Commit Graph

  • 888eaf526b State the UUID-is-the-credential rule as a rule (closes #301) (#302) next clawbot 2026-08-30 04:05:38 +02:00
  • 251cb3d3d3 1.0.0b1 - testing remains main Jeffrey Paul 2026-08-30 04:04:59 +02:00
  • d61d9dc1c1 Drop the stale open-work claim from the TODO status section clawbot 2026-08-24 15:52:44 +00:00
  • b0a011f6b4 Render unknown for a zero CreatedAt in Slack/Mattermost messages (closes #298) clawbot 2026-08-24 17:52:25 +02:00
  • 5976a4a98f Carry the event's receipt time into every delivery (closes #257) clawbot 2026-08-24 06:44:24 +02:00
  • b2c9acdaa6 Correct four documentation claims ahead of the 1.0.0 tag clawbot 2026-08-24 06:25:08 +02:00
  • af3703d748 Close the two remaining delivery terminal-state gaps (closes #107) clawbot 2026-08-24 05:12:02 +02:00
  • 322d9a6d6b Create every SQLite file 0600 (closes #255) clawbot 2026-08-24 04:33:40 +02:00
  • b9f7db6901 Fail loudly on an unparseable SENTRY_DSN and a malformed .env (closes #283) clawbot 2026-08-24 04:25:29 +02:00
  • 48cf93ec7e Derive the entrypoint URL scheme from the shared TLS predicate (closes #272) clawbot 2026-08-24 04:04:04 +02:00
  • 8d64259283 Open SQLite with WAL and bound delivery re-dispatch by ownership (closes #256) clawbot 2026-08-24 03:49:17 +02:00
  • bde32d3ee6 Record landed 1.0.0 work and drop the removed signing roadmap in TODO.md clawbot 2026-08-24 03:43:16 +02:00
  • 62576f6fc6 Bind the app port deliberately and document the proxy deployment (closes #268) (closes #226) clawbot 2026-08-24 03:38:44 +02:00
  • 37b59f8822 Remove inbound request signature verification (closes #279) clawbot 2026-08-24 03:25:09 +02:00
  • ee2276a912 Stamp the build version into the binary (closes #253) clawbot 2026-08-24 03:15:20 +02:00
  • 032f265d69 Derive cookie Secure and CSRF strictness from the request transport (closes #269) clawbot 2026-08-24 03:01:37 +02:00
  • 65ace2d856 Roll back a failed webhook deletion instead of committing it (closes #262) clawbot 2026-08-24 03:01:33 +02:00
  • 5fda446c71 Name a deleted target on its historical deliveries (closes #211) clawbot 2026-08-24 02:03:23 +02:00
  • 763d8f8058 Bound the /metrics method label (closes #261) clawbot 2026-08-24 02:03:18 +02:00
  • fd5966f807 Validate max_retries on both target forms (closes #221) clawbot 2026-08-24 01:32:48 +02:00
  • 0082f216fa Label HTTP metrics with the chi route pattern (closes #254) clawbot 2026-08-24 01:32:44 +02:00
  • 89f3b984d2 Resubmit a stored event as a new undelivered event (closes #250) clawbot 2026-08-24 00:53:37 +02:00
  • a83e8fe654 Record the completed 1.0.0 milestone in TODO.md (#249) clawbot 2026-08-20 11:16:51 +02:00
  • 687405993e Harden operator-set target headers (closes #233) (#242) clawbot 2026-08-20 10:54:43 +02:00
  • 03cd1859d7 Add an egress CIDR allowlist to the SSRF guard (closes #204) (#217) clawbot 2026-08-20 10:34:42 +02:00
  • f0512f1c3c Render delivery attempt detail in the event log (closes #202) (#219) clawbot 2026-08-20 08:36:25 +02:00
  • 3b0ed826bc Add per-delivery replay to the event log (closes #203) (#240) clawbot 2026-08-20 08:11:35 +02:00
  • 9969694a47 Add a webhooker resetpw subcommand and a bootstrap banner (closes #208) (#239) clawbot 2026-08-20 08:01:42 +02:00
  • fcead5d401 Add optional inbound webhook signature verification (closes #67) (#228) clawbot 2026-08-20 08:01:32 +02:00
  • ac782f4c5a Stop target credentials leaking into event databases (closes #206) (#223) clawbot 2026-08-20 07:55:34 +02:00
  • 89b2dadd48 Read queue depths with Find, not Scan (closes #234) (#237) clawbot 2026-08-20 07:55:20 +02:00
  • aba02bc509 Add a target edit form with headers and timeout fields (closes #127) (#229) clawbot 2026-08-20 07:24:12 +02:00
  • c6a9884f86 Take an exclusive lock on DATA_DIR at startup (closes #201) (#220) clawbot 2026-08-20 07:23:00 +02:00
  • 5af161ef60 Log SQL with placeholders, never bound values (closes #207) (#222) clawbot 2026-08-20 07:20:59 +02:00
  • 4cc83b2326 Expose delivery metrics on /metrics (closes #209) (#224) clawbot 2026-08-20 07:19:04 +02:00
  • a13e5b7ded Shut down the app when the listener fails (closes #200) (#218) clawbot 2026-08-20 06:42:36 +02:00
  • bb30b3ad64 Fail loudly on half-set metrics auth credentials (closes #205) (#216) clawbot 2026-08-20 06:30:23 +02:00
  • 10c8dd2331 Document backup, restore and upgrade procedures (closes #210) (#214) clawbot 2026-08-20 06:05:14 +02:00
  • ea51612446 Record the reopened 1.0.0 milestone in TODO.md (#213) clawbot 2026-08-20 05:58:03 +02:00
  • aa463213f5 Record the 1.0.0 milestone as complete in TODO.md clawbot 2026-08-18 10:50:00 +02:00
  • 1326f82a0b Raise script/test's per-package timeout to 90s (closes #194) clawbot 2026-08-18 10:44:04 +02:00
  • a55b6f4e55 Re-sync REPO_POLICIES.md from prompts (closes #196) clawbot 2026-08-18 09:33:28 +02:00
  • 33e4fa4faa Report handler panics through the logger and answer 500 (closes #187) clawbot 2026-08-18 08:33:12 +02:00
  • 0c64c411cc Route GORM's logger through slog and bound it (closes #178) clawbot 2026-08-18 07:17:43 +02:00
  • 563e834cf2 Bound every slog line against client-chosen text (closes #176) clawbot 2026-08-18 06:03:10 +02:00
  • f6ec78e2c8 Stop a slow host turning a login-guard test into a segfault (closes #186) clawbot 2026-08-18 05:01:13 +02:00
  • 9313b0fb41 Merge pull request 'Correct TODO.md milestone state and record seventeen landed units' (#192) from todo-md-milestone-state into next clawbot 2026-08-18 04:07:39 +02:00
  • d2cebb5783 Correct TODO.md milestone state and record seventeen landed units clawbot 2026-08-18 02:06:43 +00:00
  • b573959a26 Send the chi route pattern to Sentry, not the concrete path (closes #179) clawbot 2026-08-18 02:42:58 +02:00
  • 76725cffc4 Read form fields from the POST body only (closes #160) clawbot 2026-08-18 02:04:09 +02:00
  • 977fe87588 Verify login credentials before spending rate-limit budget (closes #150) clawbot 2026-08-18 01:55:41 +02:00
  • 992b3c68f5 Run all linting in Docker via Dockerfile.lint (closes #109) clawbot 2026-08-18 01:07:16 +02:00
  • 41ff16a817 Serve an event's full stored body over HTTP (closes #157) clawbot 2026-08-18 00:41:31 +02:00
  • 5888d14438 Bound the access log line against client-chosen text (closes #146) clawbot 2026-08-18 00:32:29 +02:00
  • 7702f38168 Mark superseded commits honestly instead of skipped (closes #152) clawbot 2026-08-18 00:31:55 +02:00
  • bef9986542 Set fx.StopTimeout inside the container stop grace (closes #134) clawbot 2026-08-18 00:12:51 +02:00
  • c3b6623be1 Bucket IPv6 rate-limit keys by /64 (closes #125) clawbot 2026-08-17 23:52:15 +02:00
  • 39064a3d6c Correct release-blocking README and startup-warning inaccuracies (closes #151) clawbot 2026-08-17 23:44:59 +02:00
  • c378690977 Fetch and verify Alpine at build time instead of committing it (closes #145) clawbot 2026-08-17 23:12:17 +02:00
  • 279effb4c2 Bound the event log's rendered bodies in the query (closes #135) clawbot 2026-08-17 22:57:08 +02:00
  • 9ae19159a3 Mask the http target's destination URL in the UI (closes #115) clawbot 2026-08-17 22:50:26 +02:00
  • 2ee720a9af Bound shutdown hooks by their stop context (closes #102) clawbot 2026-08-14 06:18:33 +02:00
  • 0b457ea713 Render templates via a buffer, not the ResponseWriter (closes #123) clawbot 2026-08-14 06:18:22 +02:00
  • 5f18bc3eae Align session codec max-age with the 7-day cap (closes #108) clawbot 2026-08-14 06:17:43 +02:00
  • d8f9d149b5 Warn when TRUSTED_PROXIES is empty in production (closes #149) clawbot 2026-08-12 13:49:39 +02:00
  • 339548d794 Record the last four milestone units in TODO.md clawbot 2026-08-12 13:21:38 +02:00
  • 95161c7768 Bound the receiver rate limit per client IP across /webhook/* (closes #139) clawbot 2026-08-12 13:19:43 +02:00
  • 0e397b3174 Correct release-blocking documentation inaccuracies (closes #141) clawbot 2026-08-12 13:15:04 +02:00
  • be576096aa Make the CI gate execute the checks it reports on (closes #119) clawbot 2026-08-12 13:00:51 +02:00
  • 3941f0b0ff Require a positive RETENTION_SWEEP_INTERVAL (closes #140) clawbot 2026-08-12 12:46:39 +02:00
  • 543005c0c2 Update TODO.md for the completed 1.0.0 milestone clawbot 2026-08-12 12:20:34 +02:00
  • 9bfd033a29 Bound X-Forwarded-For scanning allocation to the hop cap (closes #133) clawbot 2026-08-12 12:19:14 +02:00
  • fd6397154a Cap the X-Forwarded-For hop walk at 64 entries (closes #124) clawbot 2026-08-12 11:53:48 +02:00
  • d19e33671c Gate forwarded-header trust behind trusted-proxy config (closes #88) clawbot 2026-08-12 11:36:10 +02:00
  • aab448b076 Clarify web UI terminology, copy, and the entrypoint URL (closes #57) clawbot 2026-08-11 15:42:08 +02:00
  • 7c43e095a6 Mask the webhook credential in delivery errors and logs (closes #118) clawbot 2026-08-11 15:11:57 +02:00
  • 84b758b785 Rate-limit the public webhook receiver endpoint (closes #64) clawbot 2026-08-11 14:47:21 +02:00
  • d51cd0fd29 Enforce the body size limit before CSRF parses the form (closes #90) clawbot 2026-08-11 14:37:38 +02:00
  • 15a61173fc Mask target config on the source detail page (closes #113) clawbot 2026-08-11 14:37:09 +02:00
  • e50a79ced9 Allow retention_days of 0 to mean retain forever (closes #79) clawbot 2026-08-11 14:35:34 +02:00
  • c2cd2c440b Add inactivity-based session timeout (closes #66) (#105) clawbot 2026-08-10 16:12:40 +02:00
  • 45890d4f82 Fail loudly on set-but-unparseable env config values (closes #80) (#92) clawbot 2026-08-10 16:06:12 +02:00
  • 0ce8565f51 Terminally fail retrying deliveries with a non-retry target type (closes #82) (#104) clawbot 2026-08-10 16:00:03 +02:00
  • 3e261d2f01 Evict archive writers on deletion and sweep idle archives (closes #89) (#95) clawbot 2026-08-10 15:52:20 +02:00
  • 62481a6f1a Root background loops at context.Background() (closes #97) (#100) clawbot 2026-08-10 15:44:56 +02:00
  • 4f5ecb18e5 Add admin password change flow (closes #65) (#83) clawbot 2026-08-07 23:23:05 +02:00
  • 734606b7af Update golangci-lint to v2.12.2 with canonical config (#86) clawbot 2026-08-07 23:18:49 +02:00
  • ee7c626071 Implement the database archiving target (closes #43) (#84) clawbot 2026-08-07 22:50:08 +02:00
  • 8cf9d0525a feat: add receiver rate limiting (refs #64) feat/receiver-rate-limit sneak 2026-08-07 18:32:00 +00:00
  • 81413c56e9 Refactor delivery targets to a Target interface (closes #77) (#81) clawbot 2026-08-07 17:07:49 +02:00
  • f6b929f2d7 Add per-webhook event retention reaper (closes #63) (#78) clawbot 2026-08-07 16:15:13 +02:00
  • 8ea7f76540 Add NoCache middleware for authenticated pages (closes #61) (#75) clawbot 2026-08-07 15:33:44 +02:00
  • ed81db137e Implement the log delivery target (closes #70) issue-70-log-target sneak 2026-08-07 19:57:16 +07:00
  • 752d6beead Validate Slack target URLs at creation time (closes #68) (#73) clawbot 2026-08-07 14:03:56 +02:00
  • b1f43c9520 Keep the SSRF-safe transport in clientForConfig (closes #69) (#74) clawbot 2026-08-07 14:03:38 +02:00
  • 07fc63d9fa Wrap /user/{username} in RequireAuth middleware (closes #60) (#71) clawbot 2026-08-07 14:00:16 +02:00
  • 0c9c885d51 Raise HTTP WriteTimeout above the request middleware timeout (closes #62) (#72) clawbot 2026-08-07 13:58:28 +02:00
  • 2cc8723997 scripts-to-rule-them-all (#59) sneak 2026-07-07 02:14:09 +02:00
  • e0b1e7cf54 Restore TODO.md and move TODO content out of README (#58) sneak 2026-07-06 21:14:03 +02:00
  • afe88c601a refactor: use pinned golangci-lint Docker image for linting (#55) clawbot 2026-03-25 02:16:38 +01:00