenticated Endpoints #### Authenticated Endpoints
A logged-out `GET` of any of these is redirected to `/pages/login` with
its path and query as `next` when they fit in 2048 bytes, so logging in
returns to the page that was asked for.
| Method | Path | Description | | Method | Path | Description |
| ------ | ------------------------ | ----------- | | ------ | ------------------------ | ----------- |
| `GET` | `/user/{username}` | User profile page | | `GET` | `/user/{username}` | User profile page |
| `POST` | `/user/{username}/password` | Change the user's password (5 per minute per bucket, then `429`; `503` if no verification slot frees up within 5s, or immediately if 16 requests are already queued for one) | | `POST` | `/user/{username}/password` | Change the user's password (5 per minute per bucket, then `429`; `503` if no verification slot frees up within 5s, or immediately if 16 requests are already queued for one) |
| `GET` | `/settings` | Read-only list of the configuration the server is running with; `METRICS_PASSWORD` and `SENTRY_DSN` show only as set or not set | | `GET` | `/sources` | List user's webhooks |
| `GET` | `/hooks` | List user's webhooks | | `GET` | `/sources/new` | Create webhook form |
| `GET` | `/hooks/new` | Create webhook form | | `POST` | `/sources/new` | Create webhook submission |
| `POST` | `/hooks/new` | Create webhook submission | | `GET` | `/source/{id}` | Webhook detail view |
| `GET` | `/hook/{id}` | Webhook detail view | | `GET` | `/source/{id}/edit` | Edit webhook form |
| `GET` | `/hook/{id}/edit` | Edit webhook form | | `POST` | `/source/{id}/edit` | Edit webhook submission |
| `POST` | `/hook/{id}/edit` | Edit webhook submission | | `POST` | `/source/{id}/delete` | Delete webhook |
| `POST` | `/hook/{id}/delete` | Delete webhook | | `GET` | `/source/{id}/logs` | Webhook event logs |
| `GET` | `/hook/{id}/events` | Full Event Log | | `GET` | `/source/{id}/logs/{eventID}/body` | Download an event's full stored body. The log page renders each body only up to its cap, so this is the only route that serves a whole one; it is offered wherever a body is shown truncated |
| `GET` | `/hook/{id}/events/{eventID}/body` | Download an event's full stored body. The log page renders each body only up to its cap, so this is the only route that serves a whole one; it is offered wherever a body is shown truncated | | `POST` | `/source/{id}/deliveries/{deliveryID}/replay` | Replay a finished delivery: creates a new delivery for the same event against the target's current configuration (30 per minute per bucket, then `429`) |
| `POST` | `/hook/{id}/deliveries/{deliveryID}/replay` | Replay a finished delivery: creates a new delivery for the same event against the target's current configuration (30 per minute per bucket, then `429`) | | `POST` | `/source/{id}/events/{eventID}/resubmit` | Resubmit a stored event: creates a new event copying it and fans that out to every currently active target (30 per minute per bucket, then `429`) |
| `POST` | `/hook/{id}/events/{eventID}/resubmit` | Resubmit a stored event: creates a new event copying it and fans that out to every currently active target (30 per minute per bucket, then `429`) | | `POST` | `/source/{id}/entrypoints` | Add entrypoint to webhook |
| `POST` | `/hook/{id}/entrypoints` | Add entrypoint to webhook | | `POST` | `/source/{id}/entrypoints/{entrypointID}/delete` | Delete an entrypoint |
| `POST` | `/hook/{id}/entrypoints/{entrypointID}/delete` | Delete an entrypoint | | `POST` | `/source/{id}/entrypoints/{entrypointID}/toggle` | Enable or disable an entrypoint |
| `POST` | `/hook/{id}/entrypoints/{entrypointID}/toggle` | Enable or disable an entrypoint | | `POST` | `/source/{id}/targets` | Add target to webhook |
| `POST` | `/hook/{id}/targets` | Add target to webhook | | `GET` | `/source/{id}/targets/{targetID}/edit` | Edit target form. The one page that renders a target's destination URL and header values in full, rather than masked |
| `GET` | `/hook/{id}/targets/{targetID}/edit` | Edit target form. The one page that renders a target's destination URL and header values in full, rather than masked | | `POST` | `/source/{id}/targets/{targetID}/edit` | Edit target submission |
| `POST` | `/hook/{id}/targets/{targetID}/edit` | Edit target submission | | `POST` | `/source/{id}/targets/{targetID}/delete` | Delete a target |
| `POST` | `/hook/{id}/targets/{targetID}/delete` | Delete a target | | `POST` | `/source/{id}/targets/{targetID}/toggle` | Enable or disable a target |
| `POST` | `/hook/{id}/targets/{targetID}/toggle` | Enable or disable a target |
#### Infrastructure Endpoints #### Infrastructure Endpoints
@@ -2950,7 +2857,6 @@ webhooker/
│ │ ├── healthcheck.go # Health check handler │ │ ├── healthcheck.go # Health check handler
│ │ ├── index.go # Index page handler │ │ ├── index.go # Index page handler
│ │ ├── profile.go # User profile handler │ │ ├── profile.go # User profile handler
│ │ ├── settings.go # Read-only Settings page handler
│ │ ├── source_management.go # Webhook CRUD handlers │ │ ├── source_management.go # Webhook CRUD handlers
│ │ └── webhook.go # Webhook receiver handler │ │ └── webhook.go # Webhook receiver handler
│ ├── healthcheck/ │ ├── healthcheck/
@@ -3009,15 +2915,13 @@ Components are wired via Uber fx in this order:
7. `healthcheck.New` — Health check service 7. `healthcheck.New` — Health check service
8. `session.New` — Cookie-based session manager (key from database) 8. `session.New` — Cookie-based session manager (key from database)
9. `handlers.New` — HTTP handlers 9. `handlers.New` — HTTP handlers
10. `metrics.NewRegistry` — The registry `/metrics` serves 10. `middleware.New` — HTTP middleware
11. `metrics.New` — The delivery collectors, registered on that registry 11. `delivery.New` — Event-driven delivery engine
12. `middleware.New` — HTTP middleware 12. `delivery.NewArchiveSweeper` — Periodic pruning of idle archives
13. `delivery.New` — Event-driven delivery engine 13. `delivery.Engine` → `delivery.Notifier` — interface bridge
14. `delivery.NewArchiveSweeper` — Periodic pruning of idle archives 14. `delivery.Engine` → `delivery.WebhookEvictor` — interface bridge so
15. `delivery.Engine` → `delivery.Notifier` — interface bridge deleting a webhook releases its archive writer
16. `delivery.Engine` → `delivery.Archives` — interface bridge so 15. `server.New` — HTTP server and router
deleting or renaming a webhook or target reaches its archive files
17. `server.New` — HTTP server and router
The server starts via `fx.Invoke(func(*server.Server, *delivery.Engine, The server starts via `fx.Invoke(func(*server.Server, *delivery.Engine,
*database.RetentionReaper, *delivery.ArchiveSweeper) {})`, which *database.RetentionReaper, *delivery.ArchiveSweeper) {})`, which
@@ -3060,14 +2964,8 @@ local record instead of nothing. What that placement gives up is
recovery of a panic in the six entries above it, none of which does recovery of a panic in the six entries above it, none of which does
more than set a header or start a timer. more than set a header or start a timer.
Each admin page route group (`/pages`, `/user/*`, `/settings`, `/hooks`, Additionally, form endpoints (`/pages`, `/user/*`, `/sources`,
`/hook/*`) starts with its own **Recoverer** and, if `SENTRY_DSN` is set, its `/source/*`) apply a **MaxBodySize** middleware that limits
own **Sentry** error reporting. That Recoverer answers a panic with the `500`
error page in the normal layout; the global one keeps the plain-text `500` for
every other route.
Additionally, form endpoints (`/pages`, `/user/*`, `/settings`,
`/hooks`, `/hook/*`) apply a **MaxBodySize** middleware that limits
POST/PUT/PATCH request bodies to 1 MB. It is registered ahead of the POST/PUT/PATCH request bodies to 1 MB. It is registered ahead of the
CSRF middleware in every one of those route groups, because CSRF middleware in every one of those route groups, because
gorilla/csrf parses the form; if the cap were installed after it, form gorilla/csrf parses the form; if the cap were installed after it, form
@@ -3086,12 +2984,12 @@ declared length. A chunked request, or
one that lies about its length, is hard-capped by one that lies about its length, is hard-capped by
`http.MaxBytesReader` and fails downstream at form-parse time. `http.MaxBytesReader` and fails downstream at form-parse time.
Those same five route groups then apply **CSRF** and **NoCache** Those same four route groups then apply **CSRF** and **NoCache**
(`Cache-Control: no-store`, `Pragma: no-cache`), and every group except (`Cache-Control: no-store`, `Pragma: no-cache`), and every group except
`/pages` applies **RequireAuth**. The rate limiters are per-route `/pages` applies **RequireAuth**. The rate limiters are per-route
rather than global: **PasswordChangeRateLimit** on rather than global: **PasswordChangeRateLimit** on
`/user/{username}/password` and **ReceiverRateLimit** on `/user/{username}/password` and **ReceiverRateLimit** on
`/h/{uuid}`. There is deliberately none on `/pages/login` — that `/webhook/{uuid}`. There is deliberately none on `/pages/login` — that
endpoint counts failures inside the handler, after the credential endpoint counts failures inside the handler, after the credential
check, see [The login endpoint](#the-login-endpoint). check, see [The login endpoint](#the-login-endpoint).
@@ -3132,12 +3030,12 @@ check, see [The login endpoint](#the-login-endpoint).
by middleware that runs before CSRF parses the form by middleware that runs before CSRF parses the form
- **CSRF protection** via [gorilla/csrf](https://github.com/gorilla/csrf) - **CSRF protection** via [gorilla/csrf](https://github.com/gorilla/csrf)
on all state-changing forms (cookie-based double-submit tokens with on all state-changing forms (cookie-based double-submit tokens with
HMAC authentication). Applied to `/pages`, `/hooks`, `/hook`, HMAC authentication). Applied to `/pages`, `/sources`, `/source`, and
`/settings`, and `/user` routes. Excluded from `/h` (inbound webhook `/user` routes. Excluded from `/webhook` (inbound webhook POSTs) and
POSTs) and `/api` (stateless API). The middleware detects TLS `/api` (stateless API). The middleware detects TLS per-request through
per-request through `internal/reqtls.IsTLS` — the same predicate the `internal/reqtls.IsTLS` — the same predicate the session cookie uses —
session cookie uses — to set appropriate cookie security flags and to set appropriate cookie security flags and Origin/Referer validation
Origin/Referer validation mode mode
- **The entrypoint URL is the receiver's only credential.** Nothing - **The entrypoint URL is the receiver's only credential.** Nothing
about an inbound request is verified; possession of the UUID about an inbound request is verified; possession of the UUID
authorises submission, and no shared secret or signature check will authorises submission, and no shared secret or signature check will
@@ -3151,8 +3049,7 @@ check, see [The login endpoint](#the-login-endpoint).
route through a single decision function, so they cannot disagree route through a single decision function, so they cannot disagree
about a destination. An operator can permit specific blocks with about a destination. An operator can permit specific blocks with
[`ALLOWED_EGRESS_CIDRS`](#allowing-egress-to-your-own-network); the [`ALLOWED_EGRESS_CIDRS`](#allowing-egress-to-your-own-network); the
guard cannot be switched off, and link-local, the unspecified guard cannot be switched off, and link-local plus a
addresses `0.0.0.0` and `::`, and a
[pinned set](#allowing-egress-to-your-own-network) of known cloud [pinned set](#allowing-egress-to-your-own-network) of known cloud
metadata endpoints — several of which are ULAs outside link-local — metadata endpoints — several of which are ULAs outside link-local —
stay blocked whatever is listed, though listing `0.0.0.0/0` or stay blocked whatever is listed, though listing `0.0.0.0/0` or
@@ -3175,9 +3072,10 @@ check, see [The login endpoint](#the-login-endpoint).
It runs behind session auth, so only a client already holding a It runs behind session auth, so only a client already holding a
valid session reaches it, and an operator throttled out of changing valid session reaches it, and an operator throttled out of changing
a password can still log in. The bucket is per client IP only when a password can still log in. The bucket is per client IP only when
`TRUSTED_PROXIES` covers the reverse proxy; otherwise every client `TRUSTED_PROXIES` names the reverse proxy; unset, every client
shares one bucket, which costs precision rather than availability shares one bucket, which costs precision rather than availability
(see [Rate Limiting](#rate-limiting)) (see [Rate Limiting](#rate-limiting)). webhooker warns at startup
whenever `TRUSTED_PROXIES` is empty
- Prometheus metrics behind basic auth - Prometheus metrics behind basic auth
- Static assets embedded in binary (no filesystem access needed at - Static assets embedded in binary (no filesystem access needed at
runtime) runtime)
@@ -3187,8 +3085,7 @@ check, see [The login endpoint](#the-login-endpoint).
before the app starts; the image's health check; and `docker exec`, before the app starts; the image's health check; and `docker exec`,
unless given `--user` unless given `--user`
- GORM soft deletes on every entity that carries `BaseModel`, which is - GORM soft deletes on every entity that carries `BaseModel`, which is
all of them but `Setting`, `EventTotals` and `TargetTotals` (data all of them but `Setting` (data preserved for audit)
preserved for audit)
### Shutdown ### Shutdown
@@ -3310,9 +3207,8 @@ version is fixed independently of the compiler's:
rebuilds the binary with `CGO_ENABLED=1` and static linking so it rebuilds the binary with `CGO_ENABLED=1` and static linking so it
runs on musl. Both builds go through `make build`, the relink adding runs on musl. Both builds go through `make build`, the relink adding
its `-extldflags` via `GO_LDFLAGS`, so neither can drop the `-X` that its `-extldflags` via `GO_LDFLAGS`, so neither can drop the `-X` that
stamps the version. The version is the `VERSION` build arg if one is stamps the version. The version arrives as the `VERSION` build arg,
given, otherwise derived from the `.git` in the context, and the since the context has no `.git` (see
stage fails if a context with `.git` would stamp `unknown` (see
[Version stamping](#version-stamping)). [Version stamping](#version-stamping)).
3. **Runtime stage** (`alpine:3.21`) — copies the static binary and 3. **Runtime stage** (`alpine:3.21`) — copies the static binary and
`deploy/docker-entrypoint.sh`, creates the `/var/lib/webhooker` `deploy/docker-entrypoint.sh`, creates the `/var/lib/webhooker`
@@ -3344,13 +3240,19 @@ A layer cache lets `docker build .` exit 0 in seconds with the lint and
test stages replayed rather than executed, which would make a green test stages replayed rather than executed, which would make a green
check meaningless. The `check` workflow therefore writes check meaningless. The `check` workflow therefore writes
`.ci-fingerprint` into the build context before building. Its value is `.ci-fingerprint` into the build context before building. Its value is
the hash of the commit being checked, so every commit, docs-only ones the hash of the last commit that touched the build context, so:
and a squash merge whose tree matches an already-built branch included,
gets a new fingerprint, invalidates the `COPY . .` layer of both check
stages, and really runs `make fmt-check`, `golangci-lint`, `make test`,
and `make build`. A run that reports success ran them.
The module download layer sits above `COPY . .` and stays cached. - Any commit that changes code (including a squash merge whose tree
matches an already-built branch) gets a new fingerprint, invalidates
the `COPY . .` layer of both check stages, and really runs
`make fmt-check`, `golangci-lint`, `make test`, and `make build`. A
run that reports success ran them.
- A docs-only commit leaves the fingerprint unchanged — `.dockerignore`
excludes `*.md`, `LICENSE` and `.editorconfig` from the context
anyway — so the image replays from cache and costs seconds.
The module download layer sits above `COPY . .` and stays cached either
way.
A separate workflow step, run before the fingerprint is written, covers A separate workflow step, run before the fingerprint is written, covers
a second way the gate lied: Gitea cancels an in-flight run when a newer a second way the gate lied: Gitea cancels an in-flight run when a newer
+7 -1
View File
@@ -40,6 +40,12 @@ duplicate. That is deliberate — the alternative is a silent lost
delivery — and the README says so under Rationale. It is not a defect delivery — and the README says so under Rationale. It is not a defect
to re-file. to re-file.
One caveat on reading a green check: a docs-only commit deliberately
replays from the layer cache
(https://git.eeqj.de/sneak/webhooker/issues/119), so a green status on
such a commit evidences a replay rather than an executed run. A code
commit invalidates the `COPY` layer and genuinely executes.
# Next Step # Next Step
Clear the rest of the open 1.0.0 milestone Clear the rest of the open 1.0.0 milestone
@@ -381,7 +387,7 @@ point of the branch.
- 2026-03-05 security headers middleware, session regeneration on - 2026-03-05 security headers middleware, session regeneration on
login, request body size limits (#41) login, request body size limits (#41)
- 2026-03-04 tests for delivery, middleware, and session packages - 2026-03-04 tests for delivery, middleware, and session packages
(#32); removed the build-architecture global (#31) (#32); removed globals.Buildarch (#31)
- 2026-03-04 1.0 MVP merge: Webhook/Entrypoint/Target rename, core - 2026-03-04 1.0 MVP merge: Webhook/Entrypoint/Target rename, core
delivery engine with bounded worker pool and circuit breaker, delivery engine with bounded worker pool and circuit breaker,
parallel fan-out, per-webhook event databases, management UI (#16) parallel fan-out, per-webhook event databases, management UI (#16)
+5 -9
View File
@@ -16,7 +16,6 @@ import (
"sneak.berlin/go/webhooker/internal/handlers" "sneak.berlin/go/webhooker/internal/handlers"
"sneak.berlin/go/webhooker/internal/healthcheck" "sneak.berlin/go/webhooker/internal/healthcheck"
"sneak.berlin/go/webhooker/internal/logger" "sneak.berlin/go/webhooker/internal/logger"
"sneak.berlin/go/webhooker/internal/metrics"
"sneak.berlin/go/webhooker/internal/middleware" "sneak.berlin/go/webhooker/internal/middleware"
"sneak.berlin/go/webhooker/internal/resetpw" "sneak.berlin/go/webhooker/internal/resetpw"
"sneak.berlin/go/webhooker/internal/server" "sneak.berlin/go/webhooker/internal/server"
@@ -178,10 +177,6 @@ func newApp() *fx.App {
healthcheck.New, healthcheck.New,
session.New, session.New,
handlers.New, handlers.New,
// The registry /metrics serves, and the delivery
// collectors registered on it.
metrics.NewRegistry,
metrics.New,
middleware.New, middleware.New,
// The one SSRF guard both target-creation validation // The one SSRF guard both target-creation validation
// and the delivery dialer consult, so they cannot // and the delivery dialer consult, so they cannot
@@ -192,10 +187,11 @@ func newApp() *fx.App {
// Wire *delivery.Engine as delivery.Notifier so the // Wire *delivery.Engine as delivery.Notifier so the
// webhook handler can notify the engine of new deliveries. // webhook handler can notify the engine of new deliveries.
func(e *delivery.Engine) delivery.Notifier { return e }, func(e *delivery.Engine) delivery.Notifier { return e },
// Wire *delivery.Engine as delivery.Archives so deleting // Wire *delivery.Engine as delivery.WebhookEvictor so
// or renaming a webhook or target reaches its archive // deleting a webhook releases its archive writer.
// files. func(e *delivery.Engine) delivery.WebhookEvictor {
func(e *delivery.Engine) delivery.Archives { return e }, return e
},
server.New, server.New,
), ),
fx.Invoke( fx.Invoke(
+1 -1
View File
@@ -4,7 +4,6 @@ go 1.26.1
require ( require (
github.com/99designs/basicauth-go v0.0.0-20230316000542-bf6f9cbbf0f8 github.com/99designs/basicauth-go v0.0.0-20230316000542-bf6f9cbbf0f8
github.com/dustin/go-humanize v1.0.1
github.com/getsentry/sentry-go v0.25.0 github.com/getsentry/sentry-go v0.25.0
github.com/go-chi/chi v1.5.5 github.com/go-chi/chi v1.5.5
github.com/go-chi/cors v1.2.1 github.com/go-chi/cors v1.2.1
@@ -30,6 +29,7 @@ require (
github.com/beorn7/perks v1.0.1 // indirect github.com/beorn7/perks v1.0.1 // indirect
github.com/cespare/xxhash/v2 v2.2.0 // indirect github.com/cespare/xxhash/v2 v2.2.0 // indirect
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
github.com/dustin/go-humanize v1.0.1 // indirect
github.com/gorilla/securecookie v1.1.2 // indirect github.com/gorilla/securecookie v1.1.2 // indirect
github.com/jinzhu/inflection v1.0.0 // indirect github.com/jinzhu/inflection v1.0.0 // indirect
github.com/jinzhu/now v1.1.5 // indirect github.com/jinzhu/now v1.1.5 // indirect
+74 -29
View File
@@ -75,11 +75,6 @@ const (
// internet-exposed endpoint. // internet-exposed endpoint.
defaultReceiverRateLimit = 120 defaultReceiverRateLimit = 120
// defaultTrustedProxies is TRUSTED_PROXIES when it is unset: the
// RFC 1918 private ranges, which a reverse proxy reaching the
// process over a Docker network or a private LAN connects from.
defaultTrustedProxies = "10.0.0.0/8,172.16.0.0/12,192.168.0.0/16"
// maxPort is the highest valid TCP port number. The lower // maxPort is the highest valid TCP port number. The lower
// bound (at least 1) is enforced by envPositiveInt. // bound (at least 1) is enforced by envPositiveInt.
maxPort = 65535 maxPort = 65535
@@ -149,6 +144,7 @@ type ConfigParams struct {
type Config struct { type Config struct {
DataDir string DataDir string
Debug bool Debug bool
MaintenanceMode bool
Environment string Environment string
MetricsPassword string MetricsPassword string
MetricsUsername string MetricsUsername string
@@ -176,14 +172,13 @@ type Config struct {
// TrustedProxies is the set of networks whose members are // TrustedProxies is the set of networks whose members are
// allowed to speak for the client with X-Forwarded-For, the // allowed to speak for the client with X-Forwarded-For, the
// only forwarded header read. Unless TRUSTED_PROXIES is set it // only forwarded header read. It is empty unless
// is the RFC 1918 private ranges (defaultTrustedProxies); a set // TRUSTED_PROXIES is set, and empty means no peer is
// value replaces them. If any client can reach the process, or // trusted: forwarded headers are then ignored entirely and
// the proxy in front of it, from an RFC 1918 source address // clients are identified by the connection's own address.
// (directly, or through anything that can rewrite source // Members can choose their own rate-limit key, so this must
// addresses, such as NAT or a published container port), it // name proxy hosts only, never a block that also covers
// must be set to the proxy's address alone, or every rate limit // clients.
// can be bypassed by those clients.
TrustedProxies []netip.Prefix TrustedProxies []netip.Prefix
// AllowedEgressCIDRs is the set of networks a delivery target // AllowedEgressCIDRs is the set of networks a delivery target
@@ -195,13 +190,12 @@ type Config struct {
// otherwise refuse. The guard itself is always on: there is no // otherwise refuse. The guard itself is always on: there is no
// setting that disables SSRF protection, and delivery's // setting that disables SSRF protection, and delivery's
// alwaysBlockedNetworks stays blocked no matter what is listed // alwaysBlockedNetworks stays blocked no matter what is listed
// here. That set is link-local, the unspecified addresses // here. That set is link-local plus the cloud metadata
// 0.0.0.0 and ::, and the cloud metadata endpoints outside // endpoints outside it that disclose credentials or user data
// link-local that disclose credentials or user data at a // at a provider-fixed, non-public address; it is not
// provider-fixed, non-public address; it is not exhaustive of // exhaustive of every cloud's metadata address. See
// every cloud's metadata address. See // alwaysBlockedNetworks for the authoritative list and the
// alwaysBlockedNetworks for the authoritative list and why // criterion it is built from.
// each entry is on it.
AllowedEgressCIDRs []netip.Prefix AllowedEgressCIDRs []netip.Prefix
params *ConfigParams params *ConfigParams
@@ -466,15 +460,14 @@ func parseCIDR(entry string) (netip.Prefix, error) {
// envPrefixList returns the value of the named environment variable // envPrefixList returns the value of the named environment variable
// parsed as a comma-separated list of CIDR blocks (bare addresses // parsed as a comma-separated list of CIDR blocks (bare addresses
// allowed). An unset, empty, or blank value is read as defaultValue // allowed). An unset, empty, or blank value yields an empty list. A
// instead. A set value containing an unparseable entry is a hard // set value containing an unparseable entry is a hard error naming
// error naming the key and the bad entry, so startup fails loudly // the key and the bad entry, so startup fails loudly rather than
// rather than silently running with a list the operator did not // silently running with a list the operator did not intend.
// intend. func envPrefixList(key string) ([]netip.Prefix, error) {
func envPrefixList(key, defaultValue string) ([]netip.Prefix, error) {
v := strings.TrimSpace(os.Getenv(key)) v := strings.TrimSpace(os.Getenv(key))
if v == "" { if v == "" {
v = defaultValue return nil, nil
} }
var prefixes []netip.Prefix var prefixes []netip.Prefix
@@ -657,6 +650,11 @@ func loadFromEnv() (*Config, error) {
return nil, err return nil, err
} }
maintenanceMode, err := envBool("MAINTENANCE_MODE", false)
if err != nil {
return nil, err
}
retentionSweepInterval, err := envPositiveDuration( retentionSweepInterval, err := envPositiveDuration(
"RETENTION_SWEEP_INTERVAL", "RETENTION_SWEEP_INTERVAL",
defaultRetentionSweepInterval, defaultRetentionSweepInterval,
@@ -683,12 +681,12 @@ func loadFromEnv() (*Config, error) {
return nil, err return nil, err
} }
trustedProxies, err := envPrefixList("TRUSTED_PROXIES", defaultTrustedProxies) trustedProxies, err := envPrefixList("TRUSTED_PROXIES")
if err != nil { if err != nil {
return nil, err return nil, err
} }
allowedEgressCIDRs, err := envPrefixList("ALLOWED_EGRESS_CIDRS", "") allowedEgressCIDRs, err := envPrefixList("ALLOWED_EGRESS_CIDRS")
if err != nil { if err != nil {
return nil, err return nil, err
} }
@@ -706,6 +704,7 @@ func loadFromEnv() (*Config, error) {
return &Config{ return &Config{
DataDir: DataDir(), DataDir: DataDir(),
Debug: debug, Debug: debug,
MaintenanceMode: maintenanceMode,
Environment: environment, Environment: environment,
MetricsUsername: metricsUsername, MetricsUsername: metricsUsername,
MetricsPassword: metricsPassword, MetricsPassword: metricsPassword,
@@ -761,6 +760,50 @@ func (c *Config) warnEgressAllowlist(log *slog.Logger) {
) )
} }
// warnSharedRateLimitBucket logs a startup warning whenever
// TRUSTED_PROXIES is empty, in any environment.
//
// With no trusted proxies every rate limiter keys on the connecting
// peer's address. Whether that is harmless or dangerous depends on
// what is in front of the process, which this code cannot observe:
// with nothing in front, the peer is the client and the limits are
// per-client as intended; behind a reverse proxy the peer is the proxy
// for every request, so all clients share one bucket per limiter.
//
// The login endpoint no longer spends budget on arrival — it verifies
// credentials first and charges only failures — so a shared bucket
// cannot deny the operator a correct password. What it does collapse
// is the failure counting: one client's wrong passwords throttle
// everyone else's wrong passwords, and the receiver's limits become
// service-wide ceilings.
//
// The warning is deliberately not gated on WEBHOOKER_ENVIRONMENT:
// behind a proxy every client shares one bucket in dev and prod alike.
//
// The default of trusting nobody is deliberate — trusting forwarded
// headers from arbitrary peers lets any client choose its own bucket —
// so this warns rather than failing startup or changing the key.
func (c *Config) warnSharedRateLimitBucket(log *slog.Logger) {
if len(c.TrustedProxies) > 0 {
return
}
log.Warn(
"TRUSTED_PROXIES is empty: every rate limit keys on the "+
"connecting peer's address. With nothing proxying to "+
"this process that is the client itself and the limits "+
"are per-client as intended. Behind a reverse proxy the "+
"peer is the proxy on every request, so all clients "+
"share one bucket per limit: the receiver limits become "+
"service-wide ceilings, and one client's failed logins "+
"throttle every other client's failed logins — a "+
"correct password still gets in. If anything proxies to "+
"this process, set TRUSTED_PROXIES to its address.",
"environment", c.Environment,
"trustedProxies", len(c.TrustedProxies),
)
}
// New creates a Config by reading environment variables. // New creates a Config by reading environment variables.
// //
//nolint:revive // lc parameter is required by fx even if unused. //nolint:revive // lc parameter is required by fx even if unused.
@@ -792,6 +835,7 @@ func New(lc fx.Lifecycle, params ConfigParams) (*Config, error) {
// host can reach the admin UI. // host can reach the admin UI.
"bindAddress", s.BindAddress, "bindAddress", s.BindAddress,
"debug", s.Debug, "debug", s.Debug,
"maintenanceMode", s.MaintenanceMode,
"dataDir", s.DataDir, "dataDir", s.DataDir,
"retentionSweepInterval", s.RetentionSweepInterval.String(), "retentionSweepInterval", s.RetentionSweepInterval.String(),
// Logged because a perfectly valid non-positive value here // Logged because a perfectly valid non-positive value here
@@ -805,6 +849,7 @@ func New(lc fx.Lifecycle, params ConfigParams) (*Config, error) {
"hasMetricsAuth", s.MetricsAuthEnabled(), "hasMetricsAuth", s.MetricsAuthEnabled(),
) )
s.warnSharedRateLimitBucket(log)
s.warnEgressAllowlist(log) s.warnEgressAllowlist(log)
return s, nil return s, nil
+101 -26
View File
@@ -124,11 +124,6 @@ func testEnvironmentConfigSuccess(
app := fxtest.New( app := fxtest.New(
t, t,
// fx's own log is discarded, not sent to t.Logf: a hook still
// running after a start or stop timeout would write there after
// the test has returned. The same holds for every fxtest.New
// below.
fx.NopLogger,
fx.Provide( fx.Provide(
globals.New, globals.New,
logger.New, logger.New,
@@ -277,7 +272,6 @@ func testRetentionSweepIntervalSuccess(
app := fxtest.New( app := fxtest.New(
t, t,
fx.NopLogger,
fx.Provide( fx.Provide(
globals.New, globals.New,
logger.New, logger.New,
@@ -370,7 +364,6 @@ func testSessionIdleTimeoutSuccess(
app := fxtest.New( app := fxtest.New(
t, t,
fx.NopLogger,
fx.Provide( fx.Provide(
globals.New, globals.New,
logger.New, logger.New,
@@ -411,7 +404,6 @@ func TestDefaultDataDir(t *testing.T) {
app := fxtest.New( app := fxtest.New(
t, t,
fx.NopLogger,
fx.Provide( fx.Provide(
globals.New, globals.New,
logger.New, logger.New,
@@ -542,7 +534,6 @@ func testReceiverRateLimitSuccess(
app := fxtest.New( app := fxtest.New(
t, t,
fx.NopLogger,
fx.Provide( fx.Provide(
globals.New, globals.New,
logger.New, logger.New,
@@ -560,11 +551,6 @@ func testReceiverRateLimitSuccess(
} }
func TestTrustedProxies(t *testing.T) { func TestTrustedProxies(t *testing.T) {
// Unset, the RFC 1918 private ranges are trusted, so a reverse
// proxy on a Docker network or a private LAN is covered without
// configuration.
defaultProxies := []string{cidrPrivateV4, "172.16.0.0/12", "192.168.0.0/16"}
tests := []struct { tests := []struct {
name string name string
set bool set bool
@@ -573,21 +559,18 @@ func TestTrustedProxies(t *testing.T) {
expected []string expected []string
}{ }{
{ {
// The default must be "trust nobody": an empty list
// means forwarded headers are ignored, never that
// every peer may speak for the client.
name: caseUnsetUsesDefault, name: caseUnsetUsesDefault,
set: false, set: false,
expected: defaultProxies, expected: []string{},
}, },
{ {
name: "blank value uses default", name: "blank value trusts nothing",
set: true, set: true,
value: " ", value: " ",
expected: defaultProxies, expected: []string{},
},
{
name: "set value replaces the default entirely",
set: true,
value: "203.0.113.7",
expected: []string{"203.0.113.7/32"},
}, },
{ {
name: caseValidValueParsed, name: caseValidValueParsed,
@@ -659,7 +642,6 @@ func testTrustedProxiesSuccess(
app := fxtest.New( app := fxtest.New(
t, t,
fx.NopLogger,
fx.Provide( fx.Provide(
globals.New, globals.New,
logger.New, logger.New,
@@ -773,7 +755,6 @@ func testAllowedEgressCIDRsSuccess(
app := fxtest.New( app := fxtest.New(
t, t,
fx.NopLogger,
fx.Provide( fx.Provide(
globals.New, globals.New,
logger.New, logger.New,
@@ -864,6 +845,101 @@ func TestEgressAllowlistWarning(t *testing.T) {
} }
} }
// TestSharedRateLimitBucketWarning covers the startup warning that
// tells an operator a deployment behind a reverse proxy shares one
// rate-limit bucket between every client, which turns the receiver
// limits into service-wide ceilings and collapses login failure
// counting. It must fire whenever TRUSTED_PROXIES is empty, in any
// environment, because behind a proxy every client shares one bucket
// in dev and prod alike. It stays quiet once proxies are named.
func TestSharedRateLimitBucketWarning(t *testing.T) {
tests := []struct {
name string
environment string
trustedProxies string
expectWarning bool
}{
{
name: "prod without trusted proxies warns",
environment: config.EnvironmentProd,
expectWarning: true,
},
{
name: "prod with trusted proxies is quiet",
environment: config.EnvironmentProd,
trustedProxies: cidrPrivateV4,
expectWarning: false,
},
{
name: "dev without trusted proxies warns",
environment: config.EnvironmentDev,
expectWarning: true,
},
{
name: "dev with trusted proxies is quiet",
environment: config.EnvironmentDev,
trustedProxies: cidrPrivateV4,
expectWarning: false,
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
t.Setenv("WEBHOOKER_ENVIRONMENT", tt.environment)
if tt.trustedProxies == "" {
require.NoError(
t, os.Unsetenv("TRUSTED_PROXIES"),
)
} else {
t.Setenv("TRUSTED_PROXIES", tt.trustedProxies)
}
var buf bytes.Buffer
log := slog.New(slog.NewJSONHandler(
&buf, &slog.HandlerOptions{
Level: slog.LevelDebug,
},
))
require.NoError(
t,
config.WarnSharedRateLimitBucketForTest(log),
)
if !tt.expectWarning {
assert.Empty(t, buf.String())
return
}
logged := buf.String()
assert.Contains(t, logged, `"level":"WARN"`)
assert.Contains(t, logged, "TRUSTED_PROXIES")
assert.Contains(t, logged, "share one bucket")
assert.Contains(
t, logged, "throttle every other client's failed logins",
)
// The warning must not claim a lockout the login
// endpoint no longer permits: credentials are verified
// before any budget is spent.
assert.Contains(
t, logged, "a correct password still gets in",
)
// The text must stay accurate for a developer with
// nothing in front of the process, where an empty
// list costs nothing.
assert.Contains(
t, logged, "nothing proxying to this process",
)
})
}
}
// metricsEnv describes what one subtest below puts in the // metricsEnv describes what one subtest below puts in the
// environment for a single METRICS_ variable. A variable that is // environment for a single METRICS_ variable. A variable that is
// set to the empty string and one that is not set at all are // set to the empty string and one that is not set at all are
@@ -1017,7 +1093,6 @@ func assertMetricsAuthAccepted(t *testing.T, expectAuth bool) {
app := fxtest.New( app := fxtest.New(
t, t,
fx.NopLogger,
fx.Provide(globals.New, logger.New, config.New), fx.Provide(globals.New, logger.New, config.New),
fx.Populate(&cfg), fx.Populate(&cfg),
) )
+13 -4
View File
@@ -18,9 +18,10 @@ const testEnvKey = "WEBHOOKER_TEST_VALUE"
// Real configuration variables exercised by the config.New tests. // Real configuration variables exercised by the config.New tests.
const ( const (
envKeyPort = "PORT" envKeyPort = "PORT"
envKeyDebug = "DEBUG" envKeyDebug = "DEBUG"
envKeyBindAddress = "BIND_ADDRESS" envKeyMaintenanceMode = "MAINTENANCE_MODE"
envKeyBindAddress = "BIND_ADDRESS"
) )
// Sample BIND_ADDRESS values used by the tables below. // Sample BIND_ADDRESS values used by the tables below.
@@ -603,6 +604,12 @@ func flagEnvValueCases() []badEnvValueCase {
value: "ture", value: "ture",
expectError: true, expectError: true,
}, },
{
name: "unparseable MAINTENANCE_MODE aborts startup",
key: envKeyMaintenanceMode,
value: "sometimes",
expectError: true,
},
} }
} }
@@ -649,7 +656,8 @@ func TestNewUsesDefaultsWhenUnset(t *testing.T) {
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev") t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
for _, key := range []string{ for _, key := range []string{
envKeyPort, envKeyDebug, envKeyBindAddress, envKeySentryDSN, envKeyPort, envKeyDebug, envKeyMaintenanceMode,
envKeyBindAddress, envKeySentryDSN,
} { } {
require.NoError(t, os.Unsetenv(key)) require.NoError(t, os.Unsetenv(key))
} }
@@ -660,6 +668,7 @@ func TestNewUsesDefaultsWhenUnset(t *testing.T) {
assert.Equal(t, 8080, cfg.Port) assert.Equal(t, 8080, cfg.Port)
assert.False(t, cfg.Debug) assert.False(t, cfg.Debug)
assert.False(t, cfg.MaintenanceMode)
// Loopback, not the wildcard: the default must not publish the // Loopback, not the wildcard: the default must not publish the
// cleartext admin UI and the unauthenticated receiver on every // cleartext admin UI and the unauthenticated receiver on every
+15
View File
@@ -6,6 +6,21 @@ import "log/slog"
// the external config_test package so each helper can be covered by // the external config_test package so each helper can be covered by
// its own table-driven test without weakening the package API. // its own table-driven test without weakening the package API.
// WarnSharedRateLimitBucketForTest loads a Config from the current
// environment and emits its startup warnings to log. The real logger
// writes to stdout, so this lets the warning's firing condition be
// asserted against a handler the test controls.
func WarnSharedRateLimitBucketForTest(log *slog.Logger) error {
c, err := loadFromEnv()
if err != nil {
return err
}
c.warnSharedRateLimitBucket(log)
return nil
}
// WarnEgressAllowlistForTest loads a Config from the current // WarnEgressAllowlistForTest loads a Config from the current
// environment and emits its egress-allowlist startup warning to // environment and emits its egress-allowlist startup warning to
// log, so a test can assert both that the warning fires only when // log, so a test can assert both that the warning fires only when
+23 -5
View File
@@ -152,7 +152,9 @@ func TestEventTierQueriesUseTheirIndexes(t *testing.T) {
// TestStatisticsQueriesUseTheirIndexes does the same for the webhook // TestStatisticsQueriesUseTheirIndexes does the same for the webhook
// page's statistics (readEventStats in the handlers): deliveries in // page's statistics (readEventStats in the handlers): deliveries in
// progress, each target's deliveries finished since a time, which must // progress, each target's deliveries finished since a time, which must
// come from the index alone, and events received since a time. // come from the index alone, events received since a time, and the
// newest event, which must come straight off an index rather than from
// sorting every event.
func TestStatisticsQueriesUseTheirIndexes(t *testing.T) { func TestStatisticsQueriesUseTheirIndexes(t *testing.T) {
t.Parallel() t.Parallel()
@@ -170,6 +172,7 @@ func TestStatisticsQueriesUseTheirIndexes(t *testing.T) {
var ( var (
count int64 count int64
newest []time.Time
byTarget []struct{ TargetID string } byTarget []struct{ TargetID string }
) )
@@ -197,6 +200,12 @@ func TestStatisticsQueriesUseTheirIndexes(t *testing.T) {
Where("created_at >= ?", since).Count(&count), Where("created_at >= ?", since).Count(&count),
"idx_events_deleted_at_created_at "+ "idx_events_deleted_at_created_at "+
"(deleted_at=? AND created_at>?)") "(deleted_at=? AND created_at>?)")
newestEvent := dry.Model(&database.Event{}).
Order("created_at DESC").Limit(1).Pluck("created_at", &newest)
assertPlanUses(t, db, newestEvent,
"idx_events_deleted_at_created_at (deleted_at=?)")
assert.NotContains(t, queryPlan(t, db, newestEvent), "TEMP B-TREE")
} }
// assertPlanUses asserts that SQLite's plan for a statement GORM built // assertPlanUses asserts that SQLite's plan for a statement GORM built
@@ -207,6 +216,18 @@ func assertPlanUses(
) { ) {
t.Helper() t.Helper()
plan := queryPlan(t, db, built)
for _, index := range indexes {
assert.Contains(t, plan, index, built.Statement.SQL.String())
}
}
// queryPlan returns SQLite's plan for a statement GORM built in a dry
// run, run with the same SQL and arguments GORM would send.
func queryPlan(t *testing.T, db, built *gorm.DB) string {
t.Helper()
var plan []struct{ Detail string } var plan []struct{ Detail string }
require.NoError(t, db.Raw( require.NoError(t, db.Raw(
@@ -214,8 +235,5 @@ func assertPlanUses(
built.Statement.Vars..., built.Statement.Vars...,
).Scan(&plan).Error) ).Scan(&plan).Error)
for _, index := range indexes { return fmt.Sprint(plan)
assert.Contains(t, fmt.Sprint(plan), index,
built.Statement.SQL.String())
}
} }
-12
View File
@@ -5,7 +5,6 @@ import (
"io" "io"
"log/slog" "log/slog"
"os" "os"
"testing"
"time" "time"
"go.uber.org/fx" "go.uber.org/fx"
@@ -84,14 +83,3 @@ func (d *Database) ExportSetBannerOut(w io.Writer) {
func DummyPasswordHashForTest() string { func DummyPasswordHashForTest() string {
return dummyPasswordHash() return dummyPasswordHash()
} }
// HashAtShippedCostForTest makes HashPassword hash at the shipped
// memory cost until t ends. t must not run in parallel with other
// tests, which would hash at that cost alongside it.
func HashAtShippedCostForTest(t *testing.T) {
t.Helper()
hashAtShippedCostInTest = true
t.Cleanup(func() { hashAtShippedCostInTest = false })
}
-5
View File
@@ -31,11 +31,6 @@ type Event struct {
Body string `gorm:"type:text" json:"body"` Body string `gorm:"type:text" json:"body"`
ContentType string `json:"contentType"` ContentType string `json:"contentType"`
// BodyBytes is the size of Body in bytes, recorded when the event
// is stored so the recent events list can show it without reading
// the body.
BodyBytes int64 `gorm:"not null" json:"bodyBytes"`
// ResubmittedFromID names the event this one was copied from by // ResubmittedFromID names the event this one was copied from by
// an operator resubmit. It is nil for an event that arrived on // an operator resubmit. It is nil for an event that arrived on
// the receiver, which is every event created before the column // the receiver, which is every event created before the column
+5 -13
View File
@@ -2,7 +2,6 @@ package database
import ( import (
"fmt" "fmt"
"time"
"gorm.io/gorm" "gorm.io/gorm"
) )
@@ -14,17 +13,12 @@ import (
// rows it counts. // rows it counts.
// EventTotals is the single row counting a webhook's events: every // EventTotals is the single row counting a webhook's events: every
// event ever stored, how many of them retention has deleted, and when // event ever stored, and how many of them retention has deleted.
// the newest arrived, which retention leaves as it is.
type EventTotals struct { type EventTotals struct {
ID int64 `gorm:"primaryKey"` ID int64 `gorm:"primaryKey"`
Events int64 `gorm:"not null"` Events int64 `gorm:"not null"`
EventsRemoved int64 `gorm:"not null"` EventsRemoved int64 `gorm:"not null"`
// LastEventAt is when the newest event arrived, or nil before the
// first.
LastEventAt *time.Time
} }
// TableName names the table AddEventTotals updates. // TableName names the table AddEventTotals updates.
@@ -52,17 +46,15 @@ func (TargetTotals) TableName() string {
return "target_totals" return "target_totals"
} }
// AddEventTotals adds each count in add to the webhook's event totals, // AddEventTotals adds each count in add to the webhook's event totals.
// and records add.LastEventAt as when the newest event arrived if it is // Call it on the transaction that writes or deletes the events it
// set. Call it on the transaction that writes or deletes the events it
// counts. // counts.
func AddEventTotals(tx *gorm.DB, add EventTotals) error { func AddEventTotals(tx *gorm.DB, add EventTotals) error {
err := tx.Exec( err := tx.Exec(
`UPDATE event_totals SET `UPDATE event_totals SET
events = events + ?, events = events + ?,
events_removed = events_removed + ?, events_removed = events_removed + ?`,
last_event_at = coalesce(?, last_event_at)`, add.Events, add.EventsRemoved,
add.Events, add.EventsRemoved, add.LastEventAt,
).Error ).Error
if err != nil { if err != nil {
return fmt.Errorf("adding to event totals: %w", err) return fmt.Errorf("adding to event totals: %w", err)
+1 -22
View File
@@ -9,7 +9,6 @@ import (
"math/big" "math/big"
"strings" "strings"
"sync" "sync"
"testing"
"golang.org/x/crypto/argon2" "golang.org/x/crypto/argon2"
) )
@@ -64,30 +63,10 @@ func DefaultPasswordConfig() *PasswordConfig {
} }
} }
// testArgon2Memory is the Argon2id memory cost, in KiB, that a test // HashPassword generates an Argon2id hash of the password
// binary hashes with: 1 MB instead of the shipped 64 MB. Every test
// that starts a database hashes the bootstrap admin password, dozens
// of them run in parallel, and under the race detector each 64 MB hash
// holds about 150 MB. VerifyPassword reads the cost from the hash it
// checks, so verification follows.
const testArgon2Memory = 1024
// hashAtShippedCostInTest makes a test binary hash at the shipped
// memory cost. Only TestHashPassword_ShippedParameters sets it.
//
//nolint:gochecknoglobals // set by one test, see above
var hashAtShippedCostInTest bool
// HashPassword generates an Argon2id hash of the password. A binary
// built by go test hashes at testArgon2Memory; one built by go build
// always hashes at the defaults.
func HashPassword(password string) (string, error) { func HashPassword(password string) (string, error) {
config := DefaultPasswordConfig() config := DefaultPasswordConfig()
if testing.Testing() && !hashAtShippedCostInTest {
config.Memory = testArgon2Memory
}
// Generate a salt // Generate a salt
salt := make([]byte, config.SaltLen) salt := make([]byte, config.SaltLen)
-33
View File
@@ -192,39 +192,6 @@ func TestHashPasswordUniqueness(t *testing.T) {
} }
} }
// TestHashPassword_ShippedParameters hashes and verifies through
// HashPassword at the shipped Argon2id parameters. Every other test
// hashes at the lower memory cost a test binary uses, so this is the
// one that keeps production hashing covered. One hash and one
// verification: each costs 64 MB.
//
//nolint:paralleltest // changes the hashing cost for the whole binary
func TestHashPassword_ShippedParameters(t *testing.T) {
database.HashAtShippedCostForTest(t)
password := "correct horse battery staple"
hash, err := database.HashPassword(password)
if err != nil {
t.Fatalf("hashing with the shipped parameters: %v", err)
}
const shipped = "$argon2id$v=19$m=65536,t=1,p=4$"
if !strings.HasPrefix(hash, shipped) {
t.Errorf("hash = %q, want prefix %q", hash, shipped)
}
valid, err := database.VerifyPassword(password, hash)
if err != nil {
t.Fatalf("VerifyPassword() error = %v", err)
}
if !valid {
t.Error("VerifyPassword() returned false for correct password")
}
}
// TestVerifyDummyPassword_DoesRealWork covers the anti-enumeration // TestVerifyDummyPassword_DoesRealWork covers the anti-enumeration
// path. Login charges an unknown username a verification against a // path. Login charges an unknown username a verification against a
// dummy hash so that a nonexistent account is not answered in // dummy hash so that a nonexistent account is not answered in
+6 -24
View File
@@ -25,12 +25,6 @@ const hoursPerDay = 24
// busy timeout. // busy timeout.
const reapBatchSize = 1000 const reapBatchSize = 1000
// reapBatchPause is how long retention waits after one batch before
// starting the next. A writer waiting for the write lock checks for it
// again after at most 100 ms, so a longer pause lets it in between two
// batches instead of only after the whole prune.
const reapBatchPause = 200 * time.Millisecond
// RetentionReaperParams holds the fx dependencies for the // RetentionReaperParams holds the fx dependencies for the
// RetentionReaper. // RetentionReaper.
type RetentionReaperParams struct { type RetentionReaperParams struct {
@@ -200,15 +194,13 @@ func (r *RetentionReaper) sweep(ctx context.Context) {
continue continue
} }
r.reapWebhook(ctx, wh.ID, wh.RetentionDays) r.reapWebhook(wh.ID, wh.RetentionDays)
} }
} }
// reapWebhook removes every expired event (and its dependents) from a // reapWebhook removes every expired event (and its dependents) from a
// single webhook's database, or as many as it reaches before ctx is // single webhook's database.
// cancelled.
func (r *RetentionReaper) reapWebhook( func (r *RetentionReaper) reapWebhook(
ctx context.Context,
webhookID string, webhookID string,
retentionDays int, retentionDays int,
) { ) {
@@ -228,7 +220,7 @@ func (r *RetentionReaper) reapWebhook(
return return
} }
deleted, err := reapExpired(ctx, db, cutoff) deleted, err := reapExpired(db, cutoff)
if err != nil { if err != nil {
r.log.Error( r.log.Error(
"retention sweep: failed to reap expired events", "retention sweep: failed to reap expired events",
@@ -282,13 +274,9 @@ func retentionCutoff(
// reapExpired hard-deletes the events older than cutoff, with their // reapExpired hard-deletes the events older than cutoff, with their
// deliveries and delivery results, reapBatchSize events per // deliveries and delivery results, reapBatchSize events per
// transaction with reapBatchPause between transactions, until none is // transaction until none is left. It returns the number of events
// left. Once ctx is cancelled it returns after the batch in hand, // deleted.
// leaving the rest to the next sweep, so stopping the app does not func reapExpired(db *gorm.DB, cutoff time.Time) (int64, error) {
// wait for a long prune. It returns the number of events deleted.
func reapExpired(
ctx context.Context, db *gorm.DB, cutoff time.Time,
) (int64, error) {
var total int64 var total int64
for { for {
@@ -318,12 +306,6 @@ func reapExpired(
if len(eventIDs) < reapBatchSize { if len(eventIDs) < reapBatchSize {
return total, nil return total, nil
} }
select {
case <-ctx.Done():
return total, nil
case <-time.After(reapBatchPause):
}
} }
} }
+23 -218
View File
@@ -99,21 +99,29 @@ func TestWebhookDBManager_TotalsSurviveReopen(t *testing.T) {
}, readTargetTotals(t, db)) }, readTargetTotals(t, db))
} }
// seedExpiredEvents stores count events created at the given time, // TestRetentionReaper_PrunesMoreThanOneBatch verifies that a prune
// each with a delivered delivery to one target and a failed delivery // larger than one transaction's batch removes every expired event with
// to the other, and one attempt for each delivery. // its deliveries and delivery results, keeps the recent event, and
func seedExpiredEvents( // adds what it removed to the event and target totals, so the totals
t *testing.T, // within retention match the rows still stored.
db *gorm.DB, func TestRetentionReaper_PrunesMoreThanOneBatch(t *testing.T) {
webhookID string, t.Parallel()
count int,
createdAt time.Time,
delivered, failed string,
) {
t.Helper()
events := make([]database.Event, count) env := setupRetentionTest(t)
deliveries := make([]database.Delivery, 0, 2*count)
webhookID := createWebhook(t, env.mainDB.DB(), 30)
db, err := env.mgr.GetDB(webhookID)
require.NoError(t, err)
// Every expired event has a delivered delivery to one target and a
// failed one to the other, each with one attempt.
expired := database.ExportReapBatchSize + 1
delivered, failed := uuid.New().String(), uuid.New().String()
old := time.Now().Add(-40 * 24 * time.Hour)
events := make([]database.Event, expired)
deliveries := make([]database.Delivery, 0, 2*expired)
for i := range events { for i := range events {
events[i] = database.Event{ events[i] = database.Event{
@@ -122,7 +130,7 @@ func seedExpiredEvents(
Method: http.MethodPost, Method: http.MethodPost,
} }
events[i].ID = uuid.New().String() events[i].ID = uuid.New().String()
events[i].CreatedAt = createdAt events[i].CreatedAt = old
deliveries = append(deliveries, deliveries = append(deliveries,
database.Delivery{ database.Delivery{
@@ -149,51 +157,6 @@ func seedExpiredEvents(
} }
require.NoError(t, db.CreateInBatches(results, 500).Error) require.NoError(t, db.CreateInBatches(results, 500).Error)
}
// seedBareEvents stores count events created at the given time, with
// no deliveries.
func seedBareEvents(
t *testing.T,
db *gorm.DB,
webhookID string,
count int,
createdAt time.Time,
) {
t.Helper()
events := make([]database.Event, count)
for i := range events {
events[i] = database.Event{
WebhookID: webhookID,
EntrypointID: uuid.New().String(),
Method: http.MethodPost,
}
events[i].CreatedAt = createdAt
}
require.NoError(t, db.CreateInBatches(events, 500).Error)
}
// TestRetentionReaper_PrunesMoreThanOneBatch verifies that a prune
// larger than one transaction's batch removes every expired event with
// its deliveries and delivery results, keeps the recent event, and
// adds what it removed to the event and target totals, so the totals
// within retention match the rows still stored.
func TestRetentionReaper_PrunesMoreThanOneBatch(t *testing.T) {
t.Parallel()
env := setupRetentionTest(t)
webhookID := createWebhook(t, env.mainDB.DB(), 30)
db, err := env.mgr.GetDB(webhookID)
require.NoError(t, err)
expired := database.ExportReapBatchSize + 1
delivered, failed := uuid.New().String(), uuid.New().String()
seedExpiredEvents(t, db, webhookID, expired,
time.Now().Add(-40*24*time.Hour), delivered, failed)
// One recent event, delivered to the first target. // One recent event, delivered to the first target.
recent := seedEventChain(t, db, webhookID, time.Now()) recent := seedEventChain(t, db, webhookID, time.Now())
@@ -250,161 +213,3 @@ func TestRetentionReaper_PrunesMoreThanOneBatch(t *testing.T) {
assert.Equal(t, eventTotals, readEventTotals(t, db)) assert.Equal(t, eventTotals, readEventTotals(t, db))
assert.Equal(t, targetTotals, readTargetTotals(t, db)) assert.Equal(t, targetTotals, readTargetTotals(t, db))
} }
// TestRetentionReaper_WriteDuringPruneSucceeds verifies that a prune
// of several batches lets other writers in between its batches: an
// event stored once the first batch is deleted is stored while expired
// events are still left, not only after the prune has finished.
func TestRetentionReaper_WriteDuringPruneSucceeds(t *testing.T) {
t.Parallel()
env := setupRetentionTest(t)
webhookID := createWebhook(t, env.mainDB.DB(), 30)
db, err := env.mgr.GetDB(webhookID)
require.NoError(t, err)
// Three batches of expired events, with nothing else stored: only
// the number of batches matters here.
expired := 3 * database.ExportReapBatchSize
seedBareEvents(t, db, webhookID, expired,
time.Now().Add(-40*24*time.Hour))
cutoff := time.Now().Add(-30 * 24 * time.Hour)
countExpired := func() int64 {
var count int64
require.NoError(t, db.Model(&database.Event{}).
Where("created_at < ?", cutoff).
Count(&count).Error)
return count
}
pruned := make(chan struct{})
go func() {
defer close(pruned)
env.reaper.ExportSweep(context.Background())
}()
t.Cleanup(func() { <-pruned })
// Every stored event is expired until the write below.
require.Eventually(t, func() bool {
var count int64
err := db.Model(&database.Event{}).Count(&count).Error
return err == nil && count < int64(expired)
}, 10*time.Second, 10*time.Millisecond)
event := &database.Event{
WebhookID: webhookID,
EntrypointID: uuid.New().String(),
Method: http.MethodPost,
}
require.NoError(t, db.Create(event).Error)
assert.Positive(t, countExpired(),
"the event was stored only after the whole prune")
<-pruned
assert.Zero(t, countExpired())
var stored database.Event
require.NoError(t, db.First(&stored, "id = ?", event.ID).Error)
}
// TestRetentionReaper_StopDuringPruneLeavesTheRest verifies that
// stopping the reaper during a prune of several batches returns
// between two batches, well inside the stop timeout, leaving the
// remaining expired events for the next sweep, and that the totals
// match the rows left.
func TestRetentionReaper_StopDuringPruneLeavesTheRest(t *testing.T) {
t.Parallel()
env := setupRetentionTest(t)
webhookID := createWebhook(t, env.mainDB.DB(), 30)
db, err := env.mgr.GetDB(webhookID)
require.NoError(t, err)
// Two batches and one more of expired events, a few of them with a
// delivered and a failed delivery for the target totals to count.
// Most carry nothing else, to keep the test quick.
const withDeliveries = 10
expiredAt := time.Now().Add(-40 * 24 * time.Hour)
delivered, failed := uuid.New().String(), uuid.New().String()
seedExpiredEvents(t, db, webhookID, withDeliveries, expiredAt,
delivered, failed)
seedBareEvents(t, db, webhookID,
2*database.ExportReapBatchSize+1-withDeliveries, expiredAt)
n := int64(2*database.ExportReapBatchSize + 1)
require.NoError(t, database.AddEventTotals(db, database.EventTotals{
Events: n,
}))
require.NoError(t, database.AddTargetTotals(db, database.TargetTotals{
TargetID: delivered, Deliveries: withDeliveries,
Delivered: withDeliveries,
}))
require.NoError(t, database.AddTargetTotals(db, database.TargetTotals{
TargetID: failed, Deliveries: withDeliveries,
Failed: withDeliveries,
}))
env.reaper.ExportSetInterval(time.Millisecond)
env.reaper.ExportStart()
// Stop once the first batch is deleted. The stop lands in the pause
// after it, or at worst during the second batch, so at least the
// last event is left.
require.Eventually(t, func() bool {
var count int64
err := db.Model(&database.Event{}).Count(&count).Error
return err == nil && count < n
}, 10*time.Second, 10*time.Millisecond)
// The app's stop timeout.
ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
defer cancel()
require.NoError(t, env.reaper.ExportStop(ctx))
var events int64
require.NoError(t, db.Model(&database.Event{}).Count(&events).Error)
assert.Positive(t, events, "the stop waited for the whole prune")
eventTotals := readEventTotals(t, db)
assert.Equal(t, events, eventTotals.Events-eventTotals.EventsRemoved)
targetTotals := readTargetTotals(t, db)
require.Len(t, targetTotals, 2)
for target, totals := range targetTotals {
var deliveries, failures int64
require.NoError(t, db.Model(&database.Delivery{}).
Where("target_id = ?", target).
Count(&deliveries).Error)
require.NoError(t, db.Model(&database.Delivery{}).
Where("target_id = ? AND status = ?",
target, database.DeliveryStatusFailed).
Count(&failures).Error)
assert.Equal(t, deliveries,
totals.Deliveries-totals.DeliveriesRemoved, target)
assert.Equal(t, failures, totals.Failed-totals.FailedRemoved,
target)
}
}
+12 -14
View File
@@ -8,7 +8,6 @@ import (
"time" "time"
"go.uber.org/fx" "go.uber.org/fx"
"gorm.io/gorm"
"sneak.berlin/go/webhooker/internal/config" "sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/database" "sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/lifecycle" "sneak.berlin/go/webhooker/internal/lifecycle"
@@ -26,14 +25,14 @@ type ArchiveSweeperParams struct {
Logger *logger.Logger Logger *logger.Logger
} }
// ArchiveSweeper periodically prunes expired rows from the // ArchiveSweeper periodically prunes expired rows from
// archive databases of database targets that carry a positive // per-webhook archive databases whose database target carries a
// expiry. // positive expiry.
// //
// Without it, pruning happens only when an archive is // Without it, pruning happens only when an archive is
// (re)opened, and archives are only ever reopened by writes: an // (re)opened, and archives are only ever reopened by writes: an
// archive whose target has stopped receiving events would keep // archive belonging to a webhook that has stopped receiving
// its expired rows forever. The sweep closes // events would keep its expired rows forever. The sweep closes
// that gap without changing anything for archives whose expiry // that gap without changing anything for archives whose expiry
// is unset or "never". // is unset or "never".
// //
@@ -156,7 +155,7 @@ func (s *ArchiveSweeper) run(ctx context.Context) {
// soft-deleted along with it, so GORM's default scope already // soft-deleted along with it, so GORM's default scope already
// excludes them. // excludes them.
// //
// A failure for one target is logged and the sweep continues, // A failure for one webhook is logged and the sweep continues,
// matching how the write path already treats a prune error as // matching how the write path already treats a prune error as
// non-fatal. // non-fatal.
func (s *ArchiveSweeper) sweep(ctx context.Context) { func (s *ArchiveSweeper) sweep(ctx context.Context) {
@@ -211,20 +210,19 @@ func (s *ArchiveSweeper) sweepTarget(target *database.Target) {
return return
} }
err = s.eng.dbTarget.sweepArchive(target.ID, expiry) err = s.eng.dbTarget.sweepWebhook(target.WebhookID, expiry)
if err == nil { if err == nil {
return return
} }
// A writer evicted, or a target row gone, underneath the sweep // A writer evicted underneath the sweep means the operator
// means the operator deleted the target or its webhook while // deleted the webhook (or its last database target) while the
// the sweep was walking the target list. That is an ordinary // sweep was walking the target list. That is an ordinary
// interleaving, not a failure, so it must not produce an // interleaving, not a failure, so it must not produce an
// error line. // error line.
if errors.Is(err, errArchiveWriterEvicted) || if errors.Is(err, errArchiveWriterEvicted) {
errors.Is(err, gorm.ErrRecordNotFound) {
s.log.Debug( s.log.Debug(
"archive sweep: target deleted mid-sweep", "archive sweep: writer evicted mid-sweep",
"webhook_id", target.WebhookID, "webhook_id", target.WebhookID,
"target_id", target.ID, "target_id", target.ID,
) )
+133 -143
View File
@@ -34,23 +34,18 @@ const (
sweepConcurrentWrites = 20 sweepConcurrentWrites = 20
) )
// archiveTestWebhookName is the name of every webhook // sweeperEnv bundles the pieces an archive sweep test drives:
// seedDatabaseTarget creates. It is not safe in a file name as it // a main configuration database holding webhooks and targets, a
// stands, so every archive test goes through archiveNamePart. // delivery engine owning the archive writer registry, and the
const archiveTestWebhookName = "Sweep Test!" // data directory the archive files live in.
type sweeperEnv struct {
// archiveEnv bundles the pieces an archive test drives: a main
// configuration database holding webhooks and targets, a delivery
// engine owning the archive writer registry, the archive sweeper,
// and the data directory the archive files live in.
type archiveEnv struct {
sweeper *delivery.ArchiveSweeper sweeper *delivery.ArchiveSweeper
eng *delivery.Engine eng *delivery.Engine
mainDB *database.Database mainDB *database.Database
dataDir string dataDir string
} }
func setupArchiveTest(t *testing.T) *archiveEnv { func setupSweeperTest(t *testing.T) *sweeperEnv {
t.Helper() t.Helper()
dataDir := t.TempDir() dataDir := t.TempDir()
@@ -83,7 +78,7 @@ func setupArchiveTest(t *testing.T) *archiveEnv {
1, 1,
) )
return &archiveEnv{ return &sweeperEnv{
sweeper: delivery.NewTestArchiveSweeper( sweeper: delivery.NewTestArchiveSweeper(
mainDB, eng, log, mainDB, eng, log,
), ),
@@ -93,27 +88,25 @@ func setupArchiveTest(t *testing.T) *archiveEnv {
} }
} }
// archivePath returns where the engine keeps a database target's // archivePath returns where the engine keeps a webhook's
// archive file, for the names seedDatabaseTarget gave it. // archive file.
func (env *archiveEnv) archivePath(tgt *database.Target) string { func (env *sweeperEnv) archivePath(webhookID string) string {
return filepath.Join( return filepath.Join(
env.dataDir, env.dataDir, fmt.Sprintf("archive-%s.db", webhookID),
delivery.ArchiveFileName(
archiveTestWebhookName, tgt.Name, tgt.ID,
),
) )
} }
// seedDatabaseTarget creates a webhook with one database target // seedDatabaseTarget creates a webhook with one database target
// carrying the given target config JSON, and returns the target. // carrying the given target config JSON, and returns the
func (env *archiveEnv) seedDatabaseTarget( // webhook id.
func (env *sweeperEnv) seedDatabaseTarget(
t *testing.T, configJSON string, t *testing.T, configJSON string,
) *database.Target { ) string {
t.Helper() t.Helper()
wh := &database.Webhook{ wh := &database.Webhook{
UserID: uuid.New().String(), UserID: uuid.New().String(),
Name: archiveTestWebhookName, Name: "sweep-test",
} }
require.NoError( require.NoError(
t, t,
@@ -122,19 +115,9 @@ func (env *archiveEnv) seedDatabaseTarget(
Create(wh).Error, Create(wh).Error,
) )
return env.addDatabaseTarget(t, wh.ID, configJSON)
}
// addDatabaseTarget creates one more database target on an
// existing webhook and returns it.
func (env *archiveEnv) addDatabaseTarget(
t *testing.T, webhookID, configJSON string,
) *database.Target {
t.Helper()
tgt := &database.Target{ tgt := &database.Target{
WebhookID: webhookID, WebhookID: wh.ID,
Name: "Archive", Name: "archive",
Type: database.TargetTypeDatabase, Type: database.TargetTypeDatabase,
Active: true, Active: true,
Config: configJSON, Config: configJSON,
@@ -146,19 +129,19 @@ func (env *archiveEnv) addDatabaseTarget(
Create(tgt).Error, Create(tgt).Error,
) )
return tgt return wh.ID
} }
// seedArchiveRows creates the archive file for a target and // seedArchiveRows creates the archive file for a webhook and
// inserts one row per supplied archived-at timestamp, returning // inserts one row per supplied archived-at timestamp, returning
// the archive path. The handle is closed before returning, so // the archive path. The handle is closed before returning, so
// the archive is idle exactly as it would be with no traffic. // the archive is idle exactly as it would be with no traffic.
func (env *archiveEnv) seedArchiveRows( func (env *sweeperEnv) seedArchiveRows(
t *testing.T, tgt *database.Target, archivedAt ...time.Time, t *testing.T, webhookID string, archivedAt ...time.Time,
) string { ) string {
t.Helper() t.Helper()
path := env.archivePath(tgt) path := env.archivePath(webhookID)
sqlDB, err := sql.Open( sqlDB, err := sql.Open(
"sqlite", fmt.Sprintf("file:%s?mode=rwc", path), "sqlite", fmt.Sprintf("file:%s?mode=rwc", path),
@@ -177,7 +160,7 @@ func (env *archiveEnv) seedArchiveRows(
for i, at := range archivedAt { for i, at := range archivedAt {
row := delivery.ExportArchivedEvent{ row := delivery.ExportArchivedEvent{
EventID: fmt.Sprintf("ev-%d", i), EventID: fmt.Sprintf("ev-%d", i),
WebhookID: tgt.WebhookID, WebhookID: webhookID,
Method: http.MethodPost, Method: http.MethodPost,
Body: `{"seeded":true}`, Body: `{"seeded":true}`,
ArchivedAt: at, ArchivedAt: at,
@@ -260,13 +243,13 @@ func TestArchiveSweeper_LoopOutlivesStartHookContext(
) { ) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
now := time.Now() now := time.Now()
path := env.seedArchiveRows( path := env.seedArchiveRows(
t, tgt, t, webhookID,
now.Add(-48*time.Hour), now.Add(-48*time.Hour),
now.Add(-time.Minute), now.Add(-time.Minute),
) )
@@ -304,60 +287,60 @@ func TestArchiveSweeper_LoopOutlivesStartHookContext(
} }
// TestArchiveSweep_DoesNotResurrectEvictedWriter covers the // TestArchiveSweep_DoesNotResurrectEvictedWriter covers the
// interleaving where a sweep tick has already listed a target // interleaving where a sweep tick has already listed a webhook's
// when the target is deleted and its writer evicted. The sweep // target when the webhook is deleted and its writer evicted. The
// must not put a writer back into the registry: nothing would // sweep must not put a writer back into the registry: nothing
// ever evict it again, which is precisely the leak this change // would ever evict it again, which is precisely the leak this
// exists to close. // change exists to close.
func TestArchiveSweep_DoesNotResurrectEvictedWriter( func TestArchiveSweep_DoesNotResurrectEvictedWriter(
t *testing.T, t *testing.T,
) { ) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
env.seedArchiveRows( env.seedArchiveRows(
t, tgt, time.Now().Add(-48*time.Hour), t, webhookID, time.Now().Add(-48*time.Hour),
) )
// Prime the registry the way a delivery would, then evict as // Prime the registry the way a delivery would, then evict as
// the deletion path does. The target row is deliberately left // the deletion path does. The target row is deliberately left
// in place: this is the tick that listed the target before // in place: this is the tick that listed the webhook before
// the deletion committed. // the deletion committed.
_, err := env.eng.ExportEnsureArchiveWriter(tgt.ID) _, err := env.eng.ExportEnsureArchiveWriter(webhookID)
require.NoError(t, err) require.NoError(t, err)
env.eng.EvictTarget(tgt.ID) env.eng.EvictWebhook(webhookID)
require.False(t, env.eng.ExportHasArchiveWriter(tgt.ID)) require.False(t, env.eng.ExportHasArchiveWriter(webhookID))
env.sweeper.ExportSweep(context.Background()) env.sweeper.ExportSweep(context.Background())
assert.False( assert.False(
t, env.eng.ExportHasArchiveWriter(tgt.ID), t, env.eng.ExportHasArchiveWriter(webhookID),
"a sweep must never re-register a writer for a target "+ "a sweep must never re-register a writer for a webhook "+
"whose registry entry has already been released", "whose registry entry has already been released",
) )
} }
// TestArchiveSweep_LeavesNoRegistryEntry states the same // TestArchiveSweep_LeavesNoRegistryEntry states the same
// invariant in its general form: sweeping an archive whose // invariant in its general form: sweeping an archive whose
// target has no cached writer must not leave one behind, so the // webhook has no cached writer must not leave one behind, so the
// registry keeps holding only writers a delivery created and an // registry keeps holding only writers a delivery created and an
// eviction can reach. // eviction can reach.
func TestArchiveSweep_LeavesNoRegistryEntry(t *testing.T) { func TestArchiveSweep_LeavesNoRegistryEntry(t *testing.T) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
path := env.seedArchiveRows( path := env.seedArchiveRows(
t, tgt, t, webhookID,
time.Now().Add(-48*time.Hour), time.Now().Add(-48*time.Hour),
time.Now().Add(-time.Minute), time.Now().Add(-time.Minute),
) )
require.False(t, env.eng.ExportHasArchiveWriter(tgt.ID)) require.False(t, env.eng.ExportHasArchiveWriter(webhookID))
env.sweeper.ExportSweep(context.Background()) env.sweeper.ExportSweep(context.Background())
@@ -366,7 +349,7 @@ func TestArchiveSweep_LeavesNoRegistryEntry(t *testing.T) {
"the sweep must still prune an idle archive", "the sweep must still prune an idle archive",
) )
assert.False( assert.False(
t, env.eng.ExportHasArchiveWriter(tgt.ID), t, env.eng.ExportHasArchiveWriter(webhookID),
"the sweep must release the registry entry it created", "the sweep must release the registry entry it created",
) )
} }
@@ -381,31 +364,34 @@ func TestArchiveSweep_KeepsWriterAdoptedByDelivery(
) { ) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
env.seedArchiveRows( env.seedArchiveRows(
t, tgt, time.Now().Add(-48*time.Hour), t, webhookID, time.Now().Add(-48*time.Hour),
) )
webhookDB := testWebhookDB(t) webhookDB := testWebhookDB(t)
event := seedEvent(t, webhookDB, `{"n":1}`) event := seedEvent(t, webhookDB, `{"n":1}`)
d := seedDatabaseTargetDelivery(t, webhookDB, event, tgt) event.WebhookID = webhookID
d := seedDatabaseTargetDelivery(
t, webhookDB, event, `{"expiry":"1h"}`,
)
env.sweeper.ExportSweep(context.Background()) env.sweeper.ExportSweep(context.Background())
require.False(t, env.eng.ExportHasArchiveWriter(tgt.ID)) require.False(t, env.eng.ExportHasArchiveWriter(webhookID))
env.eng.ExportDeliverDatabase(webhookDB, d) env.eng.ExportDeliverDatabase(webhookDB, d)
assert.True( assert.True(
t, env.eng.ExportHasArchiveWriter(tgt.ID), t, env.eng.ExportHasArchiveWriter(webhookID),
"a delivery's writer must stay registered", "a delivery's writer must stay registered",
) )
env.sweeper.ExportSweep(context.Background()) env.sweeper.ExportSweep(context.Background())
assert.True( assert.True(
t, env.eng.ExportHasArchiveWriter(tgt.ID), t, env.eng.ExportHasArchiveWriter(webhookID),
"a sweep must not drop a writer a delivery owns", "a sweep must not drop a writer a delivery owns",
) )
} }
@@ -437,15 +423,15 @@ func TestArchiveSweep_KeepsWriterAdoptedDuringSweep(
) { ) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
env.seedArchiveRows( env.seedArchiveRows(
t, tgt, time.Now().Add(-48*time.Hour), t, webhookID, time.Now().Add(-48*time.Hour),
) )
sweepWriter, created, err := env.eng.ExportSweepWriterFor( sweepWriter, created, err := env.eng.ExportSweepWriterFor(
tgt.ID, webhookID,
) )
require.NoError(t, err) require.NoError(t, err)
require.True( require.True(
@@ -456,34 +442,37 @@ func TestArchiveSweep_KeepsWriterAdoptedDuringSweep(
// The delivery lands mid-sweep and adopts the entry. // The delivery lands mid-sweep and adopts the entry.
webhookDB := testWebhookDB(t) webhookDB := testWebhookDB(t)
event := seedEvent(t, webhookDB, `{"n":1}`) event := seedEvent(t, webhookDB, `{"n":1}`)
d := seedDatabaseTargetDelivery(t, webhookDB, event, tgt) event.WebhookID = webhookID
d := seedDatabaseTargetDelivery(
t, webhookDB, event, `{"expiry":"1h"}`,
)
env.eng.ExportDeliverDatabase(webhookDB, d) env.eng.ExportDeliverDatabase(webhookDB, d)
adopted := env.eng.ExportArchiveWriterFor(tgt.ID) adopted := env.eng.ExportArchiveWriterFor(webhookID)
require.NotNil(t, adopted) require.NotNil(t, adopted)
require.True( require.True(
t, sweepWriter.Same(adopted), t, sweepWriter.Same(adopted),
"the delivery must have adopted the sweep's writer", "the delivery must have adopted the sweep's writer",
) )
require.True( require.True(
t, env.eng.ExportArchiveHandleOpen(tgt.ID), t, env.eng.ExportArchiveHandleOpen(webhookID),
"the delivery leaves the archive handle open", "the delivery leaves the archive handle open",
) )
// The sweep finishes. // The sweep finishes.
env.eng.ExportReleaseSweepWriter(tgt.ID, sweepWriter) env.eng.ExportReleaseSweepWriter(webhookID, sweepWriter)
require.True( require.True(
t, env.eng.ExportHasArchiveWriter(tgt.ID), t, env.eng.ExportHasArchiveWriter(webhookID),
"a writer adopted by a delivery during a sweep must "+ "a writer adopted by a delivery during a sweep must "+
"stay registered, or its open handle is unreachable", "stay registered, or its open handle is unreachable",
) )
env.eng.EvictTarget(tgt.ID) env.eng.EvictWebhook(webhookID)
assert.False( assert.False(
t, env.eng.ExportHasArchiveWriter(tgt.ID), t, env.eng.ExportHasArchiveWriter(webhookID),
"the adopted writer must still be evictable", "the adopted writer must still be evictable",
) )
assert.False( assert.False(
@@ -492,34 +481,34 @@ func TestArchiveSweep_KeepsWriterAdoptedDuringSweep(
) )
} }
// TestArchiveSweep_ContinuesAfterPerTargetFailure proves a // TestArchiveSweep_ContinuesAfterPerWebhookFailure proves a
// failure for one target does not abort the sweep for the // failure for one webhook does not abort the sweep for the
// others: an unparseable expiry and an unreadable archive both // others: an unparseable expiry and an unreadable archive both
// have to be logged and stepped over. // have to be logged and stepped over.
func TestArchiveSweep_ContinuesAfterPerTargetFailure( func TestArchiveSweep_ContinuesAfterPerWebhookFailure(
t *testing.T, t *testing.T,
) { ) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
// Seeded first so the sweep reaches them before the healthy // Seeded first so the sweep reaches them before the healthy
// target: targets come back in insertion order. // webhook: targets come back in insertion order.
badConfig := env.seedDatabaseTarget(t, `{"expiry":"!!!"}`) badConfigID := env.seedDatabaseTarget(t, `{"expiry":"!!!"}`)
env.seedArchiveRows( env.seedArchiveRows(
t, badConfig, time.Now().Add(-48*time.Hour), t, badConfigID, time.Now().Add(-48*time.Hour),
) )
corrupt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) corruptID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
require.NoError(t, os.WriteFile( require.NoError(t, os.WriteFile(
env.archivePath(corrupt), env.archivePath(corruptID),
[]byte("this is not a sqlite database"), []byte("this is not a sqlite database"),
0o600, 0o600,
)) ))
healthy := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) healthyID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
healthyPath := env.seedArchiveRows( healthyPath := env.seedArchiveRows(
t, healthy, t, healthyID,
time.Now().Add(-48*time.Hour), time.Now().Add(-48*time.Hour),
time.Now().Add(-time.Minute), time.Now().Add(-time.Minute),
) )
@@ -529,14 +518,14 @@ func TestArchiveSweep_ContinuesAfterPerTargetFailure(
assert.Equal( assert.Equal(
t, []string{sweepRowNew}, t, []string{sweepRowNew},
archivedEventIDs(t, healthyPath), archivedEventIDs(t, healthyPath),
"a failure for an earlier target must not stop the "+ "a failure for an earlier webhook must not stop the "+
"sweep from pruning the ones after it", "sweep from pruning the ones after it",
) )
} }
// TestArchiveSweep_OpenExistingDoesNotCreateFile pins the second // TestArchiveSweep_OpenExistingDoesNotCreateFile pins the second
// of the two no-create guards. The first is the stat in // of the two no-create guards. The first is the stat in
// sweepExpired; this one is the SQLite open mode, which is what // sweepWebhook; this one is the SQLite open mode, which is what
// protects the window between that stat and the open. Flipping // protects the window between that stat and the open. Flipping
// the sweep's mode to create-if-missing makes this fail. // the sweep's mode to create-if-missing makes this fail.
func TestArchiveSweep_OpenExistingDoesNotCreateFile( func TestArchiveSweep_OpenExistingDoesNotCreateFile(
@@ -572,13 +561,13 @@ func TestArchiveSweep_OpenExistingDoesNotCreateFile(
func TestArchiveSweep_PrunesIdleArchive(t *testing.T) { func TestArchiveSweep_PrunesIdleArchive(t *testing.T) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
now := time.Now() now := time.Now()
path := env.seedArchiveRows( path := env.seedArchiveRows(
t, tgt, t, webhookID,
now.Add(-48*time.Hour), now.Add(-48*time.Hour),
now.Add(-time.Minute), now.Add(-time.Minute),
) )
@@ -611,11 +600,11 @@ func TestArchiveSweep_PrunesIdleArchive(t *testing.T) {
func TestArchiveSweep_LeavesArchiveClosed(t *testing.T) { func TestArchiveSweep_LeavesArchiveClosed(t *testing.T) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
path := env.seedArchiveRows( path := env.seedArchiveRows(
t, tgt, time.Now().Add(-48*time.Hour), t, webhookID, time.Now().Add(-48*time.Hour),
) )
w := delivery.NewExportArchiveWriter( w := delivery.NewExportArchiveWriter(
@@ -651,32 +640,35 @@ func TestArchiveSweep_ClosesHandleOfRegisteredWriter(
) { ) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
env.seedArchiveRows( env.seedArchiveRows(
t, tgt, time.Now().Add(-48*time.Hour), t, webhookID, time.Now().Add(-48*time.Hour),
) )
webhookDB := testWebhookDB(t) webhookDB := testWebhookDB(t)
event := seedEvent(t, webhookDB, `{"n":1}`) event := seedEvent(t, webhookDB, `{"n":1}`)
d := seedDatabaseTargetDelivery(t, webhookDB, event, tgt) event.WebhookID = webhookID
d := seedDatabaseTargetDelivery(
t, webhookDB, event, `{"expiry":"1h"}`,
)
env.eng.ExportDeliverDatabase(webhookDB, d) env.eng.ExportDeliverDatabase(webhookDB, d)
require.True( require.True(
t, env.eng.ExportArchiveHandleOpen(tgt.ID), t, env.eng.ExportArchiveHandleOpen(webhookID),
"the delivery must leave the archive handle open", "the delivery must leave the archive handle open",
) )
env.sweeper.ExportSweep(context.Background()) env.sweeper.ExportSweep(context.Background())
require.True( require.True(
t, env.eng.ExportHasArchiveWriter(tgt.ID), t, env.eng.ExportHasArchiveWriter(webhookID),
"the delivery's registry entry must survive the sweep", "the delivery's registry entry must survive the sweep",
) )
assert.False( assert.False(
t, env.eng.ExportArchiveHandleOpen(tgt.ID), t, env.eng.ExportArchiveHandleOpen(webhookID),
"the sweep must leave the archive closed", "the sweep must leave the archive closed",
) )
} }
@@ -692,11 +684,11 @@ func TestArchiveSweep_NeverExpiryUntouched(t *testing.T) {
`{"expiry":""}`, `{"expiry":""}`,
"", "",
} { } {
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, configJSON) webhookID := env.seedDatabaseTarget(t, configJSON)
path := env.seedArchiveRows( path := env.seedArchiveRows(
t, tgt, t, webhookID,
time.Now().Add(-10000*time.Hour), time.Now().Add(-10000*time.Hour),
) )
@@ -707,7 +699,7 @@ func TestArchiveSweep_NeverExpiryUntouched(t *testing.T) {
"config %q must keep rows forever", configJSON, "config %q must keep rows forever", configJSON,
) )
assert.False( assert.False(
t, env.eng.ExportHasArchiveWriter(tgt.ID), t, env.eng.ExportHasArchiveWriter(webhookID),
"config %q must leave no registry entry behind", "config %q must leave no registry entry behind",
configJSON, configJSON,
) )
@@ -730,10 +722,10 @@ func TestArchiveSweep_NeverExpirySkipsBeforeOpening(
) { ) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"never"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"never"}`)
path := env.archivePath(tgt) path := env.archivePath(webhookID)
seedUnmigratedArchive(t, path) seedUnmigratedArchive(t, path)
require.False(t, archiveTableExists(t, path)) require.False(t, archiveTableExists(t, path))
@@ -776,16 +768,16 @@ func archiveTableExists(t *testing.T, path string) bool {
} }
// TestArchiveSweep_DoesNotCreateArchiveFile proves the sweep // TestArchiveSweep_DoesNotCreateArchiveFile proves the sweep
// never conjures an archive: a database target that has never // never conjures an archive: a webhook with a database target
// received an event must still have no archive file (nor SQLite // that has never received an event must still have no archive
// sidecar) after a sweep, and no registry entry either. // file (nor SQLite sidecar) after a sweep.
func TestArchiveSweep_DoesNotCreateArchiveFile(t *testing.T) { func TestArchiveSweep_DoesNotCreateArchiveFile(t *testing.T) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
path := env.archivePath(tgt) path := env.archivePath(webhookID)
require.NoFileExists(t, path) require.NoFileExists(t, path)
@@ -797,11 +789,6 @@ func TestArchiveSweep_DoesNotCreateArchiveFile(t *testing.T) {
"the sweep must not create an archive file", "the sweep must not create an archive file",
) )
} }
assert.False(
t, env.eng.ExportHasArchiveWriter(tgt.ID),
"the sweep must leave no registry entry behind",
)
} }
// TestArchiveSweep_DoesNotCreateAfterWriterExists covers the // TestArchiveSweep_DoesNotCreateAfterWriterExists covers the
@@ -813,11 +800,11 @@ func TestArchiveSweep_DoesNotCreateAfterWriterExists(
) { ) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
path, err := env.eng.ExportEnsureArchiveWriter(tgt.ID) path, err := env.eng.ExportEnsureArchiveWriter(webhookID)
require.NoError(t, err) require.NoError(t, err)
require.NoFileExists(t, path) require.NoFileExists(t, path)
@@ -832,17 +819,17 @@ func TestArchiveSweep_DoesNotCreateAfterWriterExists(
func TestArchiveSweep_SkipsDeletedWebhookTargets(t *testing.T) { func TestArchiveSweep_SkipsDeletedWebhookTargets(t *testing.T) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
path := env.seedArchiveRows( path := env.seedArchiveRows(
t, tgt, time.Now().Add(-48*time.Hour), t, webhookID, time.Now().Add(-48*time.Hour),
) )
require.NoError( require.NoError(
t, t,
env.mainDB.DB(). env.mainDB.DB().
Where("webhook_id = ?", tgt.WebhookID). Where("webhook_id = ?", webhookID).
Delete(&database.Target{}).Error, Delete(&database.Target{}).Error,
) )
@@ -855,14 +842,14 @@ func TestArchiveSweep_SkipsDeletedWebhookTargets(t *testing.T) {
} }
// TestArchiveSweep_ConcurrentWrites proves the sweep serialises // TestArchiveSweep_ConcurrentWrites proves the sweep serialises
// against writes through the target's writer mutex. Run under // against writes through the per-webhook writer mutex. Run
// -race, an unsynchronised sweep would be caught here. // under -race, an unsynchronised sweep would be caught here.
func TestArchiveSweep_ConcurrentWrites(t *testing.T) { func TestArchiveSweep_ConcurrentWrites(t *testing.T) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
webhookDB := testWebhookDB(t) webhookDB := testWebhookDB(t)
@@ -875,10 +862,13 @@ func TestArchiveSweep_ConcurrentWrites(t *testing.T) {
for range sweepConcurrentWrites { for range sweepConcurrentWrites {
event := seedEvent(t, webhookDB, `{"n":1}`) event := seedEvent(t, webhookDB, `{"n":1}`)
event.WebhookID = webhookID
deliveries = append( deliveries = append(
deliveries, deliveries,
seedDatabaseTargetDelivery(t, webhookDB, event, tgt), seedDatabaseTargetDelivery(
t, webhookDB, event, `{"expiry":"1h"}`,
),
) )
} }
@@ -904,7 +894,7 @@ func TestArchiveSweep_ConcurrentWrites(t *testing.T) {
wg.Wait() wg.Wait()
assert.FileExists(t, env.archivePath(tgt)) assert.FileExists(t, env.archivePath(webhookID))
} }
// TestArchiveSweeper_StopsCleanly proves the background loop // TestArchiveSweeper_StopsCleanly proves the background loop
@@ -912,11 +902,11 @@ func TestArchiveSweep_ConcurrentWrites(t *testing.T) {
func TestArchiveSweeper_StopsCleanly(t *testing.T) { func TestArchiveSweeper_StopsCleanly(t *testing.T) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
tgt := env.seedDatabaseTarget(t, `{"expiry":"1h"}`) webhookID := env.seedDatabaseTarget(t, `{"expiry":"1h"}`)
env.seedArchiveRows( env.seedArchiveRows(
t, tgt, time.Now().Add(-48*time.Hour), t, webhookID, time.Now().Add(-48*time.Hour),
) )
env.sweeper.ExportSetInterval(time.Millisecond) env.sweeper.ExportSetInterval(time.Millisecond)
@@ -940,7 +930,7 @@ func TestArchiveSweeper_StopHookHonoursStopTimeout(
) { ) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) env := setupSweeperTest(t)
lc := &recordingLifecycle{} lc := &recordingLifecycle{}
env.sweeper.ExportRegisterHooks(lc) env.sweeper.ExportRegisterHooks(lc)
-61
View File
@@ -114,64 +114,3 @@ func TestUpdateDeliveryStatus_DeletedDeliveryIsNotCounted(t *testing.T) {
assert.Equal(t, database.TargetTotals{TargetID: targetID}, assert.Equal(t, database.TargetTotals{TargetID: targetID},
targetTotals(t, db, targetID)) targetTotals(t, db, targetID))
} }
// TestUpdateDeliveryStatus_FinishedDeliveryIsNotSettledAgain covers a
// delivery settled a second time, as recovery can do when a worker has
// settled it since recovery read it. Neither status writes over the
// first, and the totals do not move.
func TestUpdateDeliveryStatus_FinishedDeliveryIsNotSettledAgain(
t *testing.T,
) {
t.Parallel()
finished := []database.DeliveryStatus{
database.DeliveryStatusDelivered,
database.DeliveryStatusFailed,
}
for _, first := range finished {
t.Run(string(first), func(t *testing.T) {
t.Parallel()
db := testWebhookDB(t)
e := testEngine(t, 1)
event := seedEvent(t, db, `{}`)
targetID := uuid.New().String()
d := seedDelivery(
t, db, event.ID, targetID,
database.DeliveryStatusRetrying,
)
// The delivery as recovery read it, before the worker
// settled it.
readBefore := d
require.NoError(t, e.ExportUpdateDeliveryStatus(
db, &d, first,
))
var settled database.Delivery
require.NoError(t, db.First(&settled, "id = ?", d.ID).Error)
require.NotNil(t, settled.FinishedAt)
totals := targetTotals(t, db, targetID)
for _, again := range finished {
stale := readBefore
require.NoError(t, e.ExportUpdateDeliveryStatus(
db, &stale, again,
))
}
var stored database.Delivery
require.NoError(t, db.First(&stored, "id = ?", d.ID).Error)
assert.Equal(t, first, stored.Status)
require.NotNil(t, stored.FinishedAt)
assert.True(t, settled.FinishedAt.Equal(*stored.FinishedAt))
assert.Equal(t, totals, targetTotals(t, db, targetID))
})
}
}
+34 -90
View File
@@ -14,7 +14,6 @@ import (
"go.uber.org/fx" "go.uber.org/fx"
"gorm.io/gorm" "gorm.io/gorm"
"sneak.berlin/go/webhooker/internal/database" "sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/globals"
"sneak.berlin/go/webhooker/internal/lifecycle" "sneak.berlin/go/webhooker/internal/lifecycle"
"sneak.berlin/go/webhooker/internal/logger" "sneak.berlin/go/webhooker/internal/logger"
"sneak.berlin/go/webhooker/internal/metrics" "sneak.berlin/go/webhooker/internal/metrics"
@@ -123,24 +122,21 @@ type Notifier interface {
Notify(tasks []Task) Notify(tasks []Task)
} }
// Archives is how the handlers keep the database targets' archive // WebhookEvictor releases the delivery engine's per-webhook
// files in step with the configuration. Deleting a webhook or a // state for a webhook that no longer needs it — currently the
// target releases the cached archive writers, whose open file // cached archive writer of the database target, whose open
// handles would otherwise outlive them; renaming one renames the // file handle would otherwise outlive the webhook.
// archive files, which are named for the webhook and the target
// (see ArchiveFileName).
// //
// It is deliberately separate from Notifier: archiving lifecycle // It is deliberately separate from Notifier and deliberately
// is not notification, and a small interface keeps the handlers // one method wide: archiving lifecycle is not notification, and
// package free of any dependency on the engine's internals while // a single-method interface keeps the handlers package free of
// staying trivially fakeable in tests. // any dependency on the engine's internals while staying
// trivially fakeable in tests.
// //
// Neither eviction deletes an archive file. Both are idempotent // EvictWebhook never deletes an archive file. It is idempotent
// and are no-ops for a webhook or target with no engine state. // and is a no-op for a webhook with no engine state.
type Archives interface { type WebhookEvictor interface {
EvictWebhook(webhookID string) EvictWebhook(webhookID string)
EvictTarget(targetID string)
Rename(targetID, webhookName, targetName string) error
} }
// EngineParams are the fx dependencies for the delivery // EngineParams are the fx dependencies for the delivery
@@ -150,10 +146,8 @@ type EngineParams struct {
DB *database.Database DB *database.Database
DBManager *database.WebhookDBManager DBManager *database.WebhookDBManager
Globals *globals.Globals
Logger *logger.Logger Logger *logger.Logger
SSRFGuard *Guard SSRFGuard *Guard
Metrics *metrics.Set
} }
// Engine processes queued deliveries in the background // Engine processes queued deliveries in the background
@@ -173,14 +167,10 @@ type Engine struct {
retryCh chan Task retryCh chan Task
workers int workers int
// version is the running build's version, the one the web UI // mtr is the delivery metric set. Production wires the
// footer shows. userAgent puts it on every outbound request. // process-wide one; a test can substitute a set registered on
version string // a private registry so its assertions are not disturbed by
// deliveries other tests are making at the same time.
// mtr is the delivery metric set. Production wires the one
// registered on the registry /metrics serves; a test can
// substitute a set registered on a registry it holds, so it can
// gather what its own deliveries recorded.
mtr *metrics.Set mtr *metrics.Set
// targets maps each target type to its implementation. // targets maps each target type to its implementation.
@@ -191,7 +181,7 @@ type Engine struct {
httpTarget *httpTarget httpTarget *httpTarget
// dbTarget is retained so the engine can reach the archive // dbTarget is retained so the engine can reach the archive
// writer registry for eviction, renames and the idle sweep. // writer registry for webhook eviction and the idle sweep.
dbTarget *databaseTarget dbTarget *databaseTarget
// inflight is the set of deliveries this engine currently owns. // inflight is the set of deliveries this engine currently owns.
@@ -214,8 +204,7 @@ func New(
deliveryCh: make(chan Task, deliveryChannelSize), deliveryCh: make(chan Task, deliveryChannelSize),
retryCh: make(chan Task, retryChannelSize), retryCh: make(chan Task, retryChannelSize),
workers: defaultWorkers, workers: defaultWorkers,
version: params.Globals.Version, mtr: metrics.Default(),
mtr: params.Metrics,
} }
e.initTargets(&http.Client{ e.initTargets(&http.Client{
@@ -260,44 +249,17 @@ func (e *Engine) Notify(tasks []Task) {
} }
} }
// EvictWebhook implements Archives. The cached archive writer of // EvictWebhook implements WebhookEvictor. It releases the
// every database target of the webhook is dropped from the // engine's per-webhook archiving state: the database target's
// registry and its file handle closed. The archive files // cached archive writer is dropped from the registry and its
// themselves are left on disk — they are long-term storage the // file handle closed. The archive file itself is left on disk
// operator owns. // — it is long-term storage the operator owns.
func (e *Engine) EvictWebhook(webhookID string) { func (e *Engine) EvictWebhook(webhookID string) {
if e.dbTarget == nil { if e.dbTarget == nil {
return return
} }
e.dbTarget.evictWebhook(webhookID) e.dbTarget.evict(webhookID)
}
// EvictTarget implements Archives. It is EvictWebhook for a single
// database target, and leaves the archive file on disk the same
// way.
func (e *Engine) EvictTarget(targetID string) {
if e.dbTarget == nil {
return
}
e.dbTarget.evict(targetID)
}
// Rename implements Archives. It renames a database target's
// archive file to ArchiveFileName(webhookName, targetName,
// targetID), under the lock the target's archive writes and the
// idle sweep take. It never replaces a file: if one already has the
// new name, the error is ErrArchiveNameTaken. The caller renames
// before it saves the new name: see databaseTarget.rename.
func (e *Engine) Rename(
targetID, webhookName, targetName string,
) error {
if e.dbTarget == nil {
return nil
}
return e.dbTarget.rename(targetID, webhookName, targetName)
} }
// ScheduleRetry schedules a task to be re-enqueued onto the // ScheduleRetry schedules a task to be re-enqueued onto the
@@ -338,13 +300,6 @@ func (e *Engine) ScheduleRetry(
}) })
} }
// userAgent is the User-Agent header of every http and slack
// delivery request: the program name and the running build's
// version.
func (e *Engine) userAgent() string {
return "webhooker/" + e.version
}
// registerHooks wires the engine's start and stop into the fx // registerHooks wires the engine's start and stop into the fx
// lifecycle. The start hook's context is deliberately ignored // lifecycle. The start hook's context is deliberately ignored
// (see start for why the worker pool must not inherit it); the // (see start for why the worker pool must not inherit it); the
@@ -411,8 +366,7 @@ func (e *Engine) start() {
// Once the pool has drained it closes the archive writers, so a // Once the pool has drained it closes the archive writers, so a
// clean stop leaves no archive -wal behind. Nothing else holds a // clean stop leaves no archive -wal behind. Nothing else holds a
// writer for long by then: the archive sweeper stops before the // writer for long by then: the archive sweeper stops before the
// engine, and deleting or renaming a webhook or target only closes // engine, and deleting a webhook only closes one. If the pool did
// or moves one. If the pool did
// not drain in time, the writers are left open, as a kill would // not drain in time, the writers are left open, as a kill would
// leave them. Closing them would wait for any write in progress, // leave them. Closing them would wait for any write in progress,
// and a worker still running would then open new writers that // and a worker still running would then open new writers that
@@ -577,11 +531,6 @@ func (e *Engine) processRetryTask(
return return
} }
// Set before anything below can fail the delivery: the failure is
// added to this target's totals.
d.EventID = task.EventID
d.TargetID = task.TargetID
if d.Status != database.DeliveryStatusRetrying { if d.Status != database.DeliveryStatusRetrying {
e.log.Debug( e.log.Debug(
"skipping retry for delivery "+ "skipping retry for delivery "+
@@ -613,6 +562,8 @@ func (e *Engine) processRetryTask(
} }
target := buildTargetFromTask(task) target := buildTargetFromTask(task)
d.EventID = task.EventID
d.TargetID = task.TargetID
d.Event = event d.Event = event
d.Target = target d.Target = target
@@ -1626,11 +1577,9 @@ func (e *Engine) updateDeliveryStatus(
// writeDeliveryStatus writes a delivery's new status. A delivery that // writeDeliveryStatus writes a delivery's new status. A delivery that
// becomes delivered or failed also gets the time it finished, and is // becomes delivered or failed also gets the time it finished, and is
// added to its target's delivered or failed total. That write changes // added to its target's delivered or failed total. It is counted only
// only a delivery not yet delivered or failed, and the total moves // if the row was still there to update: retention may have deleted it
// only when it changed a row: retention may have deleted the delivery // while the engine was working on it.
// while the engine was working on it, and a recovery path may settle
// a delivery that a worker has already settled.
func writeDeliveryStatus( func writeDeliveryStatus(
tx *gorm.DB, tx *gorm.DB,
d *database.Delivery, d *database.Delivery,
@@ -1640,15 +1589,10 @@ func writeDeliveryStatus(
return tx.Model(d).Update("status", status).Error return tx.Model(d).Update("status", status).Error
} }
res := tx.Model(d). res := tx.Model(d).Updates(map[string]any{
Where("status NOT IN ?", []database.DeliveryStatus{ "status": status,
database.DeliveryStatusDelivered, "finished_at": time.Now(),
database.DeliveryStatusFailed, })
}).
Updates(map[string]any{
"status": status,
"finished_at": time.Now(),
})
if res.Error != nil || res.RowsAffected == 0 { if res.Error != nil || res.RowsAffected == 0 {
return res.Error return res.Error
} }
+10 -23
View File
@@ -2,6 +2,7 @@ package delivery_test
import ( import (
"context" "context"
"fmt"
"path/filepath" "path/filepath"
"testing" "testing"
"time" "time"
@@ -9,7 +10,6 @@ import (
"github.com/google/uuid" "github.com/google/uuid"
"github.com/stretchr/testify/require" "github.com/stretchr/testify/require"
"go.uber.org/fx" "go.uber.org/fx"
"gorm.io/gorm/clause"
"sneak.berlin/go/webhooker/internal/database" "sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/delivery" "sneak.berlin/go/webhooker/internal/delivery"
) )
@@ -272,35 +272,22 @@ func TestEngine_StopHookHonoursStopTimeout(t *testing.T) {
requireStopHookExpires(t, lc.hooks[0], "delivery engine") requireStopHookExpires(t, lc.hooks[0], "delivery engine")
} }
// deliverToArchive gives the setup's webhook a database target, // deliverToArchive runs one delivery to a database target through
// runs one delivery to it through the running engine, and returns // the running engine and returns the webhook's archive file path.
// the target's ID and archive file path. The archive writer holds // The archive writer holds the file open afterwards.
// the file open afterwards. func deliverToArchive(t *testing.T, s iSetup) string {
func deliverToArchive(t *testing.T, s iSetup) (string, string) {
t.Helper() t.Helper()
iCreateWebhook(t, s.MainDB, s.WebhookID, "hook")
tgt := &database.Target{
WebhookID: s.WebhookID,
Name: "archive",
Type: database.TargetTypeDatabase,
}
require.NoError(
t, s.MainDB.Omit(clause.Associations).Create(tgt).Error,
)
deliveryID, task := seedLogTask(t, s) deliveryID, task := seedLogTask(t, s)
task.TargetID = tgt.ID
task.TargetType = database.TargetTypeDatabase task.TargetType = database.TargetTypeDatabase
s.Engine.Notify([]delivery.Task{task}) s.Engine.Notify([]delivery.Task{task})
iWaitForDelivered(t, s.WebhookDB, deliveryID) iWaitForDelivered(t, s.WebhookDB, deliveryID)
return tgt.ID, filepath.Join( return filepath.Join(
filepath.Dir(s.DBMgr.DBPath(s.WebhookID)), filepath.Dir(s.DBMgr.DBPath(s.WebhookID)),
"archive-hook-archive-"+tgt.ID+".db", fmt.Sprintf("archive-%s.db", s.WebhookID),
) )
} }
@@ -317,7 +304,7 @@ func TestEngine_StopHookClosesArchives(t *testing.T) {
lc := startEngineViaHook(t, s.Engine) lc := startEngineViaHook(t, s.Engine)
_, path := deliverToArchive(t, s) path := deliverToArchive(t, s)
require.FileExists( require.FileExists(
t, path+"-wal", t, path+"-wal",
"an open archive should have a -wal for the stop to remove", "an open archive should have a -wal for the stop to remove",
@@ -351,7 +338,7 @@ func TestEngine_StopHookTimeoutLeavesArchivesOpen(t *testing.T) {
lc := startEngineViaHook(t, s.Engine) lc := startEngineViaHook(t, s.Engine)
targetID, _ := deliverToArchive(t, s) deliverToArchive(t, s)
release := make(chan struct{}) release := make(chan struct{})
@@ -365,7 +352,7 @@ func TestEngine_StopHookTimeoutLeavesArchivesOpen(t *testing.T) {
requireStopHookExpires(t, lc.hooks[0], "delivery engine") requireStopHookExpires(t, lc.hooks[0], "delivery engine")
require.True( require.True(
t, s.Engine.ExportArchiveHandleOpen(targetID), t, s.Engine.ExportArchiveHandleOpen(s.WebhookID),
"a stop that timed out must not close archive writers", "a stop that timed out must not close archive writers",
) )
} }
+34 -17
View File
@@ -351,15 +351,23 @@ func TestDeliverDatabase_ImmediateSuccess(
db := testWebhookDB(t) db := testWebhookDB(t)
// The database target archives for real, so the engine needs // The database target archives for real now, so the engine
// the target in the main database and a data directory. // needs a webhook DB manager to locate the data directory.
env := setupArchiveTest(t) e := delivery.NewTestEngineWithDB(
tgt := env.seedDatabaseTarget(t, "") nil,
database.NewTestWebhookDBManager(t.TempDir()),
slog.New(slog.NewTextHandler(
os.Stderr,
&slog.HandlerOptions{Level: slog.LevelDebug},
)),
&http.Client{Timeout: 5 * time.Second},
1,
)
event := seedEvent(t, db, `{"db":"target"}`) event := seedEvent(t, db, `{"db":"target"}`)
d := seedDatabaseTargetDelivery(t, db, event, tgt) d := seedDatabaseTargetDelivery(t, db, event, "")
env.eng.ExportDeliverDatabase(db, d) e.ExportDeliverDatabase(db, d)
var updated database.Delivery var updated database.Delivery
@@ -1239,6 +1247,11 @@ func TestDoHTTPRequest_ForwardsHeaders(t *testing.T) {
testContentType, testContentType,
receivedHeaders.Get("Content-Type"), receivedHeaders.Get("Content-Type"),
) )
assert.Equal(t,
"webhooker/1.0",
receivedHeaders.Get("User-Agent"),
)
} }
// The event's stored inbound headers carry the same Content-Type the // The event's stored inbound headers carry the same Content-Type the
@@ -1307,7 +1320,6 @@ func TestApplyRequestHeaders_SendsOneContentType(t *testing.T) {
ContentType: tc.event, ContentType: tc.event,
}, },
cfg, cfg,
"webhooker/dev",
) )
assert.Equal(t, assert.Equal(t,
@@ -1324,27 +1336,32 @@ func TestProcessDelivery_RoutesToCorrectHandler(
db := testWebhookDB(t) db := testWebhookDB(t)
// The database target archives for real, so the engine needs // The database target archives for real now, so the engine
// the target in the main database and a data directory. // needs a webhook DB manager to locate the data directory.
env := setupArchiveTest(t) e := delivery.NewTestEngineWithDB(
archive := env.seedDatabaseTarget(t, "") nil,
database.NewTestWebhookDBManager(t.TempDir()),
slog.New(slog.NewTextHandler(
os.Stderr,
&slog.HandlerOptions{Level: slog.LevelDebug},
)),
&http.Client{Timeout: 5 * time.Second},
1,
)
tests := []struct { tests := []struct {
name string name string
targetType database.TargetType targetType database.TargetType
targetID string
wantStatus database.DeliveryStatus wantStatus database.DeliveryStatus
}{ }{
{ {
"database target", "database target",
database.TargetTypeDatabase, database.TargetTypeDatabase,
archive.ID,
database.DeliveryStatusDelivered, database.DeliveryStatusDelivered,
}, },
{ {
"log target", "log target",
database.TargetTypeLog, database.TargetTypeLog,
uuid.New().String(),
database.DeliveryStatusDelivered, database.DeliveryStatusDelivered,
}, },
} }
@@ -1354,7 +1371,7 @@ func TestProcessDelivery_RoutesToCorrectHandler(
t.Parallel() t.Parallel()
runRoutingSubtest( runRoutingSubtest(
t, db, env.eng, tt.targetType, tt.targetID, t, db, e, tt.targetType,
tt.wantStatus, tt.wantStatus,
) )
}) })
@@ -1366,7 +1383,6 @@ func runRoutingSubtest(
db *gorm.DB, db *gorm.DB,
e *delivery.Engine, e *delivery.Engine,
targetType database.TargetType, targetType database.TargetType,
targetID string,
wantStatus database.DeliveryStatus, wantStatus database.DeliveryStatus,
) { ) {
t.Helper() t.Helper()
@@ -1374,7 +1390,8 @@ func runRoutingSubtest(
event := seedEvent(t, db, `{"routing":"test"}`) event := seedEvent(t, db, `{"routing":"test"}`)
dlv := seedDelivery( dlv := seedDelivery(
t, db, event.ID, targetID, t, db, event.ID,
uuid.New().String(),
database.DeliveryStatusPending, database.DeliveryStatusPending,
) )
+31 -38
View File
@@ -9,7 +9,6 @@ import (
"net/url" "net/url"
"time" "time"
"github.com/prometheus/client_golang/prometheus"
"go.uber.org/fx" "go.uber.org/fx"
"gorm.io/gorm" "gorm.io/gorm"
"sneak.berlin/go/webhooker/internal/database" "sneak.berlin/go/webhooker/internal/database"
@@ -41,6 +40,11 @@ const (
ExportPendingSweepMinAge = pendingSweepMinAge ExportPendingSweepMinAge = pendingSweepMinAge
) )
// ExportIsBlockedIP exposes isBlockedIP for testing.
func ExportIsBlockedIP(ip net.IP) bool {
return isBlockedIP(ip)
}
// NewTestGuard builds an SSRF Guard from an explicit egress // NewTestGuard builds an SSRF Guard from an explicit egress
// allowlist, without going through config. Passing no prefixes // allowlist, without going through config. Passing no prefixes
// yields the default guard, which blocks every private/reserved // yields the default guard, which blocks every private/reserved
@@ -66,11 +70,6 @@ func ExportBlockedNetworks() []*net.IPNet {
return blockedNetworks return blockedNetworks
} }
// ExportBlockedPublicNetworks exposes blockedPublicNetworks.
func ExportBlockedPublicNetworks() []*net.IPNet {
return blockedPublicNetworks
}
// ExportIsForwardableHeader exposes isForwardableHeader. // ExportIsForwardableHeader exposes isForwardableHeader.
func ExportIsForwardableHeader(name string) bool { func ExportIsForwardableHeader(name string) bool {
return isForwardableHeader(name) return isForwardableHeader(name)
@@ -83,9 +82,8 @@ func ExportApplyRequestHeaders(
req *http.Request, req *http.Request,
event *database.Event, event *database.Event,
cfg *HTTPTargetConfig, cfg *HTTPTargetConfig,
userAgent string,
) []string { ) []string {
return applyRequestHeaders(req, event, cfg, userAgent) return applyRequestHeaders(req, event, cfg)
} }
// ExportTruncate exposes truncate for testing. // ExportTruncate exposes truncate for testing.
@@ -401,7 +399,7 @@ func NewTestEngine(
deliveryCh: make(chan Task, deliveryChannelSize), deliveryCh: make(chan Task, deliveryChannelSize),
retryCh: make(chan Task, retryChannelSize), retryCh: make(chan Task, retryChannelSize),
workers: workers, workers: workers,
mtr: metrics.New(prometheus.NewRegistry()), mtr: metrics.Default(),
} }
e.initTargets(client) e.initTargets(client)
@@ -416,7 +414,7 @@ func NewTestEngineSmallRetry(
e := &Engine{ e := &Engine{
log: log, log: log,
retryCh: make(chan Task, 1), retryCh: make(chan Task, 1),
mtr: metrics.New(prometheus.NewRegistry()), mtr: metrics.Default(),
} }
e.initTargets(nil) e.initTargets(nil)
@@ -439,7 +437,7 @@ func NewTestEngineWithDB(
deliveryCh: make(chan Task, deliveryChannelSize), deliveryCh: make(chan Task, deliveryChannelSize),
retryCh: make(chan Task, retryChannelSize), retryCh: make(chan Task, retryChannelSize),
workers: workers, workers: workers,
mtr: metrics.New(prometheus.NewRegistry()), mtr: metrics.Default(),
} }
e.initTargets(client) e.initTargets(client)
@@ -447,7 +445,8 @@ func NewTestEngineWithDB(
} }
// ExportSetMetrics substitutes the engine's metric set, so a test can // ExportSetMetrics substitutes the engine's metric set, so a test can
// assert on collectors registered on a registry it holds. // assert on collectors registered on a private registry instead of
// the process-wide ones every other test is also moving.
func (e *Engine) ExportSetMetrics(mtr *metrics.Set) { func (e *Engine) ExportSetMetrics(mtr *metrics.Set) {
e.mtr = mtr e.mtr = mtr
} }
@@ -474,7 +473,7 @@ func NewTestCircuitBreaker(
type ExportArchivedEvent = archivedEvent type ExportArchivedEvent = archivedEvent
// ExportArchiveWriter wraps an archiveWriter so black-box tests // ExportArchiveWriter wraps an archiveWriter so black-box tests
// can exercise the archive file mechanics. // can exercise the per-webhook archive file mechanics.
type ExportArchiveWriter struct { type ExportArchiveWriter struct {
w *archiveWriter w *archiveWriter
} }
@@ -549,12 +548,6 @@ func (e *ExportArchiveWriter) Evict() {
e.w.evict() e.w.evict()
} }
// Rename gives the archive file a new name in the same directory,
// as a rename of the webhook or target does.
func (e *ExportArchiveWriter) Rename(name string) error {
return e.w.rename(name)
}
// HandleOpen reports whether the writer currently holds an open // HandleOpen reports whether the writer currently holds an open
// archive handle. // archive handle.
func (e *ExportArchiveWriter) HandleOpen() bool { func (e *ExportArchiveWriter) HandleOpen() bool {
@@ -574,16 +567,16 @@ func (e *ExportArchiveWriter) Same(
} }
// ExportArchiveWriterFor returns the archive writer the registry // ExportArchiveWriterFor returns the archive writer the registry
// currently caches for a database target, or nil when none is // currently caches for a webhook, or nil when none is cached. It
// cached. It never creates one, so a test can hold a reference to // never creates one, so a test can hold a reference to the very
// the very writer an eviction is about to detach. // writer an eviction is about to detach.
func (e *Engine) ExportArchiveWriterFor( func (e *Engine) ExportArchiveWriterFor(
targetID string, webhookID string,
) *ExportArchiveWriter { ) *ExportArchiveWriter {
e.dbTarget.mu.Lock() e.dbTarget.mu.Lock()
defer e.dbTarget.mu.Unlock() defer e.dbTarget.mu.Unlock()
w, ok := e.dbTarget.writers[targetID] w, ok := e.dbTarget.writers[webhookID]
if !ok { if !ok {
return nil return nil
} }
@@ -592,26 +585,26 @@ func (e *Engine) ExportArchiveWriterFor(
} }
// ExportHasArchiveWriter reports whether the database target // ExportHasArchiveWriter reports whether the database target
// type currently caches an archive writer for a target. // currently caches an archive writer for a webhook.
func (e *Engine) ExportHasArchiveWriter( func (e *Engine) ExportHasArchiveWriter(
targetID string, webhookID string,
) bool { ) bool {
e.dbTarget.mu.Lock() e.dbTarget.mu.Lock()
defer e.dbTarget.mu.Unlock() defer e.dbTarget.mu.Unlock()
_, ok := e.dbTarget.writers[targetID] _, ok := e.dbTarget.writers[webhookID]
return ok return ok
} }
// ExportArchiveHandleOpen reports whether the cached archive // ExportArchiveHandleOpen reports whether the cached archive
// writer for a target holds an open database handle. It // writer for a webhook holds an open database handle. It
// returns false when no writer is cached. // returns false when no writer is cached.
func (e *Engine) ExportArchiveHandleOpen( func (e *Engine) ExportArchiveHandleOpen(
targetID string, webhookID string,
) bool { ) bool {
e.dbTarget.mu.Lock() e.dbTarget.mu.Lock()
w, ok := e.dbTarget.writers[targetID] w, ok := e.dbTarget.writers[webhookID]
e.dbTarget.mu.Unlock() e.dbTarget.mu.Unlock()
if !ok { if !ok {
@@ -625,12 +618,12 @@ func (e *Engine) ExportArchiveHandleOpen(
} }
// ExportEnsureArchiveWriter creates (if needed) and returns the // ExportEnsureArchiveWriter creates (if needed) and returns the
// archive file path of the cached writer for a target, so a // archive file path of the cached writer for a webhook, so a
// test can prime the registry the way a delivery would. // test can prime the registry the way a delivery would.
func (e *Engine) ExportEnsureArchiveWriter( func (e *Engine) ExportEnsureArchiveWriter(
targetID string, webhookID string,
) (string, error) { ) (string, error) {
w, err := e.dbTarget.writerFor(targetID) w, err := e.dbTarget.writerFor(webhookID)
if err != nil { if err != nil {
return "", err return "", err
} }
@@ -638,14 +631,14 @@ func (e *Engine) ExportEnsureArchiveWriter(
return w.path, nil return w.path, nil
} }
// ExportSweepWriterFor takes a target's registry writer exactly // ExportSweepWriterFor takes a webhook's registry writer exactly
// as the idle sweep does, reporting whether the sweep had to // as the idle sweep does, reporting whether the sweep had to
// create the entry. It lets a test drive the registry through the // create the entry. It lets a test drive the registry through the
// sweep's own entry point instead of choreographing goroutines. // sweep's own entry point instead of choreographing goroutines.
func (e *Engine) ExportSweepWriterFor( func (e *Engine) ExportSweepWriterFor(
targetID string, webhookID string,
) (*ExportArchiveWriter, bool, error) { ) (*ExportArchiveWriter, bool, error) {
w, created, err := e.dbTarget.sweepWriterFor(targetID) w, created, err := e.dbTarget.sweepWriterFor(webhookID)
if err != nil { if err != nil {
return nil, false, err return nil, false, err
} }
@@ -656,9 +649,9 @@ func (e *Engine) ExportSweepWriterFor(
// ExportReleaseSweepWriter releases a sweep-created registry entry // ExportReleaseSweepWriter releases a sweep-created registry entry
// exactly as a finished sweep does. // exactly as a finished sweep does.
func (e *Engine) ExportReleaseSweepWriter( func (e *Engine) ExportReleaseSweepWriter(
targetID string, w *ExportArchiveWriter, webhookID string, w *ExportArchiveWriter,
) { ) {
e.dbTarget.releaseSweepWriter(targetID, w.w) e.dbTarget.releaseSweepWriter(webhookID, w.w)
} }
// NewTestArchiveSweeper builds an ArchiveSweeper backed by the // NewTestArchiveSweeper builds an ArchiveSweeper backed by the
+3 -2
View File
@@ -35,8 +35,9 @@ const (
) )
// mIsolate gives the setup's engine a metric set registered on a // mIsolate gives the setup's engine a metric set registered on a
// registry this test holds, so its exact assertions can gather from // private registry. The process-wide collectors are moved by every
// it. // other delivery test running in parallel, so exact assertions are
// only possible against a registry this test owns.
func mIsolate( func mIsolate(
t *testing.T, s iSetup, t *testing.T, s iSetup,
) *prometheus.Registry { ) *prometheus.Registry {
-1
View File
@@ -375,7 +375,6 @@ func TestApplyRequestHeaders_ReportsOriginScopedNames(t *testing.T) {
"Content-Type": testContentType, "Content-Type": testContentType,
}, },
}, },
"webhooker/dev",
) )
assert.Equal(t, assert.Equal(t,
+32 -104
View File
@@ -25,64 +25,36 @@ var (
errNoIPs = errors.New( errNoIPs = errors.New(
"hostname resolved to no IP addresses", "hostname resolved to no IP addresses",
) )
// ErrBlockedPrivateOrReservedIP reports an address in the errBlockedIP = errors.New(
// default blocklist's private and reserved ranges, "blocked private, reserved or cloud metadata address",
// blockedNetworks.
ErrBlockedPrivateOrReservedIP = errors.New(
"blocked private or reserved address",
)
// errBlockedPublicMetadata reports a public address on the
// default blocklist, one in blockedPublicNetworks.
errBlockedPublicMetadata = errors.New(
"blocked cloud metadata address",
) )
errBlockedMetadata = errors.New( errBlockedMetadata = errors.New(
"blocked link-local, cloud instance metadata or " + "blocked link-local or cloud instance metadata " +
"unspecified address: ALLOWED_EGRESS_CIDRS cannot open it", "address: ALLOWED_EGRESS_CIDRS cannot open it",
) )
errInvalidScheme = errors.New( errInvalidScheme = errors.New(
"only http and https are allowed", "only http and https are allowed",
) )
) )
// blockedNetworks and blockedPublicNetworks together are the // blockedNetworks is the default blocklist: the private and
// default blocklist: the private and reserved IP ranges, plus // reserved IP ranges, plus the public cloud metadata addresses,
// the public cloud metadata addresses, that are blocked to // that are blocked to prevent SSRF attacks. An operator can
// prevent SSRF attacks. An operator can permit specific blocks // permit specific blocks out of this set with
// out of this set with ALLOWED_EGRESS_CIDRS; see Guard. // ALLOWED_EGRESS_CIDRS; see Guard.
//
// blockedNetworks holds the private and reserved IP ranges.
// //
//nolint:gochecknoglobals // package-level network list is appropriate here //nolint:gochecknoglobals // package-level network list is appropriate here
var blockedNetworks []*net.IPNet var blockedNetworks []*net.IPNet
// blockedPublicNetworks holds the default blocklist's public
// addresses, kept apart from blockedNetworks so that they are
// refused as cloud metadata addresses, never as private or
// reserved ones.
//
// A public address belongs on the default blocklist only if it
// hands credentials, user data or bootstrap material to whatever
// can reach it, without the caller presenting anything; it goes
// in this list. A provider's other public addresses are not
// refused, since reaching them can be legitimate and no list of
// them could be complete.
//
//nolint:gochecknoglobals // package-level network list is appropriate here
var blockedPublicNetworks []*net.IPNet
// alwaysBlockedNetworks are the ranges no configuration can // alwaysBlockedNetworks are the ranges no configuration can
// open, so a supplied CIDR that covers one still leaves it // open: the link-local blocks and the cloud instance metadata
// blocked. An entry is here for one of two reasons: it is a // endpoints that live outside them. Reaching one is credential
// metadata endpoint (the link-local blocks and the cloud // or user-data theft rather than delivery to an internal
// instance metadata endpoints that live outside them), or it is // service, so a supplied CIDR that covers such an address still
// an unspecified address. Reaching a metadata endpoint is // leaves it blocked.
// credential or user-data theft rather than delivery to an
// internal service.
// //
// Inclusion criterion for metadata endpoints — one belongs here // Inclusion criterion — an address belongs here only if BOTH
// only if BOTH hold, and every metadata entry below satisfies // hold, and every entry below satisfies both:
// both:
// //
// 1. It is a fixed address assigned by the provider, or a // 1. It is a fixed address assigned by the provider, or a
// range reserved by IANA — never one the operator chose. // range reserved by IANA — never one the operator chose.
@@ -93,8 +65,8 @@ var blockedPublicNetworks []*net.IPNet
// not cheaply rotated. // not cheaply rotated.
// //
// Both halves are load-bearing, so use them to refuse a // Both halves are load-bearing, so use them to refuse a
// metadata candidate and say why. An endpoint disclosing only // candidate and say why. An endpoint disclosing only the
// the operator's own inventory (instance id, region, disks, NICs) // operator's own inventory (instance id, region, disks, NICs)
// fails (2): letting a delivery target reach the operator's own // fails (2): letting a delivery target reach the operator's own
// infrastructure is the feature ALLOWED_EGRESS_CIDRS exists to // infrastructure is the feature ALLOWED_EGRESS_CIDRS exists to
// provide. But (2) is not "IAM credentials only" either — // provide. But (2) is not "IAM credentials only" either —
@@ -109,21 +81,12 @@ var blockedPublicNetworks []*net.IPNet
// when it clears both halves. Nothing in this list can be // when it clears both halves. Nothing in this list can be
// reopened, so putting a public address here leaves the operator // reopened, so putting a public address here leaves the operator
// no escape hatch at all — the condition ALLOWED_EGRESS_CIDRS // no escape hatch at all — the condition ALLOWED_EGRESS_CIDRS
// exists to remove. Default-block it in blockedPublicNetworks // exists to remove. Default-block it in blockedNetworks instead,
// instead, which an allowlist can override. // which an allowlist can override.
// //
// This is a criterion, not an enumeration of every metadata // This is a criterion, not an enumeration of every metadata
// address in existence. // address in existence.
// //
// The unspecified addresses 0.0.0.0 and :: are here for a
// separate reason: they disclose nothing, but no host can have
// either, and on Linux a connection to one reaches this host's
// own loopback. Listing them means an allowlist reaches loopback
// only through an entry that covers a loopback address
// (127.0.0.0/8, ::1/128, 0.0.0.0/0), never through one that
// covers only 0.0.0.0 or :: (0.0.0.0/8, for example). Nothing
// else lives at either address, so refusing them costs nothing.
//
// Every entry is either already in blockedNetworks — this list is // Every entry is either already in blockedNetworks — this list is
// what makes it unconditional — or an alternate encoding of // what makes it unconditional — or an alternate encoding of
// 169.254.169.254 that Contains does not match against // 169.254.169.254 that Contains does not match against
@@ -143,49 +106,23 @@ var alwaysBlockedNetworks []*net.IPNet
//nolint:gochecknoinits // init is the idiomatic way to parse CIDRs once at startup //nolint:gochecknoinits // init is the idiomatic way to parse CIDRs once at startup
func init() { func init() {
blockedNetworks = mustParseCIDRs([]string{ blockedNetworks = mustParseCIDRs([]string{
// IPv4 loopback.
"127.0.0.0/8", "127.0.0.0/8",
// RFC 1918 private network.
"10.0.0.0/8", "10.0.0.0/8",
// RFC 1918 private network.
"172.16.0.0/12", "172.16.0.0/12",
// RFC 1918 private network.
"192.168.0.0/16", "192.168.0.0/16",
// IPv4 link-local.
"169.254.0.0/16", "169.254.0.0/16",
// "This network", holding the IPv4 unspecified address 0.0.0.0.
"0.0.0.0/8", "0.0.0.0/8",
// Carrier-grade NAT shared address space.
"100.64.0.0/10", "100.64.0.0/10",
// IETF protocol assignments.
"192.0.0.0/24", "192.0.0.0/24",
// IPv4 documentation (TEST-NET-1).
"192.0.2.0/24", "192.0.2.0/24",
// Benchmarking.
"198.18.0.0/15", "198.18.0.0/15",
// IPv4 documentation (TEST-NET-2).
"198.51.100.0/24", "198.51.100.0/24",
// IPv4 documentation (TEST-NET-3).
"203.0.113.0/24", "203.0.113.0/24",
// IPv4 multicast.
"224.0.0.0/4", "224.0.0.0/4",
// Reserved, including the broadcast address.
"240.0.0.0/4", "240.0.0.0/4",
// IPv6 loopback.
"::1/128", "::1/128",
// IPv6 unspecified address.
"::/128",
// IPv6 unique local addresses.
"fc00::/7", "fc00::/7",
// IPv6 link-local.
"fe80::/10", "fe80::/10",
// IPv6 multicast.
"ff00::/8",
// IPv6 documentation.
"2001:db8::/32",
})
blockedPublicNetworks = mustParseCIDRs([]string{
// Azure WireServer, a public address that serves VM credentials. // Azure WireServer, a public address that serves VM credentials.
"168.63.129.16/32", "168.63.129.16/32",
}) })
@@ -242,14 +179,6 @@ func init() {
// allowlist from opening it. // allowlist from opening it.
"192.0.0.192/32", "192.0.0.192/32",
// The unspecified addresses, each of which reaches this
// host's loopback on Linux.
//
// IPv4 unspecified address, inside the blocked 0.0.0.0/8.
"0.0.0.0/32",
// IPv6 unspecified address.
"::/128",
// 169.254.169.254 as an IPv4-compatible IPv6 address. // 169.254.169.254 as an IPv4-compatible IPv6 address.
"::a9fe:a9fe/128", "::a9fe:a9fe/128",
// 169.254.169.254 behind the NAT64 well-known prefix. // 169.254.169.254 behind the NAT64 well-known prefix.
@@ -289,6 +218,13 @@ func matchesAny(networks []*net.IPNet, ip net.IP) bool {
return false return false
} }
// isBlockedIP checks whether an IP address falls within
// the default blocklist, before any operator allowlist is
// considered.
func isBlockedIP(ip net.IP) bool {
return matchesAny(blockedNetworks, ip)
}
// Guard makes every SSRF decision in the process. // Guard makes every SSRF decision in the process.
// //
// It holds the operator's ALLOWED_EGRESS_CIDRS allowlist and // It holds the operator's ALLOWED_EGRESS_CIDRS allowlist and
@@ -386,12 +322,10 @@ func (g *Guard) allows(ip net.IP) bool {
// The order is the policy: // The order is the policy:
// //
// 1. alwaysBlockedNetworks is refused before the allowlist is // 1. alwaysBlockedNetworks is refused before the allowlist is
// consulted, so no configured CIDR reaches link-local, a // consulted, so no configured CIDR reaches link-local or a
// cloud metadata endpoint at a non-public address, or an // cloud metadata endpoint at a non-public address.
// unspecified address.
// 2. The allowlist is consulted next, so a listed private // 2. The allowlist is consulted next, so a listed private
// network, or a listed public address on the default // network becomes reachable.
// blocklist, becomes reachable.
// 3. Everything else keeps the default blocklist's answer. // 3. Everything else keeps the default blocklist's answer.
func (g *Guard) checkIP(ip net.IP) error { func (g *Guard) checkIP(ip net.IP) error {
if matchesAny(alwaysBlockedNetworks, ip) { if matchesAny(alwaysBlockedNetworks, ip) {
@@ -404,15 +338,9 @@ func (g *Guard) checkIP(ip net.IP) error {
return nil return nil
} }
if matchesAny(blockedNetworks, ip) { if isBlockedIP(ip) {
return fmt.Errorf( return fmt.Errorf(
"target IP %s: %w", ip, ErrBlockedPrivateOrReservedIP, "target IP %s: %w", ip, errBlockedIP,
)
}
if matchesAny(blockedPublicNetworks, ip) {
return fmt.Errorf(
"target IP %s: %w", ip, errBlockedPublicMetadata,
) )
} }
+12 -131
View File
@@ -23,10 +23,6 @@ const (
metadataIP = "169.254.169.254" metadataIP = "169.254.169.254"
metadataURL = "http://" + metadataIP + "/latest/meta-data/" metadataURL = "http://" + metadataIP + "/latest/meta-data/"
// linkLocalIPv4 is the IPv4 link-local block, which holds
// metadataIP.
linkLocalIPv4 = "169.254.0.0/16"
// loopbackHookURL is a target on this host: blocked by // loopbackHookURL is a target on this host: blocked by
// default, reachable only once an operator allowlists // default, reachable only once an operator allowlists
// loopback. // loopback.
@@ -168,13 +164,12 @@ func TestGuardAllowlist_UnlistedPrivateStillRefused(t *testing.T) {
// TestGuardAllowlist_MetadataAlwaysRefused is the load-bearing // TestGuardAllowlist_MetadataAlwaysRefused is the load-bearing
// case: cloud instance metadata endpoints are credential theft // case: cloud instance metadata endpoints are credential theft
// rather than delivery to an internal service, and the // rather than delivery to an internal service, so no allowlist
// unspecified addresses 0.0.0.0 and :: reach this host's loopback // reaches one. Every guard below names a CIDR that covers its
// on Linux, so no allowlist reaches any of them. Every guard // target — including 0.0.0.0/0, ::/0, and the ordinary ULA and
// below names a CIDR that covers its target — including // CGNAT blocks an operator would really list — and the address
// 0.0.0.0/0, ::/0, and the ordinary ULA and CGNAT blocks an // must stay refused anyway, on both the validation and the
// operator would really list — and the address must stay // delivery path.
// refused anyway, on both the validation and the delivery path.
func TestGuardAllowlist_MetadataAlwaysRefused(t *testing.T) { func TestGuardAllowlist_MetadataAlwaysRefused(t *testing.T) {
t.Parallel() t.Parallel()
@@ -220,17 +215,15 @@ type metadataAlwaysRefusedCase struct {
} }
// metadataAlwaysRefusedCases enumerates every unconditionally // metadataAlwaysRefusedCases enumerates every unconditionally
// blocked address (link-local, the cloud metadata endpoints and // blocked address together with an allowlist entry that would
// the unspecified addresses) together with an allowlist entry // otherwise reach it. Split by family of address only to stay
// that would otherwise reach it. Split by family of address only // under the function-length limit.
// to stay under the function-length limit.
func metadataAlwaysRefusedCases() []metadataAlwaysRefusedCase { func metadataAlwaysRefusedCases() []metadataAlwaysRefusedCase {
cases := linkLocalRefusedCases() cases := linkLocalRefusedCases()
cases = append(cases, ulaMetadataRefusedCases()...) cases = append(cases, ulaMetadataRefusedCases()...)
cases = append(cases, ipv4MetadataRefusedCases()...) cases = append(cases, ipv4MetadataRefusedCases()...)
cases = append(cases, encodedMetadataRefusedCases()...)
return append(cases, unspecifiedRefusedCases()...) return append(cases, encodedMetadataRefusedCases()...)
} }
// linkLocalRefusedCases covers the link-local blocks, including // linkLocalRefusedCases covers the link-local blocks, including
@@ -244,7 +237,7 @@ func linkLocalRefusedCases() []metadataAlwaysRefusedCase {
}, },
{ {
name: "whole link-local block", name: "whole link-local block",
allow: linkLocalIPv4, allow: "169.254.0.0/16",
target: metadataURL, target: metadataURL,
}, },
{ {
@@ -370,23 +363,6 @@ func encodedMetadataRefusedCases() []metadataAlwaysRefusedCase {
} }
} }
// unspecifiedRefusedCases covers the unspecified addresses, each
// of which reaches this host's loopback on Linux.
func unspecifiedRefusedCases() []metadataAlwaysRefusedCase {
return []metadataAlwaysRefusedCase{
{
name: "IPv4 unspecified address under 0.0.0.0/0",
allow: allowAllIPv4,
target: "http://0.0.0.0:8080/hook",
},
{
name: "IPv6 unspecified address under ::/0",
allow: allowAllIPv6,
target: "http://[::]:8080/hook",
},
}
}
// TestGuardAllowlist_PublicUnaffected asserts the allowlist does // TestGuardAllowlist_PublicUnaffected asserts the allowlist does
// not narrow anything: public addresses were reachable before it // not narrow anything: public addresses were reachable before it
// existed and stay reachable, whether or not a list is set. // existed and stay reachable, whether or not a list is set.
@@ -436,9 +412,6 @@ func TestGuardAllowlist_AzureWireServerReopenable(t *testing.T) {
"WireServer must be refused by the default blocklist, "+ "WireServer must be refused by the default blocklist, "+
"which an allowlist can override", "which an allowlist can override",
) )
require.NotErrorIs(t, err, delivery.ErrBlockedPrivateOrReservedIP,
"WireServer is public, not private or reserved",
)
assertDialRefused(t, defaultGuard, target) assertDialRefused(t, defaultGuard, target)
@@ -523,7 +496,7 @@ func TestAlwaysBlockedNetworks_PinnedSet(t *testing.T) {
want := []string{ want := []string{
// IPv4 link-local: the 169.254.169.254 metadata // IPv4 link-local: the 169.254.169.254 metadata
// service on AWS, Azure and others. // service on AWS, Azure and others.
linkLocalIPv4, "169.254.0.0/16",
// IPv6 link-local. // IPv6 link-local.
"fe80::/10", "fe80::/10",
// AWS IPv6 IMDS, inside the ULA space an operator may // AWS IPv6 IMDS, inside the ULA space an operator may
@@ -544,10 +517,6 @@ func TestAlwaysBlockedNetworks_PinnedSet(t *testing.T) {
// Oracle Cloud Classic metadata, inside the blocked // Oracle Cloud Classic metadata, inside the blocked
// 192.0.0.0/24. // 192.0.0.0/24.
"192.0.0.192/32", "192.0.0.192/32",
// The IPv4 and IPv6 unspecified addresses, each of
// which reaches this host's loopback on Linux.
"0.0.0.0/32",
"::/128",
// 169.254.169.254 as an IPv4-compatible IPv6 address. // 169.254.169.254 as an IPv4-compatible IPv6 address.
"::a9fe:a9fe/128", "::a9fe:a9fe/128",
// 169.254.169.254 behind the NAT64 well-known prefix. // 169.254.169.254 behind the NAT64 well-known prefix.
@@ -557,94 +526,6 @@ func TestAlwaysBlockedNetworks_PinnedSet(t *testing.T) {
assert.Equal(t, want, got) assert.Equal(t, want, got)
} }
// TestDefaultBlocklist_PinnedSet pins each list of the default
// blocklist on its own, the private and reserved ranges in
// blockedNetworks and the public addresses in
// blockedPublicNetworks, so moving an entry from one list to the
// other fails it. For the first address of each entry it then
// checks that the default guard refuses it, and that listing the
// entry in ALLOWED_EGRESS_CIDRS opens it unless the unconditional
// set holds that address.
func TestDefaultBlocklist_PinnedSet(t *testing.T) {
t.Parallel()
// public marks an entry of blockedPublicNetworks; every other
// entry belongs in blockedNetworks.
tests := []struct {
cidr string
public bool
reopenable bool
}{
{cidr: "127.0.0.0/8", reopenable: true},
{cidr: "10.0.0.0/8", reopenable: true},
{cidr: "172.16.0.0/12", reopenable: true},
{cidr: "192.168.0.0/16", reopenable: true},
{cidr: linkLocalIPv4, reopenable: false},
// Its first address, 0.0.0.0, is in the unconditional set.
{cidr: "0.0.0.0/8", reopenable: false},
{cidr: "100.64.0.0/10", reopenable: true},
{cidr: "192.0.0.0/24", reopenable: true},
{cidr: "192.0.2.0/24", reopenable: true},
{cidr: "198.18.0.0/15", reopenable: true},
{cidr: "198.51.100.0/24", reopenable: true},
{cidr: "203.0.113.0/24", reopenable: true},
{cidr: "224.0.0.0/4", reopenable: true},
{cidr: "240.0.0.0/4", reopenable: true},
{cidr: "::1/128", reopenable: true},
{cidr: "::/128", reopenable: false},
{cidr: "fc00::/7", reopenable: true},
{cidr: "fe80::/10", reopenable: false},
{cidr: "ff00::/8", reopenable: true},
{cidr: "2001:db8::/32", reopenable: true},
{cidr: "168.63.129.16/32", public: true, reopenable: true},
}
wantPrivate := make([]string, 0, len(tests))
wantPublic := make([]string, 0, len(tests))
for _, tt := range tests {
if tt.public {
wantPublic = append(wantPublic, tt.cidr)
} else {
wantPrivate = append(wantPrivate, tt.cidr)
}
}
gotPrivate := make([]string, 0, len(tests))
for _, n := range delivery.ExportBlockedNetworks() {
gotPrivate = append(gotPrivate, n.String())
}
gotPublic := make([]string, 0, len(tests))
for _, n := range delivery.ExportBlockedPublicNetworks() {
gotPublic = append(gotPublic, n.String())
}
assert.ElementsMatch(t, wantPrivate, gotPrivate, "blockedNetworks")
assert.ElementsMatch(t, wantPublic, gotPublic, "blockedPublicNetworks")
for _, tt := range tests {
t.Run(tt.cidr, func(t *testing.T) {
t.Parallel()
prefix := netip.MustParsePrefix(tt.cidr)
ip := net.IP(prefix.Addr().AsSlice())
require.Error(t,
delivery.NewTestGuard().ExportCheckIP(ip),
"the default guard must refuse %s", ip,
)
err := delivery.NewTestGuard(prefix).ExportCheckIP(ip)
if tt.reopenable {
assert.NoError(t, err, "listing %s must open it", tt.cidr)
} else {
assert.Error(t, err, "listing %s must not open it", tt.cidr)
}
})
}
}
// requireLoopback fails the test unless rawURL's host is a // requireLoopback fails the test unless rawURL's host is a
// loopback address, so the allowlist test cannot silently stop // loopback address, so the allowlist test cannot silently stop
// exercising a blocked range. // exercising a blocked range.
+4 -42
View File
@@ -10,7 +10,7 @@ import (
"sneak.berlin/go/webhooker/internal/delivery" "sneak.berlin/go/webhooker/internal/delivery"
) )
func TestGuardCheckIP_PrivateRanges(t *testing.T) { func TestIsBlockedIP_PrivateRanges(t *testing.T) {
t.Parallel() t.Parallel()
tests := []struct { tests := []struct {
@@ -56,14 +56,12 @@ func TestGuardCheckIP_PrivateRanges(t *testing.T) {
"failed to parse IP %s", tt.ip, "failed to parse IP %s", tt.ip,
) )
refused := delivery.NewTestGuard().ExportCheckIP(ip) != nil
assert.Equal(t, assert.Equal(t,
tt.blocked, tt.blocked,
refused, delivery.ExportIsBlockedIP(ip),
"default guard refuses %s = %v, want %v", "isBlockedIP(%s) = %v, want %v",
tt.ip, tt.ip,
refused, delivery.ExportIsBlockedIP(ip),
tt.blocked, tt.blocked,
) )
}) })
@@ -101,42 +99,6 @@ func TestValidateTargetURL_Blocked(t *testing.T) {
} }
} }
// TestDefaultGuard_RefusesUnspecifiedMulticastAndDocumentation
// covers the unspecified addresses and the IPv6 multicast and
// documentation ranges: with no allowlist set, each is refused
// both when a target is created and when a delivery dials it.
func TestDefaultGuard_RefusesUnspecifiedMulticastAndDocumentation(
t *testing.T,
) {
t.Parallel()
guard := delivery.NewTestGuard()
targets := []string{
// The unspecified addresses. On Linux a connection to
// either reaches this host's loopback.
"http://0.0.0.0:8080/hook",
"http://[::]:8080/hook",
// IPv6 multicast, all nodes.
"http://[ff02::1]/hook",
// IPv6 documentation.
"http://[2001:db8::1]/hook",
}
for _, target := range targets {
t.Run(target, func(t *testing.T) {
t.Parallel()
require.Error(t,
guard.ValidateTargetURL(context.Background(), target),
"%s must be refused at target creation", target,
)
assertDialRefused(t, guard, target)
})
}
}
func TestValidateTargetURL_Allowed(t *testing.T) { func TestValidateTargetURL_Allowed(t *testing.T) {
t.Parallel() t.Parallel()
+93 -200
View File
@@ -4,7 +4,6 @@ import (
"context" "context"
"fmt" "fmt"
"path/filepath" "path/filepath"
"strings"
"sync" "sync"
"time" "time"
@@ -12,75 +11,22 @@ import (
"sneak.berlin/go/webhooker/internal/database" "sneak.berlin/go/webhooker/internal/database"
) )
// archiveNameMaxLen is how many characters of a webhook or target // databaseTarget is a no-retry target that archives the
// name an archive file name keeps. // full inbound event into a per-webhook archive SQLite file,
const archiveNameMaxLen = 40 // separate from the per-webhook event database. The event is
// already persisted in the per-webhook event DB by the time
// databaseTarget is a no-retry target that archives the full // delivery runs; the database target additionally writes a
// inbound event into the target's own archive SQLite file, separate // durable long-term copy into archive-{webhookID}.db and then
// from the per-webhook event database. The event is already // records a single attempt whose outcome reflects whether the
// persisted in the per-webhook event DB by the time delivery runs; // archive write succeeded. See archiveWriter for the
// the database target additionally writes a durable long-term copy // close/reopen, auto-recreate, and expiry semantics.
// into the file ArchiveFileName names and then records a single
// attempt whose outcome reflects whether the archive write
// succeeded. See archiveWriter for the close/reopen, auto-recreate,
// and expiry semantics.
type databaseTarget struct { type databaseTarget struct {
eng *Engine eng *Engine
// writers holds one archive writer per database target, keyed
// by target ID.
mu sync.Mutex mu sync.Mutex
writers map[string]*archiveWriter writers map[string]*archiveWriter
} }
// ArchiveFileName returns the file name of a database target's
// archive: archive-WEBHOOKNAME-TARGETNAME-TARGETID.db, with both
// names passed through archiveNamePart. The target ID keeps the
// name unique when two targets' names come out the same.
func ArchiveFileName(webhookName, targetName, targetID string) string {
return "archive-" + archiveNamePart(webhookName) + "-" +
archiveNamePart(targetName) + "-" + targetID + ".db"
}
// archiveNamePart makes a webhook or target name safe to put in a
// file name. It is lowercased; ASCII letters and digits are kept,
// every other run of characters becomes a single "-", and no "-" is
// left at either end. It is cut to archiveNameMaxLen characters, and
// a name with nothing left is "unnamed".
func archiveNamePart(name string) string {
var b strings.Builder
dash := false
for _, r := range strings.ToLower(name) {
if (r < 'a' || r > 'z') && (r < '0' || r > '9') {
dash = b.Len() > 0
continue
}
if dash {
b.WriteByte('-')
dash = false
}
b.WriteRune(r)
}
part := b.String()
if len(part) > archiveNameMaxLen {
part = strings.TrimRight(part[:archiveNameMaxLen], "-")
}
if part == "" {
return "unnamed"
}
return part
}
// Deliver implements Target. It archives the event, then // Deliver implements Target. It archives the event, then
// records one successful attempt and marks the delivery // records one successful attempt and marks the delivery
// delivered. An archiving error fails the delivery: the // delivered. An archiving error fails the delivery: the
@@ -146,7 +92,7 @@ func (t *databaseTarget) Deliver(
) )
} }
// archive writes the full event as a row into the target's // archive writes the full event as a row into the webhook's
// archive database, honouring the optional per-target expiry // archive database, honouring the optional per-target expiry
// parsed from the target config JSON. // parsed from the target config JSON.
func (t *databaseTarget) archive(d *database.Delivery) error { func (t *databaseTarget) archive(d *database.Delivery) error {
@@ -160,7 +106,7 @@ func (t *databaseTarget) archive(d *database.Delivery) error {
return err return err
} }
w, err := t.writerFor(d.TargetID) w, err := t.writerFor(webhookID)
if err != nil { if err != nil {
return err return err
} }
@@ -178,31 +124,30 @@ func (t *databaseTarget) archive(d *database.Delivery) error {
return w.write(row, expiry) return w.write(row, expiry)
} }
// writerFor returns the archive writer for a database target, // writerFor returns the archiveWriter for a webhook, creating
// creating and caching it on first use. Each target has one writer // and caching it on first use. Each webhook has one writer so
// so its close/reopen debounce state is shared across concurrent // its close/reopen debounce state is shared across concurrent
// deliveries, and so a rename and the idle sweep take the same lock // deliveries. The archive file lives beside the per-webhook
// as its writes. // event database in the data directory.
func (t *databaseTarget) writerFor( func (t *databaseTarget) writerFor(
targetID string, webhookID string,
) (*archiveWriter, error) { ) (*archiveWriter, error) {
path, err := t.archivePath(webhookID)
if err != nil {
return nil, err
}
t.mu.Lock() t.mu.Lock()
defer t.mu.Unlock() defer t.mu.Unlock()
w, ok := t.writers[targetID] if t.writers == nil {
t.writers = make(map[string]*archiveWriter)
}
w, ok := t.writers[webhookID]
if !ok { if !ok {
var err error w = newArchiveWriter(path, t.eng.log)
t.writers[webhookID] = w
w, err = t.newWriter(targetID)
if err != nil {
return nil, err
}
if t.writers == nil {
t.writers = make(map[string]*archiveWriter)
}
t.writers[targetID] = w
} }
// A delivery claims the entry: even if the idle sweep created // A delivery claims the entry: even if the idle sweep created
@@ -214,39 +159,40 @@ func (t *databaseTarget) writerFor(
} }
// sweepWriterFor returns the archive writer the idle sweep should // sweepWriterFor returns the archive writer the idle sweep should
// prune a target's archive through, together with whether the sweep // prune a webhook through, together with whether the sweep itself
// itself created the registry entry. // created the registry entry.
// //
// The sweep must route its prune through the registered writer so // The sweep must route its prune through the registered writer so
// the writer's mutex orders it against concurrent writes, but it // the writer's mutex orders it against concurrent writes, but it
// must never leave a registry entry behind: a sweep that ran // must never leave a registry entry behind: a sweep that ran
// concurrently with the target's deletion would otherwise // concurrently with the webhook's deletion would otherwise
// re-create an entry that nothing will ever evict again, which is // re-create an entry that nothing will ever evict again, which is
// exactly the leak eviction exists to prevent. An entry the sweep // exactly the leak eviction exists to prevent. An entry the sweep
// creates is therefore marked sweep-owned and handed back to // creates is therefore marked sweep-owned and handed back to
// releaseSweepWriter when the sweep is done. // releaseSweepWriter when the sweep is done.
func (t *databaseTarget) sweepWriterFor( func (t *databaseTarget) sweepWriterFor(
targetID string, webhookID string,
) (*archiveWriter, bool, error) { ) (*archiveWriter, bool, error) {
t.mu.Lock() path, err := t.archivePath(webhookID)
defer t.mu.Unlock()
w, ok := t.writers[targetID]
if ok {
return w, false, nil
}
w, err := t.newWriter(targetID)
if err != nil { if err != nil {
return nil, false, err return nil, false, err
} }
t.mu.Lock()
defer t.mu.Unlock()
if t.writers == nil { if t.writers == nil {
t.writers = make(map[string]*archiveWriter) t.writers = make(map[string]*archiveWriter)
} }
w, ok := t.writers[webhookID]
if ok {
return w, false, nil
}
w = newArchiveWriter(path, t.eng.log)
w.sweepOwned = true w.sweepOwned = true
t.writers[targetID] = w t.writers[webhookID] = w
return w, true, nil return w, true, nil
} }
@@ -263,95 +209,57 @@ func (t *databaseTarget) sweepWriterFor(
// delivery that adopted the writer keeps a registered, evictable // delivery that adopted the writer keeps a registered, evictable
// one. // one.
func (t *databaseTarget) releaseSweepWriter( func (t *databaseTarget) releaseSweepWriter(
targetID string, w *archiveWriter, webhookID string, w *archiveWriter,
) { ) {
t.mu.Lock() t.mu.Lock()
defer t.mu.Unlock() defer t.mu.Unlock()
cur, ok := t.writers[targetID] cur, ok := t.writers[webhookID]
if !ok || cur != w || !cur.sweepOwned { if !ok || cur != w || !cur.sweepOwned {
return return
} }
delete(t.writers, targetID) delete(t.writers, webhookID)
} }
// newWriter builds the writer for a database target's archive. The // archivePath returns the archive file path for a webhook: it
// file lives beside the webhook's event database in the data // lives beside the per-webhook event database in the data
// directory and is named for the webhook and the target as the main // directory. It does not touch the filesystem.
// database has them now; from then on only rename changes the name func (t *databaseTarget) archivePath(
// the writer uses. It does not touch the archive file. webhookID string,
func (t *databaseTarget) newWriter( ) (string, error) {
targetID string,
) (*archiveWriter, error) {
if t.eng.dbManager == nil { if t.eng.dbManager == nil {
return nil, errArchiveNoDataDir return "", errArchiveNoDataDir
} }
var target database.Target dir := filepath.Dir(t.eng.dbManager.DBPath(webhookID))
err := t.eng.database.DB(). return filepath.Join(
Preload("Webhook"). dir, fmt.Sprintf("archive-%s.db", webhookID),
First(&target, "id = ?", targetID).Error ), nil
if err != nil {
return nil, fmt.Errorf(
"loading database target %s: %w", targetID, err,
)
}
dir := filepath.Dir(t.eng.dbManager.DBPath(target.WebhookID))
name := ArchiveFileName(
target.Webhook.Name, target.Name, target.ID,
)
w := newArchiveWriter(filepath.Join(dir, name), t.eng.log)
w.webhookID = target.WebhookID
return w, nil
} }
// rename moves a database target's archive file to the name for // evict drops a webhook's archive writer from the registry and
// webhookName and targetName. It goes through the target's writer, // closes its handle, so a deleted webhook does not leave a
// so the move holds the lock that writes and the idle sweep take, // writer (and an open archive handle within its debounce
// and later writes use the new name. // window) alive for the process lifetime.
//
// The writer is created if there is none, and it stays cached. The
// handlers rename before they save the new name, so until the save
// the main database still has the old one; a delivery in that window
// must find this writer rather than build one from the old name.
func (t *databaseTarget) rename(
targetID, webhookName, targetName string,
) error {
w, err := t.writerFor(targetID)
if err != nil {
return err
}
return w.rename(ArchiveFileName(webhookName, targetName, targetID))
}
// evict drops a database target's archive writer from the registry
// and closes its handle, so a deleted target does not leave a
// writer (and an open archive handle within its debounce window)
// alive for the process lifetime.
// //
// The map entry is removed under the registry lock, which is // The map entry is removed under the registry lock, which is
// then released before the handle is closed under the writer's // then released before the handle is closed under the writer's
// own lock: that ordering keeps the registry available to other // own lock: that ordering keeps the registry available to other
// targets while an in-flight write on this one drains, and // webhooks while an in-flight write on this one drains, and
// closing under the writer's lock means eviction can never race // closing under the writer's lock means eviction can never race
// a write. // a write.
// //
// Eviction is idempotent and silent for a target with no writer, // Eviction is idempotent and silent for a webhook with no
// which is the common case: only a database target that has // writer, which is the common case: a webhook with no database
// received an event or been renamed has one. It never deletes the // target never creates one. It never deletes the archive file.
// archive file. func (t *databaseTarget) evict(webhookID string) {
func (t *databaseTarget) evict(targetID string) {
t.mu.Lock() t.mu.Lock()
w, ok := t.writers[targetID] w, ok := t.writers[webhookID]
if ok { if ok {
delete(t.writers, targetID) delete(t.writers, webhookID)
} }
t.mu.Unlock() t.mu.Unlock()
@@ -364,41 +272,13 @@ func (t *databaseTarget) evict(targetID string) {
t.eng.log.Info( t.eng.log.Info(
"evicted archive writer", "evicted archive writer",
"target_id", targetID, "webhook_id", webhookID,
"path", w.path, "path", w.path,
) )
} }
// evictWebhook evicts, exactly as evict does, the writer of every
// database target of a webhook.
func (t *databaseTarget) evictWebhook(webhookID string) {
t.mu.Lock()
var gone []*archiveWriter
for targetID, w := range t.writers {
if w.webhookID == webhookID {
delete(t.writers, targetID)
gone = append(gone, w)
}
}
t.mu.Unlock()
for _, w := range gone {
w.evict()
t.eng.log.Info(
"evicted archive writer",
"webhook_id", webhookID,
"path", w.path,
)
}
}
// evictAll evicts every cached archive writer, exactly as evict // evictAll evicts every cached archive writer, exactly as evict
// does for one target. The engine calls it at shutdown, once its // does for one webhook. The engine calls it at shutdown, once its
// workers have returned. Closing the last handle on an archive // workers have returned. Closing the last handle on an archive
// moves the contents of its -wal into the .db and removes the // moves the contents of its -wal into the .db and removes the
// -wal, so a clean stop leaves each archive as a single file. // -wal, so a clean stop leaves each archive as a single file.
@@ -415,25 +295,38 @@ func (t *databaseTarget) evictAll() {
} }
} }
// sweepArchive prunes one database target's archive of rows older // sweepWebhook prunes one webhook's archive of rows older than
// than expiry, without requiring a write. A missing archive file is // expiry, without requiring a write. It returns nil (nothing to
// left missing (see sweepExpired), so a sweep never creates an // do) when the archive file does not exist, so a sweep never
// archive for a target that has never received an event. // creates an archive for a webhook that has a database target
// but has never received an event.
// //
// It also never leaves a registry entry behind: an entry it had // It also never leaves a registry entry behind: an entry it had
// to create to reach the writer's mutex is released again once // to create to reach the writer's mutex is released again once
// the prune is done, so a sweep racing a target deletion cannot // the prune is done, so a sweep racing a webhook deletion cannot
// resurrect the writer the eviction just dropped. // resurrect the writer the eviction just dropped.
func (t *databaseTarget) sweepArchive( func (t *databaseTarget) sweepWebhook(
targetID string, expiry time.Duration, webhookID string, expiry time.Duration,
) error { ) error {
w, created, err := t.sweepWriterFor(targetID) path, err := t.archivePath(webhookID)
if err != nil {
return err
}
// Check before taking a writer at all: a webhook whose
// archive has never been created gets no writer, no handle,
// and no file.
if !fileExists(path) {
return nil
}
w, created, err := t.sweepWriterFor(webhookID)
if err != nil { if err != nil {
return err return err
} }
if created { if created {
defer t.releaseSweepWriter(targetID, w) defer t.releaseSweepWriter(webhookID, w)
} }
return w.sweepExpired(expiry) return w.sweepExpired(expiry)
+17 -97
View File
@@ -4,10 +4,8 @@ import (
"encoding/json" "encoding/json"
"errors" "errors"
"fmt" "fmt"
"io/fs"
"log/slog" "log/slog"
"os" "os"
"path/filepath"
"sync" "sync"
"time" "time"
@@ -43,7 +41,7 @@ const (
var ( var (
// errArchiveMissingWebhookID is returned when an event to // errArchiveMissingWebhookID is returned when an event to
// archive has no webhook id to record in its archive row. // archive has no webhook id to key its archive file on.
errArchiveMissingWebhookID = errors.New( errArchiveMissingWebhookID = errors.New(
"cannot archive event without a webhook id", "cannot archive event without a webhook id",
) )
@@ -63,19 +61,13 @@ var (
) )
// errArchiveWriterEvicted is returned when a writer that has // errArchiveWriterEvicted is returned when a writer that has
// been evicted (its target or its webhook was deleted) is used // been evicted (its webhook was deleted, or its last database
// again. An evicted writer is no longer in the registry, so // target was removed) is used again. An evicted writer is no
// reopening its file would leak a handle nothing owns. // longer in the registry, so reopening its file would leak a
// handle nothing owns.
errArchiveWriterEvicted = errors.New( errArchiveWriterEvicted = errors.New(
"archive writer has been evicted", "archive writer has been evicted",
) )
// ErrArchiveNameTaken is returned when an archive cannot be
// renamed because a file already has the new name. That file may
// be an archive with rows of its own, so it is never replaced.
ErrArchiveNameTaken = errors.New(
"a file already has the archive's new name",
)
) )
// databaseTargetConfig is the optional per-target JSON config // databaseTargetConfig is the optional per-target JSON config
@@ -88,7 +80,7 @@ type databaseTargetConfig struct {
} }
// archivedEvent is one fully captured webhook event stored in a // archivedEvent is one fully captured webhook event stored in a
// database target's archive for long-term retention. It is a // per-webhook archive database for long-term retention. It is a
// self-contained copy — independent of the per-webhook event // self-contained copy — independent of the per-webhook event
// database, which may prune events under its own retention. // database, which may prune events under its own retention.
type archivedEvent struct { type archivedEvent struct {
@@ -178,8 +170,8 @@ func ValidateArchiveExpiry(expiry string) error {
return nil return nil
} }
// archiveWriter owns one database target's archive SQLite file. // archiveWriter owns one per-webhook archive SQLite file. It
// It serialises writes, and after each write closes and reopens // serialises writes, and after each write closes and reopens
// the file (debounced to at most once per debounce window) so // the file (debounced to at most once per debounce window) so
// an operator can move the file away for offline archiving. The // an operator can move the file away for offline archiving. The
// next write recreates a moved or removed file, because the // next write recreates a moved or removed file, because the
@@ -195,21 +187,16 @@ type archiveWriter struct {
reopens int reopens int
// evicted marks a writer that has been removed from the // evicted marks a writer that has been removed from the
// registry. Its handle is closed and it must never open the // per-webhook registry. Its handle is closed and it must
// file again: nothing holds it any more, so a reopen would // never open the file again: nothing holds it any more, so a
// leak the handle for the process lifetime. // reopen would leak the handle for the process lifetime.
evicted bool evicted bool
// webhookID is the webhook the archive's target belongs to,
// so deleting the webhook can find its writers. It is set
// when the writer is created and never changes.
webhookID string
// sweepOwned marks a registry entry that the idle sweep // sweepOwned marks a registry entry that the idle sweep
// created because no writer was cached for the target. The // created because no writer was cached for the webhook. The
// sweep removes such an entry again when it is done, so a // sweep removes such an entry again when it is done, so a
// sweep can never leave — or resurrect — a registry entry // sweep can never leave — or resurrect — a registry entry
// for a target that has been deleted. A delivery that adopts // for a webhook that has been deleted. A delivery that adopts
// the writer clears the flag, handing the entry to the // the writer clears the flag, handing the entry to the
// registry proper. // registry proper.
// //
@@ -398,78 +385,11 @@ func (w *archiveWriter) sweepExpired(expiry time.Duration) error {
return nil return nil
} }
// rename gives the archive file a new name in the same directory,
// and the writer uses the file under that name from now on. The
// handle is closed first, which folds the -wal into the .db; any
// -wal or -shm still beside the file (left by a crash) is moved with
// it, because SQLite finds them by name. A missing file is not an
// error: the operator may have moved it away, and the next write
// creates it under the new name.
//
// If a file already has the new name, nothing is moved and the
// error is ErrArchiveNameTaken. If one file fails to move, those
// already moved are moved back before the error is returned, so the
// archive is never split across two names.
func (w *archiveWriter) rename(name string) error {
w.mu.Lock()
defer w.mu.Unlock()
if w.evicted {
return fmt.Errorf(
"%w: %s", errArchiveWriterEvicted, w.path,
)
}
path := filepath.Join(filepath.Dir(w.path), name)
if path == w.path {
return nil
}
suffixes := []string{"", "-wal", "-shm"}
for _, suffix := range suffixes {
if fileExists(path + suffix) {
return fmt.Errorf(
"%w: %s", ErrArchiveNameTaken, name+suffix,
)
}
}
w.close()
for i, suffix := range suffixes {
err := os.Rename(w.path+suffix, path+suffix)
if err == nil || errors.Is(err, fs.ErrNotExist) {
continue
}
for _, moved := range suffixes[:i] {
backErr := os.Rename(path+moved, w.path+moved)
if backErr != nil && !errors.Is(backErr, fs.ErrNotExist) {
w.log.Error(
"failed to move archive file back",
"from", path+moved,
"to", w.path+moved,
"error", backErr,
)
}
}
return fmt.Errorf(
"renaming archive %s to %s: %w", w.path+suffix, path+suffix, err,
)
}
w.path = path
return nil
}
// evict closes the writer's handle and marks it unusable. It is // evict closes the writer's handle and marks it unusable. It is
// called when the writer leaves the registry, because its target // called when the writer leaves the registry, either because the
// or its webhook was deleted, or at shutdown. The archive FILE is // webhook was deleted or because its last database target was
// deliberately left on disk: it is long-term storage an operator // removed. The archive FILE is deliberately left on disk: it is
// may still want. // long-term storage an operator may still want.
func (w *archiveWriter) evict() { func (w *archiveWriter) evict() {
w.mu.Lock() w.mu.Lock()
defer w.mu.Unlock() defer w.mu.Unlock()
+82 -92
View File
@@ -17,109 +17,85 @@ import (
"sneak.berlin/go/webhooker/internal/delivery" "sneak.berlin/go/webhooker/internal/delivery"
) )
// deliverTo archives one event to a database target, leaving the // evictTestEngine builds an engine backed by a temporary data
// target's writer cached with its handle open. // directory and returns it along with that directory.
func deliverTo( func evictTestEngine(t *testing.T) (*delivery.Engine, string) {
t *testing.T, env *archiveEnv, tgt *database.Target,
) {
t.Helper() t.Helper()
webhookDB := testWebhookDB(t) dataDir := t.TempDir()
event := seedEvent(t, webhookDB, `{"archived":true}`)
env.eng.ExportDeliverDatabase( eng := delivery.NewTestEngineWithDB(
webhookDB, seedDatabaseTargetDelivery(t, webhookDB, event, tgt), nil,
database.NewTestWebhookDBManager(dataDir),
archiveTestLogger(),
&http.Client{Timeout: 5 * time.Second},
1,
) )
return eng, dataDir
} }
// TestEvictWebhook_ClosesAndRemovesWriter proves that evicting // TestEvictWebhook_ClosesAndRemovesWriter proves that evicting
// a webhook drops the archive writers of its database targets // a webhook drops its archive writer from the registry and
// from the registry and closes their open handles, rather than // closes the open archive handle, rather than leaving both
// leaving them alive for the process lifetime, and leaves another // alive for the process lifetime.
// webhook's writer alone.
func TestEvictWebhook_ClosesAndRemovesWriter(t *testing.T) { func TestEvictWebhook_ClosesAndRemovesWriter(t *testing.T) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) eng, dataDir := evictTestEngine(t)
first := env.seedDatabaseTarget(t, "")
second := env.addDatabaseTarget(t, first.WebhookID, "")
other := env.seedDatabaseTarget(t, "")
for _, tgt := range []*database.Target{first, second, other} { webhookDB := testWebhookDB(t)
deliverTo(t, env, tgt) event := seedEvent(t, webhookDB, `{"archived":true}`)
d := seedDatabaseTargetDelivery(t, webhookDB, event, "")
require.True( eng.ExportDeliverDatabase(webhookDB, d)
t, env.eng.ExportArchiveHandleOpen(tgt.ID),
"the writer should hold an open handle after a write",
)
}
env.eng.EvictWebhook(first.WebhookID) webhookID := event.WebhookID
for _, tgt := range []*database.Target{first, second} { require.True(
assert.False( t, eng.ExportHasArchiveWriter(webhookID),
t, env.eng.ExportHasArchiveWriter(tgt.ID), "a delivery should have cached an archive writer",
"eviction should remove the registry entry", )
) require.True(
assert.False( t, eng.ExportArchiveHandleOpen(webhookID),
t, env.eng.ExportArchiveHandleOpen(tgt.ID), "the writer should hold an open handle after a write",
"eviction should close the archive handle",
)
assert.FileExists(
t, env.archivePath(tgt),
"eviction must not delete the archive file",
)
}
assert.True(
t, env.eng.ExportArchiveHandleOpen(other.ID),
"another webhook's writer must be left alone",
) )
}
// TestEvictTarget_LeavesOtherTargets proves that evicting one eng.EvictWebhook(webhookID)
// database target leaves the writer of another target of the same
// webhook in place.
func TestEvictTarget_LeavesOtherTargets(t *testing.T) {
t.Parallel()
env := setupArchiveTest(t) assert.False(
doomed := env.seedDatabaseTarget(t, "") t, eng.ExportHasArchiveWriter(webhookID),
kept := env.addDatabaseTarget(t, doomed.WebhookID, "") "eviction should remove the registry entry",
)
assert.False(
t, eng.ExportArchiveHandleOpen(webhookID),
"eviction should close the archive handle",
)
deliverTo(t, env, doomed) archivePath := filepath.Join(
deliverTo(t, env, kept) dataDir, fmt.Sprintf("archive-%s.db", webhookID),
)
env.eng.EvictTarget(doomed.ID)
assert.False(t, env.eng.ExportHasArchiveWriter(doomed.ID))
assert.FileExists( assert.FileExists(
t, env.archivePath(doomed), t, archivePath,
"eviction must not delete the archive file", "eviction must not delete the archive file",
) )
assert.True(
t, env.eng.ExportArchiveHandleOpen(kept.ID),
"the other target's writer must be left alone",
)
} }
// TestEvictWebhook_UnknownWebhookIsNoOp proves eviction is safe // TestEvictWebhook_UnknownWebhookIsNoOp proves eviction is safe
// for the common case of a webhook or target that never had an // for the common case of a webhook that never had a database
// archive writer, and that repeating it does not panic. // target, and that repeating it does not panic.
func TestEvictWebhook_UnknownWebhookIsNoOp(t *testing.T) { func TestEvictWebhook_UnknownWebhookIsNoOp(t *testing.T) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) eng, _ := evictTestEngine(t)
assert.NotPanics(t, func() { assert.NotPanics(t, func() {
env.eng.EvictWebhook("no-such-webhook") eng.EvictWebhook("no-such-webhook")
env.eng.EvictWebhook("no-such-webhook") eng.EvictWebhook("no-such-webhook")
env.eng.EvictTarget("no-such-target")
env.eng.EvictTarget("no-such-target")
}) })
assert.False( assert.False(
t, env.eng.ExportHasArchiveWriter("no-such-target"), t, eng.ExportHasArchiveWriter("no-such-webhook"),
"eviction must not create a writer", "eviction must not create a writer",
) )
} }
@@ -313,14 +289,17 @@ func TestEvictWebhook_RacingWriteDoesNotReopenHandle(
) { ) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) eng, _ := evictTestEngine(t)
tgt := env.seedDatabaseTarget(t, "")
webhookDB := testWebhookDB(t)
event := seedEvent(t, webhookDB, `{"archived":true}`)
d := seedDatabaseTargetDelivery(t, webhookDB, event, "")
// Prime the registry so the test can hold the very writer the // Prime the registry so the test can hold the very writer the
// eviction is about to detach. // eviction is about to detach.
deliverTo(t, env, tgt) eng.ExportDeliverDatabase(webhookDB, d)
w := env.eng.ExportArchiveWriterFor(tgt.ID) w := eng.ExportArchiveWriterFor(event.WebhookID)
require.NotNil(t, w) require.NotNil(t, w)
require.True(t, w.HandleOpen()) require.True(t, w.HandleOpen())
@@ -330,7 +309,7 @@ func TestEvictWebhook_RacingWriteDoesNotReopenHandle(
// eviction has to contend for the writer's mutex. // eviction has to contend for the writer's mutex.
race.awaitFirstWrite() race.awaitFirstWrite()
env.eng.EvictWebhook(tgt.WebhookID) eng.EvictWebhook(event.WebhookID)
sawEvicted, otherErr := race.wait() sawEvicted, otherErr := race.wait()
@@ -345,33 +324,41 @@ func TestEvictWebhook_RacingWriteDoesNotReopenHandle(
"been evicted", "been evicted",
) )
assert.False( assert.False(
t, env.eng.ExportHasArchiveWriter(tgt.ID), t, eng.ExportHasArchiveWriter(event.WebhookID),
"the registry entry must stay gone", "the registry entry must stay gone",
) )
} }
// TestEvictWebhook_LaterDeliveryRecreatesWriter proves eviction // TestEvictWebhook_LaterDeliveryRecreatesWriter proves eviction
// does not break archiving for a target that is still alive: a // does not break archiving for a webhook that is still alive: a
// subsequent delivery gets a brand new writer from the registry. // subsequent delivery gets a brand new writer from the registry.
// It says nothing about the evicted writer itself — that is what // It says nothing about the evicted writer itself — that is what
// TestEvictedWriter_WriteDoesNotReopenFile covers. // TestEvictedWriter_WriteDoesNotReopenFile covers.
func TestEvictWebhook_LaterDeliveryRecreatesWriter(t *testing.T) { func TestEvictWebhook_LaterDeliveryRecreatesWriter(t *testing.T) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) eng, _ := evictTestEngine(t)
tgt := env.seedDatabaseTarget(t, "")
deliverTo(t, env, tgt) webhookDB := testWebhookDB(t)
require.True(t, env.eng.ExportHasArchiveWriter(tgt.ID)) event := seedEvent(t, webhookDB, `{"archived":true}`)
d := seedDatabaseTargetDelivery(t, webhookDB, event, "")
env.eng.EvictWebhook(tgt.WebhookID) eng.ExportDeliverDatabase(webhookDB, d)
require.True(
t, eng.ExportHasArchiveWriter(event.WebhookID),
)
// A fresh delivery for the same target gets a brand new eng.EvictWebhook(event.WebhookID)
// A fresh delivery for the same webhook gets a brand new
// writer from the registry, so archiving keeps working. // writer from the registry, so archiving keeps working.
deliverTo(t, env, tgt) second := seedDatabaseTargetDelivery(
t, webhookDB, event, "",
)
eng.ExportDeliverDatabase(webhookDB, second)
assert.True( assert.True(
t, env.eng.ExportHasArchiveWriter(tgt.ID), t, eng.ExportHasArchiveWriter(event.WebhookID),
"a later delivery should recreate the writer", "a later delivery should recreate the writer",
) )
} }
@@ -383,16 +370,19 @@ func TestEvictWebhook_LaterDeliveryRecreatesWriter(t *testing.T) {
func TestEngineStop_WriteAfterStopIsRefused(t *testing.T) { func TestEngineStop_WriteAfterStopIsRefused(t *testing.T) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) eng, _ := evictTestEngine(t)
tgt := env.seedDatabaseTarget(t, "")
deliverTo(t, env, tgt) webhookDB := testWebhookDB(t)
event := seedEvent(t, webhookDB, `{"archived":true}`)
d := seedDatabaseTargetDelivery(t, webhookDB, event, "")
w := env.eng.ExportArchiveWriterFor(tgt.ID) eng.ExportDeliverDatabase(webhookDB, d)
w := eng.ExportArchiveWriterFor(event.WebhookID)
require.NotNil(t, w) require.NotNil(t, w)
require.True(t, w.HandleOpen()) require.True(t, w.HandleOpen())
require.NoError(t, env.eng.ExportStop(context.Background())) require.NoError(t, eng.ExportStop(context.Background()))
err := w.Write(evictTestRow("ev-after-stop"), 0) err := w.Write(evictTestRow("ev-after-stop"), 0)
@@ -405,7 +395,7 @@ func TestEngineStop_WriteAfterStopIsRefused(t *testing.T) {
"a refused write must not reopen the archive", "a refused write must not reopen the archive",
) )
assert.False( assert.False(
t, env.eng.ExportHasArchiveWriter(tgt.ID), t, eng.ExportHasArchiveWriter(event.WebhookID),
"the stop should empty the registry", "the stop should empty the registry",
) )
+40 -307
View File
@@ -4,12 +4,13 @@ import (
"database/sql" "database/sql"
"fmt" "fmt"
"log/slog" "log/slog"
"net/http"
"os" "os"
"path/filepath" "path/filepath"
"strings"
"testing" "testing"
"time" "time"
"github.com/google/uuid"
"github.com/stretchr/testify/assert" "github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require" "github.com/stretchr/testify/require"
"gorm.io/driver/sqlite" "gorm.io/driver/sqlite"
@@ -73,18 +74,25 @@ func removeArchiveFiles(t *testing.T, path string) {
// TestDeliverDatabase_ArchivesEvent verifies that delivering to // TestDeliverDatabase_ArchivesEvent verifies that delivering to
// a database target marks the delivery delivered and archives // a database target marks the delivery delivered and archives
// the full event into the target's own archive file. // the full event into a separate per-webhook archive file.
func TestDeliverDatabase_ArchivesEvent(t *testing.T) { func TestDeliverDatabase_ArchivesEvent(t *testing.T) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) dataDir := t.TempDir()
tgt := env.seedDatabaseTarget(t, "") dbMgr := database.NewTestWebhookDBManager(dataDir)
e := delivery.NewTestEngineWithDB(
nil, dbMgr,
archiveTestLogger(),
&http.Client{Timeout: 5 * time.Second},
1,
)
webhookDB := testWebhookDB(t) webhookDB := testWebhookDB(t)
event := seedEvent(t, webhookDB, `{"archived":true}`) event := seedEvent(t, webhookDB, `{"archived":true}`)
d := seedDatabaseTargetDelivery(t, webhookDB, event, tgt) d := seedDatabaseTargetDelivery(t, webhookDB, event, "")
env.eng.ExportDeliverDatabase(webhookDB, d) e.ExportDeliverDatabase(webhookDB, d)
var updated database.Delivery var updated database.Delivery
@@ -97,7 +105,8 @@ func TestDeliverDatabase_ArchivesEvent(t *testing.T) {
) )
archivePath := filepath.Join( archivePath := filepath.Join(
env.dataDir, "archive-sweep-test-archive-"+tgt.ID+".db", dataDir,
fmt.Sprintf("archive-%s.db", event.WebhookID),
) )
assert.FileExists(t, archivePath) assert.FileExists(t, archivePath)
@@ -279,31 +288,31 @@ func TestParseArchiveExpiry(t *testing.T) {
} }
} }
// seedDatabaseTargetDelivery seeds a pending delivery of an event // seedDatabaseTargetDelivery seeds a pending delivery for a
// to a database target and returns the in-memory delivery the // database target with the given config JSON and returns the
// target handler is invoked with. // in-memory delivery the target handler is invoked with.
func seedDatabaseTargetDelivery( func seedDatabaseTargetDelivery(
t *testing.T, t *testing.T,
webhookDB *gorm.DB, webhookDB *gorm.DB,
event database.Event, event database.Event,
tgt *database.Target, config string,
) *database.Delivery { ) *database.Delivery {
t.Helper() t.Helper()
dlv := seedDelivery( dlv := seedDelivery(
t, webhookDB, event.ID, tgt.ID, t, webhookDB, event.ID, uuid.New().String(),
database.DeliveryStatusPending, database.DeliveryStatusPending,
) )
d := &database.Delivery{ d := &database.Delivery{
EventID: event.ID, EventID: event.ID,
TargetID: tgt.ID, TargetID: dlv.TargetID,
Status: database.DeliveryStatusPending, Status: database.DeliveryStatusPending,
Event: event, Event: event,
Target: database.Target{ Target: database.Target{
Name: tgt.Name, Name: "test-db",
Type: database.TargetTypeDatabase, Type: database.TargetTypeDatabase,
Config: tgt.Config, Config: config,
}, },
} }
d.ID = dlv.ID d.ID = dlv.ID
@@ -321,14 +330,22 @@ func TestDeliverDatabase_ArchiveFailureFailsDelivery(
) { ) {
t.Parallel() t.Parallel()
env := setupArchiveTest(t) dataDir := t.TempDir()
tgt := env.seedDatabaseTarget(t, `{"expiry":"nonsense"}`)
e := delivery.NewTestEngineWithDB(
nil, database.NewTestWebhookDBManager(dataDir),
archiveTestLogger(),
&http.Client{Timeout: 5 * time.Second},
1,
)
webhookDB := testWebhookDB(t) webhookDB := testWebhookDB(t)
event := seedEvent(t, webhookDB, `{"archived":false}`) event := seedEvent(t, webhookDB, `{"archived":false}`)
d := seedDatabaseTargetDelivery(t, webhookDB, event, tgt) d := seedDatabaseTargetDelivery(
t, webhookDB, event, `{"expiry":"nonsense"}`,
)
env.eng.ExportDeliverDatabase(webhookDB, d) e.ExportDeliverDatabase(webhookDB, d)
var updated database.Delivery var updated database.Delivery
@@ -356,7 +373,10 @@ func TestDeliverDatabase_ArchiveFailureFailsDelivery(
) )
assert.NoFileExists(t, assert.NoFileExists(t,
env.archivePath(tgt), filepath.Join(
dataDir,
fmt.Sprintf("archive-%s.db", event.WebhookID),
),
"no archive file should exist for a failed config", "no archive file should exist for a failed config",
) )
} }
@@ -380,290 +400,3 @@ func TestValidateArchiveExpiry(t *testing.T) {
) )
} }
} }
// TestArchiveFileName pins the archive file name and the rules
// that make a webhook or target name safe to put in it.
func TestArchiveFileName(t *testing.T) {
t.Parallel()
const id = "3f2a1c9e-8d4b-4c1a-9e2f-0a1b2c3d4e5f"
cases := []struct {
name string
webhook string
target string
want string
}{
{
"plain names", "orders", "archive",
"archive-orders-archive-" + id + ".db",
},
{
"lowercased", "Orders", "Main Archive",
"archive-orders-main-archive-" + id + ".db",
},
{
"a run of other characters is one dash",
`a /\..b`, "c__--d",
"archive-a-b-c-d-" + id + ".db",
},
{
"no dash at either end", " --orders!! ", "(archive)",
"archive-orders-archive-" + id + ".db",
},
{
"path separators", "../../etc/passwd", "a/b",
"archive-etc-passwd-a-b-" + id + ".db",
},
{
"letters outside ASCII are dropped",
"Bestellungen Größe", "café",
"archive-bestellungen-gr-e-caf-" + id + ".db",
},
{
"nothing left is unnamed", "", "!!!",
"archive-unnamed-unnamed-" + id + ".db",
},
{
"cut to 40 characters", strings.Repeat("a", 50), "x",
"archive-" + strings.Repeat("a", 40) + "-x-" + id + ".db",
},
{
"no dash left by the cut",
strings.Repeat("a", 39) + " b", "x",
"archive-" + strings.Repeat("a", 39) + "-x-" + id + ".db",
},
}
for _, tc := range cases {
t.Run(tc.name, func(t *testing.T) {
t.Parallel()
assert.Equal(
t, tc.want,
delivery.ArchiveFileName(tc.webhook, tc.target, id),
)
})
}
}
// TestDeliverDatabase_EachTargetHasItsOwnArchive proves two
// database targets of one webhook archive into separate files.
func TestDeliverDatabase_EachTargetHasItsOwnArchive(t *testing.T) {
t.Parallel()
env := setupArchiveTest(t)
first := env.seedDatabaseTarget(t, "")
second := env.addDatabaseTarget(t, first.WebhookID, "")
webhookDB := testWebhookDB(t)
event := seedEvent(t, webhookDB, `{"n":1}`)
for _, tgt := range []*database.Target{first, second} {
env.eng.ExportDeliverDatabase(
webhookDB,
seedDatabaseTargetDelivery(t, webhookDB, event, tgt),
)
}
require.NotEqual(
t, env.archivePath(first), env.archivePath(second),
)
assert.Equal(
t, []string{event.ID},
archivedEventIDs(t, env.archivePath(first)),
)
assert.Equal(
t, []string{event.ID},
archivedEventIDs(t, env.archivePath(second)),
)
}
// TestRename_MovesTheFile proves a rename moves the archive, rows
// and all, and that later writes go to the new name.
func TestRename_MovesTheFile(t *testing.T) {
t.Parallel()
env := setupArchiveTest(t)
tgt := env.seedDatabaseTarget(t, "")
oldPath := env.archivePath(tgt)
webhookDB := testWebhookDB(t)
first := seedEvent(t, webhookDB, `{"n":1}`)
env.eng.ExportDeliverDatabase(
webhookDB, seedDatabaseTargetDelivery(t, webhookDB, first, tgt),
)
require.FileExists(t, oldPath)
require.NoError(
t, env.eng.Rename(tgt.ID, "Orders", "Long Term"),
)
newPath := filepath.Join(
env.dataDir, "archive-orders-long-term-"+tgt.ID+".db",
)
assert.NoFileExists(t, oldPath)
assert.Equal(t, []string{first.ID}, archivedEventIDs(t, newPath))
second := seedEvent(t, webhookDB, `{"n":2}`)
env.eng.ExportDeliverDatabase(
webhookDB,
seedDatabaseTargetDelivery(t, webhookDB, second, tgt),
)
assert.ElementsMatch(
t, []string{first.ID, second.ID},
archivedEventIDs(t, newPath),
)
assert.NoFileExists(
t, oldPath, "a write after the rename must use the new name",
)
}
// TestRename_NeverReplacesAFile plants a file at the new name, once
// the .db alone, once a lone -wal and once a lone -shm, and proves
// each time that the rename is refused, the planted file survives,
// and the archive keeps its name and its rows.
func TestRename_NeverReplacesAFile(t *testing.T) {
t.Parallel()
for _, suffix := range archiveFileSuffixes() {
t.Run("planted .db"+suffix, func(t *testing.T) {
t.Parallel()
env := setupArchiveTest(t)
tgt := env.seedDatabaseTarget(t, "")
oldPath := env.archivePath(tgt)
webhookDB := testWebhookDB(t)
first := seedEvent(t, webhookDB, `{"n":1}`)
env.eng.ExportDeliverDatabase(
webhookDB,
seedDatabaseTargetDelivery(t, webhookDB, first, tgt),
)
newPath := filepath.Join(
env.dataDir, "archive-orders-long-term-"+tgt.ID+".db",
)
plantedPath := newPath + suffix
require.NoError(
t, os.WriteFile(plantedPath, []byte("planted"), 0o600),
)
require.ErrorIs(
t, env.eng.Rename(tgt.ID, "Orders", "Long Term"),
delivery.ErrArchiveNameTaken,
)
//nolint:gosec // reads the file the test planted under t.TempDir()
planted, err := os.ReadFile(plantedPath)
require.NoError(t, err)
assert.Equal(t, "planted", string(planted))
second := seedEvent(t, webhookDB, `{"n":2}`)
env.eng.ExportDeliverDatabase(
webhookDB,
seedDatabaseTargetDelivery(t, webhookDB, second, tgt),
)
assert.ElementsMatch(
t, []string{first.ID, second.ID},
archivedEventIDs(t, oldPath),
)
})
}
}
// TestRename_BeforeTheNameIsSaved covers the order the handlers
// use: they rename before they save the new name, so a delivery in
// between must write under the new name although the main database
// still has the old one. It also shows that renaming an archive that
// does not exist yet is not an error.
func TestRename_BeforeTheNameIsSaved(t *testing.T) {
t.Parallel()
env := setupArchiveTest(t)
tgt := env.seedDatabaseTarget(t, "")
require.NoError(
t, env.eng.Rename(tgt.ID, "Orders", "Archive"),
)
webhookDB := testWebhookDB(t)
event := seedEvent(t, webhookDB, `{"n":1}`)
env.eng.ExportDeliverDatabase(
webhookDB, seedDatabaseTargetDelivery(t, webhookDB, event, tgt),
)
assert.FileExists(
t,
filepath.Join(
env.dataDir, "archive-orders-archive-"+tgt.ID+".db",
),
)
assert.NoFileExists(t, env.archivePath(tgt))
}
// TestArchiveWriter_RenameMovesSidecars proves a rename carries
// the -wal and -shm a crash can leave beside an archive no handle
// has opened since. SQLite finds them by name, so a -wal left
// behind would lose the transactions it holds.
func TestArchiveWriter_RenameMovesSidecars(t *testing.T) {
t.Parallel()
dir := t.TempDir()
oldPath := filepath.Join(dir, "archive-old.db")
newPath := filepath.Join(dir, "archive-new.db")
for _, suffix := range archiveFileSuffixes() {
require.NoError(
t, os.WriteFile(oldPath+suffix, []byte(suffix), 0o600),
)
}
w := delivery.NewExportArchiveWriter(
oldPath, archiveTestLogger(), 0,
)
require.NoError(t, w.Rename("archive-new.db"))
for _, suffix := range archiveFileSuffixes() {
assert.NoFileExists(t, oldPath+suffix)
assert.FileExists(t, newPath+suffix)
}
assert.Equal(t, newPath, w.Path())
}
// TestArchiveWriter_RenameMovesBackOnFailure makes the -wal fail to
// move after the .db has moved, and proves the .db is moved back, so
// the archive is never split across two names. The new name is 255
// bytes, the longest a file name may be, so the .db can take it but
// the -wal, four bytes longer, cannot.
func TestArchiveWriter_RenameMovesBackOnFailure(t *testing.T) {
t.Parallel()
dir := t.TempDir()
oldPath := filepath.Join(dir, "archive-old.db")
newName := strings.Repeat("a", 252) + ".db"
for _, suffix := range archiveFileSuffixes() {
require.NoError(
t, os.WriteFile(oldPath+suffix, []byte(suffix), 0o600),
)
}
w := delivery.NewExportArchiveWriter(
oldPath, archiveTestLogger(), 0,
)
require.Error(t, w.Rename(newName))
for _, suffix := range archiveFileSuffixes() {
assert.FileExists(t, oldPath+suffix)
}
assert.NoFileExists(t, filepath.Join(dir, newName))
assert.Equal(t, oldPath, w.Path())
}
+2 -7
View File
@@ -442,9 +442,7 @@ func (t *httpTarget) doHTTPRequest(
) )
} }
originScoped := applyRequestHeaders( originScoped := applyRequestHeaders(req, event, cfg)
req, event, cfg, t.eng.userAgent(),
)
client := t.clientForRequest(cfg, originScoped) client := t.clientForRequest(cfg, originScoped)
@@ -564,13 +562,10 @@ func isForwardableHeader(name string) bool {
// Content-Type goes out once: a Content-Type configured on the target // Content-Type goes out once: a Content-Type configured on the target
// wins, otherwise the event's ContentType, otherwise none. The inbound // wins, otherwise the event's ContentType, otherwise none. The inbound
// Content-Type in the event's headers is never forwarded. // Content-Type in the event's headers is never forwarded.
//
// userAgent is set last, over any configured or inbound User-Agent.
func applyRequestHeaders( func applyRequestHeaders(
req *http.Request, req *http.Request,
event *database.Event, event *database.Event,
cfg *HTTPTargetConfig, cfg *HTTPTargetConfig,
userAgent string,
) []string { ) []string {
if event.ContentType != "" { if event.ContentType != "" {
req.Header.Set( req.Header.Set(
@@ -585,7 +580,7 @@ func applyRequestHeaders(
originScoped[http.CanonicalHeaderKey(k)] = struct{}{} originScoped[http.CanonicalHeaderKey(k)] = struct{}{}
} }
req.Header.Set("User-Agent", userAgent) req.Header.Set("User-Agent", "webhooker/1.0")
// A Content-Type configured on the target describes the body // A Content-Type configured on the target describes the body
// being sent rather than the sender. A 307/308 preserves the // being sent rather than the sender. A 307/308 preserves the
+1 -1
View File
@@ -136,7 +136,7 @@ func (t *slackTarget) attempt(
} }
req.Header.Set("Content-Type", "application/json") req.Header.Set("Content-Type", "application/json")
req.Header.Set("User-Agent", t.eng.userAgent()) req.Header.Set("User-Agent", "webhooker/1.0")
resp, doErr := executeHTTPRequest(t.client, req) resp, doErr := executeHTTPRequest(t.client, req)
durationMs := time.Since(start).Milliseconds() durationMs := time.Since(start).Milliseconds()
-32
View File
@@ -418,38 +418,6 @@ func TestProcessRetryTask_TargetDeleted_MakesNoAttempt(
assert.Zero(t, s.Engine.ExportInflightHeld()) assert.Zero(t, s.Engine.ExportInflightHeld())
} }
// TestProcessRetryTask_TargetDeleted_CountsFailureOnTarget verifies
// that the failure of a retry abandoned because its target is gone is
// added to that target's own totals, not to a row with no target.
func TestProcessRetryTask_TargetDeleted_CountsFailureOnTarget(
t *testing.T,
) {
t.Parallel()
s := newISetup(t)
var hits atomic.Int64
task, targetID := tRetryChainSetup(
t, s, "gone-counted", &hits,
)
require.NoError(t, s.MainDB.Delete(
&database.Target{}, "id = ?", targetID,
).Error)
s.Engine.ExportProcessRetryTask(
context.Background(), &task,
)
var rows []database.TargetTotals
require.NoError(t, s.WebhookDB.Find(&rows).Error)
assert.Equal(t, []database.TargetTotals{
{TargetID: targetID, Failed: 1},
}, rows)
}
// TestProcessRetryTask_TargetPresent_StillDelivers is the guard's // TestProcessRetryTask_TargetPresent_StillDelivers is the guard's
// mutation check: a liveness check that refused every retry would pass // mutation check: a liveness check that refused every retry would pass
// the test above and break every retry there is. // the test above and break every retry there is.
-91
View File
@@ -1,91 +0,0 @@
package delivery_test
import (
"context"
"encoding/json"
"net/http"
"net/http/httptest"
"net/netip"
"testing"
"github.com/google/uuid"
"github.com/prometheus/client_golang/prometheus"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"go.uber.org/fx/fxtest"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/delivery"
"sneak.berlin/go/webhooker/internal/globals"
"sneak.berlin/go/webhooker/internal/logger"
"sneak.berlin/go/webhooker/internal/metrics"
)
// Both the http and the slack target send webhooker/ and the version
// in Globals, the value the web UI footer shows. A User-Agent
// configured on the target or carried in by the sender does not
// replace it.
func TestUserAgent_IsTheBuildVersion(t *testing.T) {
t.Parallel()
const want = "webhooker/1.2.3-test"
userAgents := make(chan string, 1)
ts := httptest.NewServer(http.HandlerFunc(
func(w http.ResponseWriter, r *http.Request) {
userAgents <- r.Header.Get("User-Agent")
w.WriteHeader(http.StatusOK)
},
))
defer ts.Close()
g := &globals.Globals{Version: "1.2.3-test"}
lc := fxtest.NewLifecycle(t)
log, err := logger.New(lc, logger.LoggerParams{Globals: g})
require.NoError(t, err)
e := delivery.New(lc, delivery.EngineParams{
Globals: g,
Logger: log,
// httptest listens on loopback, which the default guard
// refuses.
SSRFGuard: delivery.NewTestGuard(
netip.MustParsePrefix("127.0.0.0/8"),
),
Metrics: metrics.New(prometheus.NewRegistry()),
})
statusCode, _, _, err := e.ExportDoHTTPRequest(
context.Background(),
&delivery.HTTPTargetConfig{
URL: ts.URL,
Headers: map[string]string{"User-Agent": "configured/1"},
},
&database.Event{Headers: `{"User-Agent":["curl/8"]}`},
)
require.NoError(t, err)
require.Equal(t, http.StatusOK, statusCode)
require.Len(t, userAgents, 1, "the http target sent no request")
assert.Equal(t, want, <-userAgents, "http target")
db := testWebhookDB(t)
targetID := uuid.New().String()
slackCfg, err := json.Marshal(
delivery.SlackTargetConfig{WebhookURL: ts.URL},
)
require.NoError(t, err)
event := seedEvent(t, db, `{"action":"test"}`)
dlv := seedDelivery(
t, db, event.ID, targetID, database.DeliveryStatusPending,
)
e.ExportDeliverSlack(context.Background(), db, buildSlackDelivery(
dlv, event, targetID, "test-slack", string(slackCfg),
))
require.Len(t, userAgents, 1, "the slack target sent no request")
assert.Equal(t, want, <-userAgents, "slack target")
}
-4
View File
@@ -137,10 +137,6 @@ func bootAtDebug(t *testing.T, dataDir string) string {
app := fxtest.New( app := fxtest.New(
t, t,
// fx's own log is discarded, not sent to t.Logf: a hook still
// running after a start or stop timeout would write there after
// the test has returned.
fx.NopLogger,
fx.Provide( fx.Provide(
globals.New, globals.New,
logger.New, logger.New,
+1 -1
View File
@@ -7,7 +7,7 @@
// SQL — parameters and all — for every statement that returns an // SQL — parameters and all — for every statement that returns an
// error, including gorm.ErrRecordNotFound. Two of this service's // error, including gorm.ErrRecordNotFound. Two of this service's
// lookups miss by design on unauthenticated routes: the entrypoint // lookups miss by design on unauthenticated routes: the entrypoint
// lookup on /h/{uuid}, whose path segment the client picks // lookup on /webhook/{uuid}, whose path segment the client picks
// outright, and the user lookup behind the login form, whose username // outright, and the user lookup behind the login form, whose username
// the client picks outright. Under the default logger each of those // the client picks outright. Under the default logger each of those
// misses printed an unbounded, attacker-chosen string, at no level the // misses printed an unbounded, attacker-chosen string, at no level the
+31 -62
View File
@@ -2,56 +2,19 @@ package handlers
import ( import (
"net/http" "net/http"
"net/url"
"strconv" "strconv"
"strings"
"unicode"
"sneak.berlin/go/webhooker/internal/database" "sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/logfield" "sneak.berlin/go/webhooker/internal/logfield"
"sneak.berlin/go/webhooker/internal/middleware"
) )
// loginDestination returns where a successful login sends the
// browser: next when it is a path on this site, otherwise "/", which
// leads to the webhook list.
//
// A browser reads "//host" as another site, reads "\" as "/", and
// drops tabs and newlines before reading at all. So the value must
// start with exactly one "/" and hold no "\" or control character
// anywhere: http.Redirect cleans "/a/../\host" down to "/\host". It
// is checked after percent-decoding, so an encoded form of any of
// these is refused too.
func loginDestination(next string) string {
if len(next) > middleware.MaxNextBytes {
return "/"
}
decoded, err := url.PathUnescape(next)
if err != nil ||
!strings.HasPrefix(decoded, "/") ||
strings.HasPrefix(decoded, "//") ||
strings.Contains(decoded, `\`) ||
strings.ContainsFunc(decoded, unicode.IsControl) {
return "/"
}
return next
}
// HandleLoginPage returns a handler for the login page (GET) // HandleLoginPage returns a handler for the login page (GET)
func (h *Handlers) HandleLoginPage() http.HandlerFunc { func (h *Handlers) HandleLoginPage() http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) { return func(w http.ResponseWriter, r *http.Request) {
next := loginDestination(
r.URL.Query().Get(middleware.NextParam),
)
// Check if already logged in // Check if already logged in
sess, err := h.session.Get(r) sess, err := h.session.Get(r)
if err == nil && h.session.IsAuthenticated(sess) { if err == nil && h.session.IsAuthenticated(sess) {
http.Redirect( //nolint:gosec // checked by loginDestination http.Redirect(w, r, "/", http.StatusSeeOther)
w, r, next, http.StatusSeeOther,
)
return return
} }
@@ -59,7 +22,6 @@ func (h *Handlers) HandleLoginPage() http.HandlerFunc {
// Render login page // Render login page
data := map[string]any{ data := map[string]any{
tmplKeyError: "", tmplKeyError: "",
tmplKeyNext: next,
} }
h.renderTemplate(w, r, "login.html", data) h.renderTemplate(w, r, "login.html", data)
@@ -74,7 +36,7 @@ func (h *Handlers) HandleLoginSubmit() http.HandlerFunc {
err := r.ParseForm() err := r.ParseForm()
if err != nil { if err != nil {
h.log.Error("failed to parse form", "error", err) h.log.Error("failed to parse form", "error", err)
h.renderError(w, r, http.StatusBadRequest) http.Error(w, "Bad request", http.StatusBadRequest)
return return
} }
@@ -115,13 +77,8 @@ func (h *Handlers) HandleLoginSubmit() http.HandlerFunc {
"user_id", user.ID, "user_id", user.ID,
) )
// The form value is the client's to set, so it is checked // Redirect to home page
// again here rather than trusted from the rendered page. http.Redirect(w, r, "/", http.StatusSeeOther)
http.Redirect( //nolint:gosec // checked by loginDestination
w, r,
loginDestination(r.PostFormValue(middleware.NextParam)),
http.StatusSeeOther,
)
} }
} }
@@ -134,9 +91,6 @@ func (h *Handlers) renderLoginError(
) { ) {
data := map[string]any{ data := map[string]any{
tmplKeyError: msg, tmplKeyError: msg,
tmplKeyNext: loginDestination(
r.PostFormValue(middleware.NextParam),
),
} }
w.WriteHeader(status) w.WriteHeader(status)
@@ -149,10 +103,9 @@ func (h *Handlers) renderLoginError(
// The credential check runs BEFORE any rate-limit budget is // The credential check runs BEFORE any rate-limit budget is
// consulted, and only a failed check spends budget. That is what // consulted, and only a failed check spends budget. That is what
// keeps the single administrative path reachable: behind the reverse // keeps the single administrative path reachable: behind the reverse
// proxy this deployment requires, when TRUSTED_PROXIES does not cover // proxy this deployment requires, with TRUSTED_PROXIES unset, every
// it, every client shares one bucket, so a limiter spent on arrival // client shares one bucket, so a limiter spent on arrival lets any
// lets any stranger deny the operator's own correct password // stranger deny the operator's own correct password indefinitely.
// indefinitely.
// //
// Verifying first means every login POST costs an Argon2id hash, so // Verifying first means every login POST costs an Argon2id hash, so
// the work is taken under a bounded number of verification slots. // the work is taken under a bounded number of verification slots.
@@ -212,7 +165,11 @@ func (h *Handlers) authenticateUser(
valid, err := database.VerifyPassword(password, user.Password) valid, err := database.VerifyPassword(password, user.Password)
if err != nil { if err != nil {
h.serverError(w, r, "failed to verify password", err) h.log.Error("failed to verify password", "error", err)
http.Error(
w, "Internal server error",
http.StatusInternalServerError,
)
return user, err return user, err
} }
@@ -284,14 +241,24 @@ func (h *Handlers) createAuthenticatedSession(
) error { ) error {
oldSess, err := h.session.Get(r) oldSess, err := h.session.Get(r)
if err != nil { if err != nil {
h.serverError(w, r, "failed to get session", err) h.log.Error("failed to get session", "error", err)
http.Error(
w, "Internal server error",
http.StatusInternalServerError,
)
return err return err
} }
sess, err := h.session.Regenerate(r, w, oldSess) sess, err := h.session.Regenerate(r, w, oldSess)
if err != nil { if err != nil {
h.serverError(w, r, "failed to regenerate session", err) h.log.Error(
"failed to regenerate session", "error", err,
)
http.Error(
w, "Internal server error",
http.StatusInternalServerError,
)
return err return err
} }
@@ -300,7 +267,11 @@ func (h *Handlers) createAuthenticatedSession(
err = h.session.Save(r, w, sess) err = h.session.Save(r, w, sess)
if err != nil { if err != nil {
h.serverError(w, r, "failed to save session", err) h.log.Error("failed to save session", "error", err)
http.Error(
w, "Internal server error",
http.StatusInternalServerError,
)
return err return err
} }
@@ -333,9 +304,7 @@ func (h *Handlers) HandleLogout() http.HandlerFunc {
) )
} }
http.Redirect( // Redirect to login page
w, r, withNotice("/pages/login", signedOut), http.Redirect(w, r, "/pages/login", http.StatusSeeOther)
http.StatusSeeOther,
)
} }
} }
+6 -202
View File
@@ -25,7 +25,7 @@ const (
// sharedProxyPeer is the whole point of this file. Production is // sharedProxyPeer is the whole point of this file. Production is
// required to run behind a TLS-terminating reverse proxy, and // required to run behind a TLS-terminating reverse proxy, and
// when TRUSTED_PROXIES does not cover it every client — attacker // TRUSTED_PROXIES defaults to empty, so every client — attacker
// and operator alike — reaches the process from the proxy's // and operator alike — reaches the process from the proxy's
// address and shares one rate-limit bucket. Both parties in // address and shares one rate-limit bucket. Both parties in
// these tests therefore use the same RemoteAddr. // these tests therefore use the same RemoteAddr.
@@ -115,11 +115,11 @@ func floodFailures(
// done-criterion of https://git.eeqj.de/sneak/webhooker/issues/150. // done-criterion of https://git.eeqj.de/sneak/webhooker/issues/150.
// //
// The attacker and the operator share one rate-limit bucket, because // The attacker and the operator share one rate-limit bucket, because
// behind the mandated reverse proxy, when TRUSTED_PROXIES does not // behind the mandated reverse proxy with TRUSTED_PROXIES unset every
// cover it, every client keys on the proxy's address. The attacker // client keys on the proxy's address. The attacker floods the
// floods the operator's own username — a single-admin product has a // operator's own username — a single-admin product has a predictable
// predictable one — far past the failure limit. The operator must // one — far past the failure limit. The operator must still be able
// still be able to log in with the correct password. // to log in with the correct password.
// //
// This fails if credentials stop being verified ahead of the limiter. // This fails if credentials stop being verified ahead of the limiter.
func TestLogin_StrangersFloodCannotLockOutTheOperator(t *testing.T) { func TestLogin_StrangersFloodCannotLockOutTheOperator(t *testing.T) {
@@ -454,202 +454,6 @@ func TestLogin_SuccessCreatesSession(t *testing.T) {
) )
} }
// TestLogin_ReturnsOnlyToAPathOnThisSite is the security half of
// https://git.eeqj.de/sneak/webhooker/issues/384: the page a login
// returns to is client-chosen, so anything that is not a path on this
// site, plain or percent-encoded, must land on "/", the webhook list.
func TestLogin_ReturnsOnlyToAPathOnThisSite(t *testing.T) {
t.Parallel()
var (
h *handlers.Handlers
db *database.Database
)
app := newTestApp(t, &h, &db)
app.RequireStart()
t.Cleanup(app.RequireStop)
seedOperator(t, db)
cases := []struct{ next, want string }{
{"/hook/abc/events?page=2", "/hook/abc/events?page=2"},
{"", "/"},
{"https://evil.example/", "/"},
{"https%3A%2F%2Fevil.example%2F", "/"},
{"//evil.example/", "/"},
{"%2F%2Fevil.example/", "/"},
{"/%2Fevil.example/", "/"},
{`/\evil.example/`, "/"},
{"%2F%5Cevil.example/", "/"},
{"/%5Cevil.example/", "/"},
{`/a/../\evil.example/`, "/"},
{"/\t/evil.example/", "/"},
{"/%09/evil.example/", "/"},
{"/\n/evil.example/", "/"},
{"/%0A/evil.example/", "/"},
{"/\r/evil.example/", "/"},
{"/%0D/evil.example/", "/"},
{"/%00/evil.example/", "/"},
{"/%7F/evil.example/", "/"},
{"%252F%252Fevil.example/", "/"},
{"https%253A%252F%252Fevil.example%252F", "/"},
{"/" + strings.Repeat("a", 4096), "/"},
}
for _, c := range cases {
form := url.Values{}
form.Set("username", operatorUser)
form.Set("password", operatorPassword)
form.Set("next", c.next)
req := httptest.NewRequestWithContext(
context.Background(),
http.MethodPost,
"/pages/login",
strings.NewReader(form.Encode()),
)
req.Header.Set(
"Content-Type", "application/x-www-form-urlencoded",
)
req.RemoteAddr = sharedProxyPeer
w := httptest.NewRecorder()
h.HandleLoginSubmit().ServeHTTP(w, req)
assert.Equal(t, http.StatusSeeOther, w.Code, "next %q", c.next)
assert.Equal(
t, c.want, w.Header().Get("Location"), "next %q", c.next,
)
}
}
// TestLogin_WrongPasswordKeepsTheRequestedPage: after a wrong
// password the login page is shown again with the same next, so the
// next attempt still returns to the page that was asked for.
func TestLogin_WrongPasswordKeepsTheRequestedPage(t *testing.T) {
t.Parallel()
var (
h *handlers.Handlers
db *database.Database
)
app := newTestApp(t, &h, &db)
app.RequireStart()
t.Cleanup(app.RequireStop)
seedOperator(t, db)
form := url.Values{}
form.Set("username", operatorUser)
form.Set("password", "wrong")
form.Set("next", "/hook/abc")
req := httptest.NewRequestWithContext(
context.Background(),
http.MethodPost,
"/pages/login",
strings.NewReader(form.Encode()),
)
req.Header.Set(
"Content-Type", "application/x-www-form-urlencoded",
)
req.RemoteAddr = sharedProxyPeer
w := httptest.NewRecorder()
h.HandleLoginSubmit().ServeHTTP(w, req)
assert.Equal(t, http.StatusUnauthorized, w.Code)
assert.Contains(
t, w.Body.String(), `name="next" value="/hook/abc"`,
)
}
// loginPageGet renders the login page as a GET with the given next
// value and cookies.
func loginPageGet(
h *handlers.Handlers, next string, cookies []*http.Cookie,
) *httptest.ResponseRecorder {
req := httptest.NewRequestWithContext(
context.Background(), http.MethodGet,
"/pages/login?"+url.Values{"next": {next}}.Encode(), nil,
)
for _, c := range cookies {
req.AddCookie(c)
}
w := httptest.NewRecorder()
h.HandleLoginPage().ServeHTTP(w, req)
return w
}
// TestLoginPage_CarriesOnlyAPathOnThisSite covers the login page
// itself: its form carries the requested page only when it is a path
// on this site, and a browser already logged in goes straight there,
// or to "/" when it is not.
func TestLoginPage_CarriesOnlyAPathOnThisSite(t *testing.T) {
t.Parallel()
var (
h *handlers.Handlers
sess *session.Session
)
app := newTestApp(t, &h, &sess)
app.RequireStart()
t.Cleanup(app.RequireStop)
assert.Contains(
t, loginPageGet(h, "/hook/abc", nil).Body.String(),
`name="next" value="/hook/abc"`,
)
assert.Contains(
t, loginPageGet(h, "//evil.example/", nil).Body.String(),
`name="next" value="/"`,
)
cookies := authenticatedCookies(t, sess, "test-user-id", "testuser")
cases := []struct{ next, want string }{
{"/hook/abc", "/hook/abc"},
{"//evil.example/", "/"},
{`/\evil.example/`, "/"},
}
for _, c := range cases {
w := loginPageGet(h, c.next, cookies)
assert.Equal(t, http.StatusSeeOther, w.Code, "next %q", c.next)
assert.Equal(
t, c.want, w.Header().Get("Location"), "next %q", c.next,
)
}
}
// TestLoginPage_HasNoLinkToItself: the navigation bar on the login
// page offers no link to the login page.
func TestLoginPage_HasNoLinkToItself(t *testing.T) {
t.Parallel()
var h *handlers.Handlers
app := newTestApp(t, &h)
app.RequireStart()
t.Cleanup(app.RequireStop)
w := loginPageGet(h, "", nil)
require.Equal(t, http.StatusOK, w.Code)
assert.NotContains(t, w.Body.String(), `href="/pages/login"`)
}
// TestLogin_UsernameAtLimitCanLogIn shows that a username of exactly // TestLogin_UsernameAtLimitCanLogIn shows that a username of exactly
// database.MaxUsernameBytes still fits in the session cookie. Past // database.MaxUsernameBytes still fits in the session cookie. Past
// what the cookie can carry, a correct login answers 500. // what the cookie can carry, a correct login answers 500.
+64 -26
View File
@@ -11,37 +11,72 @@ import (
"sneak.berlin/go/webhooker/internal/delivery" "sneak.berlin/go/webhooker/internal/delivery"
) )
// The outcomes of a replay POST, as the notice codes its redirect // replayOutcomeParam is the query parameter the replay POST redirects
// carries. noticeFor holds the line each one shows. // with and the event log page reads its banner from.
const replayOutcomeParam = "replay"
// replayOutcomeCode is the outcome of a replay POST. The redirect
// carries one of these fixed codes rather than a message, so nothing a
// client submits can reach the rendered page through it.
type replayOutcomeCode string
const ( const (
// replayQueued reports that a new delivery was created and handed // replayQueued reports that a new delivery was created and handed
// to the delivery engine. // to the delivery engine.
replayQueued noticeCode = "replay-queued" replayQueued replayOutcomeCode = "queued"
// replayTargetDeleted reports a target that once existed and has // replayTargetDeleted reports a target that once existed and has
// since been deleted. Deletes are soft and deliveries carry no // since been deleted. Deletes are soft and deliveries carry no
// foreign key to the target row, so the history survives its // foreign key to the target row, so the history survives its
// target and this is the ordinary case for an old event. // target and this is the ordinary case for an old event.
replayTargetDeleted noticeCode = "replay-target-deleted" replayTargetDeleted replayOutcomeCode = "target-deleted"
// replayTargetMissing reports a target id that names no row at // replayTargetMissing reports a target id that names no row at
// all, deleted or otherwise. // all, deleted or otherwise.
replayTargetMissing noticeCode = "replay-target-missing" replayTargetMissing replayOutcomeCode = "target-missing"
// replayTargetInactive reports a target the operator has // replayTargetInactive reports a target the operator has
// deactivated. A deactivated target receives no new deliveries, so // deactivated. A deactivated target receives no new deliveries, so
// a replay to it would be a delivery they switched off. // a replay to it would be a delivery they switched off.
replayTargetInactive noticeCode = "replay-target-inactive" replayTargetInactive replayOutcomeCode = "target-inactive"
// replayNotTerminal reports a delivery the engine has not finished // replayNotTerminal reports a delivery the engine has not finished
// with. // with.
replayNotTerminal noticeCode = "replay-not-terminal" replayNotTerminal replayOutcomeCode = "not-terminal"
// replayInFlight reports that an earlier replay of this event to // replayInFlight reports that an earlier replay of this event to
// this target is still running. // this target is still running.
replayInFlight noticeCode = "replay-in-flight" replayInFlight replayOutcomeCode = "in-flight"
) )
// replayOutcome returns the banner the event log page shows for an
// outcome code, and whether the replay was queued. An unrecognised
// code yields no banner.
func replayOutcome(code string) (string, bool) {
switch replayOutcomeCode(code) {
case replayQueued:
return "Replay queued: a new delivery was created against " +
"the target's current configuration.", true
case replayTargetDeleted:
return "Not replayed: the target this delivery was for has " +
"been deleted. Recreate the target, then replay.", false
case replayTargetMissing:
return "Not replayed: the target this delivery was for no " +
"longer exists.", false
case replayTargetInactive:
return "Not replayed: the target this delivery was for is " +
"deactivated. Activate it, then replay.", false
case replayNotTerminal:
return "Not replayed: this delivery has not finished yet.",
false
case replayInFlight:
return "Not replayed: a delivery of this event to this " +
"target is already in flight.", false
default:
return "", false
}
}
// HandleDeliveryReplay re-sends a finished delivery's event to its // HandleDeliveryReplay re-sends a finished delivery's event to its
// target. // target.
// //
@@ -70,7 +105,9 @@ func (h *Handlers) HandleDeliveryReplay() http.HandlerFunc {
// middleware, which runs before CSRF parses the form. // middleware, which runs before CSRF parses the form.
err := r.ParseForm() err := r.ParseForm()
if err != nil { if err != nil {
h.renderError(w, r, http.StatusBadRequest) http.Error(
w, "Bad request", http.StatusBadRequest,
)
return return
} }
@@ -87,14 +124,14 @@ func (h *Handlers) replayDelivery(
webhook database.Webhook, webhook database.Webhook,
) { ) {
if !h.dbMgr.DBExists(webhook.ID) { if !h.dbMgr.DBExists(webhook.ID) {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
webhookDB, err := h.dbMgr.GetDB(webhook.ID) webhookDB, err := h.dbMgr.GetDB(webhook.ID)
if err != nil { if err != nil {
h.serverError(w, r, "failed to get webhook database", err) h.serverError(w, "failed to get webhook database", err)
return return
} }
@@ -105,14 +142,14 @@ func (h *Handlers) replayDelivery(
} }
if !original.Status.Terminal() { if !original.Status.Terminal() {
redirectToEventLog(w, r, webhook, replayNotTerminal) h.finishReplay(w, r, webhook, replayNotTerminal)
return return
} }
target, code := h.replayTarget(webhook.ID, original.TargetID) target, code := h.replayTarget(webhook.ID, original.TargetID)
if target == nil { if target == nil {
redirectToEventLog(w, r, webhook, code) h.finishReplay(w, r, webhook, code)
return return
} }
@@ -136,7 +173,7 @@ func (h *Handlers) loadReplaySource(
&original, "id = ?", chi.URLParam(r, "deliveryID"), &original, "id = ?", chi.URLParam(r, "deliveryID"),
).Error ).Error
if err != nil { if err != nil {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return nil, false return nil, false
} }
@@ -158,14 +195,14 @@ func (h *Handlers) queueReplay(
) )
if err != nil { if err != nil {
h.serverError( h.serverError(
w, r, "failed to count in-flight deliveries", err, w, "failed to count in-flight deliveries", err,
) )
return return
} }
if inFlight > 0 { if inFlight > 0 {
redirectToEventLog(w, r, webhook, replayInFlight) h.finishReplay(w, r, webhook, replayInFlight)
return return
} }
@@ -175,7 +212,7 @@ func (h *Handlers) queueReplay(
err = webhookDB. err = webhookDB.
First(&event, "id = ?", original.EventID).Error First(&event, "id = ?", original.EventID).Error
if err != nil { if err != nil {
h.serverError(w, r, "failed to load event for replay", err) h.serverError(w, "failed to load event for replay", err)
return return
} }
@@ -185,7 +222,7 @@ func (h *Handlers) queueReplay(
) )
if err != nil { if err != nil {
h.serverError( h.serverError(
w, r, "failed to create replay delivery", err, w, "failed to create replay delivery", err,
) )
return return
@@ -203,7 +240,7 @@ func (h *Handlers) queueReplay(
"delivery_id", task.DeliveryID, "delivery_id", task.DeliveryID,
) )
redirectToEventLog(w, r, webhook, replayQueued) h.finishReplay(w, r, webhook, replayQueued)
} }
// replayTarget loads the delivery's target as it stands now. // replayTarget loads the delivery's target as it stands now.
@@ -216,7 +253,7 @@ func (h *Handlers) queueReplay(
// with the returned code saying why. // with the returned code saying why.
func (h *Handlers) replayTarget( func (h *Handlers) replayTarget(
webhookID, targetID string, webhookID, targetID string,
) (*database.Target, noticeCode) { ) (*database.Target, replayOutcomeCode) {
var target database.Target var target database.Target
err := h.db.DB().Unscoped().Where( err := h.db.DB().Unscoped().Where(
@@ -326,16 +363,17 @@ func replayBody(body string) *string {
return &body return &body
} }
// redirectToEventLog redirects a replay or resubmit back to the event // finishReplay redirects back to the event log the replay was
// log it was triggered from, carrying the outcome as its notice and // triggered from, carrying the outcome code the page turns into a
// the page number the form submitted. // banner and the page number the form submitted.
func redirectToEventLog( func (h *Handlers) finishReplay(
w http.ResponseWriter, w http.ResponseWriter,
r *http.Request, r *http.Request,
webhook database.Webhook, webhook database.Webhook,
code noticeCode, code replayOutcomeCode,
) { ) {
dest := withNotice("/hook/"+webhook.ID+"/events", code) dest := "/source/" + webhook.ID + "/logs?" +
replayOutcomeParam + "=" + string(code)
// The page is read from the form rather than the query string: // The page is read from the form rather than the query string:
// this is a POST, and its query string is what logs and Referer // this is a POST, and its query string is what logs and Referer
+10 -10
View File
@@ -138,7 +138,7 @@ func postReplay(
t.Helper() t.Helper()
req := postRequest( req := postRequest(
"/hook/"+webhookID+"/deliveries/"+ "/source/"+webhookID+"/deliveries/"+
deliveryID+"/replay", deliveryID+"/replay",
authenticatedCookies( authenticatedCookies(
t, sess, deleteTestUserID, deleteTestUsername, t, sess, deleteTestUserID, deleteTestUsername,
@@ -212,7 +212,7 @@ func TestHandleDeliveryReplay_AppendsDeliveryAndLeavesOriginal(
require.Equal(t, http.StatusSeeOther, w.Code) require.Equal(t, http.StatusSeeOther, w.Code)
assert.Equal( assert.Equal(
t, t,
"/hook/"+wh.ID+"/events?notice=replay-queued", "/source/"+wh.ID+"/logs?replay=queued",
w.Header().Get("Location"), w.Header().Get("Location"),
) )
@@ -362,7 +362,7 @@ func TestHandleDeliveryReplay_RefusesDeletedTarget(t *testing.T) {
require.Equal(t, http.StatusSeeOther, w.Code) require.Equal(t, http.StatusSeeOther, w.Code)
assert.Equal( assert.Equal(
t, t,
"/hook/"+wh.ID+"/events?notice=replay-target-deleted", "/source/"+wh.ID+"/logs?replay=target-deleted",
w.Header().Get("Location"), w.Header().Get("Location"),
) )
@@ -390,7 +390,7 @@ func TestHandleDeliveryReplay_RefusesDeletedTarget(t *testing.T) {
require.Equal(t, http.StatusSeeOther, missing.Code) require.Equal(t, http.StatusSeeOther, missing.Code)
assert.Equal( assert.Equal(
t, t,
"/hook/"+wh.ID+"/events?notice=replay-target-missing", "/source/"+wh.ID+"/logs?replay=target-missing",
missing.Header().Get("Location"), missing.Header().Get("Location"),
) )
} }
@@ -431,7 +431,7 @@ func TestHandleDeliveryReplay_RefusesWhileEarlierReplayInFlight(
require.Equal(t, http.StatusSeeOther, first.Code) require.Equal(t, http.StatusSeeOther, first.Code)
require.Equal( require.Equal(
t, t,
"/hook/"+wh.ID+"/events?notice=replay-queued", "/source/"+wh.ID+"/logs?replay=queued",
first.Header().Get("Location"), first.Header().Get("Location"),
) )
@@ -439,7 +439,7 @@ func TestHandleDeliveryReplay_RefusesWhileEarlierReplayInFlight(
require.Equal(t, http.StatusSeeOther, second.Code) require.Equal(t, http.StatusSeeOther, second.Code)
assert.Equal( assert.Equal(
t, t,
"/hook/"+wh.ID+"/events?notice=replay-in-flight", "/source/"+wh.ID+"/logs?replay=in-flight",
second.Header().Get("Location"), second.Header().Get("Location"),
) )
@@ -465,7 +465,7 @@ func TestHandleDeliveryReplay_RefusesWhileEarlierReplayInFlight(
require.Equal(t, http.StatusSeeOther, pending.Code) require.Equal(t, http.StatusSeeOther, pending.Code)
assert.Equal( assert.Equal(
t, t,
"/hook/"+wh.ID+"/events?notice=replay-not-terminal", "/source/"+wh.ID+"/logs?replay=not-terminal",
pending.Header().Get("Location"), pending.Header().Get("Location"),
) )
} }
@@ -501,7 +501,7 @@ func TestHandleSourceLogs_RendersReplayControlAndBanner(t *testing.T) {
assert.Contains( assert.Contains(
t, body, t, body,
`action="/hook/`+wh.ID+`/deliveries/`+ `action="/source/`+wh.ID+`/deliveries/`+
original.ID+`/replay"`, original.ID+`/replay"`,
) )
assert.Contains(t, body, `method="POST"`) assert.Contains(t, body, `method="POST"`)
@@ -509,7 +509,7 @@ func TestHandleSourceLogs_RendersReplayControlAndBanner(t *testing.T) {
assert.Contains(t, body, ">Replay<") assert.Contains(t, body, ">Replay<")
refused := renderSourceLogsPageWithQuery( refused := renderSourceLogsPageWithQuery(
t, h, sess, wh.ID, "?notice=replay-target-deleted", t, h, sess, wh.ID, "?replay=target-deleted",
) )
assert.Contains(t, refused, "alert-error") assert.Contains(t, refused, "alert-error")
@@ -517,7 +517,7 @@ func TestHandleSourceLogs_RendersReplayControlAndBanner(t *testing.T) {
// An outcome code nobody issued renders no banner at all. // An outcome code nobody issued renders no banner at all.
unknown := renderSourceLogsPageWithQuery( unknown := renderSourceLogsPageWithQuery(
t, h, sess, wh.ID, "?notice=made-up", t, h, sess, wh.ID, "?replay=made-up",
) )
assert.NotContains(t, unknown, "alert-error") assert.NotContains(t, unknown, "alert-error")
-53
View File
@@ -1,53 +0,0 @@
package handlers_test
import (
"context"
"html/template"
"net/http"
"net/http/httptest"
"testing"
"github.com/stretchr/testify/assert"
"sneak.berlin/go/webhooker/internal/handlers"
)
// TestErrorPage_RenderFailureKeepsStatus proves that an error page
// which cannot render answers with the status it was reporting, as
// plain text, and is not attempted again: a page whose own render
// fails reaches the error page, and the error page failing as well
// ends there with the 500.
func TestErrorPage_RenderFailureKeepsStatus(t *testing.T) {
t.Parallel()
var h *handlers.Handlers
app := newTestApp(t, &h)
app.RequireStart()
t.Cleanup(app.RequireStop)
// .Status is an int, so asking it for a field fails the render.
failing := `{{.Status.Missing}}`
h.AddTemplateForTest("error.html", template.Must(
template.New("error").Parse(failing),
))
h.AddTemplateForTest("failing.html", template.Must(
template.New("failing").Parse(`{{.Data.Missing}}`),
))
req := httptest.NewRequestWithContext(
context.Background(), http.MethodGet, "/", nil,
)
w := httptest.NewRecorder()
h.HandleErrorPage(http.StatusNotFound).ServeHTTP(w, req)
assert.Equal(t, http.StatusNotFound, w.Code)
assert.Equal(t, "Not Found\n", w.Body.String())
w = httptest.NewRecorder()
h.RenderTemplateForTest(w, req, "failing.html", 0)
assert.Equal(t, http.StatusInternalServerError, w.Code)
assert.Equal(t, "Internal Server Error\n", w.Body.String())
}
+5 -5
View File
@@ -52,7 +52,7 @@ func (h *Handlers) HandleEventBodyDownload() http.HandlerFunc {
// steered by a client. // steered by a client.
eventID, err := uuid.Parse(chi.URLParam(r, "eventID")) eventID, err := uuid.Parse(chi.URLParam(r, "eventID"))
if err != nil { if err != nil {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
@@ -103,21 +103,21 @@ func (h *Handlers) serveEventBody(
eventID string, eventID string,
) { ) {
if !h.dbMgr.DBExists(webhook.ID) { if !h.dbMgr.DBExists(webhook.ID) {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
webhookDB, err := h.dbMgr.GetDB(webhook.ID) webhookDB, err := h.dbMgr.GetDB(webhook.ID)
if err != nil { if err != nil {
h.serverError(w, r, "failed to get webhook database", err) h.serverError(w, "failed to get webhook database", err)
return return
} }
body, found, err := eventBody(webhookDB, webhook.ID, eventID) body, found, err := eventBody(webhookDB, webhook.ID, eventID)
if err != nil { if err != nil {
h.serverError(w, r, "failed to read event body", err) h.serverError(w, "failed to read event body", err)
return return
} }
@@ -130,7 +130,7 @@ func (h *Handlers) serveEventBody(
// row and the whole body is served, or it does not and the // row and the whole body is served, or it does not and the
// response is a clean 404. // response is a clean 404.
if !found { if !found {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
+4 -4
View File
@@ -64,8 +64,8 @@ func fetchEventBody(
req := httptest.NewRequestWithContext( req := httptest.NewRequestWithContext(
context.Background(), context.Background(),
http.MethodGet, http.MethodGet,
"/hook/"+url.PathEscape(sourceID)+ "/source/"+url.PathEscape(sourceID)+
"/events/"+url.PathEscape(eventID)+"/body", "/logs/"+url.PathEscape(eventID)+"/body",
nil, nil,
) )
@@ -490,7 +490,7 @@ func TestHandleSourceLogs_TruncationMarkerLinksToDownload(
page := renderSourceLogsPage(t, h, sess, big.ID) page := renderSourceLogsPage(t, h, sess, big.ID)
assert.Contains( assert.Contains(
t, page, t, page,
"/hook/"+big.ID+"/events/"+bigEvt.ID+"/body", "/source/"+big.ID+"/logs/"+bigEvt.ID+"/body",
) )
small := seedWebhook(t, db) small := seedWebhook(t, db)
@@ -501,6 +501,6 @@ func TestHandleSourceLogs_TruncationMarkerLinksToDownload(
page = renderSourceLogsPage(t, h, sess, small.ID) page = renderSourceLogsPage(t, h, sess, small.ID)
assert.NotContains( assert.NotContains(
t, page, t, page,
"/hook/"+small.ID+"/events/"+smallEvt.ID+"/body", "/source/"+small.ID+"/logs/"+smallEvt.ID+"/body",
) )
} }
+62 -13
View File
@@ -3,6 +3,7 @@ package handlers
import ( import (
"errors" "errors"
"net/http" "net/http"
"strconv"
"github.com/go-chi/chi" "github.com/go-chi/chi"
"github.com/google/uuid" "github.com/google/uuid"
@@ -10,19 +11,43 @@ import (
"sneak.berlin/go/webhooker/internal/database" "sneak.berlin/go/webhooker/internal/database"
) )
// The outcomes of a resubmit POST, as the notice codes its redirect // resubmitOutcomeParam is the query parameter the resubmit POST
// carries. noticeFor holds the line each one shows. // redirects with and the event log page reads its banner from.
const resubmitOutcomeParam = "resubmit"
// resubmitOutcomeCode is the outcome of a resubmit POST. The redirect
// carries one of these fixed codes rather than a message, so nothing a
// client submits can reach the rendered page through it.
type resubmitOutcomeCode string
const ( const (
// resubmitQueued reports that a new event was stored and its // resubmitQueued reports that a new event was stored and its
// deliveries handed to the delivery engine. // deliveries handed to the delivery engine.
resubmitQueued noticeCode = "resubmit-queued" resubmitQueued resubmitOutcomeCode = "queued"
// resubmitNoTargets reports a source with no active targets. The // resubmitNoTargets reports a source with no active targets. The
// new event is stored either way, exactly as a received event // new event is stored either way, exactly as a received event
// with no targets is. // with no targets is.
resubmitNoTargets noticeCode = "resubmit-no-targets" resubmitNoTargets resubmitOutcomeCode = "no-targets"
) )
// resubmitOutcome returns the banner the event log page shows for an
// outcome code, and whether the resubmit was queued. An unrecognised
// code yields no banner.
func resubmitOutcome(code string) (string, bool) {
switch resubmitOutcomeCode(code) {
case resubmitQueued:
return "Resubmitted: a new event was created from the stored " +
"one and queued to every active target.", true
case resubmitNoTargets:
return "Resubmitted: a new event was created, but this " +
"source has no active targets, so nothing was queued.",
true
default:
return "", false
}
}
// resubmitSource is the stored event a resubmit copies. Its body is // resubmitSource is the stored event a resubmit copies. Its body is
// read as bytes rather than as a string so the copy is byte-identical // read as bytes rather than as a string so the copy is byte-identical
// to what was received, whatever the payload's encoding. // to what was received, whatever the payload's encoding.
@@ -74,7 +99,7 @@ func (h *Handlers) HandleEventResubmit() http.HandlerFunc {
// middleware, which runs before CSRF parses the form. // middleware, which runs before CSRF parses the form.
err := r.ParseForm() err := r.ParseForm()
if err != nil { if err != nil {
h.renderError(w, r, http.StatusBadRequest) http.Error(w, "Bad request", http.StatusBadRequest)
return return
} }
@@ -95,20 +120,20 @@ func (h *Handlers) resubmitEvent(
// alphabet rather than from the request. // alphabet rather than from the request.
eventID, err := uuid.Parse(chi.URLParam(r, "eventID")) eventID, err := uuid.Parse(chi.URLParam(r, "eventID"))
if err != nil { if err != nil {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
if !h.dbMgr.DBExists(webhook.ID) { if !h.dbMgr.DBExists(webhook.ID) {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
webhookDB, err := h.dbMgr.GetDB(webhook.ID) webhookDB, err := h.dbMgr.GetDB(webhook.ID)
if err != nil { if err != nil {
h.serverError(w, r, "failed to get webhook database", err) h.serverError(w, "failed to get webhook database", err)
return return
} }
@@ -122,7 +147,7 @@ func (h *Handlers) resubmitEvent(
webhookDB, webhook.ID, eventID.String(), webhookDB, webhook.ID, eventID.String(),
) )
if err != nil { if err != nil {
h.serverError(w, r, "failed to load event to resubmit", err) h.serverError(w, "failed to load event to resubmit", err)
return return
} }
@@ -130,7 +155,7 @@ func (h *Handlers) resubmitEvent(
// A miss is a 404 whether the event was reaped, belongs to // A miss is a 404 whether the event was reaped, belongs to
// another webhook, or never existed. // another webhook, or never existed.
if !found { if !found {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
@@ -182,7 +207,7 @@ func (h *Handlers) queueResubmit(
// inactive one is skipped rather than refused. // inactive one is skipped rather than refused.
targets, err := h.loadActiveTargets(webhook.ID) targets, err := h.loadActiveTargets(webhook.ID)
if err != nil { if err != nil {
h.serverError(w, r, "failed to query targets", err) h.serverError(w, "failed to query targets", err)
return return
} }
@@ -200,7 +225,7 @@ func (h *Handlers) queueResubmit(
targets, targets,
) )
if err != nil { if err != nil {
h.serverError(w, r, "failed to store resubmitted event", err) h.serverError(w, "failed to store resubmitted event", err)
return return
} }
@@ -220,5 +245,29 @@ func (h *Handlers) queueResubmit(
code = resubmitNoTargets code = resubmitNoTargets
} }
redirectToEventLog(w, r, webhook, code) h.finishResubmit(w, r, webhook, code)
}
// finishResubmit redirects back to the event log the resubmit was
// triggered from, carrying the outcome code the page turns into a
// banner and the page number the form submitted.
func (h *Handlers) finishResubmit(
w http.ResponseWriter,
r *http.Request,
webhook database.Webhook,
code resubmitOutcomeCode,
) {
dest := "/source/" + webhook.ID + "/logs?" +
resubmitOutcomeParam + "=" + string(code)
// The page is read from the form rather than the query string:
// this is a POST, and its query string is what logs and Referer
// headers record.
if page := pageOrFirst(
r.PostFormValue("page"),
); page > 1 {
dest += "&page=" + strconv.Itoa(page)
}
http.Redirect(w, r, dest, http.StatusSeeOther)
} }
+6 -7
View File
@@ -65,7 +65,7 @@ func postResubmit(
t.Helper() t.Helper()
req := postRequest( req := postRequest(
"/hook/"+webhookID+"/events/"+eventID+"/resubmit", "/source/"+webhookID+"/events/"+eventID+"/resubmit",
authenticatedCookies( authenticatedCookies(
t, sess, deleteTestUserID, deleteTestUsername, t, sess, deleteTestUserID, deleteTestUsername,
), ),
@@ -154,7 +154,7 @@ func TestHandleEventResubmit_DeliversToTargetCreatedAfterTheEvent(
require.Equal(t, http.StatusSeeOther, w.Code) require.Equal(t, http.StatusSeeOther, w.Code)
assert.Equal( assert.Equal(
t, t,
"/hook/"+wh.ID+"/events?notice=resubmit-queued", "/source/"+wh.ID+"/logs?resubmit=queued",
w.Header().Get("Location"), w.Header().Get("Location"),
) )
@@ -204,7 +204,6 @@ func assertEventCopy(
assert.Equal(t, original.Method, fresh.Method) assert.Equal(t, original.Method, fresh.Method)
assert.Equal(t, original.Headers, fresh.Headers) assert.Equal(t, original.Headers, fresh.Headers)
assert.Equal(t, original.Body, fresh.Body) assert.Equal(t, original.Body, fresh.Body)
assert.Equal(t, int64(len(original.Body)), fresh.BodyBytes)
assert.Equal(t, original.ContentType, fresh.ContentType) assert.Equal(t, original.ContentType, fresh.ContentType)
assert.Equal(t, original.EntrypointID, fresh.EntrypointID) assert.Equal(t, original.EntrypointID, fresh.EntrypointID)
assert.Equal(t, original.WebhookID, fresh.WebhookID) assert.Equal(t, original.WebhookID, fresh.WebhookID)
@@ -282,7 +281,7 @@ func TestHandleEventResubmit_IsRepeatable(t *testing.T) {
require.Equal(t, http.StatusSeeOther, w.Code) require.Equal(t, http.StatusSeeOther, w.Code)
assert.Equal( assert.Equal(
t, t,
"/hook/"+wh.ID+"/events?notice=resubmit-queued", "/source/"+wh.ID+"/logs?resubmit=queued",
w.Header().Get("Location"), w.Header().Get("Location"),
"a resubmit must not be refused while an earlier "+ "a resubmit must not be refused while an earlier "+
"one is in flight", "one is in flight",
@@ -436,7 +435,7 @@ func TestHandleEventResubmit_SkipsInactiveTarget(t *testing.T) {
require.Equal(t, http.StatusSeeOther, w.Code) require.Equal(t, http.StatusSeeOther, w.Code)
assert.Equal( assert.Equal(
t, t,
"/hook/"+wh.ID+"/events?notice=resubmit-queued", "/source/"+wh.ID+"/logs?resubmit=queued",
w.Header().Get("Location"), w.Header().Get("Location"),
"an inactive target is skipped, not an error", "an inactive target is skipped, not an error",
) )
@@ -482,7 +481,7 @@ func TestHandleEventResubmit_NoActiveTargetsStillStoresEvent(
require.Equal(t, http.StatusSeeOther, w.Code) require.Equal(t, http.StatusSeeOther, w.Code)
assert.Equal( assert.Equal(
t, t,
"/hook/"+wh.ID+"/events?notice=resubmit-no-targets", "/source/"+wh.ID+"/logs?resubmit=no-targets",
w.Header().Get("Location"), w.Header().Get("Location"),
) )
@@ -598,7 +597,7 @@ func TestHandleSourceLogs_ShowsResubmitProvenance(t *testing.T) {
) )
assert.Contains( assert.Contains(
t, body, t, body,
"/hook/"+wh.ID+"/events/"+original.ID+"/resubmit", "/source/"+wh.ID+"/events/"+original.ID+"/resubmit",
"the log must offer the resubmit action per event", "the log must offer the resubmit action per event",
) )
} }
+2 -12
View File
@@ -1,11 +1,9 @@
package handlers package handlers
import ( import (
"context"
"html/template" "html/template"
"log/slog" "log/slog"
"net/http" "net/http"
"net/http/httptest"
"time" "time"
"gorm.io/gorm" "gorm.io/gorm"
@@ -67,7 +65,7 @@ func (s *Handlers) LoadEventLogViewsForTest(
page int, page int,
) []EventLogView { ) []EventLogView {
views, _, _ := s.loadEventsWithDeliveries( views, _, _ := s.loadEventsWithDeliveries(
w, newRequestForTest(), webhook, nil, page, w, webhook, nil, page,
) )
return views return views
@@ -96,14 +94,6 @@ func FinishedByTargetForTest(
return finishedByTarget(webhookDB, since) return finishedByTarget(webhookDB, since)
} }
// newRequestForTest is the request the helpers here pass on for
// callers that have none: it is used only to render the error page.
func newRequestForTest() *http.Request {
return httptest.NewRequestWithContext(
context.Background(), http.MethodGet, "/", nil,
)
}
// AddTemplateForTest registers a template under a page name so that // AddTemplateForTest registers a template under a page name so that
// the handlers_test package can drive the render path with a // the handlers_test package can drive the render path with a
// template of its own. // template of its own.
@@ -157,5 +147,5 @@ func (s *Handlers) BuildDatabaseTargetConfigForTest(
w http.ResponseWriter, w http.ResponseWriter,
expiry string, expiry string,
) (string, error) { ) (string, error) {
return s.buildDatabaseTargetConfig(w, newRequestForTest(), expiry) return s.buildDatabaseTargetConfig(w, expiry)
} }
+1 -1
View File
@@ -306,7 +306,7 @@ func postWebhook(
t.Helper() t.Helper()
req := httptest.NewRequestWithContext( req := httptest.NewRequestWithContext(
context.Background(), http.MethodPost, "/h/x", context.Background(), http.MethodPost, "/webhook/x",
strings.NewReader("{}"), strings.NewReader("{}"),
) )
+28 -125
View File
@@ -10,12 +10,9 @@ import (
"html/template" "html/template"
"log/slog" "log/slog"
"net/http" "net/http"
"sync"
"sync/atomic" "sync/atomic"
"github.com/prometheus/client_golang/prometheus"
"go.uber.org/fx" "go.uber.org/fx"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/database" "sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/delivery" "sneak.berlin/go/webhooker/internal/delivery"
"sneak.berlin/go/webhooker/internal/globals" "sneak.berlin/go/webhooker/internal/globals"
@@ -31,7 +28,7 @@ const (
// maxBodyShift is the bit shift for 1 MB body limit. // maxBodyShift is the bit shift for 1 MB body limit.
maxBodyShift = 20 maxBodyShift = 20
// recentEventLimit is the number of recent events to show. // recentEventLimit is the number of recent events to show.
recentEventLimit = 50 recentEventLimit = 20
// paginationPerPage is the number of items per page. // paginationPerPage is the number of items per page.
paginationPerPage = 25 paginationPerPage = 25
@@ -39,9 +36,6 @@ const (
tmplKeyError = "Error" tmplKeyError = "Error"
// tmplKeyWebhook is the template data key for a webhook. // tmplKeyWebhook is the template data key for a webhook.
tmplKeyWebhook = "Webhook" tmplKeyWebhook = "Webhook"
// tmplKeyNext is the template data key for the page to return
// to after login.
tmplKeyNext = "Next"
) )
// errInvalidPassword is returned when a password does not match. // errInvalidPassword is returned when a password does not match.
@@ -59,17 +53,14 @@ type HandlersParams struct {
Logger *logger.Logger Logger *logger.Logger
Globals *globals.Globals Globals *globals.Globals
Config *config.Config
Database *database.Database Database *database.Database
WebhookDBMgr *database.WebhookDBManager WebhookDBMgr *database.WebhookDBManager
Healthcheck *healthcheck.Healthcheck Healthcheck *healthcheck.Healthcheck
Session *session.Session Session *session.Session
Middleware *middleware.Middleware Middleware *middleware.Middleware
Notifier delivery.Notifier Notifier delivery.Notifier
Archives delivery.Archives Evictor delivery.WebhookEvictor
SSRFGuard *delivery.Guard SSRFGuard *delivery.Guard
Metrics *metrics.Set
Registry *prometheus.Registry
} }
// Handlers provides HTTP handler methods for all application // Handlers provides HTTP handler methods for all application
@@ -83,7 +74,7 @@ type Handlers struct {
session *session.Session session *session.Session
mw *middleware.Middleware mw *middleware.Middleware
notifier delivery.Notifier notifier delivery.Notifier
archives delivery.Archives evictor delivery.WebhookEvictor
mtr *metrics.Set mtr *metrics.Set
templates map[string]*template.Template templates map[string]*template.Template
@@ -92,14 +83,6 @@ type Handlers struct {
// is one delivery will actually attempt. // is one delivery will actually attempt.
ssrf *delivery.Guard ssrf *delivery.Guard
// renameMu makes the webhook edit, the target edit and target
// creation run one at a time, each held from loading the stored
// names through the archive rename, the save and any move back.
// Interleaved, one could rename an archive between another's
// rename and save, leaving the file named for one edit and the
// stored names from the other.
renameMu sync.Mutex
// dummyVerifications counts the equivalent-cost verifications // dummyVerifications counts the equivalent-cost verifications
// charged for usernames that do not exist. It exists so a test // charged for usernames that do not exist. It exists so a test
// can prove that path runs without measuring wall-clock time. // can prove that path runs without measuring wall-clock time.
@@ -108,10 +91,10 @@ type Handlers struct {
// parsePageTemplate parses a page-specific template set from the // parsePageTemplate parses a page-specific template set from the
// embedded FS. Each page template is combined with the shared // embedded FS. Each page template is combined with the shared
// base, htmlheader, navbar and notice templates, and with any further // base, htmlheader, and navbar templates, and with any further files
// files the page includes. The page file must be listed first so that // the page includes. The page file must be listed first so that its
// its root action ({{template "base" .}}) becomes the template set's // root action ({{template "base" .}}) becomes the template set's entry
// entry point. // point.
func parsePageTemplate( func parsePageTemplate(
pageFile string, included ...string, pageFile string, included ...string,
) *template.Template { ) *template.Template {
@@ -120,7 +103,6 @@ func parsePageTemplate(
"base.html", "base.html",
"htmlheader.html", "htmlheader.html",
"navbar.html", "navbar.html",
"notice.html",
}, included...) }, included...)
return template.Must( return template.Must(
@@ -143,22 +125,20 @@ func New(
s.session = params.Session s.session = params.Session
s.mw = params.Middleware s.mw = params.Middleware
s.notifier = params.Notifier s.notifier = params.Notifier
s.archives = params.Archives s.evictor = params.Evictor
s.mtr = params.Metrics s.mtr = metrics.Default()
s.ssrf = params.SSRFGuard s.ssrf = params.SSRFGuard
// Parse all page templates once at startup // Parse all page templates once at startup
s.templates = map[string]*template.Template{ s.templates = map[string]*template.Template{
"login.html": parsePageTemplate("login.html"), "login.html": parsePageTemplate("login.html"),
"profile.html": parsePageTemplate("profile.html"), "profile.html": parsePageTemplate("profile.html"),
"settings.html": parsePageTemplate("settings.html"),
"sources_list.html": parsePageTemplate("sources_list.html"), "sources_list.html": parsePageTemplate("sources_list.html"),
"sources_new.html": parsePageTemplate("sources_new.html"), "sources_new.html": parsePageTemplate("sources_new.html"),
"source_detail.html": parsePageTemplate("source_detail.html", "webhook_stats.html"), "source_detail.html": parsePageTemplate("source_detail.html", "webhook_stats.html"),
"source_edit.html": parsePageTemplate("source_edit.html"), "source_edit.html": parsePageTemplate("source_edit.html"),
"source_logs.html": parsePageTemplate("source_logs.html"), "source_logs.html": parsePageTemplate("source_logs.html"),
"target_edit.html": parsePageTemplate("target_edit.html"), "target_edit.html": parsePageTemplate("target_edit.html"),
"error.html": parsePageTemplate("error.html"),
} }
lc.Append(fx.Hook{ lc.Append(fx.Hook{
@@ -170,16 +150,6 @@ func New(
return s, nil return s, nil
} }
// HandleErrorPage returns a handler that answers every request with
// the error page for status. The router uses it for unknown paths, the
// CSRF middleware for a refused form, and each admin page route
// group's recoverer for a panic.
func (s *Handlers) HandleErrorPage(status int) http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) {
s.renderError(w, r, status)
}
}
func (s *Handlers) respondJSON( func (s *Handlers) respondJSON(
w http.ResponseWriter, w http.ResponseWriter,
_ *http.Request, _ *http.Request,
@@ -197,78 +167,15 @@ func (s *Handlers) respondJSON(
} }
} }
// serverError logs an error and answers with the 500 error page. // serverError logs an error and sends a 500 response.
func (s *Handlers) serverError( func (s *Handlers) serverError(
w http.ResponseWriter, r *http.Request, msg string, err error, w http.ResponseWriter, msg string, err error,
) { ) {
s.log.Error(msg, "error", err) s.log.Error(msg, "error", err)
s.renderError(w, r, http.StatusInternalServerError) http.Error(
} w, "Internal server error",
http.StatusInternalServerError,
// renderError answers with status and the error page: the normal )
// layout, one fixed line explaining the status, and a link back to the
// webhook list, or to sign-in when nobody is signed in.
//
// It renders the page itself rather than through renderTemplate,
// whose own failure comes here. If the error page cannot render
// either, the answer is the same status in plain text: never a second
// attempt, and never a different status.
func (s *Handlers) renderError(
w http.ResponseWriter,
r *http.Request,
status int,
) {
// The page names the signed-in user, and some error pages are
// served outside the routes where NoCache runs.
w.Header().Set("Cache-Control", "no-store")
// No notice: one would say an action worked above a page saying
// the request failed.
data := s.pageData(r, map[string]any{
"Status": status,
"StatusText": http.StatusText(status),
"Message": errorPageText(status),
}, nil)
var buf bytes.Buffer
err := s.templates["error.html"].Execute(&buf, data)
if err != nil {
s.log.Error("failed to render error page", "error", err)
http.Error(w, http.StatusText(status), status)
return
}
w.Header().Set("Content-Type", "text/html; charset=utf-8")
w.WriteHeader(status)
_, err = buf.WriteTo(w)
if err != nil {
s.log.Error("failed to write error page", "error", err)
}
}
// errorPageText is the line the error page shows for status. It is
// fixed per status, so the page tells the reader no more than the
// plain-text answers it replaced did.
func errorPageText(status int) string {
switch status {
case http.StatusBadRequest:
return "The request could not be read."
case http.StatusForbidden:
return "The request was refused. If it came from a form " +
"left open for a long time, reload the page and try " +
"again."
case http.StatusNotFound:
return "There is nothing here. It may have been deleted, " +
"or the address may be wrong."
case http.StatusServiceUnavailable:
return "The server is busy. Please try again in a moment."
default: // http.StatusInternalServerError
return "Something went wrong on the server. Please try " +
"again."
}
} }
// UserInfo represents user information for templates // UserInfo represents user information for templates
@@ -282,7 +189,6 @@ type templateDataWrapper struct {
User *UserInfo User *UserInfo
CSRFToken string CSRFToken string
Version string Version string
Notice *notice
Data any Data any
} }
@@ -322,20 +228,14 @@ func (s *Handlers) renderTemplate(
"template not found", "template not found",
"template", pageTemplate, "template", pageTemplate,
) )
s.renderError(w, r, http.StatusInternalServerError) http.Error(
w, "Internal server error",
http.StatusInternalServerError,
)
return return
} }
s.executeTemplate(w, r, tmpl, s.pageData(r, data, noticeFor(r)))
}
// pageData adds the fields the shared layout renders to a page's own
// data. The layout shows the notice, when there is one, above the
// page.
func (s *Handlers) pageData(
r *http.Request, data any, pageNotice *notice,
) any {
userInfo := s.getUserInfo(r) userInfo := s.getUserInfo(r)
csrfToken := middleware.CSRFToken(r) csrfToken := middleware.CSRFToken(r)
@@ -349,18 +249,19 @@ func (s *Handlers) pageData(
m["User"] = userInfo m["User"] = userInfo
m["CSRFToken"] = csrfToken m["CSRFToken"] = csrfToken
m["Version"] = version m["Version"] = version
m["Notice"] = pageNotice s.executeTemplate(w, tmpl, m)
return m return
} }
return templateDataWrapper{ wrapper := templateDataWrapper{
User: userInfo, User: userInfo,
CSRFToken: csrfToken, CSRFToken: csrfToken,
Version: version, Version: version,
Notice: pageNotice,
Data: data, Data: data,
} }
s.executeTemplate(w, tmpl, wrapper)
} }
// executeTemplate renders the template into a buffer and writes to // executeTemplate renders the template into a buffer and writes to
@@ -373,7 +274,6 @@ func (s *Handlers) pageData(
// this reason. // this reason.
func (s *Handlers) executeTemplate( func (s *Handlers) executeTemplate(
w http.ResponseWriter, w http.ResponseWriter,
r *http.Request,
tmpl *template.Template, tmpl *template.Template,
data any, data any,
) { ) {
@@ -384,7 +284,10 @@ func (s *Handlers) executeTemplate(
s.log.Error( s.log.Error(
"failed to execute template", "error", err, "failed to execute template", "error", err,
) )
s.renderError(w, r, http.StatusInternalServerError) http.Error(
w, "Internal server error",
http.StatusInternalServerError,
)
return return
} }
+19 -142
View File
@@ -3,7 +3,6 @@ package handlers_test
import ( import (
"context" "context"
"errors" "errors"
"fmt"
"html/template" "html/template"
"net/http" "net/http"
"net/http/httptest" "net/http/httptest"
@@ -21,7 +20,6 @@ import (
"sneak.berlin/go/webhooker/internal/handlers" "sneak.berlin/go/webhooker/internal/handlers"
"sneak.berlin/go/webhooker/internal/healthcheck" "sneak.berlin/go/webhooker/internal/healthcheck"
"sneak.berlin/go/webhooker/internal/logger" "sneak.berlin/go/webhooker/internal/logger"
"sneak.berlin/go/webhooker/internal/metrics"
"sneak.berlin/go/webhooker/internal/middleware" "sneak.berlin/go/webhooker/internal/middleware"
"sneak.berlin/go/webhooker/internal/session" "sneak.berlin/go/webhooker/internal/session"
) )
@@ -53,103 +51,23 @@ func (n *recordingNotifier) Tasks() []delivery.Task {
return out return out
} }
// recordingArchives is a delivery.Archives that records what it // recordingEvictor is a delivery.WebhookEvictor that records
// was asked to do, so a test can prove that a deletion or rename // the webhook ids it was asked to evict, so a test can prove
// path reached the delivery engine. After FailRenames, every // that a deletion path reached the delivery engine.
// rename of that target fails with the given error. After type recordingEvictor struct {
// BlockNextRename, the next rename is recorded and then waits. mu sync.Mutex
type recordingArchives struct { evicted []string
mu sync.Mutex
evicted []string
evictedTargets []string
renames []archiveRename
renameErrs map[string]error
entered chan struct{}
release chan struct{}
} }
// errInjectedRename is the failure a test hands FailRenames. func (r *recordingEvictor) EvictWebhook(webhookID string) {
var errInjectedRename = errors.New("injected rename failure")
// errNameTaken is what the delivery engine returns when a file
// already has an archive's new name, here archive-taken.db.
var errNameTaken = fmt.Errorf(
"%w: archive-taken.db", delivery.ErrArchiveNameTaken,
)
// archiveRename is one recorded Rename call.
type archiveRename struct {
TargetID string
WebhookName string
TargetName string
}
func (r *recordingArchives) EvictWebhook(webhookID string) {
r.mu.Lock() r.mu.Lock()
defer r.mu.Unlock() defer r.mu.Unlock()
r.evicted = append(r.evicted, webhookID) r.evicted = append(r.evicted, webhookID)
} }
func (r *recordingArchives) EvictTarget(targetID string) {
r.mu.Lock()
defer r.mu.Unlock()
r.evictedTargets = append(r.evictedTargets, targetID)
}
func (r *recordingArchives) Rename(
targetID, webhookName, targetName string,
) error {
r.mu.Lock()
r.renames = append(r.renames, archiveRename{
TargetID: targetID,
WebhookName: webhookName,
TargetName: targetName,
})
err := r.renameErrs[targetID]
entered, release := r.entered, r.release
r.entered, r.release = nil, nil
r.mu.Unlock()
if entered != nil {
close(entered)
<-release
}
return err
}
// BlockNextRename makes the next rename, once recorded, wait until
// the returned release is called. The returned channel is closed
// when that rename starts waiting.
func (r *recordingArchives) BlockNextRename() (<-chan struct{}, func()) {
entered := make(chan struct{})
release := make(chan struct{})
r.mu.Lock()
r.entered, r.release = entered, release
r.mu.Unlock()
return entered, func() { close(release) }
}
// FailRenames makes every later rename of targetID fail with err.
func (r *recordingArchives) FailRenames(targetID string, err error) {
r.mu.Lock()
defer r.mu.Unlock()
if r.renameErrs == nil {
r.renameErrs = map[string]error{}
}
r.renameErrs[targetID] = err
}
// Evicted returns a copy of the recorded webhook ids. // Evicted returns a copy of the recorded webhook ids.
func (r *recordingArchives) Evicted() []string { func (r *recordingEvictor) Evicted() []string {
r.mu.Lock() r.mu.Lock()
defer r.mu.Unlock() defer r.mu.Unlock()
@@ -159,57 +77,22 @@ func (r *recordingArchives) Evicted() []string {
return out return out
} }
// EvictedTargets returns a copy of the recorded target ids.
func (r *recordingArchives) EvictedTargets() []string {
r.mu.Lock()
defer r.mu.Unlock()
out := make([]string, len(r.evictedTargets))
copy(out, r.evictedTargets)
return out
}
// Renames returns a copy of the recorded renames.
func (r *recordingArchives) Renames() []archiveRename {
r.mu.Lock()
defer r.mu.Unlock()
out := make([]archiveRename, len(r.renames))
copy(out, r.renames)
return out
}
func newTestApp( func newTestApp(
t *testing.T, t *testing.T,
targets ...any, targets ...any,
) *fxtest.App { ) *fxtest.App {
t.Helper() t.Helper()
return newTestAppWithConfig(
t, &config.Config{DataDir: t.TempDir()}, targets...,
)
}
// newTestAppWithConfig is newTestApp over a caller-supplied Config.
func newTestAppWithConfig(
t *testing.T,
cfg *config.Config,
targets ...any,
) *fxtest.App {
t.Helper()
return fxtest.New( return fxtest.New(
t, t,
// fx's own log is discarded, not sent to t.Logf: a hook still
// running after a start or stop timeout would write there after
// the test has returned.
fx.NopLogger,
fx.Provide( fx.Provide(
globals.New, globals.New,
logger.New, logger.New,
func() *config.Config { return cfg }, func() *config.Config {
return &config.Config{
DataDir: t.TempDir(),
}
},
database.New, database.New,
database.NewWebhookDBManager, database.NewWebhookDBManager,
healthcheck.New, healthcheck.New,
@@ -220,14 +103,12 @@ func newTestAppWithConfig(
func(n *recordingNotifier) delivery.Notifier { func(n *recordingNotifier) delivery.Notifier {
return n return n
}, },
func() *recordingArchives { func() *recordingEvictor {
return &recordingArchives{} return &recordingEvictor{}
}, },
func(r *recordingArchives) delivery.Archives { func(r *recordingEvictor) delivery.WebhookEvictor {
return r return r
}, },
metrics.NewRegistry,
metrics.New,
middleware.New, middleware.New,
delivery.NewGuard, delivery.NewGuard,
handlers.New, handlers.New,
@@ -295,7 +176,7 @@ func TestHandleIndex_Authenticated(t *testing.T) {
assert.Equal(t, http.StatusSeeOther, w2.Code) assert.Equal(t, http.StatusSeeOther, w2.Code)
assert.Equal( assert.Equal(
t, "/hooks", w2.Header().Get("Location"), t, "/sources", w2.Header().Get("Location"),
) )
} }
@@ -426,14 +307,10 @@ func TestRenderTemplateMidRenderErrorSendsNoPartialBody(t *testing.T) {
t, http.StatusInternalServerError, w.Code, t, http.StatusInternalServerError, w.Code,
"a failed render must report a 500", "a failed render must report a 500",
) )
assert.NotContains( assert.Equal(
t, w.Body.String(), partialPageMarker, t, "Internal server error\n", w.Body.String(),
"the response must carry no part of the aborted page", "the response must carry no part of the aborted page",
) )
assert.Contains(
t, w.Body.String(), "500 Internal Server Error",
"a failed render must answer with the error page",
)
} }
func TestBuildDatabaseTargetConfig_Valid(t *testing.T) { func TestBuildDatabaseTargetConfig_Valid(t *testing.T) {
+2 -2
View File
@@ -5,13 +5,13 @@ import (
) )
// HandleIndex returns a handler for the root path that redirects // HandleIndex returns a handler for the root path that redirects
// based on authentication state: authenticated users go to /hooks // based on authentication state: authenticated users go to /sources
// (the dashboard), unauthenticated users go to the login page. // (the dashboard), unauthenticated users go to the login page.
func (s *Handlers) HandleIndex() http.HandlerFunc { func (s *Handlers) HandleIndex() http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) { return func(w http.ResponseWriter, r *http.Request) {
sess, err := s.session.Get(r) sess, err := s.session.Get(r)
if err == nil && s.session.IsAuthenticated(sess) { if err == nil && s.session.IsAuthenticated(sess) {
http.Redirect(w, r, "/hooks", http.StatusSeeOther) http.Redirect(w, r, "/sources", http.StatusSeeOther)
return return
} }
+5 -5
View File
@@ -4,7 +4,7 @@ package handlers_test
// this package reach a value an UNAUTHENTICATED client picks outright // this package reach a value an UNAUTHENTICATED client picks outright
// and of a length it picks outright: // and of a length it picks outright:
// //
// - the unknown-entrypoint DEBUG line on /h/{uuid}, whose // - the unknown-entrypoint DEBUG line on /webhook/{uuid}, whose
// path segment matched no stored entrypoint and so is bounded by // path segment matched no stored entrypoint and so is bounded by
// nothing; // nothing;
// - the failed-login DEBUG lines, whose username is a form field. // - the failed-login DEBUG lines, whose username is a form field.
@@ -190,12 +190,12 @@ func assertNoClientText(t *testing.T, buf *bytes.Buffer) {
// route pattern. // route pattern.
func receiverRouter(h *handlers.Handlers) *chi.Mux { func receiverRouter(h *handlers.Handlers) *chi.Mux {
router := chi.NewRouter() router := chi.NewRouter()
router.Post("/h/{uuid}", h.HandleWebhook()) router.Post("/webhook/{uuid}", h.HandleWebhook())
return router return router
} }
// postReceiver sends one POST at /h/<segment>. // postReceiver sends one POST at /webhook/<segment>.
// //
// RawPath is cleared after parsing so chi routes on the decoded path // RawPath is cleared after parsing so chi routes on the decoded path
// and the handler sees the raw bytes rather than their percent-escaped // and the handler sees the raw bytes rather than their percent-escaped
@@ -210,7 +210,7 @@ func postReceiver(
req := httptest.NewRequestWithContext( req := httptest.NewRequestWithContext(
context.Background(), context.Background(),
http.MethodPost, http.MethodPost,
"/h/"+url.PathEscape(segment), "/webhook/"+url.PathEscape(segment),
strings.NewReader(""), strings.NewReader(""),
) )
req.URL.RawPath = "" req.URL.RawPath = ""
@@ -507,7 +507,7 @@ func TestVerificationCapacity_LogLineDoesNotTrackPathSize(
http.StatusServiceUnavailable, http.StatusServiceUnavailable,
postLoginAtPath( postLoginAtPath(
t, h, t, h,
"/hook/"+url.PathEscape( "/source/"+url.PathEscape(
oversizedFill(fill), oversizedFill(fill),
)+"/login", )+"/login",
), ),
-21
View File
@@ -1,21 +0,0 @@
package handlers
import (
"net/http"
"github.com/prometheus/client_golang/prometheus/promhttp"
)
// HandleMetrics returns the Prometheus scrape handler for the
// registry built by metrics.NewRegistry, which the HTTP, delivery, Go
// runtime and process collectors register on. It is what
// promhttp.Handler builds for the global default registry, including
// the promhttp_metric_handler_* series that count scrapes, pointed at
// that registry instead.
func (s *Handlers) HandleMetrics() http.HandlerFunc {
reg := s.params.Registry
return promhttp.InstrumentMetricHandler(
reg, promhttp.HandlerFor(reg, promhttp.HandlerOpts{}),
).ServeHTTP
}
-109
View File
@@ -1,109 +0,0 @@
package handlers
import "net/http"
// noticeParam is the query parameter an action's redirect carries its
// notice code in.
const noticeParam = "notice"
// noticeCode names one of the fixed lines noticeFor knows. An action
// redirects with the code rather than the line, so nothing a client
// puts in the URL reaches the page: a code noticeFor does not know
// shows nothing.
type noticeCode string
// The codes of the actions on the webhook pages and of signing out.
// Replay's codes, with the reasons a replay can be refused, and
// resubmit's codes are defined beside those actions.
const (
webhookCreated noticeCode = "webhook-created"
webhookSaved noticeCode = "webhook-saved"
webhookDeleted noticeCode = "webhook-deleted"
entrypointAdded noticeCode = "entrypoint-added"
entrypointDeleted noticeCode = "entrypoint-deleted"
entrypointActivated noticeCode = "entrypoint-activated"
entrypointDeactivated noticeCode = "entrypoint-deactivated"
targetAdded noticeCode = "target-added"
targetSaved noticeCode = "target-saved"
targetDeleted noticeCode = "target-deleted"
targetActivated noticeCode = "target-activated"
targetDeactivated noticeCode = "target-deactivated"
signedOut noticeCode = "signed-out"
)
// notice is the line templates/notice.html shows above a page to say
// what an action did.
type notice struct {
Text string
// Failed shows the line as an error: the action was refused.
Failed bool
}
// noticeFor returns the notice the request's URL names, or nil when it
// names none or an unknown code.
func noticeFor(r *http.Request) *notice {
n, ok := map[noticeCode]notice{
webhookCreated: {Text: "Webhook created."},
webhookSaved: {Text: "Webhook saved."},
webhookDeleted: {Text: "Webhook deleted."},
entrypointAdded: {Text: "Entrypoint added."},
entrypointDeleted: {Text: "Entrypoint deleted."},
entrypointActivated: {Text: "Entrypoint activated."},
entrypointDeactivated: {Text: "Entrypoint deactivated."},
targetAdded: {Text: "Target added."},
targetSaved: {Text: "Target saved."},
targetDeleted: {Text: "Target deleted."},
targetActivated: {Text: "Target activated."},
targetDeactivated: {Text: "Target deactivated."},
signedOut: {Text: "Signed out."},
replayQueued: {
Text: "Replay queued: a new delivery was created " +
"against the target's current configuration.",
},
replayTargetDeleted: {
Text: "Not replayed: the target this delivery was for " +
"has been deleted. Recreate the target, then replay.",
Failed: true,
},
replayTargetMissing: {
Text: "Not replayed: the target this delivery was for " +
"no longer exists.",
Failed: true,
},
replayTargetInactive: {
Text: "Not replayed: the target this delivery was for " +
"is deactivated. Activate it, then replay.",
Failed: true,
},
replayNotTerminal: {
Text: "Not replayed: this delivery has not finished yet.",
Failed: true,
},
replayInFlight: {
Text: "Not replayed: a delivery of this event to this " +
"target is already in flight.",
Failed: true,
},
resubmitQueued: {
Text: "Resubmitted: a new event was created from the " +
"stored one and queued to every active target.",
},
resubmitNoTargets: {
Text: "Resubmitted: a new event was created, but this " +
"source has no active targets, so nothing was queued.",
},
}[noticeCode(r.URL.Query().Get(noticeParam))]
if !ok {
return nil
}
return &n
}
// withNotice returns path with code added as its notice.
func withNotice(path string, code noticeCode) string {
return path + "?" + noticeParam + "=" + string(code)
}
+28 -16
View File
@@ -1,6 +1,7 @@
package handlers package handlers
import ( import (
"context"
"net/http" "net/http"
"github.com/go-chi/chi" "github.com/go-chi/chi"
@@ -36,14 +37,14 @@ func (h *Handlers) HandlePasswordChange() http.HandlerFunc {
err := r.ParseForm() err := r.ParseForm()
if err != nil { if err != nil {
h.log.Error("failed to parse form", "error", err) h.log.Error("failed to parse form", "error", err)
h.renderError(w, r, http.StatusBadRequest) http.Error(w, "Bad request", http.StatusBadRequest)
return return
} }
successMessage, errorMessage, handled := h.applyPasswordChange( successMessage, errorMessage, handled := h.applyPasswordChange(
r.Context(),
w, w,
r,
sessionUsername, sessionUsername,
// PostFormValue, not FormValue: the credential must // PostFormValue, not FormValue: the credential must
// come from the body, never from the query string. // come from the body, never from the query string.
@@ -65,12 +66,12 @@ func (h *Handlers) HandlePasswordChange() http.HandlerFunc {
// applyPasswordChange verifies the current password and, on success, // applyPasswordChange verifies the current password and, on success,
// persists a fresh hash for the user, reusing the same helpers that // persists a fresh hash for the user, reusing the same helpers that
// bootstrap the admin user. It returns the success and error messages // bootstrap the admin user. It returns the success and error messages
// to display on the profile page. On an internal failure it writes the // to display on the profile page. On an internal failure it writes a
// error page itself and returns handled=false, signalling the caller // 500 response itself and returns handled=false, signalling the caller
// to stop without re-rendering the page. // to stop without re-rendering the page.
func (h *Handlers) applyPasswordChange( func (h *Handlers) applyPasswordChange(
ctx context.Context,
w http.ResponseWriter, w http.ResponseWriter,
r *http.Request,
username, currentPassword, newPassword, confirmPassword string, username, currentPassword, newPassword, confirmPassword string,
) (string, string, bool) { ) (string, string, bool) {
// This endpoint verifies one password and hashes another, at // This endpoint verifies one password and hashes another, at
@@ -78,10 +79,15 @@ func (h *Handlers) applyPasswordChange(
// endpoint uses. The bound is per hash, not per endpoint: leaving // endpoint uses. The bound is per hash, not per endpoint: leaving
// this path outside it would leave a hole in it. The slot is held // this path outside it would leave a hole in it. The slot is held
// across both hashes. // across both hashes.
release, ok := h.mw.BeginPasswordVerification(r.Context()) release, ok := h.mw.BeginPasswordVerification(ctx)
if !ok { if !ok {
h.log.Warn("password verification capacity exhausted") h.log.Warn("password verification capacity exhausted")
h.renderError(w, r, http.StatusServiceUnavailable) http.Error(
w,
"The server is busy verifying credentials. "+
"Please try again.",
http.StatusServiceUnavailable,
)
return "", "", false return "", "", false
} }
@@ -97,7 +103,7 @@ func (h *Handlers) applyPasswordChange(
).First(&user).Error ).First(&user).Error
if err != nil { if err != nil {
h.serverError( h.serverError(
w, r, "failed to load user for password change", err, w, "failed to load user for password change", err,
) )
return "", "", false return "", "", false
@@ -107,7 +113,7 @@ func (h *Handlers) applyPasswordChange(
currentPassword, user.Password, currentPassword, user.Password,
) )
if err != nil { if err != nil {
h.serverError(w, r, "failed to verify password", err) h.serverError(w, "failed to verify password", err)
return "", "", false return "", "", false
} }
@@ -126,7 +132,7 @@ func (h *Handlers) applyPasswordChange(
hashedPassword, err := database.HashPassword(newPassword) hashedPassword, err := database.HashPassword(newPassword)
if err != nil { if err != nil {
h.serverError(w, r, "failed to hash new password", err) h.serverError(w, "failed to hash new password", err)
return "", "", false return "", "", false
} }
@@ -135,7 +141,7 @@ func (h *Handlers) applyPasswordChange(
"password", hashedPassword, "password", hashedPassword,
).Error ).Error
if err != nil { if err != nil {
h.serverError(w, r, "failed to update password", err) h.serverError(w, "failed to update password", err)
return "", "", false return "", "", false
} }
@@ -156,7 +162,7 @@ func (h *Handlers) profileOwnerOrDeny(
) (string, string, bool) { ) (string, string, bool) {
requestedUsername := chi.URLParam(r, "username") requestedUsername := chi.URLParam(r, "username")
if requestedUsername == "" { if requestedUsername == "" {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return "", "", false return "", "", false
} }
@@ -166,7 +172,7 @@ func (h *Handlers) profileOwnerOrDeny(
// unexpected retrieval error. // unexpected retrieval error.
sess, err := h.session.Get(r) sess, err := h.session.Get(r)
if err != nil { if err != nil {
h.serverError(w, r, "failed to get session", err) h.serverError(w, "failed to get session", err)
return "", "", false return "", "", false
} }
@@ -174,7 +180,10 @@ func (h *Handlers) profileOwnerOrDeny(
sessionUsername, ok := h.session.GetUsername(sess) sessionUsername, ok := h.session.GetUsername(sess)
if !ok { if !ok {
h.log.Error("authenticated session missing username") h.log.Error("authenticated session missing username")
h.renderError(w, r, http.StatusInternalServerError) http.Error(
w, "Internal server error",
http.StatusInternalServerError,
)
return "", "", false return "", "", false
} }
@@ -182,14 +191,17 @@ func (h *Handlers) profileOwnerOrDeny(
sessionUserID, ok := h.session.GetUserID(sess) sessionUserID, ok := h.session.GetUserID(sess)
if !ok { if !ok {
h.log.Error("authenticated session missing user ID") h.log.Error("authenticated session missing user ID")
h.renderError(w, r, http.StatusInternalServerError) http.Error(
w, "Internal server error",
http.StatusInternalServerError,
)
return "", "", false return "", "", false
} }
// Only allow users to act on their own profile. // Only allow users to act on their own profile.
if requestedUsername != sessionUsername { if requestedUsername != sessionUsername {
h.renderError(w, r, http.StatusForbidden) http.Error(w, "Forbidden", http.StatusForbidden)
return "", "", false return "", "", false
} }
+3 -10
View File
@@ -88,8 +88,6 @@ func TestHandleProfile_OwnProfile_OK(t *testing.T) {
h.HandleProfile().ServeHTTP(w, req) h.HandleProfile().ServeHTTP(w, req)
assert.Equal(t, http.StatusOK, w.Code) assert.Equal(t, http.StatusOK, w.Code)
assert.Contains(t, w.Body.String(), "Account Information")
assert.NotContains(t, w.Body.String(), "Account Type")
} }
func TestHandleProfile_OtherProfile_Forbidden(t *testing.T) { func TestHandleProfile_OtherProfile_Forbidden(t *testing.T) {
@@ -128,9 +126,7 @@ func TestUserRoute_Unauthenticated_RedirectedByMiddleware(t *testing.T) {
var sess *session.Session var sess *session.Session
var h *handlers.Handlers app := newTestApp(t, &log, &cfg, &sess)
app := newTestApp(t, &log, &cfg, &sess, &h)
app.RequireStart() app.RequireStart()
t.Cleanup(app.RequireStop) t.Cleanup(app.RequireStop)
@@ -141,7 +137,7 @@ func TestUserRoute_Unauthenticated_RedirectedByMiddleware(t *testing.T) {
router := chi.NewRouter() router := chi.NewRouter()
router.Route("/user/{username}", func(r chi.Router) { router.Route("/user/{username}", func(r chi.Router) {
r.Use(mw.CSRF(h.HandleErrorPage(http.StatusForbidden))) r.Use(mw.CSRF())
r.Use(mw.RequireAuth()) r.Use(mw.RequireAuth())
r.Get("/", func(w http.ResponseWriter, _ *http.Request) { r.Get("/", func(w http.ResponseWriter, _ *http.Request) {
handlerReached = true handlerReached = true
@@ -162,10 +158,7 @@ func TestUserRoute_Unauthenticated_RedirectedByMiddleware(t *testing.T) {
"handler must not be reached for unauthenticated request", "handler must not be reached for unauthenticated request",
) )
assert.Equal(t, http.StatusSeeOther, w.Code) assert.Equal(t, http.StatusSeeOther, w.Code)
assert.Equal( assert.Equal(t, "/pages/login", w.Header().Get("Location"))
t, "/pages/login?next=%2Fuser%2Ftestuser",
w.Header().Get("Location"),
)
} }
// passwordChangeRequest builds a POST request to the password-change // passwordChangeRequest builds a POST request to the password-change
-293
View File
@@ -1,293 +0,0 @@
package handlers
import (
"net/http"
"slices"
"strconv"
"time"
"github.com/dustin/go-humanize"
"gorm.io/gorm"
"sneak.berlin/go/webhooker/internal/database"
)
// recentEventColumns is the recent events list's projection. It
// leaves out the body, for the reason maxRenderedBodyBytes gives,
// and reads its size from body_bytes, recorded when the event was
// stored.
const recentEventColumns = "id, created_at, method, content_type, " +
"resubmitted_from_id, body_bytes"
// recentAttemptColumns is the part of a recorded attempt the list
// uses. The event log's deliveryResultColumns also reads response
// bodies, which the list does not show.
const recentAttemptColumns = "delivery_id, status_code, created_at"
// RecentEventView is one row of the recent events list on a
// webhook's page.
type RecentEventView struct {
Method string
ContentType string
// ResubmittedFromID names the event this one was copied from,
// empty for an event that arrived on the receiver.
ResubmittedFromID string
// Received is how long ago the event arrived, and ReceivedUTC
// the full timestamp the page shows on hover.
Received string
ReceivedUTC string
// Size is the size of the stored body.
Size string
// ProcessingTime is how long the event's slowest delivery
// took; see processingTime.
ProcessingTime string
// Status is what the webhook's HTTP target answered, and
// StatusClass its colour; see targetStatus. Both are empty
// unless the webhook has exactly one HTTP target.
Status string
StatusClass string
}
// recentEventRow is one row of recentEventColumns.
type recentEventRow struct {
ID string
CreatedAt time.Time
Method string
ContentType string
ResubmittedFromID *string
BodyBytes uint64
}
// recentAttemptRow is one row of recentAttemptColumns. CreatedAt is
// when the attempt's result was recorded, which is when the attempt
// finished.
type recentAttemptRow struct {
DeliveryID string
StatusCode int
CreatedAt time.Time
}
// singleHTTPTargetID returns the ID of the webhook's HTTP target
// when it has exactly one, and "" when it has none or several.
func singleHTTPTargetID(targets []database.Target) string {
id := ""
count := 0
for i := range targets {
if targets[i].Type == database.TargetTypeHTTP {
id = targets[i].ID
count++
}
}
if count != 1 {
return ""
}
return id
}
// loadRecentEvents loads the webhook's recentEventLimit newest
// events for its page, newest first. statusTargetID is the
// webhook's only HTTP target, or "" when the list shows no status.
func loadRecentEvents(
webhookDB *gorm.DB, webhookID, statusTargetID string,
) ([]RecentEventView, error) {
var rows []recentEventRow
err := webhookDB.Model(&database.Event{}).
Select(recentEventColumns).
Where("webhook_id = ?", webhookID).
Order("created_at DESC").
Limit(recentEventLimit).
Find(&rows).Error
if err != nil {
return nil, err
}
eventIDs := make([]string, len(rows))
for i := range rows {
eventIDs[i] = rows[i].ID
}
// Oldest first, so an event's last delivery to a target is its
// newest: a replay adds a delivery rather than changing the
// earlier one.
var deliveries []database.Delivery
err = webhookDB.
Select("id, event_id, target_id, status, created_at").
Where("event_id IN ?", eventIDs).
Order("created_at ASC").
Find(&deliveries).Error
if err != nil {
return nil, err
}
byEvent := make(map[string][]database.Delivery, len(rows))
deliveryIDs := make([]string, len(deliveries))
for i := range deliveries {
eventID := deliveries[i].EventID
byEvent[eventID] = append(byEvent[eventID], deliveries[i])
deliveryIDs[i] = deliveries[i].ID
}
attempts, err := loadRecentAttempts(webhookDB, deliveryIDs)
if err != nil {
return nil, err
}
views := make([]RecentEventView, len(rows))
for i := range rows {
views[i] = rows[i].view(
byEvent[rows[i].ID], attempts, statusTargetID,
)
}
return views, nil
}
// loadRecentAttempts loads the recorded attempts of the listed
// events' deliveries, keyed by delivery ID, each delivery's in
// attempt order. The IDs go in chunks for the reason
// deliveryIDChunkSize gives.
func loadRecentAttempts(
webhookDB *gorm.DB, deliveryIDs []string,
) (map[string][]recentAttemptRow, error) {
byDelivery := make(map[string][]recentAttemptRow)
for chunk := range slices.Chunk(deliveryIDs, deliveryIDChunkSize) {
var rows []recentAttemptRow
err := webhookDB.Model(&database.DeliveryResult{}).
Select(recentAttemptColumns).
Where("delivery_id IN ?", chunk).
Order("attempt_num ASC").
Find(&rows).Error
if err != nil {
return nil, err
}
for i := range rows {
id := rows[i].DeliveryID
byDelivery[id] = append(byDelivery[id], rows[i])
}
}
return byDelivery, nil
}
// view projects a loaded row for rendering. deliveries is the
// event's deliveries, oldest first, and attempts their recorded
// attempts keyed by delivery ID.
func (r *recentEventRow) view(
deliveries []database.Delivery,
attempts map[string][]recentAttemptRow,
statusTargetID string,
) RecentEventView {
v := RecentEventView{
Method: r.Method,
ContentType: r.ContentType,
Received: humanize.Time(r.CreatedAt),
ReceivedUTC: r.CreatedAt.UTC().Format(time.DateTime) + " UTC",
Size: humanize.Bytes(r.BodyBytes),
ProcessingTime: processingTime(deliveries, attempts),
}
if r.ResubmittedFromID != nil {
v.ResubmittedFromID = *r.ResubmittedFromID
}
if statusTargetID != "" {
v.Status, v.StatusClass = targetStatus(
deliveries, attempts, statusTargetID,
)
}
return v
}
// processingTime is how long the event's slowest delivery took,
// from being queued to its last recorded attempt, time spent
// waiting between retries included. A delivery is queued when its
// event is received, or when an operator replays it, so a replay
// is timed from the replay rather than from the event's arrival.
// It is "in progress" while any delivery is pending or retrying,
// and empty for an event with no deliveries.
func processingTime(
deliveries []database.Delivery,
attempts map[string][]recentAttemptRow,
) string {
if len(deliveries) == 0 {
return ""
}
var slowest time.Duration
for i := range deliveries {
if !deliveries[i].Status.Terminal() {
return "in progress"
}
tries := attempts[deliveries[i].ID]
if len(tries) == 0 {
continue
}
last := tries[len(tries)-1].CreatedAt
slowest = max(slowest, last.Sub(deliveries[i].CreatedAt))
}
return slowest.Round(time.Millisecond).String()
}
// targetStatus is what the target answered for the event, and the
// colour to show it in: the HTTP status code of the last attempt of
// the event's newest delivery to the target. Without a code it is
// "no response" when that attempt failed before a response
// arrived, the delivery's status ("pending") before any attempt,
// and "not sent" when the event has no delivery to the target.
func targetStatus(
deliveries []database.Delivery,
attempts map[string][]recentAttemptRow,
targetID string,
) (string, string) {
newest := -1
for i := range deliveries {
if deliveries[i].TargetID == targetID {
newest = i
}
}
if newest < 0 {
return "not sent", "text-gray-400"
}
tries := attempts[deliveries[newest].ID]
if len(tries) == 0 {
return string(deliveries[newest].Status), "text-gray-400"
}
code := tries[len(tries)-1].StatusCode
switch {
case code == 0:
return "no response", "text-red-600"
case code >= http.StatusInternalServerError:
return strconv.Itoa(code), "text-red-600"
case code >= http.StatusBadRequest:
return strconv.Itoa(code), "text-yellow-600"
case code >= http.StatusMultipleChoices:
return strconv.Itoa(code), "text-gray-500"
case code >= http.StatusOK:
return strconv.Itoa(code), "text-green-600"
default:
return strconv.Itoa(code), "text-gray-500"
}
}
-362
View File
@@ -1,362 +0,0 @@
package handlers_test
import (
"context"
"fmt"
"net/http"
"net/http/httptest"
"strings"
"testing"
"time"
"github.com/go-chi/chi"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"gorm.io/gorm"
"gorm.io/gorm/clause"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/handlers"
"sneak.berlin/go/webhooker/internal/session"
)
// statusTitle marks the status column's cell in a recent events
// row; it is absent from the page when the column is not shown.
const statusTitle = `title="HTTP status from the HTTP target"`
// recentEventsFixture is one started app and a webhook whose
// recent events list a test fills.
type recentEventsFixture struct {
h *handlers.Handlers
sess *session.Session
db *database.Database
webhook *database.Webhook
webhookDB *gorm.DB
}
func newRecentEventsFixture(t *testing.T) *recentEventsFixture {
t.Helper()
f := &recentEventsFixture{}
var dbMgr *database.WebhookDBManager
app := newTestApp(t, &f.h, &f.sess, &f.db, &dbMgr)
app.RequireStart()
t.Cleanup(app.RequireStop)
f.webhook = seedWebhook(t, f.db)
webhookDB, err := dbMgr.GetDB(f.webhook.ID)
require.NoError(t, err)
f.webhookDB = webhookDB
return f
}
func (f *recentEventsFixture) render(t *testing.T) string {
t.Helper()
return renderSourceDetailPage(t, f.h, f.sess, f.webhook.ID)
}
// event records an event received at receivedAt, with its body's
// size as the receiver records it.
func (f *recentEventsFixture) event(
t *testing.T, contentType, body string, receivedAt time.Time,
) *database.Event {
t.Helper()
event := &database.Event{
WebhookID: f.webhook.ID,
Method: http.MethodPost,
Body: body,
BodyBytes: int64(len(body)),
ContentType: contentType,
}
event.CreatedAt = receivedAt
require.NoError(t, f.webhookDB.Omit(
clause.Associations,
).Create(event).Error)
return event
}
// delivery records a delivery of the event to the target, queued
// when the event was received.
func (f *recentEventsFixture) delivery(
t *testing.T,
event *database.Event,
targetID string,
status database.DeliveryStatus,
) *database.Delivery {
t.Helper()
return f.deliveryQueuedAt(
t, event, targetID, status, event.CreatedAt,
)
}
// deliveryQueuedAt records a delivery of the event to the target,
// queued at queuedAt, as a replay is.
func (f *recentEventsFixture) deliveryQueuedAt(
t *testing.T,
event *database.Event,
targetID string,
status database.DeliveryStatus,
queuedAt time.Time,
) *database.Delivery {
t.Helper()
dlv := &database.Delivery{
EventID: event.ID,
TargetID: targetID,
Status: status,
}
dlv.CreatedAt = queuedAt
require.NoError(t, f.webhookDB.Omit(
clause.Associations,
).Create(dlv).Error)
return dlv
}
// attempt records one attempt of the delivery that finished took
// after the delivery was queued, with HTTP status code (0 for no
// response).
func (f *recentEventsFixture) attempt(
t *testing.T, dlv *database.Delivery, code int, took time.Duration,
) {
t.Helper()
result := &database.DeliveryResult{
DeliveryID: dlv.ID,
AttemptNum: 1,
StatusCode: code,
}
result.CreatedAt = dlv.CreatedAt.Add(took)
require.NoError(t, f.webhookDB.Omit(
clause.Associations,
).Create(result).Error)
}
// statusCell is the status column's cell as the page renders it.
func statusCell(class, text string) string {
return `<span class="font-medium ` + class + `" ` + statusTitle +
`>` + text + `</span>`
}
// TestHandleSourceDetail_ShowsFiftyNewestEvents proves the list is
// headed "50 Most Recent Events" and holds the 50 newest events,
// newest first, and not one more.
func TestHandleSourceDetail_ShowsFiftyNewestEvents(t *testing.T) {
t.Parallel()
f := newRecentEventsFixture(t)
base := time.Now().Add(-time.Hour)
for i := range 51 {
f.event(
t, fmt.Sprintf("application/x-recent-%02d", i), "{}",
base.Add(time.Duration(i)*time.Second),
)
}
body := f.render(t)
assert.Contains(t, body, ">50 Most Recent Events</h2>")
assert.Equal(t, 50, strings.Count(body, `title="Body size"`))
assert.NotContains(t, body, "application/x-recent-00")
assert.Contains(t, body, "application/x-recent-01")
assert.Less(
t,
strings.Index(body, "application/x-recent-50"),
strings.Index(body, "application/x-recent-49"),
)
}
// TestHandleSourceDetail_RecentEventColumns proves a row shows its
// time relative with the UTC timestamp on hover, its body size,
// and its processing time once every delivery has finished.
func TestHandleSourceDetail_RecentEventColumns(t *testing.T) {
t.Parallel()
f := newRecentEventsFixture(t)
logTarget := seedTarget(t, f.db, f.webhook.ID, database.TargetTypeLog)
receivedAt := time.Now().Add(-210 * time.Second).
UTC().Truncate(time.Second)
done := f.event(
t, contentTypeJSON, strings.Repeat("x", 2048), receivedAt,
)
f.attempt(
t,
f.delivery(t, done, logTarget.ID, database.DeliveryStatusDelivered),
0, 1500*time.Millisecond,
)
waiting := f.event(t, "text/plain", "{}", receivedAt)
f.delivery(t, waiting, logTarget.ID, database.DeliveryStatusPending)
body := f.render(t)
assert.Contains(
t, body,
`<span title="`+receivedAt.Format(time.DateTime)+
` UTC">3 minutes ago</span>`,
)
assert.Contains(t, body, `<span title="Body size">2.0 kB</span>`)
assert.Contains(t, body, ">1.5s</span>")
assert.Contains(t, body, ">in progress</span>")
}
// TestHandleSourceDetail_StatusWithSingleHTTPTarget proves that a
// webhook with exactly one HTTP target shows, colour-coded, what
// that target answered for each event. The log target beside it
// does not count against "exactly one".
func TestHandleSourceDetail_StatusWithSingleHTTPTarget(t *testing.T) {
t.Parallel()
f := newRecentEventsFixture(t)
target := seedTarget(t, f.db, f.webhook.ID, database.TargetTypeHTTP)
seedTarget(t, f.db, f.webhook.ID, database.TargetTypeLog)
now := time.Now()
for _, code := range []int{204, 302, 404, 503, 0} {
dlv := f.delivery(
t, f.event(t, contentTypeJSON, "{}", now), target.ID,
database.DeliveryStatusDelivered,
)
f.attempt(t, dlv, code, time.Second)
}
f.delivery(
t, f.event(t, contentTypeJSON, "{}", now), target.ID,
database.DeliveryStatusPending,
)
f.event(t, contentTypeJSON, "{}", now)
// A replay is a newer delivery, and its answer is the one shown.
replayed := f.event(t, contentTypeJSON, "{}", now)
f.attempt(t, f.delivery(
t, replayed, target.ID, database.DeliveryStatusFailed,
), 502, time.Second)
f.attempt(t, f.deliveryQueuedAt(
t, replayed, target.ID, database.DeliveryStatusDelivered,
now.Add(time.Minute),
), 200, time.Second)
body := f.render(t)
assert.Contains(t, body, statusCell("text-green-600", "204"))
assert.Contains(t, body, statusCell("text-gray-500", "302"))
assert.Contains(t, body, statusCell("text-yellow-600", "404"))
assert.Contains(t, body, statusCell("text-red-600", "503"))
assert.Contains(t, body, statusCell("text-red-600", "no response"))
assert.Contains(t, body, statusCell("text-gray-400", "pending"))
assert.Contains(t, body, statusCell("text-gray-400", "not sent"))
assert.Contains(t, body, statusCell("text-green-600", "200"))
assert.NotContains(t, body, ">502<")
}
// TestHandleSourceDetail_NoStatusWithoutSingleHTTPTarget proves the
// status column is absent when the webhook has no HTTP target or
// more than one.
func TestHandleSourceDetail_NoStatusWithoutSingleHTTPTarget(
t *testing.T,
) {
t.Parallel()
cases := map[string][]database.TargetType{
"none": {database.TargetTypeLog},
"several": {database.TargetTypeHTTP, database.TargetTypeHTTP},
}
for name, types := range cases {
t.Run(name, func(t *testing.T) {
t.Parallel()
f := newRecentEventsFixture(t)
event := f.event(t, contentTypeJSON, "{}", time.Now())
for _, tt := range types {
target := seedTarget(t, f.db, f.webhook.ID, tt)
f.attempt(t, f.delivery(
t, event, target.ID,
database.DeliveryStatusDelivered,
), 200, time.Second)
}
body := f.render(t)
assert.Contains(t, body, `title="Body size"`)
assert.NotContains(t, body, statusTitle)
})
}
}
// TestHandleWebhook_RecordsBodySize proves the receiver records the
// body's size in bytes, not characters, with the event it stores.
func TestHandleWebhook_RecordsBodySize(t *testing.T) {
t.Parallel()
f := newRecentEventsFixture(t)
seedEntrypoint(t, f.db, f.webhook.ID)
// Two bytes per character.
body := strings.Repeat("é", 1024)
req := httptest.NewRequestWithContext(
context.Background(), http.MethodPost, "/h/x",
strings.NewReader(body),
)
rctx := chi.NewRouteContext()
rctx.URLParams.Add("uuid", "ep-"+f.webhook.ID)
req = req.WithContext(context.WithValue(
req.Context(), chi.RouteCtxKey, rctx,
))
w := httptest.NewRecorder()
f.h.HandleWebhook().ServeHTTP(w, req)
require.Equal(t, http.StatusOK, w.Code)
var stored database.Event
require.NoError(t, f.webhookDB.First(&stored).Error)
assert.Equal(t, int64(2048), stored.BodyBytes)
}
// TestHandleSourceDetail_FailedLoadIsAnError proves that when the
// list cannot be loaded the page answers with an error, rather than
// an empty list claiming the webhook has no events.
func TestHandleSourceDetail_FailedLoadIsAnError(t *testing.T) {
t.Parallel()
f := newRecentEventsFixture(t)
target := seedTarget(t, f.db, f.webhook.ID, database.TargetTypeHTTP)
f.attempt(t, f.delivery(
t, f.event(t, contentTypeJSON, "{}", time.Now()), target.ID,
database.DeliveryStatusDelivered,
), 200, time.Second)
// The attempts are the list's last query, so its events and
// deliveries have already loaded when it fails.
require.NoError(t, f.webhookDB.Exec(
"DROP TABLE delivery_results",
).Error)
w := serveSourceDetailPage(t, f.h, f.sess, f.webhook.ID)
assert.Equal(t, http.StatusInternalServerError, w.Code)
assert.NotContains(t, w.Body.String(), "No events received yet.")
}
-128
View File
@@ -1,128 +0,0 @@
package handlers
import (
"net/http"
"net/netip"
"strconv"
"strings"
"sneak.berlin/go/webhooker/internal/config"
)
// notSet is what the Settings page shows for a value that is empty.
const notSet = "not set"
// settingRow is one line of the Settings page: an environment
// variable, what it controls, and the value the server loaded for it.
type settingRow struct {
Name string
Description string
Value string
}
// HandleSettings returns a handler for the read-only Settings page,
// which lists the configuration the server started with.
func (h *Handlers) HandleSettings() http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) {
h.renderTemplate(w, r, "settings.html", map[string]any{
"Settings": settingRows(h.params.Config),
})
}
}
// settingRows lists every field of cfg under the environment variable
// it is read from, with the description the README's configuration
// table gives it (less its pointers to other README sections), in the
// table's order. METRICS_PASSWORD and SENTRY_DSN are credentials, so
// their values never reach the page: only whether they are set.
func settingRows(cfg *config.Config) []settingRow {
metricsUsername := cfg.MetricsUsername
if metricsUsername == "" {
metricsUsername = notSet
}
return []settingRow{
{"WEBHOOKER_ENVIRONMENT", "dev or prod", cfg.Environment},
{"PORT", "HTTP listen port", strconv.Itoa(cfg.Port)},
{
"BIND_ADDRESS",
"IP address the HTTP listener binds. Loopback by default, " +
"so the cleartext listener is not published on every " +
"interface. The Docker image ships 0.0.0.0 instead",
cfg.BindAddress,
},
{"DATA_DIR", "Directory for all SQLite databases", cfg.DataDir},
{"DEBUG", "Enable debug logging", strconv.FormatBool(cfg.Debug)},
{
"METRICS_USERNAME",
"Basic auth username for /metrics. Must be set together " +
"with METRICS_PASSWORD; one without the other fails " +
"startup",
metricsUsername,
},
{
"METRICS_PASSWORD",
"Basic auth password for /metrics. Must be set together " +
"with METRICS_USERNAME; one without the other fails " +
"startup",
setOrNotSet(cfg.MetricsPassword),
},
{
"SENTRY_DSN",
"Sentry error reporting DSN. Unset leaves error reporting " +
"off; a value the Sentry SDK cannot parse fails startup " +
"rather than serving with reporting silently off",
setOrNotSet(cfg.SentryDSN),
},
{
"RETENTION_SWEEP_INTERVAL",
"How often the retention reaper and archive sweeper run " +
"(Go duration, must be positive)",
cfg.RetentionSweepInterval.String(),
},
{
"SESSION_IDLE_TIMEOUT",
"Idle session timeout (Go duration)",
cfg.SessionIdleTimeout.String(),
},
{
"RECEIVER_RATE_LIMIT",
"Receiver requests/minute per IP per entrypoint " +
"(10x that per IP across the route)",
strconv.Itoa(cfg.ReceiverRateLimit),
},
{
"TRUSTED_PROXIES",
"CIDRs whose forwarded headers are trusted. A set value " +
"replaces the default. If any client can reach webhooker, " +
"or the proxy in front of it, from an RFC 1918 source " +
"address, set it to the proxy's address alone",
cidrList(cfg.TrustedProxies),
},
{
"ALLOWED_EGRESS_CIDRS",
"CIDRs that delivery targets may reach despite the " +
"SSRF blocklist",
cidrList(cfg.AllowedEgressCIDRs),
},
}
}
// setOrNotSet is how the Settings page shows a credential: whether it
// has a value, never the value itself.
func setOrNotSet(value string) string {
if value == "" {
return notSet
}
return "set"
}
// cidrList renders a CIDR list setting for the Settings page.
func cidrList(prefixes []netip.Prefix) string {
if len(prefixes) == 0 {
return "none"
}
return strings.Join(config.PrefixStrings(prefixes), ", ")
}
-148
View File
@@ -1,148 +0,0 @@
package handlers_test
import (
"context"
"html"
"net/http"
"net/http/httptest"
"net/netip"
"regexp"
"testing"
"time"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/handlers"
"sneak.berlin/go/webhooker/internal/session"
)
// settingsShown renders the Settings page over cfg as a logged-in user
// and returns the value it shows for each variable name, plus the
// whole page.
func settingsShown(
t *testing.T, cfg *config.Config,
) (map[string]string, string) {
t.Helper()
var h *handlers.Handlers
var sess *session.Session
app := newTestAppWithConfig(t, cfg, &h, &sess)
app.RequireStart()
t.Cleanup(app.RequireStop)
req := httptest.NewRequestWithContext(
context.Background(), http.MethodGet, "/settings", nil,
)
for _, c := range authenticatedCookies(t, sess, "id", "admin") {
req.AddCookie(c)
}
w := httptest.NewRecorder()
h.HandleSettings().ServeHTTP(w, req)
require.Equal(t, http.StatusOK, w.Code)
body := w.Body.String()
row := regexp.MustCompile(
`<code[^>]*>([A-Z_]+)</code>\s*<code[^>]*>([^<]*)</code>`,
)
shown := map[string]string{}
for _, match := range row.FindAllStringSubmatch(body, -1) {
shown[match[1]] = html.UnescapeString(match[2])
}
return shown, body
}
func TestSettingsPageShowsLoadedConfiguration(t *testing.T) {
t.Parallel()
// Each of METRICS_USERNAME, METRICS_PASSWORD and SENTRY_DSN is the
// only one of the three set in one of the content tests, so each
// row is checked against its own field.
cfg := &config.Config{
DataDir: t.TempDir(),
Debug: true,
Environment: config.EnvironmentDev,
MetricsUsername: "scraper",
MetricsPassword: "",
Port: 9123,
SentryDSN: "",
BindAddress: "192.0.2.10",
RetentionSweepInterval: 17 * time.Minute,
SessionIdleTimeout: 3 * time.Hour,
ReceiverRateLimit: 77,
TrustedProxies: []netip.Prefix{
netip.MustParsePrefix("10.1.0.0/16"),
},
AllowedEgressCIDRs: []netip.Prefix{
netip.MustParsePrefix("192.168.5.0/24"),
netip.MustParsePrefix("fd00::/8"),
},
}
shown, body := settingsShown(t, cfg)
assert.Equal(t, map[string]string{
"WEBHOOKER_ENVIRONMENT": "dev",
"PORT": "9123",
"BIND_ADDRESS": "192.0.2.10",
"DATA_DIR": cfg.DataDir,
"DEBUG": "true",
"METRICS_USERNAME": "scraper",
"METRICS_PASSWORD": "not set",
"SENTRY_DSN": "not set",
"RETENTION_SWEEP_INTERVAL": "17m0s",
"SESSION_IDLE_TIMEOUT": "3h0m0s",
"RECEIVER_RATE_LIMIT": "77",
"TRUSTED_PROXIES": "10.1.0.0/16",
"ALLOWED_EGRESS_CIDRS": "192.168.5.0/24, fd00::/8",
}, shown)
assert.Contains(
t, body, `href="/settings"`,
"the navigation bar links to the page",
)
}
func TestSettingsPageShowsUnsetValues(t *testing.T) {
t.Parallel()
const metricsPassword = "metrics-password-1f9a"
shown, body := settingsShown(t, &config.Config{
DataDir: t.TempDir(),
MetricsPassword: metricsPassword,
})
assert.Equal(t, "not set", shown["METRICS_USERNAME"])
assert.Equal(t, "set", shown["METRICS_PASSWORD"])
assert.Equal(t, "not set", shown["SENTRY_DSN"])
assert.NotContains(t, body, metricsPassword)
assert.Equal(t, "none", shown["TRUSTED_PROXIES"])
assert.Equal(t, "none", shown["ALLOWED_EGRESS_CIDRS"])
}
func TestSettingsPageShowsSentryDSNOnlyAsSet(t *testing.T) {
t.Parallel()
const (
sentryKey = "dsnkey7c2e"
sentryDSN = "https://" + sentryKey + "@errors.example.com/42"
)
shown, body := settingsShown(t, &config.Config{
DataDir: t.TempDir(),
SentryDSN: sentryDSN,
})
assert.Equal(t, "not set", shown["METRICS_USERNAME"])
assert.Equal(t, "not set", shown["METRICS_PASSWORD"])
assert.Equal(t, "set", shown["SENTRY_DSN"])
assert.NotContains(t, body, sentryKey)
}
+87 -68
View File
@@ -15,7 +15,6 @@ import (
"gorm.io/gorm" "gorm.io/gorm"
"gorm.io/gorm/clause" "gorm.io/gorm/clause"
"sneak.berlin/go/webhooker/internal/database" "sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/delivery"
"sneak.berlin/go/webhooker/internal/handlers" "sneak.berlin/go/webhooker/internal/handlers"
"sneak.berlin/go/webhooker/internal/session" "sneak.berlin/go/webhooker/internal/session"
) )
@@ -80,10 +79,6 @@ func seedTarget(
// from a delete statement. // from a delete statement.
var errInjectedDelete = errors.New("injected delete failure") var errInjectedDelete = errors.New("injected delete failure")
// errInjectedSave is the failure failSaveOnTable reports from a
// save of an existing row.
var errInjectedSave = errors.New("injected save failure")
// seedEntrypoint inserts an entrypoint for a webhook. // seedEntrypoint inserts an entrypoint for a webhook.
func seedEntrypoint( func seedEntrypoint(
t *testing.T, t *testing.T,
@@ -151,42 +146,19 @@ func failDeleteOnTable(
) )
} }
// failSaveOnTable is failDeleteOnTable for saves: every update of
// an existing row in the named table fails.
func failSaveOnTable(
t *testing.T,
db *database.Database,
table string,
) {
t.Helper()
require.NoError(t, db.DB().Callback().Update().
Before("gorm:update").
Register(
"test:fail_save_"+table,
func(tx *gorm.DB) {
if tx.Statement.Table == table {
_ = tx.AddError(errInjectedSave)
}
},
),
)
}
// archivePathFor returns the archive database path the // archivePathFor returns the archive database path the
// delivery engine would use for a database target: beside the // delivery engine would use for a webhook: beside the webhook's
// webhook's event database in the data directory. // event database in the data directory.
func archivePathFor( func archivePathFor(
t *testing.T, t *testing.T,
mgr *database.WebhookDBManager, mgr *database.WebhookDBManager,
wh *database.Webhook, webhookID string,
tgt *database.Target,
) string { ) string {
t.Helper() t.Helper()
return filepath.Join( return filepath.Join(
filepath.Dir(mgr.DBPath(wh.ID)), filepath.Dir(mgr.DBPath(webhookID)),
delivery.ArchiveFileName(wh.Name, tgt.Name, tgt.ID), "archive-"+webhookID+".db",
) )
} }
@@ -223,8 +195,8 @@ func postRequest(
// TestHandleSourceDelete_EvictsArchiveWriter proves that // TestHandleSourceDelete_EvictsArchiveWriter proves that
// deleting a webhook reaches the delivery engine and releases // deleting a webhook reaches the delivery engine and releases
// the webhook's archive writers, exercised through the real // the webhook's archive writer, exercised through the real
// deletion handler rather than by calling the engine directly. // deletion handler rather than by calling the evictor directly.
func TestHandleSourceDelete_EvictsArchiveWriter(t *testing.T) { func TestHandleSourceDelete_EvictsArchiveWriter(t *testing.T) {
t.Parallel() t.Parallel()
@@ -232,7 +204,7 @@ func TestHandleSourceDelete_EvictsArchiveWriter(t *testing.T) {
h *handlers.Handlers h *handlers.Handlers
sess *session.Session sess *session.Session
db *database.Database db *database.Database
ev *recordingArchives ev *recordingEvictor
) )
app := newTestApp(t, &h, &sess, &db, &ev) app := newTestApp(t, &h, &sess, &db, &ev)
@@ -248,7 +220,7 @@ func TestHandleSourceDelete_EvictsArchiveWriter(t *testing.T) {
) )
req := postRequest( req := postRequest(
"/hook/"+wh.ID+"/delete", "/source/"+wh.ID+"/delete",
cookies, cookies,
map[string]string{paramSourceID: wh.ID}, map[string]string{paramSourceID: wh.ID},
) )
@@ -282,10 +254,9 @@ func TestHandleSourceDelete_KeepsArchiveFile(t *testing.T) {
t.Cleanup(app.RequireStop) t.Cleanup(app.RequireStop)
wh := seedWebhook(t, db) wh := seedWebhook(t, db)
tgt := seedTarget(t, db, wh.ID, database.TargetTypeDatabase)
// Place an archive file where the delivery engine would. // Place an archive file where the delivery engine would.
archivePath := archivePathFor(t, mgr, wh, tgt) archivePath := archivePathFor(t, mgr, wh.ID)
require.NoError( require.NoError(
t, t,
writeArchivePlaceholder(archivePath), writeArchivePlaceholder(archivePath),
@@ -296,7 +267,7 @@ func TestHandleSourceDelete_KeepsArchiveFile(t *testing.T) {
) )
req := postRequest( req := postRequest(
"/hook/"+wh.ID+"/delete", "/source/"+wh.ID+"/delete",
cookies, cookies,
map[string]string{paramSourceID: wh.ID}, map[string]string{paramSourceID: wh.ID},
) )
@@ -352,7 +323,7 @@ func TestHandleSourceDelete_FailedDeleteKeepsEverything(
) )
req := postRequest( req := postRequest(
"/hook/"+wh.ID+"/delete", "/source/"+wh.ID+"/delete",
cookies, cookies,
map[string]string{paramSourceID: wh.ID}, map[string]string{paramSourceID: wh.ID},
) )
@@ -366,7 +337,7 @@ func TestHandleSourceDelete_FailedDeleteKeepsEverything(
) )
assert.Empty( assert.Empty(
t, w.Header().Get("Location"), t, w.Header().Get("Location"),
"a failed deletion must not redirect to /hooks", "a failed deletion must not redirect to /sources",
) )
assert.Equal( assert.Equal(
@@ -431,7 +402,7 @@ func TestHandleSourceDelete_RemovesConfigAndEventDatabase(
) )
req := postRequest( req := postRequest(
"/hook/"+wh.ID+"/delete", "/source/"+wh.ID+"/delete",
cookies, cookies,
map[string]string{paramSourceID: wh.ID}, map[string]string{paramSourceID: wh.ID},
) )
@@ -440,9 +411,7 @@ func TestHandleSourceDelete_RemovesConfigAndEventDatabase(
h.HandleSourceDelete().ServeHTTP(w, req) h.HandleSourceDelete().ServeHTTP(w, req)
require.Equal(t, http.StatusSeeOther, w.Code) require.Equal(t, http.StatusSeeOther, w.Code)
assert.Equal( assert.Equal(t, "/sources", w.Header().Get("Location"))
t, "/hooks?notice=webhook-deleted", w.Header().Get("Location"),
)
assert.Equal( assert.Equal(
t, int64(0), t, int64(0),
@@ -466,17 +435,68 @@ func TestHandleSourceDelete_RemovesConfigAndEventDatabase(
) )
} }
// TestHandleTargetDelete_EvictsThatTarget proves that deleting a // TestHandleTargetDelete_EvictsWhenLastDatabaseTargetGone
// database target releases that target's archive writer and no // proves that removing the last database target releases the
// other: the webhook's other database target keeps its own. // archive writer.
func TestHandleTargetDelete_EvictsThatTarget(t *testing.T) { func TestHandleTargetDelete_EvictsWhenLastDatabaseTargetGone(
t *testing.T,
) {
t.Parallel() t.Parallel()
var ( var (
h *handlers.Handlers h *handlers.Handlers
sess *session.Session sess *session.Session
db *database.Database db *database.Database
ev *recordingArchives ev *recordingEvictor
)
app := newTestApp(t, &h, &sess, &db, &ev)
app.RequireStart()
t.Cleanup(app.RequireStop)
wh := seedWebhook(t, db)
tgt := seedTarget(
t, db, wh.ID, database.TargetTypeDatabase,
)
cookies := authenticatedCookies(
t, sess, deleteTestUserID, deleteTestUsername,
)
req := postRequest(
"/source/"+wh.ID+"/targets/"+tgt.ID+"/delete",
cookies,
map[string]string{
paramSourceID: wh.ID,
paramTargetID: tgt.ID,
},
)
w := httptest.NewRecorder()
h.HandleTargetDelete().ServeHTTP(w, req)
require.Equal(t, http.StatusSeeOther, w.Code)
assert.Equal(
t, []string{wh.ID}, ev.Evicted(),
"removing the last database target should evict",
)
}
// TestHandleTargetDelete_KeepsWriterWhenDatabaseTargetRemains
// proves that deleting one of several database targets leaves
// the still-needed archive writer alone: the surviving target
// keeps archiving to the same file, so the writer must stay.
func TestHandleTargetDelete_KeepsWriterWhenDatabaseTargetRemains(
t *testing.T,
) {
t.Parallel()
var (
h *handlers.Handlers
sess *session.Session
db *database.Database
ev *recordingEvictor
) )
app := newTestApp(t, &h, &sess, &db, &ev) app := newTestApp(t, &h, &sess, &db, &ev)
@@ -495,7 +515,7 @@ func TestHandleTargetDelete_EvictsThatTarget(t *testing.T) {
) )
req := postRequest( req := postRequest(
"/hook/"+wh.ID+"/targets/"+doomed.ID+"/delete", "/source/"+wh.ID+"/targets/"+doomed.ID+"/delete",
cookies, cookies,
map[string]string{ map[string]string{
paramSourceID: wh.ID, paramSourceID: wh.ID,
@@ -507,17 +527,17 @@ func TestHandleTargetDelete_EvictsThatTarget(t *testing.T) {
h.HandleTargetDelete().ServeHTTP(w, req) h.HandleTargetDelete().ServeHTTP(w, req)
require.Equal(t, http.StatusSeeOther, w.Code) require.Equal(t, http.StatusSeeOther, w.Code)
assert.Equal( assert.Empty(
t, []string{doomed.ID}, ev.EvictedTargets(), t, ev.Evicted(),
"deleting a database target should evict its writer", "a second database target still needs the writer",
) )
assert.Empty(t, ev.Evicted(), "the webhook is not deleted")
} }
// TestHandleTargetDelete_IgnoresAnotherWebhooksTarget proves that // TestHandleTargetDelete_KeepsWriterWhenOtherTypeDeleted proves
// a target id from the URL that is not a target of the webhook // that deleting a target of an unrelated type leaves a
// deletes nothing and so evicts nothing. // still-needed archive writer alone: the webhook's database
func TestHandleTargetDelete_IgnoresAnotherWebhooksTarget( // target is untouched, so its writer must stay.
func TestHandleTargetDelete_KeepsWriterWhenOtherTypeDeleted(
t *testing.T, t *testing.T,
) { ) {
t.Parallel() t.Parallel()
@@ -526,7 +546,7 @@ func TestHandleTargetDelete_IgnoresAnotherWebhooksTarget(
h *handlers.Handlers h *handlers.Handlers
sess *session.Session sess *session.Session
db *database.Database db *database.Database
ev *recordingArchives ev *recordingEvictor
) )
app := newTestApp(t, &h, &sess, &db, &ev) app := newTestApp(t, &h, &sess, &db, &ev)
@@ -535,20 +555,19 @@ func TestHandleTargetDelete_IgnoresAnotherWebhooksTarget(
t.Cleanup(app.RequireStop) t.Cleanup(app.RequireStop)
wh := seedWebhook(t, db) wh := seedWebhook(t, db)
elsewhere := seedTarget( seedTarget(t, db, wh.ID, database.TargetTypeDatabase)
t, db, seedWebhook(t, db).ID, database.TargetTypeDatabase, other := seedTarget(t, db, wh.ID, database.TargetTypeLog)
)
cookies := authenticatedCookies( cookies := authenticatedCookies(
t, sess, deleteTestUserID, deleteTestUsername, t, sess, deleteTestUserID, deleteTestUsername,
) )
req := postRequest( req := postRequest(
"/hook/"+wh.ID+"/targets/"+elsewhere.ID+"/delete", "/source/"+wh.ID+"/targets/"+other.ID+"/delete",
cookies, cookies,
map[string]string{ map[string]string{
paramSourceID: wh.ID, paramSourceID: wh.ID,
paramTargetID: elsewhere.ID, paramTargetID: other.ID,
}, },
) )
w := httptest.NewRecorder() w := httptest.NewRecorder()
@@ -557,7 +576,7 @@ func TestHandleTargetDelete_IgnoresAnotherWebhooksTarget(
require.Equal(t, http.StatusSeeOther, w.Code) require.Equal(t, http.StatusSeeOther, w.Code)
assert.Empty( assert.Empty(
t, ev.EvictedTargets(), t, ev.Evicted(),
"another webhook's target must not be evicted", "a surviving database target must keep its writer",
) )
} }
@@ -81,7 +81,7 @@ func (f *baseURLFixture) entrypointURL(
req := httptest.NewRequestWithContext( req := httptest.NewRequestWithContext(
context.Background(), context.Background(),
http.MethodGet, http.MethodGet,
"/hook/"+f.webhook, "/source/"+f.webhook,
nil, nil,
) )
req.Host = host req.Host = host
@@ -213,7 +213,7 @@ func TestSourceDetailBaseURL_ForwardedProtoSpellings(t *testing.T) {
assert.Equal( assert.Equal(
t, t,
tc.scheme+"://"+host+"/h/"+fixture.path, tc.scheme+"://"+host+"/webhook/"+fixture.path,
fixture.entrypointURL( fixture.entrypointURL(
t, host, forwardedProto(tc.header), t, host, forwardedProto(tc.header),
), ),
@@ -244,7 +244,7 @@ func TestSourceDetailBaseURL_DirectTLSBeatsPlaintextHeader(
assert.Equal( assert.Equal(
t, t,
"https://"+host+"/h/"+fixture.path, "https://"+host+"/webhook/"+fixture.path,
got, got,
"a connection this process terminated with TLS "+ "a connection this process terminated with TLS "+
"outranks a header claiming plaintext", "outranks a header claiming plaintext",
@@ -272,7 +272,7 @@ func TestSourceDetailBaseURL_KeepsHostAuthority(t *testing.T) {
assert.Equal( assert.Equal(
t, t,
"https://"+host+"/h/"+fixture.path, "https://"+host+"/webhook/"+fixture.path,
fixture.entrypointURL( fixture.entrypointURL(
t, host, forwardedProto("HTTPS"), t, host, forwardedProto("HTTPS"),
), ),
+4 -53
View File
@@ -62,27 +62,10 @@ func renderSourceDetailPage(
) string { ) string {
t.Helper() t.Helper()
w := serveSourceDetailPage(t, h, sess, webhookID)
require.Equal(t, http.StatusOK, w.Code)
return w.Body.String()
}
// serveSourceDetailPage runs the real source detail handler for a
// webhook and returns its response, whatever its status.
func serveSourceDetailPage(
t *testing.T,
h *handlers.Handlers,
sess *session.Session,
webhookID string,
) *httptest.ResponseRecorder {
t.Helper()
req := httptest.NewRequestWithContext( req := httptest.NewRequestWithContext(
context.Background(), context.Background(),
http.MethodGet, http.MethodGet,
"/hook/"+webhookID, "/source/"+webhookID,
nil, nil,
) )
@@ -104,7 +87,9 @@ func serveSourceDetailPage(
w := httptest.NewRecorder() w := httptest.NewRecorder()
h.HandleSourceDetail().ServeHTTP(w, req) h.HandleSourceDetail().ServeHTTP(w, req)
return w require.Equal(t, http.StatusOK, w.Code)
return w.Body.String()
} }
// TestHandleSourceDetail_MasksSlackWebhookURL is the // TestHandleSourceDetail_MasksSlackWebhookURL is the
@@ -241,37 +226,3 @@ func TestHandleSourceDetail_RendersNamedTargetFields(
assert.Contains(t, body, "(unavailable)") assert.Contains(t, body, "(unavailable)")
assert.NotContains(t, body, "beak") assert.NotContains(t, body, "beak")
} }
// TestHandleSourceDetail_FitsWideAndNarrowWindows pins the webhook
// page's maximum width at 108rem (1728 px), half again the 72rem of
// max-w-6xl that the webhook list and the event log use, so an
// entrypoint URL fits on one line in a 1920-pixel window; and the
// wrapping of its title row, so the buttons beside the title do not
// push a phone-width window into scrolling sideways.
func TestHandleSourceDetail_FitsWideAndNarrowWindows(t *testing.T) {
t.Parallel()
var (
h *handlers.Handlers
sess *session.Session
db *database.Database
)
app := newTestApp(t, &h, &sess, &db)
app.RequireStart()
t.Cleanup(app.RequireStop)
wh := seedWebhook(t, db)
body := renderSourceDetailPage(t, h, sess, wh.ID)
assert.Contains(
t, body,
`<div class="mx-auto px-6 py-8" style="max-width: 108rem"`,
)
assert.Contains(
t, body,
`<div class="flex flex-wrap justify-between items-center gap-2 mt-2">`,
)
}
-467
View File
@@ -1,467 +0,0 @@
package handlers_test
import (
"net/http"
"net/http/httptest"
"regexp"
"strings"
"testing"
"time"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"gorm.io/gorm"
"gorm.io/gorm/clause"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/handlers"
"sneak.berlin/go/webhooker/internal/logger"
"sneak.berlin/go/webhooker/internal/session"
)
// failedHighlight is how the list marks a number of failed deliveries
// that is not zero.
const failedHighlight = `class="font-medium text-red-600"`
// listWebhook adds a webhook with the given name, owned by the test
// user.
func listWebhook(
t *testing.T, db *database.Database, name string,
) *database.Webhook {
t.Helper()
wh := &database.Webhook{UserID: deleteTestUserID, Name: name}
require.NoError(t, db.DB().Omit(clause.Associations).Create(wh).Error)
return wh
}
// addEntrypoints adds the given number of entrypoints, all active or
// all inactive, to a webhook and returns their paths.
func addEntrypoints(
t *testing.T, db *database.Database, webhookID string,
count int, active bool,
) []string {
t.Helper()
paths := make([]string, count)
for i := range paths {
paths[i] = statsEntrypoint(t, db, webhookID, active)
}
return paths
}
// addTargets adds the given number of targets, all active or all
// inactive, to a webhook and returns them.
func addTargets(
t *testing.T, db *database.Database, webhookID string,
count int, active bool,
) []*database.Target {
t.Helper()
targets := make([]*database.Target, count)
for i := range targets {
targets[i] = seedTarget(t, db, webhookID, database.TargetTypeLog)
require.NoError(t, db.DB().Model(targets[i]).
Update("active", active).Error)
}
return targets
}
// renderWebhookList runs the real webhook list handler as the test user
// and returns the rendered page.
func renderWebhookList(
t *testing.T, h *handlers.Handlers, sess *session.Session,
) string {
t.Helper()
cookies := authenticatedCookies(
t, sess, deleteTestUserID, deleteTestUsername,
)
w := httptest.NewRecorder()
h.HandleSourceList().ServeHTTP(
w, getRequest(t, "/hooks", cookies, nil),
)
require.Equal(t, http.StatusOK, w.Code)
return w.Body.String()
}
// listCard returns one webhook's entry in a rendered webhook list, its
// markup as rendered and its text with the markup taken out and each
// run of space made one space.
func listCard(t *testing.T, page, webhookID string) (string, string) {
t.Helper()
_, card, found := strings.Cut(page, `href="/hook/`+webhookID+`"`)
require.True(t, found, "the list has no entry for %s", webhookID)
card, _, _ = strings.Cut(card, "</a>")
text := regexp.MustCompile(`<[^>]*>`).ReplaceAllString(card, " ")
return card, strings.Join(strings.Fields(text), " ")
}
// receiveEvents posts the given number of events to an entrypoint
// through the real receiver, and returns the webhook's event database
// and its events, oldest first.
func receiveEvents(
t *testing.T,
h *handlers.Handlers,
dbMgr *database.WebhookDBManager,
webhookID, path string,
count int,
) (*gorm.DB, []database.Event) {
t.Helper()
router := receiverRouter(h)
for range count {
require.Equal(t, http.StatusOK, postReceiver(t, router, path))
}
webhookDB, err := dbMgr.GetDB(webhookID)
require.NoError(t, err)
events := listEvents(t, webhookDB)
require.Len(t, events, count)
return webhookDB, events
}
// seedFailingWebhook adds a webhook with six entrypoints, two of them
// inactive, and seven targets, five of them inactive. Four events reach
// its two active targets, arriving 31, 5, 4 and 3 hours ago, and its
// event totals row records the last one. Three deliveries failed in the
// last 24 hours, two to the first target and one to the second, one
// failed 30 hours ago, two were delivered, and two are still pending.
// It returns the webhook and when its last event arrived.
func seedFailingWebhook(
t *testing.T,
h *handlers.Handlers,
db *database.Database,
dbMgr *database.WebhookDBManager,
) (*database.Webhook, time.Time) {
t.Helper()
wh := listWebhook(t, db, "failing")
paths := addEntrypoints(t, db, wh.ID, 4, true)
addEntrypoints(t, db, wh.ID, 2, false)
active := addTargets(t, db, wh.ID, 2, true)
first, second := active[0], active[1]
addTargets(t, db, wh.ID, 5, false)
webhookDB, events := receiveEvents(t, h, dbMgr, wh.ID, paths[0], 4)
now := time.Now()
lastEventAt := now.Add(-3 * time.Hour)
statsAge(t, webhookDB, events[0].ID, now.Add(-31*time.Hour))
statsAge(t, webhookDB, events[1].ID, now.Add(-5*time.Hour))
statsAge(t, webhookDB, events[2].ID, now.Add(-4*time.Hour))
statsAge(t, webhookDB, events[3].ID, lastEventAt)
require.NoError(t, database.AddEventTotals(webhookDB,
database.EventTotals{LastEventAt: &lastEventAt}))
statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, events[0].ID, first.ID),
database.DeliveryStatusFailed, now.Add(-30*time.Hour))
statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, events[0].ID, second.ID),
database.DeliveryStatusDelivered, now.Add(-30*time.Hour))
statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, events[1].ID, first.ID),
database.DeliveryStatusFailed, now.Add(-time.Hour))
statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, events[2].ID, first.ID),
database.DeliveryStatusFailed, now.Add(-time.Minute))
statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, events[2].ID, second.ID),
database.DeliveryStatusFailed, now.Add(-time.Minute))
statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, events[3].ID, second.ID),
database.DeliveryStatusDelivered, now.Add(-time.Minute))
return wh, lastEventAt
}
// seedHealthyWebhook adds a webhook with four entrypoints and two
// targets, all active, and three events, arriving 8, 7 and 6 hours ago
// and each delivered to both targets. Its event totals row records the
// last event. It returns the webhook and when its last event arrived.
func seedHealthyWebhook(
t *testing.T,
h *handlers.Handlers,
db *database.Database,
dbMgr *database.WebhookDBManager,
) (*database.Webhook, time.Time) {
t.Helper()
wh := listWebhook(t, db, "healthy")
paths := addEntrypoints(t, db, wh.ID, 4, true)
targets := addTargets(t, db, wh.ID, 2, true)
webhookDB, events := receiveEvents(t, h, dbMgr, wh.ID, paths[0], 3)
now := time.Now()
lastEventAt := now.Add(-6 * time.Hour)
statsAge(t, webhookDB, events[0].ID, now.Add(-8*time.Hour))
statsAge(t, webhookDB, events[1].ID, now.Add(-7*time.Hour))
statsAge(t, webhookDB, events[2].ID, lastEventAt)
require.NoError(t, database.AddEventTotals(webhookDB,
database.EventTotals{LastEventAt: &lastEventAt}))
for _, ev := range events {
for _, target := range targets {
statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, ev.ID, target.ID),
database.DeliveryStatusDelivered, now)
}
}
return wh, lastEventAt
}
// lastEventText is how the list shows when the last event arrived.
func lastEventText(at time.Time) string {
return at.UTC().Format("2006-01-02 15:04:05 UTC")
}
// TestSourceList_ShowsActivityOfEachWebhook checks the figures the list
// shows for a webhook with recent failures, a healthy one, a new one
// that has received no event, and one without an event database.
func TestSourceList_ShowsActivityOfEachWebhook(t *testing.T) {
t.Parallel()
var (
h *handlers.Handlers
sess *session.Session
db *database.Database
dbMgr *database.WebhookDBManager
)
app := newTestApp(t, &h, &sess, &db, &dbMgr)
app.RequireStart()
t.Cleanup(app.RequireStop)
failing, failingLastEvent := seedFailingWebhook(t, h, db, dbMgr)
healthy, healthyLastEvent := seedHealthyWebhook(t, h, db, dbMgr)
// Creating a webhook creates its event database.
fresh := listWebhook(t, db, "fresh")
require.NoError(t, dbMgr.CreateDB(fresh.ID))
addEntrypoints(t, db, fresh.ID, 2, true)
addTargets(t, db, fresh.ID, 3, true)
quiet := listWebhook(t, db, "quiet")
addEntrypoints(t, db, quiet.ID, 2, true)
addTargets(t, db, quiet.ID, 3, true)
page := renderWebhookList(t, h, sess)
card, text := listCard(t, page, failing.ID)
assert.Contains(t, text, "6 entrypoints, 2 inactive")
assert.Contains(t, text, "7 targets, 5 inactive")
assert.Contains(t, text, "4 events within retention")
assert.Contains(t, text, "Last event "+lastEventText(failingLastEvent))
assert.Contains(t, card,
failedHighlight+">3 failed deliveries in the last 24 hours<")
card, text = listCard(t, page, healthy.ID)
assert.Contains(t, text, "4 entrypoints")
assert.Contains(t, text, "2 targets")
assert.Contains(t, text, "3 events within retention")
assert.Contains(t, text, "Last event "+lastEventText(healthyLastEvent))
assert.Contains(t, text, "0 failed deliveries in the last 24 hours")
assert.NotContains(t, text, "inactive")
assert.NotContains(t, card, failedHighlight)
card, text = listCard(t, page, fresh.ID)
assert.Contains(t, text, "2 entrypoints")
assert.Contains(t, text, "3 targets")
assert.Contains(t, text, "0 events within retention")
assert.Contains(t, text, "No events yet")
assert.Contains(t, text, "0 failed deliveries in the last 24 hours")
assert.NotContains(t, card, failedHighlight)
card, text = listCard(t, page, quiet.ID)
assert.Contains(t, text, "2 entrypoints")
assert.Contains(t, text, "3 targets")
assert.Contains(t, text, "0 events within retention")
assert.Contains(t, text, "No events yet")
assert.Contains(t, text, "0 failed deliveries in the last 24 hours")
assert.NotContains(t, card, failedHighlight)
assert.False(t, dbMgr.DBExists(quiet.ID),
"showing the list must not create an event database")
}
// TestSourceList_CountsOnlyEventsWithinRetention checks that once
// retention has removed one of a webhook's three events, the list
// counts the two still stored.
func TestSourceList_CountsOnlyEventsWithinRetention(t *testing.T) {
t.Parallel()
var (
h *handlers.Handlers
sess *session.Session
db *database.Database
dbMgr *database.WebhookDBManager
log *logger.Logger
)
app := newTestApp(t, &h, &sess, &db, &dbMgr, &log)
app.RequireStart()
t.Cleanup(app.RequireStop)
wh := &database.Webhook{
UserID: deleteTestUserID, Name: "pruned", RetentionDays: 14,
}
require.NoError(t, db.DB().Omit(clause.Associations).Create(wh).Error)
paths := addEntrypoints(t, db, wh.ID, 3, true)
addTargets(t, db, wh.ID, 4, true)
webhookDB, events := receiveEvents(t, h, dbMgr, wh.ID, paths[0], 3)
statsAge(t, webhookDB, events[0].ID, time.Now().Add(-15*24*time.Hour))
statsPrune(t, db, dbMgr, log, webhookDB)
require.Len(t, listEvents(t, webhookDB), 2)
_, text := listCard(t, renderWebhookList(t, h, sess), wh.ID)
assert.Contains(t, text, "3 entrypoints")
assert.Contains(t, text, "4 targets")
assert.Contains(t, text, "2 events within retention")
}
// TestSourceList_LastEventSurvivesPruningEveryEvent checks that once
// retention has removed every event of a webhook, the list still shows
// when the last one arrived rather than "No events yet".
func TestSourceList_LastEventSurvivesPruningEveryEvent(t *testing.T) {
t.Parallel()
var (
h *handlers.Handlers
sess *session.Session
db *database.Database
dbMgr *database.WebhookDBManager
log *logger.Logger
)
app := newTestApp(t, &h, &sess, &db, &dbMgr, &log)
app.RequireStart()
t.Cleanup(app.RequireStop)
wh := &database.Webhook{
UserID: deleteTestUserID, Name: "emptied", RetentionDays: 1,
}
require.NoError(t, db.DB().Omit(clause.Associations).Create(wh).Error)
paths := addEntrypoints(t, db, wh.ID, 2, true)
addTargets(t, db, wh.ID, 3, true)
webhookDB, events := receiveEvents(t, h, dbMgr, wh.ID, paths[0], 1)
lastEventAt := time.Now().Add(-50 * time.Hour)
statsAge(t, webhookDB, events[0].ID, lastEventAt)
require.NoError(t, database.AddEventTotals(webhookDB,
database.EventTotals{LastEventAt: &lastEventAt}))
statsPrune(t, db, dbMgr, log, webhookDB)
require.Empty(t, listEvents(t, webhookDB))
_, text := listCard(t, renderWebhookList(t, h, sess), wh.ID)
assert.Contains(t, text, "0 events within retention")
assert.Contains(t, text, "Last event "+lastEventText(lastEventAt))
assert.NotContains(t, text, "No events yet")
}
// TestSourceList_CountsOfOneInSingular checks that a webhook with one
// entrypoint, one target, one event within retention and one failed
// delivery in the last 24 hours has each written in the singular.
func TestSourceList_CountsOfOneInSingular(t *testing.T) {
t.Parallel()
var (
h *handlers.Handlers
sess *session.Session
db *database.Database
dbMgr *database.WebhookDBManager
)
app := newTestApp(t, &h, &sess, &db, &dbMgr)
app.RequireStart()
t.Cleanup(app.RequireStop)
wh := listWebhook(t, db, "single")
paths := addEntrypoints(t, db, wh.ID, 1, true)
targets := addTargets(t, db, wh.ID, 1, true)
webhookDB, events := receiveEvents(t, h, dbMgr, wh.ID, paths[0], 1)
now := time.Now()
lastEventAt := now.Add(-9 * time.Hour)
statsAge(t, webhookDB, events[0].ID, lastEventAt)
require.NoError(t, database.AddEventTotals(webhookDB,
database.EventTotals{LastEventAt: &lastEventAt}))
statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, events[0].ID, targets[0].ID),
database.DeliveryStatusFailed, now.Add(-time.Hour))
card, text := listCard(t, renderWebhookList(t, h, sess), wh.ID)
assert.Contains(t, card, ">1 entrypoint<")
assert.Contains(t, card, ">1 target<")
assert.Contains(t, card, ">1 event within retention<")
assert.Contains(t, text, "Last event "+lastEventText(lastEventAt))
assert.Contains(t, card,
failedHighlight+">1 failed delivery in the last 24 hours<")
}
// TestSourceList_UnreadableEventDatabase checks that a webhook whose
// event database cannot be read says so in its entry instead of
// showing zeros, and that the rest of the list is still shown.
func TestSourceList_UnreadableEventDatabase(t *testing.T) {
t.Parallel()
var (
h *handlers.Handlers
sess *session.Session
db *database.Database
dbMgr *database.WebhookDBManager
)
app := newTestApp(t, &h, &sess, &db, &dbMgr)
app.RequireStart()
t.Cleanup(app.RequireStop)
broken := listWebhook(t, db, "broken")
addEntrypoints(t, db, broken.ID, 2, true)
addTargets(t, db, broken.ID, 3, true)
brokenDB, err := dbMgr.GetDB(broken.ID)
require.NoError(t, err)
require.NoError(t,
brokenDB.Migrator().DropTable(&database.EventTotals{}))
quiet := listWebhook(t, db, "quiet")
addEntrypoints(t, db, quiet.ID, 2, true)
addTargets(t, db, quiet.ID, 3, true)
page := renderWebhookList(t, h, sess)
_, text := listCard(t, page, broken.ID)
assert.Contains(t, text, "2 entrypoints")
assert.Contains(t, text, "3 targets")
assert.Contains(t, text, "The event figures could not be read.")
assert.NotContains(t, text, "events")
assert.NotContains(t, text, "failed")
_, text = listCard(t, page, quiet.ID)
assert.Contains(t, text, "No events yet")
}
@@ -28,7 +28,7 @@ func deleteTargetThroughHandler(
t.Helper() t.Helper()
req := postRequest( req := postRequest(
"/hook/"+webhookID+"/targets/"+targetID+"/delete", "/source/"+webhookID+"/targets/"+targetID+"/delete",
authenticatedCookies( authenticatedCookies(
t, sess, deleteTestUserID, deleteTestUsername, t, sess, deleteTestUserID, deleteTestUsername,
), ),
+1 -1
View File
@@ -84,7 +84,7 @@ func renderSourceLogsPageWithQuery(
req := httptest.NewRequestWithContext( req := httptest.NewRequestWithContext(
context.Background(), context.Background(),
http.MethodGet, http.MethodGet,
"/hook/"+webhookID+"/events"+query, "/source/"+webhookID+"/logs"+query,
nil, nil,
) )
+180 -343
View File
@@ -3,12 +3,10 @@ package handlers
import ( import (
"encoding/json" "encoding/json"
"errors" "errors"
"fmt"
"net/http" "net/http"
"slices" "slices"
"strconv" "strconv"
"strings" "strings"
"time"
"github.com/go-chi/chi" "github.com/go-chi/chi"
"github.com/google/uuid" "github.com/google/uuid"
@@ -22,20 +20,9 @@ import (
type WebhookListItem struct { type WebhookListItem struct {
database.Webhook database.Webhook
EntrypointCount int EntrypointCount int64
InactiveEntrypointCount int TargetCount int64
TargetCount int EventCount int64
InactiveTargetCount int
// EventCount is how many events the webhook holds, LastEventAt
// when the newest arrived (nil before the first), and
// FailedLast24Hours how many of its deliveries failed in the last
// 24 hours. When the webhook's event database could not be read,
// EventsUnreadable is set and these three are not known.
EventCount int64
LastEventAt *time.Time
FailedLast24Hours int64
EventsUnreadable bool
} }
// errMissingURL signals that a required URL was not provided. // errMissingURL signals that a required URL was not provided.
@@ -162,17 +149,18 @@ func (h *Handlers) HandleSourceList() http.HandlerFunc {
"user_id = ?", userID, "user_id = ?", userID,
).Order("created_at DESC").Find(&webhooks).Error ).Order("created_at DESC").Find(&webhooks).Error
if err != nil { if err != nil {
h.serverError(w, r, "failed to list webhooks", err) h.log.Error(
"failed to list webhooks", "error", err,
)
http.Error(
w, "Internal server error",
http.StatusInternalServerError,
)
return return
} }
items, err := h.buildWebhookListItems(webhooks) items := h.buildWebhookListItems(webhooks)
if err != nil {
h.serverError(w, r, "failed to list webhooks", err)
return
}
data := map[string]any{ data := map[string]any{
"Webhooks": items, "Webhooks": items,
@@ -182,115 +170,36 @@ func (h *Handlers) HandleSourceList() http.HandlerFunc {
} }
} }
// buildWebhookListItems builds the list's entry for each webhook. It // buildWebhookListItems builds list items with counts.
// fails when the main database cannot be read. A webhook whose event
// database cannot be read is marked on its own entry, and the error is
// logged.
func (h *Handlers) buildWebhookListItems( func (h *Handlers) buildWebhookListItems(
webhooks []database.Webhook, webhooks []database.Webhook,
) ([]WebhookListItem, error) { ) []WebhookListItem {
items := make([]WebhookListItem, len(webhooks)) items := make([]WebhookListItem, len(webhooks))
since := time.Now().Add(-longWindow)
for i := range webhooks { for i := range webhooks {
item := &items[i] items[i].Webhook = webhooks[i]
item.Webhook = webhooks[i]
var err error h.db.DB().Model(&database.Entrypoint{}).Where(
"webhook_id = ?", webhooks[i].ID,
).Count(&items[i].EntrypointCount)
item.EntrypointCount, item.InactiveEntrypointCount, err = h.db.DB().Model(&database.Target{}).Where(
h.countWithInactive(&database.Entrypoint{}, item.ID) "webhook_id = ?", webhooks[i].ID,
if err != nil { ).Count(&items[i].TargetCount)
return nil, err
}
item.TargetCount, item.InactiveTargetCount, err = if h.dbMgr.DBExists(webhooks[i].ID) {
h.countWithInactive(&database.Target{}, item.ID) webhookDB, err := h.dbMgr.GetDB(
if err != nil { webhooks[i].ID,
return nil, err
}
// Opening an event database that does not exist would create
// it, and it would hold nothing to count.
if !h.dbMgr.DBExists(item.ID) {
continue
}
err = h.readListEventFigures(item, since)
if err != nil {
h.log.Error(
"failed to read webhook list figures",
"webhook_id", item.ID,
"error", err,
) )
if err == nil {
item.EventsUnreadable = true webhookDB.Model(
&database.Event{},
).Count(&items[i].EventCount)
}
} }
} }
return items, nil return items
}
// countWithInactive returns how many entrypoints or targets, as model
// says, a webhook has, and how many of them are inactive.
func (h *Handlers) countWithInactive(
model any, webhookID string,
) (int, int, error) {
var active []bool
err := h.db.DB().Model(model).
Where("webhook_id = ?", webhookID).
Pluck("active", &active).Error
if err != nil {
return 0, 0, fmt.Errorf(
"reading active flags of webhook %s: %w", webhookID, err,
)
}
inactive := 0
for _, a := range active {
if !a {
inactive++
}
}
return len(active), inactive, nil
}
// readListEventFigures fills in the figures the list shows from the
// webhook's event database, with the statistics pane's own queries:
// the event count and last arrival from the event totals row, and the
// deliveries that failed since the given time from the deliveries'
// status index.
func (h *Handlers) readListEventFigures(
item *WebhookListItem, since time.Time,
) error {
webhookDB, err := h.dbMgr.GetDB(item.ID)
if err != nil {
return err
}
var totals database.EventTotals
err = webhookDB.Take(&totals).Error
if err != nil {
return fmt.Errorf("reading event totals: %w", err)
}
item.EventCount = totals.Events - totals.EventsRemoved
item.LastEventAt = totals.LastEventAt
byTarget, err := finishedByTarget(webhookDB, since)
if err != nil {
return err
}
for _, f := range byTarget {
item.FailedLast24Hours += f.Failed
}
return nil
} }
// HandleSourceCreate shows the form to create a new webhook. // HandleSourceCreate shows the form to create a new webhook.
@@ -340,7 +249,9 @@ func (h *Handlers) HandleSourceCreateSubmit() http.HandlerFunc {
// middleware, which runs before CSRF parses the form. // middleware, which runs before CSRF parses the form.
err := r.ParseForm() err := r.ParseForm()
if err != nil { if err != nil {
h.renderError(w, r, http.StatusBadRequest) http.Error(
w, "Bad request", http.StatusBadRequest,
)
return return
} }
@@ -400,7 +311,7 @@ func (h *Handlers) createWebhookWithEntrypoint(
err := h.commitWebhook(webhook) err := h.commitWebhook(webhook)
if err != nil { if err != nil {
h.serverError(w, r, "failed to create webhook", err) h.serverError(w, "failed to create webhook", err)
return return
} }
@@ -419,8 +330,7 @@ func (h *Handlers) createWebhookWithEntrypoint(
) )
http.Redirect( http.Redirect(
w, r, withNotice("/hook/"+webhook.ID, webhookCreated), w, r, "/source/"+webhook.ID, http.StatusSeeOther,
http.StatusSeeOther,
) )
} }
@@ -478,7 +388,7 @@ func (h *Handlers) HandleSourceDetail() http.HandlerFunc {
"id = ? AND user_id = ?", sourceID, userID, "id = ? AND user_id = ?", sourceID, userID,
).First(&webhook).Error ).First(&webhook).Error
if err != nil { if err != nil {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
@@ -505,23 +415,16 @@ func (h *Handlers) renderSourceDetail(
"webhook_id = ?", webhook.ID, "webhook_id = ?", webhook.ID,
).Find(&targets) ).Find(&targets)
var events []RecentEventView var events []database.Event
if h.dbMgr.DBExists(webhook.ID) { if h.dbMgr.DBExists(webhook.ID) {
webhookDB, err := h.dbMgr.GetDB(webhook.ID) webhookDB, dbErr := h.dbMgr.GetDB(webhook.ID)
if err != nil { if dbErr == nil {
h.serverError(w, r, "failed to get webhook database", err) webhookDB.Where(
"webhook_id = ?", webhook.ID,
return ).Order("created_at DESC").Limit(
} recentEventLimit,
).Find(&events)
events, err = loadRecentEvents(
webhookDB, webhook.ID, singleHTTPTargetID(targets),
)
if err != nil {
h.serverError(w, r, "failed to load recent events", err)
return
} }
} }
@@ -573,7 +476,7 @@ func (h *Handlers) HandleSourceEdit() http.HandlerFunc {
"id = ? AND user_id = ?", sourceID, userID, "id = ? AND user_id = ?", sourceID, userID,
).First(&webhook).Error ).First(&webhook).Error
if err != nil { if err != nil {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
@@ -602,16 +505,13 @@ func (h *Handlers) HandleSourceEditSubmit() http.HandlerFunc {
sourceID := chi.URLParam(r, "sourceID") sourceID := chi.URLParam(r, "sourceID")
h.renameMu.Lock()
defer h.renameMu.Unlock()
var webhook database.Webhook var webhook database.Webhook
err := h.db.DB().Where( err := h.db.DB().Where(
"id = ? AND user_id = ?", sourceID, userID, "id = ? AND user_id = ?", sourceID, userID,
).First(&webhook).Error ).First(&webhook).Error
if err != nil { if err != nil {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
@@ -620,7 +520,9 @@ func (h *Handlers) HandleSourceEditSubmit() http.HandlerFunc {
// middleware, which runs before CSRF parses the form. // middleware, which runs before CSRF parses the form.
err = r.ParseForm() err = r.ParseForm()
if err != nil { if err != nil {
h.renderError(w, r, http.StatusBadRequest) http.Error(
w, "Bad request", http.StatusBadRequest,
)
return return
} }
@@ -650,7 +552,6 @@ func (h *Handlers) applyWebhookEdit(
return return
} }
oldName := webhook.Name
webhook.Name = name webhook.Name = name
webhook.Description = r.PostFormValue("description") webhook.Description = r.PostFormValue("description")
@@ -673,50 +574,15 @@ func (h *Handlers) applyWebhookEdit(
webhook.RetentionDays = retentionDays webhook.RetentionDays = retentionDays
// A new name renames the archive files before it is saved (see err := h.db.DB().Save(webhook).Error
// delivery.Engine.Rename). If either step fails, the same targets'
// archives go back to the name that is still stored, without
// reading the main database again.
targets, err := h.renameWebhookArchives(
webhook.ID, oldName, webhook.Name,
)
if err == nil {
err = h.db.DB().Save(webhook).Error
}
if err != nil { if err != nil {
restoreErr := h.renameArchives(targets, oldName) h.serverError(w, "failed to update webhook", err)
if restoreErr != nil {
h.log.Error(
"failed to rename archives back",
"webhook_id", webhook.ID,
"error", restoreErr,
)
}
if errors.Is(err, delivery.ErrArchiveNameTaken) {
data := map[string]any{
tmplKeyWebhook: webhook,
tmplKeyError: "Not saved: " + err.Error() +
". Move that archive out of the data directory, " +
"its .db together with any -wal and -shm beside " +
"it, then save again.",
}
w.WriteHeader(http.StatusConflict)
h.renderTemplate(w, r, "source_edit.html", data)
return
}
h.serverError(w, r, "failed to update webhook", err)
return return
} }
http.Redirect( http.Redirect(
w, r, withNotice("/hook/"+webhook.ID, webhookSaved), w, r, "/source/"+webhook.ID, http.StatusSeeOther,
http.StatusSeeOther,
) )
} }
@@ -740,7 +606,7 @@ func (h *Handlers) HandleSourceDelete() http.HandlerFunc {
"id = ? AND user_id = ?", sourceID, userID, "id = ? AND user_id = ?", sourceID, userID,
).First(&webhook).Error ).First(&webhook).Error
if err != nil { if err != nil {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
@@ -767,7 +633,7 @@ func (h *Handlers) deleteWebhookResources(
// be removed by hand; deleted history cannot be recovered. // be removed by hand; deleted history cannot be recovered.
err := h.commitWebhookDeletion(&webhook) err := h.commitWebhookDeletion(&webhook)
if err != nil { if err != nil {
h.serverError(w, r, "failed to delete webhook", err) h.serverError(w, "failed to delete webhook", err)
return return
} }
@@ -793,15 +659,13 @@ func (h *Handlers) deleteWebhookResources(
// redirecting as though everything succeeded: the file // redirecting as though everything succeeded: the file
// needs removing by hand, and the logged error names it. // needs removing by hand, and the logged error names it.
h.serverError( h.serverError(
w, r, "failed to delete webhook event database", err, w, "failed to delete webhook event database", err,
) )
return return
} }
http.Redirect( http.Redirect(w, r, "/sources", http.StatusSeeOther)
w, r, withNotice("/hooks", webhookDeleted), http.StatusSeeOther,
)
} }
// commitWebhookDeletion soft-deletes a webhook's entrypoints, // commitWebhookDeletion soft-deletes a webhook's entrypoints,
@@ -846,11 +710,11 @@ func (h *Handlers) commitWebhookDeletion(
return tx.Commit().Error return tx.Commit().Error
} }
// evictArchiveWriter asks the delivery engine to drop the cached // evictArchiveWriter asks the delivery engine to drop its
// archive writers of a webhook's database targets, closing their // cached archive writer for a webhook, closing the archive file
// archive file handles. // handle.
// //
// The archive database files are NOT deleted. Unlike the event // The archive database file is NOT deleted. Unlike the event
// database — which is per-webhook working storage and is // database — which is per-webhook working storage and is
// hard-deleted with the webhook — an archive is explicitly // hard-deleted with the webhook — an archive is explicitly
// long-term storage that an operator may want to keep or move // long-term storage that an operator may want to keep or move
@@ -858,72 +722,50 @@ func (h *Handlers) commitWebhookDeletion(
// deleting a webhook would be a surprising and unrecoverable // deleting a webhook would be a surprising and unrecoverable
// data loss, so the file is left for the operator to handle. // data loss, so the file is left for the operator to handle.
func (h *Handlers) evictArchiveWriter(webhookID string) { func (h *Handlers) evictArchiveWriter(webhookID string) {
if h.archives == nil { if h.evictor == nil {
return return
} }
h.archives.EvictWebhook(webhookID) h.evictor.EvictWebhook(webhookID)
} }
// evictTargetArchiveWriter is evictArchiveWriter for one deleted // evictArchiveWriterIfUnused releases a webhook's archive
// target, and leaves its archive file on disk for the same reason. // writer once the webhook has no database target left to feed
// A target that is not a database target has no writer, and // it.
// evicting it does nothing. //
func (h *Handlers) evictTargetArchiveWriter(targetID string) { // It is called after any child resource of a webhook is
if h.archives == nil { // deleted, and is correct without knowing which kind was: it
return // evicts only when no database target remains, so deleting one
} // of several database targets — or deleting an unrelated
// target type — leaves a still-needed writer alone. When no
h.archives.EvictTarget(targetID) // database target ever existed there is no writer and eviction
} // is a no-op. Soft-deleted targets are excluded by GORM's
// default scope, so the row just deleted is not counted.
// renameWebhookArchives renames the archive file of every database func (h *Handlers) evictArchiveWriterIfUnused(webhookID string) {
// target of a webhook from the webhook name oldName to newName, var remaining int64
// keeping each target's own name. It does nothing when the name is
// unchanged. It returns the targets it read, so that a failed edit can
// move those same archives back with renameArchives.
func (h *Handlers) renameWebhookArchives(
webhookID, oldName, newName string,
) ([]database.Target, error) {
if h.archives == nil || oldName == newName {
return nil, nil
}
var targets []database.Target
err := h.db.DB(). err := h.db.DB().
Model(&database.Target{}).
Where( Where(
"webhook_id = ? AND type = ?", "webhook_id = ? AND type = ?",
webhookID, database.TargetTypeDatabase, webhookID, database.TargetTypeDatabase,
). ).
Find(&targets).Error Count(&remaining).Error
if err != nil { if err != nil {
return nil, err h.log.Error(
} "failed to count remaining database targets",
"webhook_id", webhookID,
return targets, h.renameArchives(targets, newName) "error", err,
}
// renameArchives renames the archive file of each of the given
// database targets to the webhook name webhookName, keeping each
// target's own name. It tries every target even after one fails, so
// that moving the archives back after a failed edit leaves none under
// the new name, and returns every failure joined.
func (h *Handlers) renameArchives(
targets []database.Target, webhookName string,
) error {
var errs []error
for i := range targets {
err := h.archives.Rename(
targets[i].ID, webhookName, targets[i].Name,
) )
if err != nil {
errs = append(errs, err) return
}
} }
return errors.Join(errs...) if remaining > 0 {
return
}
h.evictArchiveWriter(webhookID)
} }
// ownedWebhook resolves the request's sourceID parameter to a // ownedWebhook resolves the request's sourceID parameter to a
@@ -961,7 +803,7 @@ func (h *Handlers) ownedWebhook(
"id = ? AND user_id = ?", sourceID, userID, "id = ? AND user_id = ?", sourceID, userID,
).First(&webhook).Error ).First(&webhook).Error
if err != nil { if err != nil {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return database.Webhook{}, false return database.Webhook{}, false
} }
@@ -983,7 +825,7 @@ func (h *Handlers) HandleSourceLogs() http.HandlerFunc {
// Without the map every delivery renders through a // Without the map every delivery renders through a
// zero redactor, so failing the page is the only // zero redactor, so failing the page is the only
// safe answer. // safe answer.
h.serverError(w, r, "failed to load targets", err) h.serverError(w, "failed to load targets", err)
return return
} }
@@ -991,7 +833,7 @@ func (h *Handlers) HandleSourceLogs() http.HandlerFunc {
page := h.parsePage(r) page := h.parsePage(r)
evts, total, ok := h.loadEventsWithDeliveries( evts, total, ok := h.loadEventsWithDeliveries(
w, r, webhook, targets, page, w, webhook, targets, page,
) )
if !ok { if !ok {
return return
@@ -1002,16 +844,31 @@ func (h *Handlers) HandleSourceLogs() http.HandlerFunc {
totalPages++ totalPages++
} }
// The banner a replay or resubmit POST redirected back
// with. The message comes from a fixed set keyed by the
// outcome code, never from the query string itself.
replayMsg, replayOK := replayOutcome(
r.URL.Query().Get(replayOutcomeParam),
)
resubmitMsg, resubmitOK := resubmitOutcome(
r.URL.Query().Get(resubmitOutcomeParam),
)
data := map[string]any{ data := map[string]any{
tmplKeyWebhook: &webhook, tmplKeyWebhook: &webhook,
"Events": evts, "Events": evts,
"Page": page, "ReplayMessage": replayMsg,
"TotalPages": totalPages, "ReplayQueued": replayOK,
"TotalEvents": total, "ResubmitMessage": resubmitMsg,
"HasPrev": page > 1, "ResubmitQueued": resubmitOK,
"HasNext": page < totalPages, "Page": page,
"PrevPage": page - 1, "TotalPages": totalPages,
"NextPage": page + 1, "TotalEvents": total,
"HasPrev": page > 1,
"HasNext": page < totalPages,
"PrevPage": page - 1,
"NextPage": page + 1,
} }
h.renderTemplate(w, r, "source_logs.html", data) h.renderTemplate(w, r, "source_logs.html", data)
@@ -1086,7 +943,6 @@ func (h *Handlers) parsePage(r *http.Request) int {
// caller must then render nothing further. // caller must then render nothing further.
func (h *Handlers) loadEventsWithDeliveries( func (h *Handlers) loadEventsWithDeliveries(
w http.ResponseWriter, w http.ResponseWriter,
r *http.Request,
webhook database.Webhook, webhook database.Webhook,
targetMap map[string]eventLogTarget, targetMap map[string]eventLogTarget,
page int, page int,
@@ -1100,7 +956,7 @@ func (h *Handlers) loadEventsWithDeliveries(
webhookDB, err := h.dbMgr.GetDB(webhook.ID) webhookDB, err := h.dbMgr.GetDB(webhook.ID)
if err != nil { if err != nil {
h.serverError( h.serverError(
w, r, "failed to get webhook database", err, w, "failed to get webhook database", err,
) )
return nil, 0, false return nil, 0, false
@@ -1137,7 +993,7 @@ func (h *Handlers) loadEventsWithDeliveries(
) )
if err != nil { if err != nil {
h.serverError( h.serverError(
w, r, "failed to load delivery attempts", err, w, "failed to load delivery attempts", err,
) )
return nil, 0, false return nil, 0, false
@@ -1146,7 +1002,7 @@ func (h *Handlers) loadEventsWithDeliveries(
resubmits, err := resubmitCounts(webhookDB, eventIDs) resubmits, err := resubmitCounts(webhookDB, eventIDs)
if err != nil { if err != nil {
h.serverError( h.serverError(
w, r, "failed to count event resubmissions", err, w, "failed to count event resubmissions", err,
) )
return nil, 0, false return nil, 0, false
@@ -1369,7 +1225,7 @@ func (h *Handlers) HandleEntrypointCreate() http.HandlerFunc {
"id = ? AND user_id = ?", sourceID, userID, "id = ? AND user_id = ?", sourceID, userID,
).First(&webhook).Error ).First(&webhook).Error
if err != nil { if err != nil {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
@@ -1378,7 +1234,9 @@ func (h *Handlers) HandleEntrypointCreate() http.HandlerFunc {
// middleware, which runs before CSRF parses the form. // middleware, which runs before CSRF parses the form.
err = r.ParseForm() err = r.ParseForm()
if err != nil { if err != nil {
h.renderError(w, r, http.StatusBadRequest) http.Error(
w, "Bad request", http.StatusBadRequest,
)
return return
} }
@@ -1394,14 +1252,13 @@ func (h *Handlers) HandleEntrypointCreate() http.HandlerFunc {
err = h.db.DB().Create(entrypoint).Error err = h.db.DB().Create(entrypoint).Error
if err != nil { if err != nil {
h.serverError(w, r, "failed to create entrypoint", err) h.serverError(w, "failed to create entrypoint", err)
return return
} }
http.Redirect( http.Redirect(
w, r, withNotice("/hook/"+webhook.ID, entrypointAdded), w, r, "/source/"+webhook.ID, http.StatusSeeOther,
http.StatusSeeOther,
) )
} }
} }
@@ -1420,16 +1277,13 @@ func (h *Handlers) HandleTargetCreate() http.HandlerFunc {
sourceID := chi.URLParam(r, "sourceID") sourceID := chi.URLParam(r, "sourceID")
h.renameMu.Lock()
defer h.renameMu.Unlock()
var webhook database.Webhook var webhook database.Webhook
err := h.db.DB().Where( err := h.db.DB().Where(
"id = ? AND user_id = ?", sourceID, userID, "id = ? AND user_id = ?", sourceID, userID,
).First(&webhook).Error ).First(&webhook).Error
if err != nil { if err != nil {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
@@ -1438,7 +1292,9 @@ func (h *Handlers) HandleTargetCreate() http.HandlerFunc {
// middleware, which runs before CSRF parses the form. // middleware, which runs before CSRF parses the form.
err = r.ParseForm() err = r.ParseForm()
if err != nil { if err != nil {
h.renderError(w, r, http.StatusBadRequest) http.Error(
w, "Bad request", http.StatusBadRequest,
)
return return
} }
@@ -1458,7 +1314,7 @@ func (h *Handlers) processTargetCreate(
// //
// Every field here is read with PostFormValue, not FormValue. // Every field here is read with PostFormValue, not FormValue.
// FormValue falls back to the query string, which would let // FormValue falls back to the query string, which would let
// `POST /hook/{id}/targets?url=https://hooks.slack.com/...` // `POST /source/{id}/targets?url=https://hooks.slack.com/...`
// configure a target from a value the request line carries — and // configure a target from a value the request line carries — and
// the request line, unlike the body, is what logs, proxies, // the request line, unlike the body, is what logs, proxies,
// Referer headers and error trackers record. // Referer headers and error trackers record.
@@ -1509,14 +1365,13 @@ func (h *Handlers) processTargetCreate(
err = h.db.DB().Create(target).Error err = h.db.DB().Create(target).Error
if err != nil { if err != nil {
h.serverError(w, r, "failed to create target", err) h.serverError(w, "failed to create target", err)
return return
} }
http.Redirect( http.Redirect(
w, r, withNotice("/hook/"+webhook.ID, targetAdded), w, r, "/source/"+webhook.ID, http.StatusSeeOther,
http.StatusSeeOther,
) )
} }
@@ -1574,7 +1429,7 @@ type targetFormInput struct {
// //
// Every field is read with PostFormValue, not FormValue. FormValue // Every field is read with PostFormValue, not FormValue. FormValue
// falls back to the query string, which would let // falls back to the query string, which would let
// `POST /hook/{id}/targets?url=https://hooks.slack.com/...` // `POST /source/{id}/targets?url=https://hooks.slack.com/...`
// configure a target from a value the request line carries — and the // configure a target from a value the request line carries — and the
// request line, unlike the body, is what logs, proxies, Referer // request line, unlike the body, is what logs, proxies, Referer
// headers and error trackers record. The headers field is under the // headers and error trackers record. The headers field is under the
@@ -1604,7 +1459,7 @@ func (h *Handlers) buildTargetConfig(
case database.TargetTypeSlack: case database.TargetTypeSlack:
return h.buildSlackTargetConfig(w, r, in.URL) return h.buildSlackTargetConfig(w, r, in.URL)
case database.TargetTypeDatabase: case database.TargetTypeDatabase:
return h.buildDatabaseTargetConfig(w, r, in.Expiry) return h.buildDatabaseTargetConfig(w, in.Expiry)
case database.TargetTypeLog: case database.TargetTypeLog:
return "", nil return "", nil
default: default:
@@ -1654,7 +1509,7 @@ func (h *Handlers) buildHTTPTargetConfig(
return "", err return "", err
} }
return h.marshalTargetConfig(w, r, delivery.HTTPTargetConfig{ return marshalTargetConfig(w, delivery.HTTPTargetConfig{
URL: in.URL, URL: in.URL,
Headers: headers, Headers: headers,
Timeout: timeout, Timeout: timeout,
@@ -1676,7 +1531,7 @@ func (h *Handlers) buildSlackTargetConfig(
return "", err return "", err
} }
return h.marshalTargetConfig(w, r, delivery.SlackTargetConfig{ return marshalTargetConfig(w, delivery.SlackTargetConfig{
WebhookURL: targetURL, WebhookURL: targetURL,
}) })
} }
@@ -1716,23 +1571,11 @@ func (h *Handlers) validateTargetURL(
"url", delivery.MaskURL(targetURL), "url", delivery.MaskURL(targetURL),
"error", err, "error", err,
) )
http.Error(
msg := "Invalid target URL: " + err.Error() w,
"Invalid target URL: "+err.Error(),
// Only a private or reserved address's refusal says how http.StatusBadRequest,
// to allow it. Other refusals never do: link-local, the )
// unspecified addresses and the unconditional metadata
// addresses cannot be opened, and the default
// blocklist's public addresses, which listing does open,
// hand out credentials.
if errors.Is(err, delivery.ErrBlockedPrivateOrReservedIP) {
msg += ". Private and reserved addresses are refused " +
"by default; the server's ALLOWED_EGRESS_CIDRS " +
"setting allows named networks (see \"Allowing " +
"egress to your own network\" in the README)."
}
http.Error(w, msg, http.StatusBadRequest)
return err return err
} }
@@ -1742,14 +1585,16 @@ func (h *Handlers) validateTargetURL(
// marshalTargetConfig serialises a target configuration for storage, // marshalTargetConfig serialises a target configuration for storage,
// writing a 500 itself if it cannot. // writing a 500 itself if it cannot.
func (h *Handlers) marshalTargetConfig( func marshalTargetConfig(
w http.ResponseWriter, w http.ResponseWriter,
r *http.Request,
cfg any, cfg any,
) (string, error) { ) (string, error) {
configBytes, err := json.Marshal(cfg) configBytes, err := json.Marshal(cfg)
if err != nil { if err != nil {
h.serverError(w, r, "failed to encode target config", err) http.Error(
w, "Internal server error",
http.StatusInternalServerError,
)
return "", err return "", err
} }
@@ -1765,7 +1610,6 @@ func (h *Handlers) marshalTargetConfig(
// expiry yields an empty config (the keep-forever default). // expiry yields an empty config (the keep-forever default).
func (h *Handlers) buildDatabaseTargetConfig( func (h *Handlers) buildDatabaseTargetConfig(
w http.ResponseWriter, w http.ResponseWriter,
r *http.Request,
expiry string, expiry string,
) (string, error) { ) (string, error) {
expiry = strings.TrimSpace(expiry) expiry = strings.TrimSpace(expiry)
@@ -1784,8 +1628,8 @@ func (h *Handlers) buildDatabaseTargetConfig(
return "", err return "", err
} }
return h.marshalTargetConfig( return marshalTargetConfig(
w, r, map[string]any{"expiry": expiry}, w, map[string]any{"expiry": expiry},
) )
} }
@@ -1795,33 +1639,30 @@ func (h *Handlers) HandleEntrypointDelete() http.HandlerFunc {
"entrypointID", &database.Entrypoint{}, "entrypointID", &database.Entrypoint{},
"failed to delete entrypoint", "failed to delete entrypoint",
nil, nil,
entrypointDeleted,
) )
} }
// HandleTargetDelete handles deleting a target. A deleted // HandleTargetDelete handles deleting a target. Deleting the
// database target's archive writer is evicted and its handle // last database target of a webhook leaves its archive writer
// closed; the archive file is left on disk. // with nothing to write, so the writer is evicted and its
// handle closed; the archive file is left on disk.
func (h *Handlers) HandleTargetDelete() http.HandlerFunc { func (h *Handlers) HandleTargetDelete() http.HandlerFunc {
return h.deleteChildResource( return h.deleteChildResource(
"targetID", &database.Target{}, "targetID", &database.Target{},
"failed to delete target", "failed to delete target",
h.evictTargetArchiveWriter, h.evictArchiveWriterIfUnused,
targetDeleted,
) )
} }
// deleteChildResource returns a handler that deletes a child // deleteChildResource returns a handler that deletes a child
// resource (entrypoint or target) belonging to a webhook. The // resource (entrypoint or target) belonging to a webhook. The
// optional afterDelete hook runs with the child's id once the // optional afterDelete hook runs with the webhook's id once the
// delete has removed it, before the redirect, which carries done as // delete has succeeded, before the redirect.
// its notice.
func (h *Handlers) deleteChildResource( func (h *Handlers) deleteChildResource(
idParam string, idParam string,
model any, model any,
errMsg string, errMsg string,
afterDelete func(childID string), afterDelete func(webhookID string),
done noticeCode,
) http.HandlerFunc { ) http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) { return func(w http.ResponseWriter, r *http.Request) {
userID, ok := h.getUserID(r) userID, ok := h.getUserID(r)
@@ -1842,7 +1683,7 @@ func (h *Handlers) deleteChildResource(
"id = ? AND user_id = ?", sourceID, userID, "id = ? AND user_id = ?", sourceID, userID,
).First(&webhook).Error ).First(&webhook).Error
if err != nil { if err != nil {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
@@ -1852,20 +1693,22 @@ func (h *Handlers) deleteChildResource(
childID, webhook.ID, childID, webhook.ID,
).Delete(model) ).Delete(model)
if result.Error != nil { if result.Error != nil {
h.serverError(w, r, errMsg, result.Error) h.log.Error(errMsg, "error", result.Error)
http.Error(
w, "Internal server error",
http.StatusInternalServerError,
)
return return
} }
// Only for a row this webhook really had: the id came from if afterDelete != nil {
// the URL and may name another webhook's child. afterDelete(webhook.ID)
if afterDelete != nil && result.RowsAffected > 0 {
afterDelete(childID)
} }
http.Redirect( http.Redirect(
w, r, w, r,
withNotice("/hook/"+webhook.ID, done), "/source/"+webhook.ID,
http.StatusSeeOther, http.StatusSeeOther,
) )
} }
@@ -1876,7 +1719,7 @@ func (h *Handlers) deleteChildResource(
func (h *Handlers) HandleEntrypointToggle() http.HandlerFunc { func (h *Handlers) HandleEntrypointToggle() http.HandlerFunc {
return h.toggleChildResource( return h.toggleChildResource(
"entrypointID", "entrypointID",
func(webhookID, childID string) (bool, error) { func(webhookID, childID string) error {
var ep database.Entrypoint var ep database.Entrypoint
err := h.db.DB().Where( err := h.db.DB().Where(
@@ -1884,15 +1727,14 @@ func (h *Handlers) HandleEntrypointToggle() http.HandlerFunc {
childID, webhookID, childID, webhookID,
).First(&ep).Error ).First(&ep).Error
if err != nil { if err != nil {
return false, err return err
} }
ep.Active = !ep.Active ep.Active = !ep.Active
return ep.Active, h.db.DB().Save(&ep).Error return h.db.DB().Save(&ep).Error
}, },
"failed to toggle entrypoint", "failed to toggle entrypoint",
entrypointActivated, entrypointDeactivated,
) )
} }
@@ -1900,7 +1742,7 @@ func (h *Handlers) HandleEntrypointToggle() http.HandlerFunc {
func (h *Handlers) HandleTargetToggle() http.HandlerFunc { func (h *Handlers) HandleTargetToggle() http.HandlerFunc {
return h.toggleChildResource( return h.toggleChildResource(
"targetID", "targetID",
func(webhookID, childID string) (bool, error) { func(webhookID, childID string) error {
var tgt database.Target var tgt database.Target
err := h.db.DB().Where( err := h.db.DB().Where(
@@ -1908,27 +1750,23 @@ func (h *Handlers) HandleTargetToggle() http.HandlerFunc {
childID, webhookID, childID, webhookID,
).First(&tgt).Error ).First(&tgt).Error
if err != nil { if err != nil {
return false, err return err
} }
tgt.Active = !tgt.Active tgt.Active = !tgt.Active
return tgt.Active, h.db.DB().Save(&tgt).Error return h.db.DB().Save(&tgt).Error
}, },
"failed to toggle target", "failed to toggle target",
targetActivated, targetDeactivated,
) )
} }
// toggleChildResource returns a handler that toggles the active // toggleChildResource returns a handler that toggles the active
// state of a child resource belonging to a webhook. toggleFn returns // state of a child resource belonging to a webhook.
// the new state, and the redirect carries activated or deactivated as
// its notice to match.
func (h *Handlers) toggleChildResource( func (h *Handlers) toggleChildResource(
idParam string, idParam string,
toggleFn func(webhookID, childID string) (bool, error), toggleFn func(webhookID, childID string) error,
errMsg string, errMsg string,
activated, deactivated noticeCode,
) http.HandlerFunc { ) http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) { return func(w http.ResponseWriter, r *http.Request) {
userID, ok := h.getUserID(r) userID, ok := h.getUserID(r)
@@ -1949,26 +1787,25 @@ func (h *Handlers) toggleChildResource(
"id = ? AND user_id = ?", sourceID, userID, "id = ? AND user_id = ?", sourceID, userID,
).First(&webhook).Error ).First(&webhook).Error
if err != nil { if err != nil {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return return
} }
active, err := toggleFn(webhook.ID, childID) err = toggleFn(webhook.ID, childID)
if err != nil { if err != nil {
h.serverError(w, r, errMsg, err) h.log.Error(errMsg, "error", err)
http.Error(
w, "Internal server error",
http.StatusInternalServerError,
)
return return
} }
done := deactivated
if active {
done = activated
}
http.Redirect( http.Redirect(
w, r, w, r,
withNotice("/hook/"+webhook.ID, done), "/source/"+webhook.ID,
http.StatusSeeOther, http.StatusSeeOther,
) )
} }
+8 -311
View File
@@ -2,20 +2,16 @@ package handlers_test
import ( import (
"context" "context"
"errors"
"net/http" "net/http"
"net/http/httptest" "net/http/httptest"
"net/url" "net/url"
"strconv" "strconv"
"strings" "strings"
"sync/atomic"
"testing" "testing"
"time"
"github.com/go-chi/chi" "github.com/go-chi/chi"
"github.com/stretchr/testify/assert" "github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require" "github.com/stretchr/testify/require"
"gorm.io/gorm"
"gorm.io/gorm/clause" "gorm.io/gorm/clause"
"sneak.berlin/go/webhooker/internal/database" "sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/handlers" "sneak.berlin/go/webhooker/internal/handlers"
@@ -109,7 +105,7 @@ func submitCreate(
form.Set("retention_days", *retention) form.Set("retention_days", *retention)
} }
req := formRequest("/hooks/new", cookies, form, nil) req := formRequest("/sources/new", cookies, form, nil)
w := httptest.NewRecorder() w := httptest.NewRecorder()
h.HandleSourceCreateSubmit().ServeHTTP(w, req) h.HandleSourceCreateSubmit().ServeHTTP(w, req)
@@ -191,7 +187,6 @@ func storedRetentionDays(
type sourceTestEnv struct { type sourceTestEnv struct {
handlers *handlers.Handlers handlers *handlers.Handlers
db *database.Database db *database.Database
archives *recordingArchives
cookies []*http.Cookie cookies []*http.Cookie
} }
@@ -204,9 +199,7 @@ func setupSourceTest(t *testing.T) *sourceTestEnv {
var db *database.Database var db *database.Database
var archives *recordingArchives app := newTestApp(t, &h, &sess, &db)
app := newTestApp(t, &h, &sess, &db, &archives)
app.RequireStart() app.RequireStart()
t.Cleanup(app.RequireStop) t.Cleanup(app.RequireStop)
@@ -214,7 +207,6 @@ func setupSourceTest(t *testing.T) *sourceTestEnv {
return &sourceTestEnv{ return &sourceTestEnv{
handlers: h, handlers: h,
db: db, db: db,
archives: archives,
cookies: authenticatedCookies( cookies: authenticatedCookies(
t, sess, sourceTestUserID, "sourceuser", t, sess, sourceTestUserID, "sourceuser",
), ),
@@ -273,7 +265,7 @@ func TestHandleSourceCreate_PrefillsDefaultFromConstant(t *testing.T) {
w := httptest.NewRecorder() w := httptest.NewRecorder()
env.handlers.HandleSourceCreate().ServeHTTP( env.handlers.HandleSourceCreate().ServeHTTP(
w, getRequest(t, "/hooks/new", env.cookies, nil), w, getRequest(t, "/sources/new", env.cookies, nil),
) )
require.Equal(t, http.StatusOK, w.Code) require.Equal(t, http.StatusOK, w.Code)
@@ -410,7 +402,7 @@ func TestHandleSourceCreateSubmit_RejectedFormKeepsUserInput(
form.Set("description", description) form.Set("description", description)
form.Set("retention_days", "nonsense") form.Set("retention_days", "nonsense")
req := formRequest("/hooks/new", env.cookies, form, nil) req := formRequest("/sources/new", env.cookies, form, nil)
w := httptest.NewRecorder() w := httptest.NewRecorder()
env.handlers.HandleSourceCreateSubmit().ServeHTTP(w, req) env.handlers.HandleSourceCreateSubmit().ServeHTTP(w, req)
@@ -438,7 +430,7 @@ func submitEdit(
form.Set("retention_days", retention) form.Set("retention_days", retention)
req := formRequest( req := formRequest(
"/hook/"+wh.ID+"/edit", "/source/"+wh.ID+"/edit",
env.cookies, env.cookies,
form, form,
map[string]string{sourceIDParam: wh.ID}, map[string]string{sourceIDParam: wh.ID},
@@ -506,301 +498,6 @@ func TestHandleSourceEditSubmit_EmptyRetentionLeavesValueUnchanged(
assert.Equal(t, 7, storedRetentionDays(t, env.db, wh.ID)) assert.Equal(t, 7, storedRetentionDays(t, env.db, wh.ID))
} }
// renamedWebhookName is the name the rename tests give a webhook.
const renamedWebhookName = "Renamed"
// TestHandleSourceEditSubmit_RenamesArchives proves that a save
// that keeps the webhook's name renames nothing, and that renaming a
// webhook renames the archive of each of its database targets and
// asks nothing of its other targets.
func TestHandleSourceEditSubmit_RenamesArchives(t *testing.T) {
t.Parallel()
env := setupSourceTest(t)
wh := seedWebhookWithRetention(t, env.db, 7)
first := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
second := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
seedTarget(t, env.db, wh.ID, database.TargetTypeLog)
w := submitEdit(t, env, wh, "")
require.Equal(t, http.StatusSeeOther, w.Code)
assert.Empty(t, env.archives.Renames())
wh.Name = renamedWebhookName
w = submitEdit(t, env, wh, "")
require.Equal(t, http.StatusSeeOther, w.Code)
assert.ElementsMatch(
t,
[]archiveRename{
{first.ID, renamedWebhookName, first.Name},
{second.ID, renamedWebhookName, second.Name},
},
env.archives.Renames(),
)
}
// TestHandleSourceEditSubmit_FailedRenameKeepsTheName proves that a
// webhook whose archive cannot be renamed keeps its stored name, so
// the name on disk and the name in the UI do not part, and that the
// handler puts back what it may already have moved.
func TestHandleSourceEditSubmit_FailedRenameKeepsTheName(
t *testing.T,
) {
t.Parallel()
env := setupSourceTest(t)
wh := seedWebhookWithRetention(t, env.db, 7)
tgt := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
env.archives.FailRenames(tgt.ID, errInjectedRename)
oldName := wh.Name
wh.Name = renamedWebhookName
w := submitEdit(t, env, wh, "")
require.Equal(t, http.StatusInternalServerError, w.Code)
var stored database.Webhook
require.NoError(
t, env.db.DB().First(&stored, "id = ?", wh.ID).Error,
)
assert.Equal(t, oldName, stored.Name)
assert.Equal(
t,
[]archiveRename{
{tgt.ID, renamedWebhookName, tgt.Name},
{tgt.ID, oldName, tgt.Name},
},
env.archives.Renames(),
)
}
// TestHandleSourceEditSubmit_FailedSaveRenamesBack proves that when
// the archive is renamed but the new name cannot be saved, the
// archive is renamed back to the stored name and the stored name
// stays.
func TestHandleSourceEditSubmit_FailedSaveRenamesBack(t *testing.T) {
t.Parallel()
env := setupSourceTest(t)
wh := seedWebhookWithRetention(t, env.db, 7)
tgt := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
failSaveOnTable(t, env.db, "webhooks")
oldName := wh.Name
wh.Name = renamedWebhookName
w := submitEdit(t, env, wh, "")
require.Equal(t, http.StatusInternalServerError, w.Code)
var stored database.Webhook
require.NoError(
t, env.db.DB().First(&stored, "id = ?", wh.ID).Error,
)
assert.Equal(t, oldName, stored.Name)
assert.Equal(
t,
[]archiveRename{
{tgt.ID, renamedWebhookName, tgt.Name},
{tgt.ID, oldName, tgt.Name},
},
env.archives.Renames(),
)
}
// errInjectedRead is the failure a test makes reads of the main
// database report.
var errInjectedRead = errors.New("injected read failure")
// TestHandleSourceEditSubmit_FailedSaveRenamesBackWithoutReading
// proves that when the save fails and every later read of the main
// database fails too, each archive the rename moved is still renamed
// back: the move back needs no second read of the webhook's targets.
func TestHandleSourceEditSubmit_FailedSaveRenamesBackWithoutReading(
t *testing.T,
) {
t.Parallel()
env := setupSourceTest(t)
wh := seedWebhookWithRetention(t, env.db, 7)
first := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
second := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
var saveFailed atomic.Bool
require.NoError(t, env.db.DB().Callback().Update().
Before("gorm:update").
Register("test:fail_save", func(tx *gorm.DB) {
saveFailed.Store(true)
_ = tx.AddError(errInjectedSave)
}),
)
require.NoError(t, env.db.DB().Callback().Query().
Before("gorm:query").
Register("test:fail_reads_after_save", func(tx *gorm.DB) {
if saveFailed.Load() {
_ = tx.AddError(errInjectedRead)
}
}),
)
oldName := wh.Name
wh.Name = renamedWebhookName
w := submitEdit(t, env, wh, "")
require.Equal(t, http.StatusInternalServerError, w.Code)
assert.Equal(
t,
[]archiveRename{
{first.ID, renamedWebhookName, first.Name},
{second.ID, renamedWebhookName, second.Name},
{first.ID, oldName, first.Name},
{second.ID, oldName, second.Name},
},
env.archives.Renames(),
)
}
// TestHandleSourceEditSubmit_EditsDoNotInterleave proves that a second
// webhook edit submitted while the first is inside its archive rename
// does not run until the first is saved, so afterwards the stored
// names are the ones the archive was last renamed to. The stand-in's
// last rename is the name the file has on disk.
func TestHandleSourceEditSubmit_EditsDoNotInterleave(t *testing.T) {
t.Parallel()
env := setupSourceTest(t)
wh := seedWebhookWithRetention(t, env.db, 7)
tgt := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
entered, release := env.archives.BlockNextRename()
firstEdit, secondEdit := wh, wh
firstEdit.Name = "First"
secondEdit.Name = "Second"
firstCode := make(chan int, 1)
go func() { firstCode <- submitEdit(t, env, firstEdit, "").Code }()
<-entered
secondCode := make(chan int, 1)
go func() { secondCode <- submitEdit(t, env, secondEdit, "").Code }()
// Were the edits not ordered, the second would run to its end in
// this time, while the first is still inside its rename.
time.Sleep(200 * time.Millisecond)
release()
assert.Equal(t, http.StatusSeeOther, <-firstCode)
assert.Equal(t, http.StatusSeeOther, <-secondCode)
var (
storedWebhook database.Webhook
storedTarget database.Target
)
require.NoError(
t, env.db.DB().First(&storedWebhook, "id = ?", wh.ID).Error,
)
require.NoError(
t, env.db.DB().First(&storedTarget, "id = ?", tgt.ID).Error,
)
renames := env.archives.Renames()
require.NotEmpty(t, renames)
assert.Equal(
t,
archiveRename{tgt.ID, storedWebhook.Name, storedTarget.Name},
renames[len(renames)-1],
)
}
// TestHandleSourceEditSubmit_FailedRenameRenamesTheOthersBack proves
// that when a webhook has three database targets and only the middle
// one's archive cannot be renamed, the stored name stays and both
// others are renamed back, the last one included: the move back does
// not stop at the target it cannot rename. The handler reaches the
// targets in the order they were created, which the exact sequence
// below pins, so the refused target always comes before the last.
func TestHandleSourceEditSubmit_FailedRenameRenamesTheOthersBack(
t *testing.T,
) {
t.Parallel()
env := setupSourceTest(t)
wh := seedWebhookWithRetention(t, env.db, 7)
first := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
middle := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
last := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
env.archives.FailRenames(middle.ID, errNameTaken)
oldName := wh.Name
wh.Name = renamedWebhookName
w := submitEdit(t, env, wh, "")
require.Equal(t, http.StatusConflict, w.Code)
var stored database.Webhook
require.NoError(
t, env.db.DB().First(&stored, "id = ?", wh.ID).Error,
)
assert.Equal(t, oldName, stored.Name)
assert.Equal(
t,
[]archiveRename{
{first.ID, renamedWebhookName, first.Name},
{middle.ID, renamedWebhookName, middle.Name},
{last.ID, renamedWebhookName, last.Name},
{first.ID, oldName, first.Name},
{middle.ID, oldName, middle.Name},
{last.ID, oldName, last.Name},
},
env.archives.Renames(),
)
}
// TestHandleSourceEditSubmit_ArchiveNameTaken proves that when a file
// already has an archive's new name, the edit is refused with an
// error naming that file, and the webhook keeps its stored name.
func TestHandleSourceEditSubmit_ArchiveNameTaken(t *testing.T) {
t.Parallel()
env := setupSourceTest(t)
wh := seedWebhookWithRetention(t, env.db, 7)
tgt := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
env.archives.FailRenames(tgt.ID, errNameTaken)
oldName := wh.Name
wh.Name = renamedWebhookName
w := submitEdit(t, env, wh, "")
require.Equal(t, http.StatusConflict, w.Code)
assert.Contains(t, w.Body.String(), "archive-taken.db")
var stored database.Webhook
require.NoError(
t, env.db.DB().First(&stored, "id = ?", wh.ID).Error,
)
assert.Equal(t, oldName, stored.Name)
}
// TestSourceEditForm_ForeverWebhookRoundTrips walks the exact path that // TestSourceEditForm_ForeverWebhookRoundTrips walks the exact path that
// the removed max="365" cap used to break: render the edit form for a // the removed max="365" cap used to break: render the edit form for a
// retain-forever webhook, confirm the pre-filled sentinel is not capped // retain-forever webhook, confirm the pre-filled sentinel is not capped
@@ -815,7 +512,7 @@ func TestSourceEditForm_ForeverWebhookRoundTrips(t *testing.T) {
) )
req := getRequest( req := getRequest(
t, "/hook/"+wh.ID+"/edit", env.cookies, t, "/source/"+wh.ID+"/edit", env.cookies,
map[string]string{sourceIDParam: wh.ID}, map[string]string{sourceIDParam: wh.ID},
) )
w := httptest.NewRecorder() w := httptest.NewRecorder()
@@ -870,7 +567,7 @@ func TestSourceListAndDetail_ShowForeverNotTheSentinelNumber(
listW := httptest.NewRecorder() listW := httptest.NewRecorder()
env.handlers.HandleSourceList().ServeHTTP( env.handlers.HandleSourceList().ServeHTTP(
listW, getRequest(t, "/hooks", env.cookies, nil), listW, getRequest(t, "/sources", env.cookies, nil),
) )
require.Equal(t, http.StatusOK, listW.Code) require.Equal(t, http.StatusOK, listW.Code)
@@ -881,7 +578,7 @@ func TestSourceListAndDetail_ShowForeverNotTheSentinelNumber(
env.handlers.HandleSourceDetail().ServeHTTP( env.handlers.HandleSourceDetail().ServeHTTP(
detailW, detailW,
getRequest( getRequest(
t, "/hook/"+wh.ID, env.cookies, t, "/source/"+wh.ID, env.cookies,
map[string]string{sourceIDParam: wh.ID}, map[string]string{sourceIDParam: wh.ID},
), ),
) )
@@ -76,11 +76,11 @@ func postTargetCreate(
router := chi.NewRouter() router := chi.NewRouter()
router.Use(mw.Logging()) router.Use(mw.Logging())
router.Post( router.Post(
"/hook/{sourceID}/targets", "/source/{sourceID}/targets",
env.handlers.HandleTargetCreate(), env.handlers.HandleTargetCreate(),
) )
target := "/hook/" + webhookID + "/targets" target := "/source/" + webhookID + "/targets"
if query != "" { if query != "" {
target += "?" + query target += "?" + query
} }
@@ -114,7 +114,7 @@ func postTargetCreate(
// regression test for the ingress leak. r.FormValue falls back to the // regression test for the ingress leak. r.FormValue falls back to the
// query string when a field is absent from the POST body, so // query string when a field is absent from the POST body, so
// //
// POST /hook/{id}/targets?url=https://hooks.slack.com/services/... // POST /source/{id}/targets?url=https://hooks.slack.com/services/...
// //
// with an empty url field used to create a working target from a value // with an empty url field used to create a working target from a value
// carried on the request line — where logs, proxies, Referer headers // carried on the request line — where logs, proxies, Referer headers
+8 -58
View File
@@ -1,7 +1,6 @@
package handlers package handlers
import ( import (
"errors"
"net/http" "net/http"
"github.com/go-chi/chi" "github.com/go-chi/chi"
@@ -48,7 +47,7 @@ type targetEditView struct {
// //
// This page is the one place the full destination URL and header // This page is the one place the full destination URL and header
// values are shown. It is reachable only through the // values are shown. It is reachable only through the
// /hook/{sourceID} route group, which supplies RequireAuth and // /source/{sourceID} route group, which supplies RequireAuth and
// NoCache, and only for a target of a webhook the session's user // NoCache, and only for a target of a webhook the session's user
// owns; masking (delivery.TargetView) is unchanged everywhere else. // owns; masking (delivery.TargetView) is unchanged everywhere else.
func (h *Handlers) HandleTargetEdit() http.HandlerFunc { func (h *Handlers) HandleTargetEdit() http.HandlerFunc {
@@ -80,9 +79,6 @@ func (h *Handlers) HandleTargetEdit() http.HandlerFunc {
// HandleTargetEditSubmit handles the target edit form submission. // HandleTargetEditSubmit handles the target edit form submission.
func (h *Handlers) HandleTargetEditSubmit() http.HandlerFunc { func (h *Handlers) HandleTargetEditSubmit() http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) { return func(w http.ResponseWriter, r *http.Request) {
h.renameMu.Lock()
defer h.renameMu.Unlock()
webhook, target, ok := h.ownedTarget(w, r) webhook, target, ok := h.ownedTarget(w, r)
if !ok { if !ok {
return return
@@ -92,7 +88,9 @@ func (h *Handlers) HandleTargetEditSubmit() http.HandlerFunc {
// middleware, which runs before CSRF parses the form. // middleware, which runs before CSRF parses the form.
err := r.ParseForm() err := r.ParseForm()
if err != nil { if err != nil {
h.renderError(w, r, http.StatusBadRequest) http.Error(
w, "Bad request", http.StatusBadRequest,
)
return return
} }
@@ -154,69 +152,21 @@ func (h *Handlers) applyTargetEdit(
target.MaxRetries = retries target.MaxRetries = retries
} }
oldName := target.Name
target.Name = name target.Name = name
target.Config = configJSON target.Config = configJSON
// A new name renames the archive file before it is saved (see err = h.db.DB().Save(target).Error
// delivery.Engine.Rename). If either step fails, it goes back to
// the name that is still stored.
err = h.renameTargetArchive(target, webhook.Name, oldName, name)
if err == nil {
err = h.db.DB().Save(target).Error
}
if err != nil { if err != nil {
restoreErr := h.renameTargetArchive( h.serverError(w, "failed to update target", err)
target, webhook.Name, name, oldName,
)
if restoreErr != nil {
h.log.Error(
"failed to rename archive back",
"target_id", target.ID,
"error", restoreErr,
)
}
if errors.Is(err, delivery.ErrArchiveNameTaken) {
http.Error(
w,
"Not saved: "+err.Error()+
". Move that archive out of the data directory, "+
"its .db together with any -wal and -shm beside "+
"it, then save again.",
http.StatusConflict,
)
return
}
h.serverError(w, r, "failed to update target", err)
return return
} }
http.Redirect( http.Redirect(
w, r, withNotice("/hook/"+webhook.ID, targetSaved), w, r, "/source/"+webhook.ID, http.StatusSeeOther,
http.StatusSeeOther,
) )
} }
// renameTargetArchive renames a database target's archive file from
// the target name oldName to newName. It does nothing when the name
// is unchanged; other target types have no archive.
func (h *Handlers) renameTargetArchive(
target *database.Target,
webhookName, oldName, newName string,
) error {
if h.archives == nil || oldName == newName ||
target.Type != database.TargetTypeDatabase {
return nil
}
return h.archives.Rename(target.ID, webhookName, newName)
}
// renderTargetEdit renders the target edit page with an optional // renderTargetEdit renders the target edit page with an optional
// error message. // error message.
func (h *Handlers) renderTargetEdit( func (h *Handlers) renderTargetEdit(
@@ -270,7 +220,7 @@ func (h *Handlers) ownedTarget(
chi.URLParam(r, "targetID"), webhook.ID, chi.URLParam(r, "targetID"), webhook.ID,
).First(&target).Error ).First(&target).Error
if err != nil { if err != nil {
h.renderError(w, r, http.StatusNotFound) http.NotFound(w, r)
return database.Webhook{}, nil, false return database.Webhook{}, nil, false
} }
+9 -106
View File
@@ -42,15 +42,15 @@ const (
func targetRouter(env *sourceTestEnv) *chi.Mux { func targetRouter(env *sourceTestEnv) *chi.Mux {
router := chi.NewRouter() router := chi.NewRouter()
router.Post( router.Post(
"/hook/{sourceID}/targets", "/source/{sourceID}/targets",
env.handlers.HandleTargetCreate(), env.handlers.HandleTargetCreate(),
) )
router.Get( router.Get(
"/hook/{sourceID}/targets/{targetID}/edit", "/source/{sourceID}/targets/{targetID}/edit",
env.handlers.HandleTargetEdit(), env.handlers.HandleTargetEdit(),
) )
router.Post( router.Post(
"/hook/{sourceID}/targets/{targetID}/edit", "/source/{sourceID}/targets/{targetID}/edit",
env.handlers.HandleTargetEditSubmit(), env.handlers.HandleTargetEditSubmit(),
) )
@@ -117,7 +117,7 @@ func seedHTTPTarget(
w := serveTarget( w := serveTarget(
env, http.MethodPost, env, http.MethodPost,
"/hook/"+webhook.ID+"/targets", form, "/source/"+webhook.ID+"/targets", form,
) )
require.Equal(t, http.StatusSeeOther, w.Code, w.Body.String()) require.Equal(t, http.StatusSeeOther, w.Code, w.Body.String())
@@ -188,7 +188,7 @@ func submitTargetEdit(
) *httptest.ResponseRecorder { ) *httptest.ResponseRecorder {
return serveTarget( return serveTarget(
env, http.MethodPost, env, http.MethodPost,
"/hook/"+webhookID+"/targets/"+targetID+"/edit", "/source/"+webhookID+"/targets/"+targetID+"/edit",
form, form,
) )
} }
@@ -401,7 +401,7 @@ func TestHandleTargetEdit_PrefillsTheStoredValuesUnmasked(
w := serveTarget( w := serveTarget(
env, http.MethodGet, env, http.MethodGet,
"/hook/"+webhook.ID+"/targets/"+target.ID+"/edit", "/source/"+webhook.ID+"/targets/"+target.ID+"/edit",
nil, nil,
) )
require.Equal(t, http.StatusOK, w.Code) require.Equal(t, http.StatusOK, w.Code)
@@ -508,7 +508,7 @@ func assertEditIgnoresQueryString(
w := serveTarget( w := serveTarget(
env, http.MethodPost, env, http.MethodPost,
"/hook/"+webhook.ID+"/targets/"+target.ID+ "/source/"+webhook.ID+"/targets/"+target.ID+
"/edit?url="+url.QueryEscape(editReplacedURL)+ "/edit?url="+url.QueryEscape(editReplacedURL)+
"&headers="+url.QueryEscape(editAuthHeader), "&headers="+url.QueryEscape(editAuthHeader),
form, form,
@@ -592,7 +592,7 @@ func assertTargetOfAnotherWebhook404s(
get := serveTarget( get := serveTarget(
env, http.MethodGet, env, http.MethodGet,
"/hook/"+mine.ID+"/targets/"+target.ID+"/edit", nil, "/source/"+mine.ID+"/targets/"+target.ID+"/edit", nil,
) )
assert.Equal(t, http.StatusNotFound, get.Code) assert.Equal(t, http.StatusNotFound, get.Code)
@@ -630,105 +630,8 @@ func assertWebhookOfAnotherUser404s(
w := serveTarget( w := serveTarget(
env, http.MethodGet, env, http.MethodGet,
"/hook/"+other.ID+"/targets/"+target.ID+"/edit", nil, "/source/"+other.ID+"/targets/"+target.ID+"/edit", nil,
) )
assert.Equal(t, http.StatusNotFound, w.Code) assert.Equal(t, http.StatusNotFound, w.Code)
} }
// renamedTargetName is the name the rename tests give a target.
const renamedTargetName = "Long Term"
// TestHandleTargetEditSubmit_RenamesArchive proves that renaming a
// database target renames its archive, that a save that keeps the
// name renames nothing, that a target of another type has no archive
// to rename, and that a target whose archive cannot be renamed keeps
// its stored name. When a file already has the archive's new name,
// the edit is refused with an error naming that file.
func TestHandleTargetEditSubmit_RenamesArchive(t *testing.T) {
t.Parallel()
env := setupSourceTest(t)
wh := seedWebhookWithRetention(t, env.db, 7)
archive := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
rename := url.Values{"name": {renamedTargetName}}
w := submitTargetEdit(env, wh.ID, archive.ID, rename)
require.Equal(t, http.StatusSeeOther, w.Code, w.Body.String())
assert.Equal(
t,
[]archiveRename{{archive.ID, wh.Name, renamedTargetName}},
env.archives.Renames(),
)
w = submitTargetEdit(env, wh.ID, archive.ID, rename)
require.Equal(t, http.StatusSeeOther, w.Code, w.Body.String())
assert.Len(
t, env.archives.Renames(), 1,
"a save that keeps the name renames nothing",
)
httpWebhook, httpTarget := seedHTTPTarget(t, env, "", "")
w = submitTargetEdit(
env, httpWebhook.ID, httpTarget.ID,
editForm(editOriginalURL, "", ""),
)
require.Equal(t, http.StatusSeeOther, w.Code, w.Body.String())
assert.Len(
t, env.archives.Renames(), 1,
"an HTTP target has no archive to rename",
)
again := url.Values{"name": {"Again"}}
env.archives.FailRenames(archive.ID, errInjectedRename)
w = submitTargetEdit(env, wh.ID, archive.ID, again)
require.Equal(t, http.StatusInternalServerError, w.Code)
assert.Equal(
t, renamedTargetName, storedTarget(t, env, archive.ID).Name,
"a target whose archive was not renamed keeps its name",
)
env.archives.FailRenames(archive.ID, errNameTaken)
w = submitTargetEdit(env, wh.ID, archive.ID, again)
require.Equal(t, http.StatusConflict, w.Code)
assert.Contains(t, w.Body.String(), "archive-taken.db")
assert.Equal(
t, renamedTargetName, storedTarget(t, env, archive.ID).Name,
)
}
// TestHandleTargetEditSubmit_FailedSaveRenamesBack proves that when a
// database target's archive is renamed but the new name cannot be
// saved, the archive is renamed back to the stored name and the
// stored name stays.
func TestHandleTargetEditSubmit_FailedSaveRenamesBack(t *testing.T) {
t.Parallel()
env := setupSourceTest(t)
wh := seedWebhookWithRetention(t, env.db, 7)
archive := seedTarget(t, env.db, wh.ID, database.TargetTypeDatabase)
failSaveOnTable(t, env.db, "targets")
form := url.Values{}
form.Set("name", renamedTargetName)
w := submitTargetEdit(env, wh.ID, archive.ID, form)
require.Equal(t, http.StatusInternalServerError, w.Code)
assert.Equal(
t, archive.Name, storedTarget(t, env, archive.ID).Name,
)
assert.Equal(
t,
[]archiveRename{
{archive.ID, wh.Name, renamedTargetName},
{archive.ID, wh.Name, archive.Name},
},
env.archives.Renames(),
)
}
@@ -1,116 +0,0 @@
package handlers_test
import (
"net/http"
"net/url"
"testing"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/internal/database"
)
// privateRefusalHint is the sentence that tells an operator a private
// destination is refused on purpose, and how to allow one.
const privateRefusalHint = "Private and reserved addresses are " +
"refused by default; the server's ALLOWED_EGRESS_CIDRS setting " +
"allows named networks (see \"Allowing egress to your own " +
"network\" in the README)."
// TestTargetRefusal_PrivateDestinationSaysHowToAllowIt covers both
// target types that take a URL, on add and on edit.
func TestTargetRefusal_PrivateDestinationSaysHowToAllowIt(
t *testing.T,
) {
t.Parallel()
env := setupSourceTest(t)
targetTypes := []database.TargetType{
database.TargetTypeHTTP,
database.TargetTypeSlack,
}
for _, targetType := range targetTypes {
t.Run(string(targetType), func(t *testing.T) {
t.Parallel()
webhook := seedWebhookWithRetention(t, env.db, 30)
targetsPath := "/hook/" + webhook.ID + "/targets"
form := url.Values{}
form.Set("name", "private")
form.Set("type", string(targetType))
form.Set("url", editBlockedURL)
added := serveTarget(
env, http.MethodPost, targetsPath, form,
)
assert.Equal(t, http.StatusBadRequest, added.Code)
assert.Contains(
t, added.Body.String(), privateRefusalHint,
)
form.Set("url", editOriginalURL)
created := serveTarget(
env, http.MethodPost, targetsPath, form,
)
require.Equal(
t, http.StatusSeeOther, created.Code,
created.Body.String(),
)
targets := targetsForWebhook(t, env.db, webhook.ID)
require.Len(t, targets, 1)
form.Set("url", editBlockedURL)
edited := submitTargetEdit(
env, webhook.ID, targets[0].ID, form,
)
assert.Equal(t, http.StatusBadRequest, edited.Code)
assert.Contains(
t, edited.Body.String(), privateRefusalHint,
)
})
}
}
// TestTargetRefusal_MetadataDestinationDoesNotSayHowToAllowIt: no
// setting opens a link-local address, and Azure's WireServer hands out
// VM credentials, so neither refusal points at the setting.
func TestTargetRefusal_MetadataDestinationDoesNotSayHowToAllowIt(
t *testing.T,
) {
t.Parallel()
env := setupSourceTest(t)
metadataURLs := map[string]string{
"link-local": "http://169.254.169.254/latest/meta-data/",
"wireserver": "http://168.63.129.16/?comp=versions",
}
for name, metadataURL := range metadataURLs {
t.Run(name, func(t *testing.T) {
t.Parallel()
webhook := seedWebhookWithRetention(t, env.db, 30)
form := url.Values{}
form.Set("name", "metadata")
form.Set("type", string(database.TargetTypeHTTP))
form.Set("url", metadataURL)
w := serveTarget(
env, http.MethodPost,
"/hook/"+webhook.ID+"/targets", form,
)
assert.Equal(t, http.StatusBadRequest, w.Code)
assert.NotContains(
t, w.Body.String(), privateRefusalHint,
)
})
}
}
+1 -1
View File
@@ -102,7 +102,7 @@ func createWithRetries(
w := serveTarget( w := serveTarget(
env, http.MethodPost, env, http.MethodPost,
"/hook/"+webhook.ID+"/targets", "/source/"+webhook.ID+"/targets",
createRetriesForm(retries), createRetriesForm(retries),
) )
+10 -55
View File
@@ -54,7 +54,8 @@ func renderPage(
} }
// TestNavbarUsesWebhookTerminology pins the user-visible navigation // TestNavbarUsesWebhookTerminology pins the user-visible navigation
// label to "Webhooks" and its link to the webhook list at /hooks. // label to "Webhooks". The /sources route is deliberately unchanged, so
// the assertion targets the link text rather than the href.
func TestNavbarUsesWebhookTerminology(t *testing.T) { func TestNavbarUsesWebhookTerminology(t *testing.T) {
t.Parallel() t.Parallel()
@@ -94,11 +95,15 @@ func TestNavbarUsesWebhookTerminology(t *testing.T) {
t, body, ">Sources<", t, body, ">Sources<",
"no user-visible element may still be labelled Sources", "no user-visible element may still be labelled Sources",
) )
assert.Contains(t, body, `href="/hooks"`) assert.Contains(
t, body, `href="/sources"`,
"the /sources route itself must not change",
)
} }
// TestEditPageUsesWebhookTerminology pins the edit page's heading and // TestEditPageUsesWebhookTerminology pins the edit page's heading and
// its back link to the webhook page at /hook/{id}. // its back link. The link's href still points at /source/{id}, which is
// intentional: only user-visible copy changes.
func TestEditPageUsesWebhookTerminology(t *testing.T) { func TestEditPageUsesWebhookTerminology(t *testing.T) {
t.Parallel() t.Parallel()
@@ -125,57 +130,7 @@ func TestEditPageUsesWebhookTerminology(t *testing.T) {
assert.Contains(t, body, "Edit Webhook") assert.Contains(t, body, "Edit Webhook")
assert.NotContains(t, body, ">Sources<") assert.NotContains(t, body, ">Sources<")
assert.Contains(t, body, `href="/hook/wh-1"`) assert.Contains(t, body, `href="/source/wh-1"`)
}
// TestEventLogPageIsCalledFullEventLog pins the one name the event log
// page at /hook/{id}/events goes by: both links to it on the webhook
// page, and its own heading, read "Full Event Log".
func TestEventLogPageIsCalledFullEventLog(t *testing.T) {
t.Parallel()
var h *handlers.Handlers
var sess *session.Session
app := newTestApp(t, &h, &sess)
app.RequireStart()
t.Cleanup(app.RequireStop)
// A pointer, as in the handlers: source_detail.html calls
// Webhook.RetentionLabel, a pointer method. Both pages only range
// over their lists, and a list left out renders as empty, so the
// lists are left out.
webhook := &database.Webhook{Name: "wh", RetentionDays: 14}
webhook.ID = testWebhookID
detailBody := renderPage(
t, h, sess, "source_detail.html", map[string]any{
dataKeyWebhook: webhook,
},
)
assert.Contains(
t, detailBody,
`<a href="/hook/wh-1/events" class="btn-secondary">Full Event Log</a>`,
"the button at the top of the webhook page",
)
assert.Contains(
t, detailBody,
`<a href="/hook/wh-1/events" class="btn-text text-sm">Full Event Log</a>`,
"the link under recent events",
)
logBody := renderPage(t, h, sess, "source_logs.html", map[string]any{
dataKeyWebhook: webhook,
"TotalEvents": int64(0),
})
assert.Contains(
t, logBody,
`<h1 class="text-2xl font-medium text-gray-900">Full Event Log</h1>`,
)
} }
// TestCreateFormRetentionCopyMatchesBehaviour pins the create form's // TestCreateFormRetentionCopyMatchesBehaviour pins the create form's
@@ -328,7 +283,7 @@ func TestEntrypointCopyButtonIsProgressiveEnhancement(t *testing.T) {
t, body, t, body,
`<code id="entrypoint-url-ep-1"`, `<code id="entrypoint-url-ep-1"`,
) )
assert.Contains(t, body, "https://hooks.example.com/h/abc123") assert.Contains(t, body, "https://hooks.example.com/webhook/abc123")
assert.Contains( assert.Contains(
t, body, t, body,
`hidden data-copy-target="entrypoint-url-ep-1"`, `hidden data-copy-target="entrypoint-url-ep-1"`,
+6 -24
View File
@@ -88,14 +88,14 @@ func (h *Handlers) processWebhookRequest(
headersJSON, err := json.Marshal(r.Header) headersJSON, err := json.Marshal(r.Header)
if err != nil { if err != nil {
h.receiverError(w, "failed to serialize headers", err) h.serverError(w, "failed to serialize headers", err)
return return
} }
targets, err := h.loadActiveTargets(entrypoint.WebhookID) targets, err := h.loadActiveTargets(entrypoint.WebhookID)
if err != nil { if err != nil {
h.receiverError(w, "failed to query targets", err) h.serverError(w, "failed to query targets", err)
return return
} }
@@ -131,7 +131,7 @@ func (h *Handlers) lookupEntrypoint(
"path = ?", entrypointUUID, "path = ?", entrypointUUID,
).First(&entrypoint) ).First(&entrypoint)
if result.Error != nil { if result.Error != nil {
// The receiver is unauthenticated and /h/{uuid} // The receiver is unauthenticated and /webhook/{uuid}
// matches any single segment, so this value is entirely // matches any single segment, so this value is entirely
// client-chosen on exactly the branch where the lookup // client-chosen on exactly the branch where the lookup
// failed. DEBUG is off by default; the cap is what keeps // failed. DEBUG is off by default; the cap is what keeps
@@ -150,9 +150,7 @@ func (h *Handlers) lookupEntrypoint(
return entrypoint, true return entrypoint, true
} }
// readWebhookBody reads and validates the request body size. This is // readWebhookBody reads and validates the request body size.
// the receiver's only body cap: /h/{uuid} has no MaxBodySize
// middleware (see Server.setupWebhookRoutes).
func (h *Handlers) readWebhookBody( func (h *Handlers) readWebhookBody(
w http.ResponseWriter, w http.ResponseWriter,
r *http.Request, r *http.Request,
@@ -198,7 +196,7 @@ func (h *Handlers) createAndDeliverEvent(
targets, targets,
) )
if err != nil { if err != nil {
h.receiverError(w, "failed to store webhook event", err) h.serverError(w, "failed to store webhook event", err)
return return
} }
@@ -206,19 +204,6 @@ func (h *Handlers) createAndDeliverEvent(
h.finishWebhookResponse(w, event, entrypoint, tasks) h.finishWebhookResponse(w, event, entrypoint, tasks)
} }
// receiverError logs an error and answers the sender with a plain-text
// 500. The receiver's answers are for programs, so it never sends the
// error page the web UI uses.
func (h *Handlers) receiverError(
w http.ResponseWriter, msg string, err error,
) {
h.log.Error(msg, "error", err)
http.Error(
w, "Internal server error",
http.StatusInternalServerError,
)
}
// eventSource carries the fields a new event is built from. The // eventSource carries the fields a new event is built from. The
// receiver fills it from the live request; the resubmit handler fills // receiver fills it from the live request; the resubmit handler fills
// it from a stored event. Both then go through createAndFanOut, so an // it from a stored event. Both then go through createAndFanOut, so an
@@ -245,7 +230,6 @@ func (s eventSource) event() *database.Event {
Method: s.Method, Method: s.Method,
Headers: s.HeadersJSON, Headers: s.HeadersJSON,
Body: string(s.Body), Body: string(s.Body),
BodyBytes: int64(len(s.Body)),
ContentType: s.ContentType, ContentType: s.ContentType,
ResubmittedFromID: s.ResubmittedFromID, ResubmittedFromID: s.ResubmittedFromID,
} }
@@ -313,9 +297,7 @@ func (h *Handlers) createAndFanOut(
return nil, nil, err return nil, nil, err
} }
err = database.AddEventTotals(tx, database.EventTotals{ err = database.AddEventTotals(tx, database.EventTotals{Events: 1})
Events: 1, LastEventAt: &event.CreatedAt,
})
if err != nil { if err != nil {
tx.Rollback() tx.Rollback()
+18 -6
View File
@@ -34,8 +34,8 @@ type WebhookStats struct {
// InProgress counts the deliveries still pending or retrying. // InProgress counts the deliveries still pending or retrying.
InProgress int64 InProgress int64
// LastEventAt is when the newest event arrived, or nil when none // LastEventAt is when the newest stored event arrived, or nil when
// has. Retention does not change it. // none is stored.
LastEventAt *time.Time LastEventAt *time.Time
Last10Minutes RecentWindow Last10Minutes RecentWindow
@@ -154,6 +154,20 @@ func readEventStats(
return fmt.Errorf("counting deliveries in progress: %w", err) return fmt.Errorf("counting deliveries in progress: %w", err)
} }
var newest []time.Time
err = db.Model(&database.Event{}).
Order("created_at DESC").
Limit(1).
Pluck("created_at", &newest).Error
if err != nil {
return fmt.Errorf("reading newest event time: %w", err)
}
if len(newest) > 0 {
stats.LastEventAt = &newest[0]
}
stats.Last10Minutes, err = readRecentWindow( stats.Last10Minutes, err = readRecentWindow(
db, now.Add(-shortWindow), db, now.Add(-shortWindow),
) )
@@ -168,9 +182,8 @@ func readEventStats(
return err return err
} }
// readTotals fills in the lifetime and within-retention figures, and // readTotals fills in the lifetime and within-retention figures from
// when the last event arrived, from the running totals: the events' // the running totals: the events' row, and the targets' rows summed.
// row, and the targets' rows summed.
func readTotals(db *gorm.DB, stats *WebhookStats) error { func readTotals(db *gorm.DB, stats *WebhookStats) error {
var events database.EventTotals var events database.EventTotals
@@ -188,7 +201,6 @@ func readTotals(db *gorm.DB, stats *WebhookStats) error {
stats.Lifetime.Events = events.Events stats.Lifetime.Events = events.Events
stats.WithinRetention.Events = events.Events - events.EventsRemoved stats.WithinRetention.Events = events.Events - events.EventsRemoved
stats.LastEventAt = events.LastEventAt
for _, t := range targets { for _, t := range targets {
stats.Lifetime.Deliveries += t.Deliveries stats.Lifetime.Deliveries += t.Deliveries
+68 -205
View File
@@ -2,7 +2,6 @@ package handlers_test
import ( import (
"net/http" "net/http"
"regexp"
"strings" "strings"
"testing" "testing"
"time" "time"
@@ -121,17 +120,13 @@ type statsHistory struct {
first, second string first, second string
} }
// seedStatsHistory builds the webhook the statistics test checks: 14 // seedStatsHistory builds the webhook the statistics test checks: one
// days of retention, twelve entrypoints (one inactive) and six targets // day of retention, two entrypoints (one inactive) and three targets
// (four inactive). Ten events arrive through the receiver, and so each // (one inactive). Three events arrive through the receiver, and so
// has a delivery to the two active targets. The oldest event is past // each has a delivery to the two active targets. The oldest event is
// retention, the next 30 hours old, the next six hours old, the other // past retention, the middle one six hours old, the newest just in.
// seven just in. Six deliveries are settled as the delivery engine // Their deliveries are settled as the delivery engine would, and a
// would, two of them inside a recent window though their event arrived // replay adds a pending delivery to the oldest event.
// before it. The newest event's delivery to the second target is
// retrying, the rest are left pending, and a replay adds a pending
// delivery to the oldest event. Once retention has removed the oldest
// event, every figure in the pane differs from every other.
func seedStatsHistory( func seedStatsHistory(
t *testing.T, t *testing.T,
h *handlers.Handlers, h *handlers.Handlers,
@@ -141,14 +136,12 @@ func seedStatsHistory(
) statsHistory { ) statsHistory {
t.Helper() t.Helper()
wh := &database.Webhook{UserID: deleteTestUserID, Name: "stats", RetentionDays: 14} wh := &database.Webhook{
UserID: deleteTestUserID, Name: "stats", RetentionDays: 1,
}
require.NoError(t, db.DB().Omit(clause.Associations).Create(wh).Error) require.NoError(t, db.DB().Omit(clause.Associations).Create(wh).Error)
path := statsEntrypoint(t, db, wh.ID, true) path := statsEntrypoint(t, db, wh.ID, true)
for range 10 {
statsEntrypoint(t, db, wh.ID, true)
}
statsEntrypoint(t, db, wh.ID, false) statsEntrypoint(t, db, wh.ID, false)
first := seedConfiguredTarget( first := seedConfiguredTarget(
@@ -156,16 +149,13 @@ func seedStatsHistory(
`{"url":"`+replayTargetURL+`"}`, `{"url":"`+replayTargetURL+`"}`,
) )
second := seedTarget(t, db, wh.ID, database.TargetTypeLog) second := seedTarget(t, db, wh.ID, database.TargetTypeLog)
inactive := seedTarget(t, db, wh.ID, database.TargetTypeLog)
for range 4 { require.NoError(t, db.DB().Model(inactive).
inactive := seedTarget(t, db, wh.ID, database.TargetTypeLog) Update("active", false).Error)
require.NoError(t, db.DB().Model(inactive).
Update("active", false).Error)
}
router := receiverRouter(h) router := receiverRouter(h)
for range 10 { for range 3 {
require.Equal(t, http.StatusOK, postReceiver(t, router, path)) require.Equal(t, http.StatusOK, postReceiver(t, router, path))
} }
@@ -173,44 +163,39 @@ func seedStatsHistory(
require.NoError(t, err) require.NoError(t, err)
events := listEvents(t, webhookDB) events := listEvents(t, webhookDB)
require.Len(t, events, 10) require.Len(t, events, 3)
oldest, yesterday, middle, newest := events[0], events[1], events[2], events[9] oldest, middle, newest := events[0], events[1], events[2]
now := time.Now() now := time.Now()
statsAge(t, webhookDB, oldest.ID, now.Add(-15*24*time.Hour)) statsAge(t, webhookDB, oldest.ID, now.Add(-50*time.Hour))
statsAge(t, webhookDB, yesterday.ID, now.Add(-30*time.Hour))
statsAge(t, webhookDB, middle.ID, now.Add(-6*time.Hour)) statsAge(t, webhookDB, middle.ID, now.Add(-6*time.Hour))
oldestFailure := statsDelivery(t, webhookDB, oldest.ID, first.ID) oldestFailure := statsDelivery(t, webhookDB, oldest.ID, first.ID)
statsFinish(t, webhookDB, oldestFailure, statsFinish(t, webhookDB, oldestFailure,
database.DeliveryStatusFailed, now.Add(-14*24*time.Hour)) database.DeliveryStatusFailed, now.Add(-49*time.Hour))
statsFinish(t, webhookDB, statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, yesterday.ID, first.ID), statsDelivery(t, webhookDB, oldest.ID, second.ID),
database.DeliveryStatusFailed, now.Add(-29*time.Hour)) database.DeliveryStatusDelivered, now.Add(-49*time.Hour))
statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, yesterday.ID, second.ID),
database.DeliveryStatusFailed, now.Add(-23*time.Hour))
statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, middle.ID, second.ID),
database.DeliveryStatusFailed, now.Add(-5*time.Hour))
statsFinish(t, webhookDB, statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, middle.ID, first.ID), statsDelivery(t, webhookDB, middle.ID, first.ID),
database.DeliveryStatusFailed, now.Add(-5*time.Hour))
statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, middle.ID, second.ID),
database.DeliveryStatusFailed, now.Add(-time.Minute)) database.DeliveryStatusFailed, now.Add(-time.Minute))
statsFinish(t, webhookDB, statsFinish(t, webhookDB,
statsDelivery(t, webhookDB, newest.ID, first.ID), statsDelivery(t, webhookDB, newest.ID, first.ID),
database.DeliveryStatusDelivered, now.Add(-2*time.Minute)) database.DeliveryStatusDelivered, now.Add(-2*time.Minute))
retrying := statsDelivery(t, webhookDB, newest.ID, second.ID)
require.NoError(t, webhookDB.Model(&retrying).
Update("status", database.DeliveryStatusRetrying).Error)
require.Equal(t, http.StatusSeeOther, require.Equal(t, http.StatusSeeOther,
postReplay(t, h, sess, wh.ID, oldestFailure.ID).Code) postReplay(t, h, sess, wh.ID, oldestFailure.ID).Code)
return statsHistory{ return statsHistory{
webhook: wh, webhookDB: webhookDB, newest: newest, webhook: wh,
first: first.ID, second: second.ID, webhookDB: webhookDB,
newest: newest,
first: first.ID,
second: second.ID,
} }
} }
@@ -248,11 +233,8 @@ func statsPrune(
lc.RequireStop() lc.RequireStop()
} }
// statsPane returns the text of the statistics pane in a rendered // statsPane returns the statistics pane from a rendered webhook page:
// webhook page, everything from its heading to the next heading on the // everything from its heading to the next heading on the page.
// page, with the markup taken out and each run of space made one
// space. A table then reads header by header and row by row, each
// row's label followed by its figures in column order.
func statsPane(t *testing.T, page string) string { func statsPane(t *testing.T, page string) string {
t.Helper() t.Helper()
@@ -260,62 +242,8 @@ func statsPane(t *testing.T, page string) string {
require.True(t, found, "the page has no statistics pane") require.True(t, found, "the page has no statistics pane")
pane, _, _ = strings.Cut(pane, "<h2") pane, _, _ = strings.Cut(pane, "<h2")
pane = regexp.MustCompile(`<[^>]*>`).ReplaceAllString(pane, " ")
return strings.Join(strings.Fields(pane), " ") return pane
}
// assertStatsTargets checks, for the history seedStatsHistory builds,
// each target's totals and its deliveries finished in the last 24
// hours. The first target has ten deliveries and the replay, the
// second ten; the inactive targets have none and so no row.
func assertStatsTargets(t *testing.T, hist statsHistory) {
t.Helper()
first, second := hist.first, hist.second
assert.Equal(t, map[string]database.TargetTotals{
first: {TargetID: first, Deliveries: 11, Delivered: 1, Failed: 3},
second: {TargetID: second, Deliveries: 10, Failed: 2},
}, statsTargetTotals(t, hist.webhookDB))
lastDay, err := handlers.FinishedByTargetForTest(
hist.webhookDB, time.Now().Add(-24*time.Hour),
)
require.NoError(t, err)
assert.ElementsMatch(t, []handlers.TargetFinished{
{TargetID: first, Delivered: 1, Failed: 1},
{TargetID: second, Failed: 2},
}, lastDay)
}
// assertStatsPaneAfterPrune checks the rendered statistics pane for the
// history seedStatsHistory builds, once retention has removed the
// oldest event: each figure after its label, in its column.
func assertStatsPaneAfterPrune(
t *testing.T,
h *handlers.Handlers,
sess *session.Session,
hist statsHistory,
) {
t.Helper()
pane := statsPane(t, renderSourceDetailPage(t, h, sess, hist.webhook.ID))
lastEvent := hist.newest.CreatedAt.UTC().Format("2006-01-02 15:04:05 UTC")
assert.Contains(t, pane, "Entrypoints 12 (11 active) "+
"Targets 6 (2 active) "+
"Deliveries in progress 13 "+
"Last event "+lastEvent+" "+
"Retention 14 days")
assert.Contains(t, pane, "Lifetime Within retention "+
"Events 10 9 "+
"Deliveries 21 18 "+
"Failures 5 4")
assert.Contains(t, pane, "Last 10 minutes Last 24 hours "+
"Events 7 8 "+
"Failures 1 3 "+
"Failure percentage 50.0% 75.0%")
} }
// TestWebhookStats_EveryFigureAcrossRetentionPrune checks every figure // TestWebhookStats_EveryFigureAcrossRetentionPrune checks every figure
@@ -344,138 +272,74 @@ func TestWebhookStats_EveryFigureAcrossRetentionPrune(t *testing.T) {
stats := h.WebhookStatsForTest(hist.webhook.ID) stats := h.WebhookStatsForTest(hist.webhook.ID)
require.NotNil(t, stats) require.NotNil(t, stats)
assert.Equal(t, 12, stats.Entrypoints) assert.Equal(t, 2, stats.Entrypoints)
assert.Equal(t, 11, stats.ActiveEntrypoints) assert.Equal(t, 1, stats.ActiveEntrypoints)
assert.Equal(t, 6, stats.Targets) assert.Equal(t, 3, stats.Targets)
assert.Equal(t, 2, stats.ActiveTargets) assert.Equal(t, 2, stats.ActiveTargets)
assert.Equal(t, handlers.Counts{Events: 10, Deliveries: 21, Failures: 5}, assert.Equal(t, handlers.Counts{Events: 3, Deliveries: 7, Failures: 3},
stats.Lifetime) stats.Lifetime)
assert.Equal(t, stats.Lifetime, stats.WithinRetention) assert.Equal(t, stats.Lifetime, stats.WithinRetention)
assert.Equal(t, int64(15), stats.InProgress) assert.Equal(t, int64(2), stats.InProgress)
require.NotNil(t, stats.LastEventAt) require.NotNil(t, stats.LastEventAt)
assert.True(t, hist.newest.CreatedAt.Equal(*stats.LastEventAt)) assert.True(t, hist.newest.CreatedAt.Equal(*stats.LastEventAt))
assert.Equal(t, handlers.RecentWindow{ assert.Equal(t, handlers.RecentWindow{
Events: 7, Delivered: 1, Failed: 1, Events: 1, Delivered: 1, Failed: 1,
}, stats.Last10Minutes) }, stats.Last10Minutes)
assert.Equal(t, handlers.RecentWindow{ assert.Equal(t, handlers.RecentWindow{
Events: 8, Delivered: 1, Failed: 3, Events: 2, Delivered: 1, Failed: 2,
}, stats.Last24Hours) }, stats.Last24Hours)
assert.Equal(t, "50.0%", stats.Last10Minutes.FailurePercent()) assert.Equal(t, "50.0%", stats.Last10Minutes.FailurePercent())
assert.Equal(t, "75.0%", stats.Last24Hours.FailurePercent()) assert.Equal(t, "66.7%", stats.Last24Hours.FailurePercent())
assertStatsTargets(t, hist) // The first target has three deliveries and the replay, the second
// three; the inactive target has none and so no row.
assert.Equal(t, map[string]database.TargetTotals{
first: {TargetID: first, Deliveries: 4, Delivered: 1, Failed: 2},
second: {
TargetID: second, Deliveries: 3, Delivered: 1, Failed: 1,
},
}, statsTargetTotals(t, hist.webhookDB))
lastDay, err := handlers.FinishedByTargetForTest(
hist.webhookDB, time.Now().Add(-24*time.Hour),
)
require.NoError(t, err)
assert.ElementsMatch(t, []handlers.TargetFinished{
{TargetID: first, Delivered: 1, Failed: 1},
{TargetID: second, Failed: 1},
}, lastDay)
// Retention removes the oldest event with its three deliveries: // Retention removes the oldest event with its three deliveries:
// the first target's failed one and the pending replay, and the // the first target's failed one and the pending replay, and the
// second target's pending one. // second target's delivered one.
statsPrune(t, db, dbMgr, log, hist.webhookDB) statsPrune(t, db, dbMgr, log, hist.webhookDB)
after := h.WebhookStatsForTest(hist.webhook.ID) after := h.WebhookStatsForTest(hist.webhook.ID)
require.NotNil(t, after) require.NotNil(t, after)
assert.Equal(t, stats.Lifetime, after.Lifetime) assert.Equal(t, stats.Lifetime, after.Lifetime)
assert.Equal(t, handlers.Counts{Events: 9, Deliveries: 18, Failures: 4}, assert.Equal(t, handlers.Counts{Events: 2, Deliveries: 4, Failures: 2},
after.WithinRetention) after.WithinRetention)
assert.Equal(t, int64(13), after.InProgress) assert.Equal(t, int64(1), after.InProgress)
assert.Equal(t, stats.LastEventAt, after.LastEventAt) assert.Equal(t, stats.LastEventAt, after.LastEventAt)
assert.Equal(t, stats.Last10Minutes, after.Last10Minutes) assert.Equal(t, stats.Last10Minutes, after.Last10Minutes)
assert.Equal(t, stats.Last24Hours, after.Last24Hours) assert.Equal(t, stats.Last24Hours, after.Last24Hours)
assert.Equal(t, map[string]database.TargetTotals{ assert.Equal(t, map[string]database.TargetTotals{
first: { first: {
TargetID: first, Deliveries: 11, Delivered: 1, Failed: 3, TargetID: first, Deliveries: 4, Delivered: 1, Failed: 2,
DeliveriesRemoved: 2, FailedRemoved: 1, DeliveriesRemoved: 2, FailedRemoved: 1,
}, },
second: { second: {
TargetID: second, Deliveries: 10, Failed: 2, TargetID: second, Deliveries: 3, Delivered: 1, Failed: 1,
DeliveriesRemoved: 1, DeliveriesRemoved: 1,
}, },
}, statsTargetTotals(t, hist.webhookDB)) }, statsTargetTotals(t, hist.webhookDB))
assertStatsPaneAfterPrune(t, h, sess, hist) pane := statsPane(t, renderSourceDetailPage(t, h, sess, hist.webhook.ID))
} assert.Contains(t, pane, "Within retention")
assert.Contains(t, pane, "50.0%")
// TestWebhookStats_LastEventSurvivesPruningEveryEvent checks that once assert.Contains(t, pane, "66.7%")
// retention has removed every event, the pane still shows when the last
// one arrived rather than "none".
func TestWebhookStats_LastEventSurvivesPruningEveryEvent(t *testing.T) {
t.Parallel()
var (
h *handlers.Handlers
sess *session.Session
db *database.Database
dbMgr *database.WebhookDBManager
log *logger.Logger
)
app := newTestApp(t, &h, &sess, &db, &dbMgr, &log)
app.RequireStart()
t.Cleanup(app.RequireStop)
wh := &database.Webhook{
UserID: deleteTestUserID, Name: "pruned", RetentionDays: 1,
}
require.NoError(t, db.DB().Omit(clause.Associations).Create(wh).Error)
path := statsEntrypoint(t, db, wh.ID, true)
require.Equal(t, http.StatusOK,
postReceiver(t, receiverRouter(h), path))
webhookDB, err := dbMgr.GetDB(wh.ID)
require.NoError(t, err)
events := listEvents(t, webhookDB)
require.Len(t, events, 1)
arrived := events[0].CreatedAt
statsAge(t, webhookDB, events[0].ID, time.Now().Add(-50*time.Hour))
statsPrune(t, db, dbMgr, log, webhookDB)
require.Empty(t, listEvents(t, webhookDB))
stats := h.WebhookStatsForTest(wh.ID)
require.NotNil(t, stats)
require.NotNil(t, stats.LastEventAt)
assert.True(t, arrived.Equal(*stats.LastEventAt))
pane := statsPane(t, renderSourceDetailPage(t, h, sess, wh.ID))
assert.Contains(t, pane,
"Last event "+arrived.UTC().Format("2006-01-02 15:04:05 UTC"))
}
// TestWebhookStats_LastEventInUTC checks that the pane shows when the
// last event arrived in UTC, as the event list does, when the time was
// stored in another zone, as it is on a host whose local time is not
// UTC.
func TestWebhookStats_LastEventInUTC(t *testing.T) {
t.Parallel()
var (
h *handlers.Handlers
sess *session.Session
db *database.Database
dbMgr *database.WebhookDBManager
)
app := newTestApp(t, &h, &sess, &db, &dbMgr)
app.RequireStart()
t.Cleanup(app.RequireStop)
wh := seedWebhook(t, db)
webhookDB, err := dbMgr.GetDB(wh.ID)
require.NoError(t, err)
arrived := time.Date(2026, time.March, 4, 22, 30, 0, 0,
time.FixedZone("EST", -5*60*60))
require.NoError(t, database.AddEventTotals(webhookDB,
database.EventTotals{Events: 1, LastEventAt: &arrived}))
pane := statsPane(t, renderSourceDetailPage(t, h, sess, wh.ID))
assert.Contains(t, pane, "Last event 2026-03-05 03:30:00 UTC")
} }
// TestWebhookStats_PaneShowsRetentionPeriod checks that the statistics // TestWebhookStats_PaneShowsRetentionPeriod checks that the statistics
@@ -513,7 +377,8 @@ func TestWebhookStats_PaneShowsRetentionPeriod(t *testing.T) {
db.DB().Omit(clause.Associations).Create(wh).Error) db.DB().Omit(clause.Associations).Create(wh).Error)
pane := statsPane(t, renderSourceDetailPage(t, h, sess, wh.ID)) pane := statsPane(t, renderSourceDetailPage(t, h, sess, wh.ID))
assert.Contains(t, pane, "Retention "+tt.want) assert.Contains(t, pane, "Retention", tt.want)
assert.Contains(t, pane, tt.want)
} }
} }
@@ -541,9 +406,7 @@ func TestWebhookStats_WebhookWithNoEvents(t *testing.T) {
assert.Equal(t, &handlers.WebhookStats{}, h.WebhookStatsForTest(wh.ID)) assert.Equal(t, &handlers.WebhookStats{}, h.WebhookStatsForTest(wh.ID))
assert.Equal(t, "—", handlers.RecentWindow{}.FailurePercent()) assert.Equal(t, "—", handlers.RecentWindow{}.FailurePercent())
pane := statsPane(t, renderSourceDetailPage(t, h, sess, wh.ID)) statsPane(t, renderSourceDetailPage(t, h, sess, wh.ID))
assert.Contains(t, pane, "Last event none")
assert.Contains(t, pane, "Failure percentage — —")
assert.False(t, dbMgr.DBExists(wh.ID)) assert.False(t, dbMgr.DBExists(wh.ID))
} }
+4
View File
@@ -7,6 +7,7 @@ import (
"time" "time"
"go.uber.org/fx" "go.uber.org/fx"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/database" "sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/globals" "sneak.berlin/go/webhooker/internal/globals"
"sneak.berlin/go/webhooker/internal/logger" "sneak.berlin/go/webhooker/internal/logger"
@@ -17,6 +18,7 @@ type HealthcheckParams struct {
fx.In fx.In
Globals *globals.Globals Globals *globals.Globals
Config *config.Config
Logger *logger.Logger Logger *logger.Logger
Database *database.Database Database *database.Database
} }
@@ -62,6 +64,7 @@ func (s *Healthcheck) Healthcheck() *Response {
UptimeHuman: s.uptime().String(), UptimeHuman: s.uptime().String(),
Appname: s.params.Globals.Appname, Appname: s.params.Globals.Appname,
Version: s.params.Globals.Version, Version: s.params.Globals.Version,
Maintenance: s.params.Config.MaintenanceMode,
} }
return resp return resp
@@ -75,6 +78,7 @@ type Response struct {
UptimeHuman string `json:"uptimeHuman"` UptimeHuman string `json:"uptimeHuman"`
Version string `json:"version"` Version string `json:"version"`
Appname string `json:"appname"` Appname string `json:"appname"`
Maintenance bool `json:"maintenanceMode"`
} }
func (s *Healthcheck) uptime() time.Duration { func (s *Healthcheck) uptime() time.Duration {
+1 -1
View File
@@ -201,7 +201,7 @@ func TestTruncate_LeavesShortValuesAlone(t *testing.T) {
t.Parallel() t.Parallel()
for _, s := range []string{ for _, s := range []string{
"", "GET", "/hook/abc/edit", "Mozilla/5.0 (X11)", "", "GET", "/source/abc/edit", "Mozilla/5.0 (X11)",
} { } {
assert.Equal(t, s, logfield.Truncate(s, budget)) assert.Equal(t, s, logfield.Truncate(s, budget))
} }
+20 -28
View File
@@ -3,18 +3,17 @@
// deliveries are attempted, how they end, how long they take, how // deliveries are attempted, how they end, how long they take, how
// deep the queues are, and how many circuit breakers are open. // deep the queues are, and how many circuit breakers are open.
// //
// It also builds the registry the authenticated /metrics route // The inbound HTTP metrics come from the go-http-metrics recorder in
// serves. In production, these collectors, the inbound HTTP metrics // internal/middleware and land on prometheus.DefaultRegisterer. These
// recorded in internal/middleware, and the Go runtime and process // collectors register there too, so both surfaces are gathered by the
// collectors all register on that one registry, never on Prometheus's // one promhttp handler mounted on the authenticated /metrics route.
// global default.
package metrics package metrics
import ( import (
"sync"
"time" "time"
"github.com/prometheus/client_golang/prometheus" "github.com/prometheus/client_golang/prometheus"
"github.com/prometheus/client_golang/prometheus/collectors"
"github.com/prometheus/client_golang/prometheus/promauto" "github.com/prometheus/client_golang/prometheus/promauto"
"sneak.berlin/go/webhooker/internal/database" "sneak.berlin/go/webhooker/internal/database"
) )
@@ -58,31 +57,25 @@ var knownTargetTypes = []database.TargetType{
database.TargetTypeSlack, database.TargetTypeSlack,
} }
// NewRegistry returns the registry /metrics serves, carrying the Go // defaultSet is the process-wide metric set, registered on the same
// runtime and process collectors that Prometheus's global default // registry the HTTP middleware and the /metrics handler already use.
// registry carries, so the go_* and process_* series stay in the // It is built on first use rather than in an init so that a test
// scrape. // binary that never touches metrics never registers them.
// //
// A registry of its own, rather than the global default, is what lets //nolint:gochecknoglobals // one process-wide registration, by design
// two dependency graphs in one process — two tests, say — each var defaultSet = sync.OnceValue(func() *Set {
// register their collectors without the second registration return New(prometheus.DefaultRegisterer)
// panicking. })
func NewRegistry() *prometheus.Registry {
reg := prometheus.NewRegistry()
reg.MustRegister(
collectors.NewGoCollector(),
collectors.NewProcessCollector(
collectors.ProcessCollectorOpts{},
),
)
return reg // Default returns the process-wide metric set.
func Default() *Set {
return defaultSet()
} }
// Set is one registered group of webhooker's delivery collectors. // Set is one registered group of webhooker's delivery collectors.
// Production builds one on the registry /metrics serves; tests build // Production uses the single Default set; tests build their own
// one on a registry of their own so they can gather what their own // against a private registry so assertions are not disturbed by
// deliveries recorded. // deliveries other tests are making concurrently.
type Set struct { type Set struct {
eventsReceived prometheus.Counter eventsReceived prometheus.Counter
deliveryAttempts *prometheus.CounterVec deliveryAttempts *prometheus.CounterVec
@@ -100,7 +93,7 @@ type Set struct {
// New registers a full set of delivery collectors on reg and returns // New registers a full set of delivery collectors on reg and returns
// it. It panics if reg already holds them, which is the intended // it. It panics if reg already holds them, which is the intended
// behaviour for a duplicate registration. // behaviour for a duplicate registration.
func New(reg *prometheus.Registry) *Set { func New(reg prometheus.Registerer) *Set {
factory := promauto.With(reg) factory := promauto.With(reg)
s := &Set{ s := &Set{
@@ -384,7 +377,6 @@ func (s *Set) initSeries() {
s.deliveriesFailed.WithLabelValues(label) s.deliveriesFailed.WithLabelValues(label)
s.deliveryRetries.WithLabelValues(label) s.deliveryRetries.WithLabelValues(label)
s.deliveryReplays.WithLabelValues(label) s.deliveryReplays.WithLabelValues(label)
s.deliveryDuration.WithLabelValues(label)
s.deliveriesPending.WithLabelValues(label) s.deliveriesPending.WithLabelValues(label)
s.deliveriesRetrying.WithLabelValues(label) s.deliveriesRetrying.WithLabelValues(label)
s.circuitBreakersOpen.WithLabelValues(label) s.circuitBreakersOpen.WithLabelValues(label)
-1
View File
@@ -167,7 +167,6 @@ func TestKnownSeriesExistBeforeAnyDelivery(t *testing.T) {
"webhooker_deliveries_succeeded_total", "webhooker_deliveries_succeeded_total",
"webhooker_deliveries_failed_total", "webhooker_deliveries_failed_total",
"webhooker_delivery_retries_total", "webhooker_delivery_retries_total",
"webhooker_delivery_duration_seconds",
"webhooker_circuit_breakers_open", "webhooker_circuit_breakers_open",
} { } {
assert.ElementsMatch(t, assert.ElementsMatch(t,
+8 -8
View File
@@ -119,7 +119,7 @@ func accessLogRouter(m *middleware.Middleware) *chi.Mux {
) )
router.HandleFunc( router.HandleFunc(
"/h/{uuid}", "/webhook/{uuid}",
func(w http.ResponseWriter, r *http.Request) { func(w http.ResponseWriter, r *http.Request) {
// Stands in for the real handler: an unknown entrypoint // Stands in for the real handler: an unknown entrypoint
// UUID 404s, a known one succeeds. // UUID 404s, a known one succeeds.
@@ -271,11 +271,11 @@ func TestAccessLog_InventedReceiverPathsLogRoutePattern(t *testing.T) {
assertFloodIsBounded( assertFloodIsBounded(
t, t,
func(i int) string { func(i int) string {
return "/h/" + attackerMarker + return "/webhook/" + attackerMarker +
strings.Repeat("x", i) + "?q=" + attackerMarker strings.Repeat("x", i) + "?q=" + attackerMarker
}, },
http.StatusNotFound, http.StatusNotFound,
"/h/{uuid}", "/webhook/{uuid}",
) )
} }
@@ -346,10 +346,10 @@ type sizeCase struct {
func lineSizeCases() map[string]sizeCase { func lineSizeCases() map[string]sizeCase {
cases := map[string]sizeCase{ cases := map[string]sizeCase{
"oversized path segment": { "oversized path segment": {
target: "/h/" + attackerMarker + target: "/webhook/" + attackerMarker +
strings.Repeat("x", oversizedSegmentBytes), strings.Repeat("x", oversizedSegmentBytes),
wantStatus: http.StatusNotFound, wantStatus: http.StatusNotFound,
wantURL: "/h/{uuid}", wantURL: "/webhook/{uuid}",
bound: maxLineBytes, bound: maxLineBytes,
}, },
// /.well-known/healthcheck answers 200 to anyone and has no // /.well-known/healthcheck answers 200 to anyone and has no
@@ -605,14 +605,14 @@ func TestAccessLog_SuccessKeepsConcretePathAndRedactsQuery(
router := accessLogRouter(m) router := accessLogRouter(m)
assert.Equal( assert.Equal(
t, http.StatusOK, get(t, router, "/h/known?src=ci"), t, http.StatusOK, get(t, router, "/webhook/known?src=ci"),
) )
// The path resolved against a stored entrypoint, so it stays. The // The path resolved against a stored entrypoint, so it stays. The
// query never does: see TestAccessLog_UnauthenticatedSuccess... // query never does: see TestAccessLog_UnauthenticatedSuccess...
entries := accessLogEntries(t, buf) entries := accessLogEntries(t, buf)
require.Len(t, entries, 1) require.Len(t, entries, 1)
assert.Equal(t, "/h/known?(redacted)", entries[0]["url"]) assert.Equal(t, "/webhook/known?(redacted)", entries[0]["url"])
assert.NotContains(t, buf.String(), "src=ci") assert.NotContains(t, buf.String(), "src=ci")
} }
@@ -640,7 +640,7 @@ func TestAccessLog_RetainsEveryOtherField(t *testing.T) {
assert.Equal( assert.Equal(
t, t,
http.StatusNotFound, http.StatusNotFound,
get(t, router, "/h/"+attackerMarker), get(t, router, "/webhook/"+attackerMarker),
) )
entries := accessLogEntries(t, buf) entries := accessLogEntries(t, buf)
+4 -6
View File
@@ -19,7 +19,7 @@ func CSRFToken(r *http.Request) string {
// key to sign a CSRF cookie and validates a masked token submitted via // key to sign a CSRF cookie and validates a masked token submitted via
// the "csrf_token" form field (or the "X-CSRF-Token" header) on // the "csrf_token" form field (or the "X-CSRF-Token" header) on
// POST/PUT/PATCH/DELETE requests. Requests with an invalid or missing // POST/PUT/PATCH/DELETE requests. Requests with an invalid or missing
// token are logged and answered by forbidden, which must write the 403. // token receive a 403 Forbidden response.
// //
// The middleware detects the client-facing transport protocol // The middleware detects the client-facing transport protocol
// per-request via reqtls.IsTLS, the single TLS predicate the session // per-request via reqtls.IsTLS, the single TLS predicate the session
@@ -36,14 +36,12 @@ func CSRFToken(r *http.Request) string {
// Two gorilla/csrf instances are maintained — one with Secure cookies // Two gorilla/csrf instances are maintained — one with Secure cookies
// (for TLS) and one without (for plaintext HTTP) — because the // (for TLS) and one without (for plaintext HTTP) — because the
// csrf.Secure option is set at creation time, not per-request. // csrf.Secure option is set at creation time, not per-request.
func (m *Middleware) CSRF( func (m *Middleware) CSRF() func(http.Handler) http.Handler {
forbidden http.Handler,
) func(http.Handler) http.Handler {
csrfErrorHandler := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { csrfErrorHandler := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
// CSRF is registered ahead of RequireAuth on every route // CSRF is registered ahead of RequireAuth on every route
// group that uses it, so this WARN is reachable by an // group that uses it, so this WARN is reachable by an
// unauthenticated client: a POST with no token to // unauthenticated client: a POST with no token to
// /hook/<any length of any text>/edit lands here. The // /source/<any length of any text>/edit lands here. The
// method and path are capped against the same budgets as // method and path are capped against the same budgets as
// the access log. remote_addr is set by net/http from the // the access log. remote_addr is set by net/http from the
// accepted connection rather than by the client, and // accepted connection rather than by the client, and
@@ -59,7 +57,7 @@ func (m *Middleware) CSRF(
"remote_addr", r.RemoteAddr, "remote_addr", r.RemoteAddr,
"reason", csrf.FailureReason(r), "reason", csrf.FailureReason(r),
) )
forbidden.ServeHTTP(w, r) http.Error(w, "Forbidden - invalid CSRF token", http.StatusForbidden)
}) })
key := m.session.GetKey() key := m.session.GetKey()
+9 -15
View File
@@ -18,12 +18,6 @@ import (
// csrfCookieName is the gorilla/csrf cookie name. // csrfCookieName is the gorilla/csrf cookie name.
const csrfCookieName = "_gorilla_csrf" const csrfCookieName = "_gorilla_csrf"
// forbidden stands in for the error page the server hands CSRF to
// answer a refused request with.
func forbidden(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(http.StatusForbidden)
}
// csrfGetToken performs a GET request through the CSRF middleware // csrfGetToken performs a GET request through the CSRF middleware
// and returns the token and cookies. // and returns the token and cookies.
func csrfGetToken( func csrfGetToken(
@@ -104,7 +98,7 @@ func TestCSRF_GETSetsToken(t *testing.T) {
var gotToken string var gotToken string
handler := m.CSRF(http.HandlerFunc(forbidden))(http.HandlerFunc( handler := m.CSRF()(http.HandlerFunc(
func(_ http.ResponseWriter, r *http.Request) { func(_ http.ResponseWriter, r *http.Request) {
gotToken = middleware.CSRFToken(r) gotToken = middleware.CSRFToken(r)
}, },
@@ -126,7 +120,7 @@ func TestCSRF_POSTWithValidToken(t *testing.T) {
t.Parallel() t.Parallel()
m, _ := testMiddleware(t, config.EnvironmentDev) m, _ := testMiddleware(t, config.EnvironmentDev)
csrfMW := m.CSRF(http.HandlerFunc(forbidden)) csrfMW := m.CSRF()
getReq := httptest.NewRequestWithContext( getReq := httptest.NewRequestWithContext(
context.Background(), context.Background(),
@@ -158,7 +152,7 @@ func csrfPOSTWithoutTokenTest(
t.Helper() t.Helper()
m, _ := testMiddleware(t, env) m, _ := testMiddleware(t, env)
csrfMW := m.CSRF(http.HandlerFunc(forbidden)) csrfMW := m.CSRF()
// GET to establish the CSRF cookie // GET to establish the CSRF cookie
getHandler := csrfMW(http.HandlerFunc( getHandler := csrfMW(http.HandlerFunc(
@@ -215,7 +209,7 @@ func TestCSRF_POSTWithInvalidToken(t *testing.T) {
t.Parallel() t.Parallel()
m, _ := testMiddleware(t, config.EnvironmentDev) m, _ := testMiddleware(t, config.EnvironmentDev)
csrfMW := m.CSRF(http.HandlerFunc(forbidden)) csrfMW := m.CSRF()
// GET to establish the CSRF cookie // GET to establish the CSRF cookie
getHandler := csrfMW(http.HandlerFunc( getHandler := csrfMW(http.HandlerFunc(
@@ -271,7 +265,7 @@ func TestCSRF_GETDoesNotValidate(t *testing.T) {
var called bool var called bool
handler := m.CSRF(http.HandlerFunc(forbidden))(http.HandlerFunc( handler := m.CSRF()(http.HandlerFunc(
func(_ http.ResponseWriter, _ *http.Request) { func(_ http.ResponseWriter, _ *http.Request) {
called = true called = true
}, },
@@ -334,7 +328,7 @@ func csrfTookStrictPath(
t.Helper() t.Helper()
m, _ := testMiddleware(t, env) m, _ := testMiddleware(t, env)
csrfMW := m.CSRF(http.HandlerFunc(forbidden)) csrfMW := m.CSRF()
newReq := func(method string) *http.Request { newReq := func(method string) *http.Request {
r := httptest.NewRequestWithContext( r := httptest.NewRequestWithContext(
@@ -483,7 +477,7 @@ func TestCSRF_ProdMode_PlaintextHTTP_POSTWithValidToken(
t.Parallel() t.Parallel()
m, _ := testMiddleware(t, config.EnvironmentProd) m, _ := testMiddleware(t, config.EnvironmentProd)
csrfMW := m.CSRF(http.HandlerFunc(forbidden)) csrfMW := m.CSRF()
getReq := httptest.NewRequestWithContext( getReq := httptest.NewRequestWithContext(
context.Background(), context.Background(),
@@ -523,7 +517,7 @@ func TestCSRF_ProdMode_BehindProxy_POSTWithValidToken(
t.Parallel() t.Parallel()
m, _ := testMiddleware(t, config.EnvironmentProd) m, _ := testMiddleware(t, config.EnvironmentProd)
csrfMW := m.CSRF(http.HandlerFunc(forbidden)) csrfMW := m.CSRF()
getReq := httptest.NewRequestWithContext( getReq := httptest.NewRequestWithContext(
context.Background(), context.Background(),
@@ -568,7 +562,7 @@ func TestCSRF_ProdMode_DirectTLS_POSTWithValidToken(
t.Parallel() t.Parallel()
m, _ := testMiddleware(t, config.EnvironmentProd) m, _ := testMiddleware(t, config.EnvironmentProd)
csrfMW := m.CSRF(http.HandlerFunc(forbidden)) csrfMW := m.CSRF()
getReq := httptest.NewRequestWithContext( getReq := httptest.NewRequestWithContext(
context.Background(), context.Background(),
+2 -1
View File
@@ -10,7 +10,8 @@ import (
// MetricsMiddlewareForTest builds the metrics recording middleware // MetricsMiddlewareForTest builds the metrics recording middleware
// against a caller-supplied recorder, so a test can gather from its // against a caller-supplied recorder, so a test can gather from its
// own Prometheus registry without building a whole Middleware. // own Prometheus registry rather than the process-wide default one
// that Middleware.Metrics uses.
func MetricsMiddlewareForTest( func MetricsMiddlewareForTest(
rec httpmetrics.Recorder, rec httpmetrics.Recorder,
) func(http.Handler) http.Handler { ) func(http.Handler) http.Handler {
+4 -6
View File
@@ -260,9 +260,7 @@ func logSites() map[string]logSite {
) http.Handler { ) http.Handler {
t.Helper() t.Helper()
return m.CSRF(http.HandlerFunc(forbidden))( return m.CSRF()(unreachable(t))
unreachable(t),
)
}, },
send: postNoToken, send: postNoToken,
wantStatus: http.StatusForbidden, wantStatus: http.StatusForbidden,
@@ -385,7 +383,7 @@ func TestLogLines_ClientChosenPathDoesNotSizeTheLine(t *testing.T) {
t, newHandler, t, newHandler,
) )
path := "/hook/" + path := "/source/" +
oversizedPathSegment(fill) + "/edit" oversizedPathSegment(fill) + "/edit"
assert.Equal( assert.Equal(
@@ -436,7 +434,7 @@ func TestLoginThrottle_LogLineDoesNotTrackPathSize(t *testing.T) {
req := httptest.NewRequestWithContext( req := httptest.NewRequestWithContext(
context.Background(), context.Background(),
http.MethodPost, http.MethodPost,
"/hook/"+ "/source/"+
oversizedPathSegment(fill)+"/login", oversizedPathSegment(fill)+"/login",
nil, nil,
) )
@@ -501,7 +499,7 @@ func TestMaxBodySize_FloodOfOversizePathsDoesNotGrowTheLog(
http.StatusRequestEntityTooLarge, http.StatusRequestEntityTooLarge,
postOversize( postOversize(
h, h,
"/hook/"+segment(i)+"/edit", "/source/"+segment(i)+"/edit",
), ),
) )
} }
+4 -4
View File
@@ -108,10 +108,10 @@ type failureWindow struct {
// //
// A limiter that spends budget on arrival cannot protect a // A limiter that spends budget on arrival cannot protect a
// single-admin product: behind the reverse proxy the deployment // single-admin product: behind the reverse proxy the deployment
// requires, when TRUSTED_PROXIES does not cover it, every client // requires, with TRUSTED_PROXIES unset, every client keys on the
// keys on the proxy, so a stranger trickling five POSTs a minute // proxy, so a stranger trickling five POSTs a minute keeps the one
// keeps the one bucket full and the operator's own correct password // bucket full and the operator's own correct password is answered 429
// is answered 429 forever. There is no second administrative path. // forever. There is no second administrative path.
// //
// So budget is spent only by a FAILED verification. A correct // So budget is spent only by a FAILED verification. A correct
// password is never throttled, whatever the counters say, which is // password is never throttled, whatever the counters say, which is
+18 -75
View File
@@ -7,7 +7,9 @@ import (
"github.com/go-chi/chi" "github.com/go-chi/chi"
httpmetrics "github.com/slok/go-http-metrics/metrics" httpmetrics "github.com/slok/go-http-metrics/metrics"
prommetrics "github.com/slok/go-http-metrics/metrics/prometheus"
ghmm "github.com/slok/go-http-metrics/middleware" ghmm "github.com/slok/go-http-metrics/middleware"
"github.com/slok/go-http-metrics/middleware/std"
) )
// inflightHandler is the fixed `handler` label on // inflightHandler is the fixed `handler` label on
@@ -38,7 +40,7 @@ const unmatchedMethod = unmatchedRoute
// //
// The pattern is what bounds the label's domain to the routes the // The pattern is what bounds the label's domain to the routes the
// service registers. The path does not bound it at all — every byte // service registers. The path does not bound it at all — every byte
// after /h/ is client-chosen, so labelling by path lets any // after /webhook/ is client-chosen, so labelling by path lets any
// unauthenticated client mint permanent series at will, and publishes // unauthenticated client mint permanent series at will, and publishes
// the entrypoint UUID (the receiver's only credential) in the scrape // the entrypoint UUID (the receiver's only credential) in the scrape
// while doing it. // while doing it.
@@ -149,17 +151,17 @@ func (r boundedLabelRecorder) AddInflightRequests(
var _ httpmetrics.Recorder = boundedLabelRecorder{} var _ httpmetrics.Recorder = boundedLabelRecorder{}
// Metrics returns middleware that records Prometheus HTTP metrics // Metrics returns middleware that records Prometheus HTTP metrics on
// with the Middleware's one recorder, which New builds on the registry // the default registry, which is the one the /metrics route gathers.
// the /metrics route serves and NewForTest on a registry of its own.
// Every call reuses that recorder, so any number of routers can
// install it.
func (s *Middleware) Metrics() func(http.Handler) http.Handler { func (s *Middleware) Metrics() func(http.Handler) http.Handler {
return metricsMiddleware(s.metricsRecorder) return metricsMiddleware(
prommetrics.NewRecorder(prommetrics.Config{}),
)
} }
// metricsMiddleware builds the recording middleware against a given // metricsMiddleware builds the recording middleware against a given
// recorder, so tests can gather from a registry of their own. // recorder, so tests can gather from a registry of their own instead
// of the process-wide default.
func metricsMiddleware( func metricsMiddleware(
rec httpmetrics.Recorder, rec httpmetrics.Recorder,
) func(http.Handler) http.Handler { ) func(http.Handler) http.Handler {
@@ -168,72 +170,13 @@ func metricsMiddleware(
}) })
return func(next http.Handler) http.Handler { return func(next http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { // The handler id is unmatchedRoute rather than "" so that
mw := &metricsResponseWriter{ // the client-chosen URL path never enters the metrics
ResponseWriter: w, // pipeline at all: an empty id is the library's signal to
request: r, // substitute it. boundedLabelRecorder overwrites this value
statusCode: http.StatusOK, // on every observation, so it is reachable only if that
} // decorator is removed — in which case the metrics collapse
// to one series instead of leaking again.
// The handler id is unmatchedRoute rather than "" so return std.Handler(unmatchedRoute, mdlw, next)
// that the client-chosen URL path never enters the
// metrics pipeline at all: an empty id is the library's
// signal to substitute it. boundedLabelRecorder
// overwrites this value on every observation, so it is
// reachable only if that decorator is removed — in which
// case the metrics collapse to one series instead of
// leaking again.
mdlw.Measure(unmatchedRoute, mw, func() {
next.ServeHTTP(mw, r)
})
})
} }
} }
// metricsResponseWriter records the status code and body size of a
// response, and hands them with the request to go-http-metrics'
// Measure as its Reporter.
//
// It stands in for the library's std.Handler, whose writer has no
// Unwrap: behind it, http.ResponseController cannot reach net/http's
// own writer, so a handler's write deadline fails with metrics on.
type metricsResponseWriter struct {
http.ResponseWriter
request *http.Request
statusCode int
bytesWritten int64
}
func (w *metricsResponseWriter) WriteHeader(code int) {
w.statusCode = code
w.ResponseWriter.WriteHeader(code)
}
func (w *metricsResponseWriter) Write(b []byte) (int, error) {
w.bytesWritten += int64(len(b))
//nolint:wrapcheck // Pass the writer's own error through unchanged.
return w.ResponseWriter.Write(b)
}
// Unwrap lets http.ResponseController reach the writer underneath, so
// a handler can still flush or set a write deadline with metrics on.
func (w *metricsResponseWriter) Unwrap() http.ResponseWriter {
return w.ResponseWriter
}
func (w *metricsResponseWriter) Method() string { return w.request.Method }
func (w *metricsResponseWriter) Context() context.Context {
return w.request.Context()
}
func (w *metricsResponseWriter) URLPath() string { return w.request.URL.Path }
func (w *metricsResponseWriter) StatusCode() int { return w.statusCode }
func (w *metricsResponseWriter) BytesWritten() int64 { return w.bytesWritten }
var _ ghmm.Reporter = (*metricsResponseWriter)(nil)
+1 -1
View File
@@ -50,7 +50,7 @@ func realMethods() []string {
// dimension varying, so any series growth a probe produces is the // dimension varying, so any series growth a probe produces is the
// method label's and nothing else's. // method label's and nothing else's.
func methodProbePath() string { func methodProbePath() string {
return "/h/" + uuid.NewString() return "/webhook/" + uuid.NewString()
} }
// inventedMethods returns n distinct RFC 9110 method tokens that no // inventedMethods returns n distinct RFC 9110 method tokens that no
+9 -34
View File
@@ -28,7 +28,7 @@ const (
// receiverRoutePattern is the one handler label every receiver // receiverRoutePattern is the one handler label every receiver
// request must produce, however the client varies the path. // request must produce, however the client varies the path.
receiverRoutePattern = "/h/{uuid}" receiverRoutePattern = "/webhook/{uuid}"
// okRoute is a static route used to pin that the response-writer // okRoute is a static route used to pin that the response-writer
// interceptor still reports status and size after the handler id // interceptor still reports status and size after the handler id
@@ -57,8 +57,9 @@ const (
// Server.setupWebhookRoutes inside it. That ordering is the whole // Server.setupWebhookRoutes inside it. That ordering is the whole
// defect, so a test that flattens it would prove nothing. // defect, so a test that flattens it would prove nothing.
// //
// The recorder writes to a registry of the test's own, so each test // The recorder writes to a registry of the test's own rather than the
// observes only its own traffic. // process-wide default one, so each test observes only its own
// traffic.
func metricsTestRouter( func metricsTestRouter(
t *testing.T, t *testing.T,
receiverLimit int, receiverLimit int,
@@ -142,13 +143,13 @@ func drivePaths(
return drive(t, h, probes) return drive(t, h, probes)
} }
// receiverPaths returns n distinct /h/ paths, each naming a // receiverPaths returns n distinct /webhook/ paths, each naming a
// fresh UUID exactly as an unauthenticated flood would. // fresh UUID exactly as an unauthenticated flood would.
func receiverPaths(n int) []string { func receiverPaths(n int) []string {
paths := make([]string, 0, n) paths := make([]string, 0, n)
for range n { for range n {
paths = append(paths, "/h/"+uuid.NewString()) paths = append(paths, "/webhook/"+uuid.NewString())
} }
return paths return paths
@@ -219,7 +220,7 @@ func keys(set map[string]struct{}) []string {
// TestMetrics_DistinctReceiverPathsMintOneLabelSet is the direct // TestMetrics_DistinctReceiverPathsMintOneLabelSet is the direct
// assertion the issue asks for: N requests to N distinct // assertion the issue asks for: N requests to N distinct
// /h/<uuid> paths must produce exactly ONE handler label, the // /webhook/<uuid> paths must produce exactly ONE handler label, the
// route pattern. Before the fix this produced N of them. // route pattern. Before the fix this produced N of them.
func TestMetrics_DistinctReceiverPathsMintOneLabelSet(t *testing.T) { func TestMetrics_DistinctReceiverPathsMintOneLabelSet(t *testing.T) {
t.Parallel() t.Parallel()
@@ -249,7 +250,7 @@ func TestMetrics_DistinctReceiverPathsMintOneLabelSet(t *testing.T) {
// The scrape must not republish the UUIDs it was driven with. // The scrape must not republish the UUIDs it was driven with.
// They are the receiver's only credential. // They are the receiver's only credential.
for _, p := range paths { for _, p := range paths {
id := strings.TrimPrefix(p, "/h/") id := strings.TrimPrefix(p, "/webhook/")
for label := range labels { for label := range labels {
assert.NotContains( assert.NotContains(
t, label, id, t, label, id,
@@ -353,7 +354,7 @@ func TestMetrics_UnmatchedPathsCollapseToTheSentinel(t *testing.T) {
if i%2 == 0 { if i%2 == 0 {
paths = append(paths, "/"+id) paths = append(paths, "/"+id)
} else { } else {
paths = append(paths, "/h/"+id+"/"+id) paths = append(paths, "/webhook/"+id+"/"+id)
} }
} }
@@ -454,29 +455,3 @@ func TestMetrics_StatusAndSizeStillRecorded(t *testing.T) {
"the interceptor must still count written bytes", "the interceptor must still count written bytes",
) )
} }
// TestMetrics_WorksOnNewForTestMiddleware pins that a Middleware built
// by NewForTest has a recorder of its own: its Metrics() serves a
// request instead of panicking, and a second one does not collide
// with the first.
func TestMetrics_WorksOnNewForTestMiddleware(t *testing.T) {
t.Parallel()
log := slog.New(slog.DiscardHandler)
cfg := &config.Config{Environment: "prod"}
ok := http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
_, _ = w.Write([]byte(okBody))
})
for range 2 {
h := middleware.NewForTest(log, cfg, nil).Metrics()(ok)
req := httptest.NewRequestWithContext(
t.Context(), http.MethodGet, okRoute, nil,
)
w := httptest.NewRecorder()
h.ServeHTTP(w, req)
assert.Equal(t, http.StatusOK, w.Code)
}
}
+8 -55
View File
@@ -6,7 +6,6 @@ import (
"log/slog" "log/slog"
"net" "net"
"net/http" "net/http"
"net/url"
"sync" "sync"
"time" "time"
@@ -14,9 +13,6 @@ import (
"github.com/go-chi/chi" "github.com/go-chi/chi"
"github.com/go-chi/chi/middleware" "github.com/go-chi/chi/middleware"
"github.com/go-chi/cors" "github.com/go-chi/cors"
"github.com/prometheus/client_golang/prometheus"
httpmetrics "github.com/slok/go-http-metrics/metrics"
prommetrics "github.com/slok/go-http-metrics/metrics/prometheus"
"go.uber.org/fx" "go.uber.org/fx"
"sneak.berlin/go/webhooker/internal/config" "sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/globals" "sneak.berlin/go/webhooker/internal/globals"
@@ -152,11 +148,10 @@ const (
type MiddlewareParams struct { type MiddlewareParams struct {
fx.In fx.In
Logger *logger.Logger Logger *logger.Logger
Globals *globals.Globals Globals *globals.Globals
Config *config.Config Config *config.Config
Session *session.Session Session *session.Session
Registry *prometheus.Registry
} }
// Middleware provides HTTP middleware for logging, CORS, auth, and // Middleware provides HTTP middleware for logging, CORS, auth, and
@@ -166,14 +161,6 @@ type Middleware struct {
params *MiddlewareParams params *MiddlewareParams
session *session.Session session *session.Session
// metricsRecorder records the inbound HTTP metrics. New builds
// it on the registry /metrics serves, NewForTest on a registry
// of its own. Either way it is built once per Middleware and
// Metrics reuses it, because building it registers its
// collectors, and a second registration on the same registry
// panics.
metricsRecorder httpmetrics.Recorder
// loginGuard counts failed credential verifications and bounds // loginGuard counts failed credential verifications and bounds
// concurrent password hashing. It is built on first use so that // concurrent password hashing. It is built on first use so that
// every construction path gets one; see guard(). // every construction path gets one; see guard().
@@ -192,9 +179,6 @@ func New(
s.params = &params s.params = &params
s.log = params.Logger.Get() s.log = params.Logger.Get()
s.session = params.Session s.session = params.Session
s.metricsRecorder = prommetrics.NewRecorder(
prommetrics.Config{Registry: params.Registry},
)
return s, nil return s, nil
} }
@@ -233,13 +217,6 @@ func (lrw *loggingResponseWriter) WriteHeader(code int) {
lrw.ResponseWriter.WriteHeader(code) lrw.ResponseWriter.WriteHeader(code)
} }
// Unwrap lets http.ResponseController reach the writer underneath, so
// a handler can still flush or set a write deadline through the access
// log.
func (lrw *loggingResponseWriter) Unwrap() http.ResponseWriter {
return lrw.ResponseWriter
}
// concreteLogURL renders the request's own URL for the access log // concreteLogURL renders the request's own URL for the access log
// branches that keep it, with the query string replaced by a fixed // branches that keep it, with the query string replaced by a fixed
// marker. // marker.
@@ -280,7 +257,7 @@ func concreteLogURL(r *http.Request) string {
// //
// 3xx and 4xx responses get the chi route pattern instead. Those are // 3xx and 4xx responses get the chi route pattern instead. Those are
// the outcomes an unauthenticated client drives for free: 404 or 429 // the outcomes an unauthenticated client drives for free: 404 or 429
// on any invented /h/ path, 303 to the login page on any // on any invented /webhook/ path, 303 to the login page on any
// invented /user/ path. Logging the concrete URL there lets a flood // invented /user/ path. Logging the concrete URL there lets a flood
// write attacker-chosen text, of attacker-chosen length, into the // write attacker-chosen text, of attacker-chosen length, into the
// operator's log at one line per request. The pattern comes from the // operator's log at one line per request. The pattern comes from the
@@ -389,30 +366,6 @@ func (s *Middleware) CORS() func(http.Handler) http.Handler {
} }
} }
// NextParam is the query parameter on the login redirect, and the
// login form field, that holds the page to return to after login.
const NextParam = "next"
// MaxNextBytes bounds the NextParam value. The login page writes it
// into its form, and every page is rendered into a buffer first, so
// without a bound a request would choose the size of that buffer.
const MaxNextBytes = 2048
// loginURL is the login page RequireAuth redirects to. A GET carries
// its own path and query in NextParam so that logging in returns to
// it, unless they are longer than MaxNextBytes; loginDestination in
// the handlers package checks whether that value is safe to follow.
// Other methods carry nothing, since a redirect cannot repeat them.
func loginURL(r *http.Request) string {
next := r.URL.RequestURI()
if r.Method != http.MethodGet || len(next) > MaxNextBytes {
return "/pages/login"
}
return "/pages/login?" + url.Values{NextParam: {next}}.Encode()
}
// RequireAuth returns middleware that checks for a valid session. // RequireAuth returns middleware that checks for a valid session.
// Unauthenticated users are redirected to the login page. // Unauthenticated users are redirected to the login page.
func (s *Middleware) RequireAuth() func(http.Handler) http.Handler { func (s *Middleware) RequireAuth() func(http.Handler) http.Handler {
@@ -428,7 +381,7 @@ func (s *Middleware) RequireAuth() func(http.Handler) http.Handler {
"error", err, "error", err,
) )
http.Redirect( http.Redirect(
w, r, loginURL(r), http.StatusSeeOther, w, r, "/pages/login", http.StatusSeeOther,
) )
return return
@@ -456,7 +409,7 @@ func (s *Middleware) RequireAuth() func(http.Handler) http.Handler {
), ),
) )
http.Redirect( http.Redirect(
w, r, loginURL(r), http.StatusSeeOther, w, r, "/pages/login", http.StatusSeeOther,
) )
return return
@@ -607,7 +560,7 @@ func (s *Middleware) MaxBodySize(
// internal/server/routes.go), so an // internal/server/routes.go), so an
// unauthenticated client reaches it with a path // unauthenticated client reaches it with a path
// of its own choosing and its own length — // of its own choosing and its own length —
// POST /hook/<8 KB>/edit with an oversize // POST /source/<8 KB>/edit with an oversize
// declared Content-Length costs nothing to // declared Content-Length costs nothing to
// send. At WARN, on by default, that is a // send. At WARN, on by default, that is a
// write into the operator's log sized by the // write into the operator's log sized by the
+3 -77
View File
@@ -338,76 +338,6 @@ func TestRequireAuth_NoSession_RedirectsToLogin(t *testing.T) {
"unauthenticated request", "unauthenticated request",
) )
assert.Equal(t, http.StatusSeeOther, w.Code) assert.Equal(t, http.StatusSeeOther, w.Code)
assert.Equal(
t, "/pages/login?next=%2Fdashboard", w.Header().Get("Location"),
)
}
// TestRequireAuth_LoginRedirectCarriesOnlyAGet pins what the login
// redirect carries: a GET's path and query, so logging in can return
// there, and nothing for a POST, which a redirect cannot repeat.
func TestRequireAuth_LoginRedirectCarriesOnlyAGet(t *testing.T) {
t.Parallel()
m, _ := testMiddleware(t, config.EnvironmentDev)
handler := m.RequireAuth()(http.HandlerFunc(
func(_ http.ResponseWriter, _ *http.Request) {},
))
get := httptest.NewRequestWithContext(
context.Background(),
http.MethodGet, "/hook/abc/events?page=2", nil,
)
w := httptest.NewRecorder()
handler.ServeHTTP(w, get)
assert.Equal(
t, "/pages/login?next=%2Fhook%2Fabc%2Fevents%3Fpage%3D2",
w.Header().Get("Location"),
)
post := httptest.NewRequestWithContext(
context.Background(),
http.MethodPost, "/hook/abc/delete", nil,
)
w = httptest.NewRecorder()
handler.ServeHTTP(w, post)
assert.Equal(t, "/pages/login", w.Header().Get("Location"))
}
// TestRequireAuth_LoginRedirectLeavesOutALongURL: a GET whose path
// and query are longer than the login page accepts goes to the plain
// login page, so a long URL does not make the redirect long.
func TestRequireAuth_LoginRedirectLeavesOutALongURL(t *testing.T) {
t.Parallel()
m, _ := testMiddleware(t, config.EnvironmentDev)
handler := m.RequireAuth()(http.HandlerFunc(
func(_ http.ResponseWriter, _ *http.Request) {},
))
atLimit := "/" + strings.Repeat("a", middleware.MaxNextBytes-1)
get := httptest.NewRequestWithContext(
context.Background(), http.MethodGet, atLimit, nil,
)
w := httptest.NewRecorder()
handler.ServeHTTP(w, get)
assert.Equal(
t, "/pages/login?next=%2F"+atLimit[1:],
w.Header().Get("Location"),
)
get = httptest.NewRequestWithContext(
context.Background(), http.MethodGet, atLimit+"a", nil,
)
w = httptest.NewRecorder()
handler.ServeHTTP(w, get)
assert.Equal(t, "/pages/login", w.Header().Get("Location")) assert.Equal(t, "/pages/login", w.Header().Get("Location"))
} }
@@ -513,9 +443,7 @@ func TestRequireAuth_UnauthenticatedSession_RedirectsToLogin(
"unauthenticated session", "unauthenticated session",
) )
assert.Equal(t, http.StatusSeeOther, w.Code) assert.Equal(t, http.StatusSeeOther, w.Code)
assert.Equal( assert.Equal(t, "/pages/login", w.Header().Get("Location"))
t, "/pages/login?next=%2Fdashboard", w.Header().Get("Location"),
)
} }
// --- RequireAuth Session Expiry Tests --- // --- RequireAuth Session Expiry Tests ---
@@ -613,9 +541,7 @@ func TestRequireAuth_IdleExpiredSession_RedirectsToLogin(
"handler should not run for an idle-expired session", "handler should not run for an idle-expired session",
) )
assert.Equal(t, http.StatusSeeOther, w.Code) assert.Equal(t, http.StatusSeeOther, w.Code)
assert.Equal( assert.Equal(t, "/pages/login", w.Header().Get("Location"))
t, "/pages/login?next=%2Fdashboard", w.Header().Get("Location"),
)
assert.Empty( assert.Empty(
t, sessionCookies(w), t, sessionCookies(w),
"an expired session must not be refreshed", "an expired session must not be refreshed",
@@ -714,7 +640,7 @@ func TestNoCache_SetsHeaders(t *testing.T) {
req := httptest.NewRequestWithContext( req := httptest.NewRequestWithContext(
context.Background(), context.Background(),
http.MethodGet, "/hooks", nil, http.MethodGet, "/sources", nil,
) )
w := httptest.NewRecorder() w := httptest.NewRecorder()
+5 -4
View File
@@ -63,7 +63,7 @@ const (
// receiverAggregateMultiplier scales the configured // receiverAggregateMultiplier scales the configured
// per-entrypoint receiver limit into the aggregate limit one // per-entrypoint receiver limit into the aggregate limit one
// client IP may spend across the whole /h/* route. Ten // client IP may spend across the whole /webhook/* route. Ten
// entrypoints' worth lets a single sender address drive several // entrypoints' worth lets a single sender address drive several
// entrypoints at their full rate, while still capping what one // entrypoints at their full rate, while still capping what one
// address costs the unauthenticated receiver. // address costs the unauthenticated receiver.
@@ -123,8 +123,9 @@ func bucketKey(addr netip.Addr) string {
return prefix.String() return prefix.String()
} }
// isTrustedProxy reports whether addr belongs to a network in // isTrustedProxy reports whether addr belongs to a network the
// TRUSTED_PROXIES, which by default is the RFC 1918 private ranges. // operator listed in TRUSTED_PROXIES. The list is empty by default,
// so by default nothing is trusted.
func (m *Middleware) isTrustedProxy(addr netip.Addr) bool { func (m *Middleware) isTrustedProxy(addr netip.Addr) bool {
for _, prefix := range m.params.Config.TrustedProxies { for _, prefix := range m.params.Config.TrustedProxies {
if prefix.Contains(addr) { if prefix.Contains(addr) {
@@ -389,7 +390,7 @@ func (m *Middleware) postRateLimit(
// It is Config.ReceiverRateLimit requests per minute. // It is Config.ReceiverRateLimit requests per minute.
// //
// That limit alone bounds nothing in aggregate. The route pattern // That limit alone bounds nothing in aggregate. The route pattern
// /h/{uuid} matches any single segment, so a client that // /webhook/{uuid} matches any single segment, so a client that
// invents a fresh path per request mints a fresh bucket per request // invents a fresh path per request mints a fresh bucket per request
// and never refills one — and every such request still reaches the // and never refills one — and every such request still reaches the
// handler's entrypoint lookup before it 404s. The outer limit is // handler's entrypoint lookup before it 404s. The outer limit is
+21 -22
View File
@@ -275,7 +275,7 @@ func TestReceiverRateLimit_LimitsPerIPAndPath(t *testing.T) {
// pass. // pass.
for i := range limit { for i := range limit {
w := receiverPost( w := receiverPost(
handler, "9.9.9.9:1234", "/h/uuid-a", handler, "9.9.9.9:1234", "/webhook/uuid-a",
) )
assert.Equal( assert.Equal(
t, http.StatusOK, w.Code, t, http.StatusOK, w.Code,
@@ -286,7 +286,7 @@ func TestReceiverRateLimit_LimitsPerIPAndPath(t *testing.T) {
// The next request over the limit is rejected with a 429 // The next request over the limit is rejected with a 429
// carrying a Retry-After header. // carrying a Retry-After header.
w := receiverPost( w := receiverPost(
handler, "9.9.9.9:1234", "/h/uuid-a", handler, "9.9.9.9:1234", "/webhook/uuid-a",
) )
assert.Equal(t, http.StatusTooManyRequests, w.Code) assert.Equal(t, http.StatusTooManyRequests, w.Code)
assert.NotEmpty( assert.NotEmpty(
@@ -296,7 +296,7 @@ func TestReceiverRateLimit_LimitsPerIPAndPath(t *testing.T) {
// The same IP is not limited on a different entrypoint. // The same IP is not limited on a different entrypoint.
w = receiverPost( w = receiverPost(
handler, "9.9.9.9:1234", "/h/uuid-b", handler, "9.9.9.9:1234", "/webhook/uuid-b",
) )
assert.Equal( assert.Equal(
t, http.StatusOK, w.Code, t, http.StatusOK, w.Code,
@@ -305,7 +305,7 @@ func TestReceiverRateLimit_LimitsPerIPAndPath(t *testing.T) {
// A different IP is not limited on the same entrypoint. // A different IP is not limited on the same entrypoint.
w = receiverPost( w = receiverPost(
handler, "8.8.8.8:1234", "/h/uuid-a", handler, "8.8.8.8:1234", "/webhook/uuid-a",
) )
assert.Equal( assert.Equal(
t, http.StatusOK, w.Code, t, http.StatusOK, w.Code,
@@ -322,7 +322,7 @@ func TestReceiverRateLimit_CountsEveryMethod(t *testing.T) {
const ( const (
limit = 2 limit = 2
ip = "7.7.7.7:1234" ip = "7.7.7.7:1234"
path = "/h/uuid-c" path = "/webhook/uuid-c"
) )
handler := receiverLimitedHandler(t, limit) handler := receiverLimitedHandler(t, limit)
@@ -384,8 +384,8 @@ const (
// trustedProxyCIDR is the proxy network the forwarded-path // trustedProxyCIDR is the proxy network the forwarded-path
// tests configure, and trustedPeer an address inside it. A // tests configure, and trustedPeer an address inside it. A
// production deployment is required to run behind a reverse // production deployment is required to run behind a reverse
// proxy that TRUSTED_PROXIES covers, either by the default or by // proxy with TRUSTED_PROXIES set, so this is the shape the
// a set value, so this is the shape the bucketing has to hold in. // bucketing has to hold in.
trustedProxyCIDR = "10.0.0.0/8" trustedProxyCIDR = "10.0.0.0/8"
trustedPeer = "10.0.0.1:44444" trustedPeer = "10.0.0.1:44444"
) )
@@ -426,8 +426,8 @@ func assertSharedBucket(
} }
// TestRateLimitKey_SpoofedForwardedFromUntrustedPeer is the test // TestRateLimitKey_SpoofedForwardedFromUntrustedPeer is the test
// this gating exists for: from a peer that is not a trusted // this gating exists for: with no trusted proxies configured (the
// proxy, a client that rotates a forwarded header on every // default), a client that rotates a forwarded header on every
// request must stay in one bucket. If forwarded headers were // request must stay in one bucket. If forwarded headers were
// trusted unconditionally, each spoofed value would mint a fresh // trusted unconditionally, each spoofed value would mint a fresh
// bucket and the limit would stop no one. // bucket and the limit would stop no one.
@@ -715,7 +715,7 @@ func TestReceiverRateLimit_LimitsAggregateAcrossInventedPaths(
// none of them shares a per-entrypoint bucket with another. // none of them shares a per-entrypoint bucket with another.
for i := range aggregate { for i := range aggregate {
w := receiverPost( w := receiverPost(
handler, ip, fmt.Sprintf("/h/invented-%d", i), handler, ip, fmt.Sprintf("/webhook/invented-%d", i),
) )
assert.Equal( assert.Equal(
t, http.StatusOK, w.Code, t, http.StatusOK, w.Code,
@@ -724,17 +724,17 @@ func TestReceiverRateLimit_LimitsAggregateAcrossInventedPaths(
} }
w := receiverPost( w := receiverPost(
handler, ip, fmt.Sprintf("/h/invented-%d", aggregate), handler, ip, fmt.Sprintf("/webhook/invented-%d", aggregate),
) )
assert.Equal( assert.Equal(
t, http.StatusTooManyRequests, w.Code, t, http.StatusTooManyRequests, w.Code,
"a client must not be able to raise its aggregate rate "+ "a client must not be able to raise its aggregate rate "+
"against /h/* by varying the path", "against /webhook/* by varying the path",
) )
// The aggregate limit is still per client IP: exhausting one // The aggregate limit is still per client IP: exhausting one
// address must not throttle another. // address must not throttle another.
w = receiverPost(handler, "6.6.6.7:1234", "/h/invented-0") w = receiverPost(handler, "6.6.6.7:1234", "/webhook/invented-0")
assert.Equal( assert.Equal(
t, http.StatusOK, w.Code, t, http.StatusOK, w.Code,
"a different client IP must not be affected", "a different client IP must not be affected",
@@ -771,7 +771,7 @@ func TestReceiverRateLimit_RejectedRequestsCountTowardAggregate(
// limit requests are served; the rest are rejected by the // limit requests are served; the rest are rejected by the
// per-entrypoint limiter but still count against the aggregate. // per-entrypoint limiter but still count against the aggregate.
for i := range aggregate { for i := range aggregate {
w := receiverPost(handler, ip, "/h/exhausted") w := receiverPost(handler, ip, "/webhook/exhausted")
want := http.StatusTooManyRequests want := http.StatusTooManyRequests
if i < limit { if i < limit {
@@ -784,7 +784,7 @@ func TestReceiverRateLimit_RejectedRequestsCountTowardAggregate(
) )
} }
w := receiverPost(handler, ip, "/h/never-used") w := receiverPost(handler, ip, "/webhook/never-used")
assert.Equal( assert.Equal(
t, http.StatusTooManyRequests, w.Code, t, http.StatusTooManyRequests, w.Code,
"requests rejected per entrypoint must still count "+ "requests rejected per entrypoint must still count "+
@@ -823,7 +823,7 @@ func TestReceiverRateLimit_IgnoresForwardedFromUntrustedPeer(
const ( const (
limit = 3 limit = 3
peer = "203.0.113.10:44444" peer = "203.0.113.10:44444"
path = "/h/uuid-d" path = "/webhook/uuid-d"
) )
handler := receiverLimitedHandler(t, limit) handler := receiverLimitedHandler(t, limit)
@@ -1097,9 +1097,8 @@ func TestPostRateLimit_IPv4IndependentPerAddress(t *testing.T) {
// that arrives from trustedPeer — a configured trusted proxy — and // that arrives from trustedPeer — a configured trusted proxy — and
// names forwarded as its client in X-Forwarded-For. That is the // names forwarded as its client in X-Forwarded-For. That is the
// production path: a deployment is required to run behind a reverse // production path: a deployment is required to run behind a reverse
// proxy that TRUSTED_PROXIES covers, either by the default or by a // proxy with TRUSTED_PROXIES set, so the forwarded address, not the
// set value, so the forwarded address, not the peer, is what the // peer, is what the limiters bucket on there.
// limiters bucket on there.
func forwardedKeyFor( func forwardedKeyFor(
t *testing.T, m *middleware.Middleware, forwarded string, t *testing.T, m *middleware.Middleware, forwarded string,
) string { ) string {
@@ -1179,9 +1178,9 @@ func TestRateLimitKey_ForwardedIPv6BucketsByPrefix(t *testing.T) {
// //
// Every existing test of this fallback uses an IPv4 proxy, where // Every existing test of this fallback uses an IPv4 proxy, where
// bucketKey is the identity function, so replacing the call with // bucketKey is the identity function, so replacing the call with
// peer.String() leaves the whole suite green. Only addresses inside // peer.String() leaves the whole suite green. Only operator-listed
// TRUSTED_PROXIES reach this line and the fallback is fail-closed, so // addresses reach this line and the fallback is fail-closed, so this
// this pins behaviour rather than fixing a defect. // pins behaviour rather than fixing a defect.
func TestRateLimitKey_TrustedPeerUnusableForwardedMasksPeer( func TestRateLimitKey_TrustedPeerUnusableForwardedMasksPeer(
t *testing.T, t *testing.T,
) { ) {
+3 -37
View File
@@ -109,8 +109,7 @@ func (w *recoverResponseWriter) Unwrap() http.ResponseWriter {
// Recoverer returns middleware that turns a handler panic into one // Recoverer returns middleware that turns a handler panic into one
// structured ERROR record and a 500, rather than a dropped // structured ERROR record and a 500, rather than a dropped
// connection. The 500 is page when page is not nil, and plain text // connection.
// when it is nil or when page panics before writing anything.
// //
// It replaces chi's middleware.Recoverer, which does neither on a // It replaces chi's middleware.Recoverer, which does neither on a
// current Go release. chi v1.5.5's pretty-printer scans the stack for // current Go release. chi v1.5.5's pretty-printer scans the stack for
@@ -137,13 +136,9 @@ func (w *recoverResponseWriter) Unwrap() http.ResponseWriter {
// //
// Unlike http.Error on its own, it deletes any Set-Cookie the handler // Unlike http.Error on its own, it deletes any Set-Cookie the handler
// set before panicking, because a request that failed must not hand // set before panicking, because a request that failed must not hand
// the client a credential. It touches no other header: when page // the client a credential; every other header is left to http.Error.
// answers, every other header the handler set goes out with it, apart
// from any page sets itself; otherwise they are left to http.Error.
// See https://git.eeqj.de/sneak/webhooker/issues/193. // See https://git.eeqj.de/sneak/webhooker/issues/193.
func (s *Middleware) Recoverer( func (s *Middleware) Recoverer() func(http.Handler) http.Handler {
page http.Handler,
) func(http.Handler) http.Handler {
return func(next http.Handler) http.Handler { return func(next http.Handler) http.Handler {
return http.HandlerFunc(func( return http.HandlerFunc(func(
w http.ResponseWriter, w http.ResponseWriter,
@@ -176,14 +171,6 @@ func (s *Middleware) Recoverer(
rw.Header().Del("Set-Cookie") rw.Header().Del("Set-Cookie")
if page != nil {
s.servePage(rw, r, page)
}
if rw.committed {
return
}
http.Error( http.Error(
rw, rw,
http.StatusText( http.StatusText(
@@ -198,27 +185,6 @@ func (s *Middleware) Recoverer(
} }
} }
// servePage answers with page. A panic in page itself is logged and
// recovered here, so the Recoverer can still send its plain 500.
func (s *Middleware) servePage(
w http.ResponseWriter,
r *http.Request,
page http.Handler,
) {
defer func() {
rvr := recover()
if rvr != nil {
s.log.Error("error page panic",
"panic", logfield.Truncate(
fmt.Sprint(rvr), maxPanicValueBytes,
),
)
}
}()
page.ServeHTTP(w, r)
}
// logPanic writes the record. Every field it can grow is truncated to // logPanic writes the record. Every field it can grow is truncated to
// a fixed budget, so MaxPanicLogLineBytes holds. // a fixed budget, so MaxPanicLogLineBytes holds.
// //

Some files were not shown because too many files have changed in this diff Show More