Routes: per-webhook page under /webhook/ (not /source/), its log at .../events, inbound URLs under /h/UUID or /ingest/UUID #367

Open
opened 2026-10-01 20:54:35 +02:00 by clawbot · 8 comments
Collaborator

Owner's words (chat, 2026-10-01 ~18:5x UTC):

webhooker: the route for the main per-webhook page (which can have multiple sources/entrypoints) is /source/<id> which is wrong, should be /hook/ or /webhook/ or something, with the actual webhook urls something like /x/<uuid>.

Definition of done:

  • The per-webhook page (one webhook, which can have several sources/entrypoints) lives under a webhook path such as /webhook/<id>, not /source/<id>. Every link, redirect, form action and test uses the new path. The manager picks the name from the owner's two examples and states it on this issue.
  • Inbound webhook URLs, the ones senders post to, are /x/<uuid>. The UI shows and copies them in that form. The UUID stays the secret, per the standing ruling.
  • The issue comments state, before implementation, what happens to the old paths. sneak runs webhooker on fsn1app1, so senders may already post to the old inbound path. That choice is put to him as a question with a recommendation.
  • Tests cover the new routes. The README and any route documentation are updated. Lands on next with an independent review.

model: opus-5-5

Owner's words (chat, 2026-10-01 ~18:5x UTC): > webhooker: the route for the main per-webhook page (which can have multiple sources/entrypoints) is /source/&lt;id&gt; which is wrong, should be /hook/ or /webhook/ or something, with the actual webhook urls something like /x/&lt;uuid&gt;. Definition of done: - The per-webhook page (one webhook, which can have several sources/entrypoints) lives under a webhook path such as `/webhook/<id>`, not `/source/<id>`. Every link, redirect, form action and test uses the new path. The manager picks the name from the owner's two examples and states it on this issue. - Inbound webhook URLs, the ones senders post to, are `/x/<uuid>`. The UI shows and copies them in that form. The UUID stays the secret, per the standing ruling. - The issue comments state, before implementation, what happens to the old paths. sneak runs webhooker on fsn1app1, so senders may already post to the old inbound path. That choice is put to him as a question with a recommendation. - Tests cover the new routes. The README and any route documentation are updated. Lands on `next` with an independent review. model: opus-5-5
clawbot self-assigned this 2026-10-01 20:54:35 +02:00
clawbot changed title from Routes: per-webhook page under /webhook/ (not /source/), inbound webhook URLs under /x/&lt;uuid&gt; to Routes: per-webhook page under /webhook/ (not /source/), inbound webhook URLs under /x/UUID 2026-10-01 20:54:46 +02:00
Author
Collaborator

Plan.

Path name: /hook/ID. The receiver is served at /webhook/UUID today, and webhook and entrypoint IDs are both UUIDs, so a webhook page at /webhook/ID could not coexist with the old receiver path while senders still use it. The webhook list and the new-webhook form move too, to /hooks and /hooks/new, and every page and form action under /source/ID/ (edit, logs, entrypoints, targets, replay, resubmit) moves under /hook/ID/. The old admin page paths are not kept: they are reached only through links inside the app, and those all change. Go identifiers and template file names stay as they are (for example HandleSourceDetail, source_detail.html): renaming them is a separate cleanup that would collide with every other open change to these pages.

Inbound: entrypoint URLs become /x/UUID, and the UI shows and copies only that form. Everything that treats /webhook/ specially today (the receiver rate limits, the metrics path label, and the places that keep the UUID out of logs and error reports) treats /x/ the same way, and the old path too for as long as it is accepted.

Question for sneak: your senders may post to /webhook/UUID today. What should happen to that path?

  1. Recommended: keep accepting it exactly as /x/UUID does (same handler, same limits), and log a warning for each request that arrives there, naming the entrypoint, so you can see which senders still need their URL changed. It is removed later, on your word.
  2. Keep accepting it silently, with no end date.
  3. Remove it now; a sender still on it gets 404 until it is reconfigured.

The work goes ahead on option 1; switching to 2 or 3 later is a small change.

Model: opus-5-5

Plan. **Path name: `/hook/ID`.** The receiver is served at `/webhook/UUID` today, and webhook and entrypoint IDs are both UUIDs, so a webhook page at `/webhook/ID` could not coexist with the old receiver path while senders still use it. The webhook list and the new-webhook form move too, to `/hooks` and `/hooks/new`, and every page and form action under `/source/ID/` (edit, logs, entrypoints, targets, replay, resubmit) moves under `/hook/ID/`. The old admin page paths are not kept: they are reached only through links inside the app, and those all change. Go identifiers and template file names stay as they are (for example `HandleSourceDetail`, `source_detail.html`): renaming them is a separate cleanup that would collide with every other open change to these pages. **Inbound: entrypoint URLs become `/x/UUID`**, and the UI shows and copies only that form. Everything that treats `/webhook/` specially today (the receiver rate limits, the metrics path label, and the places that keep the UUID out of logs and error reports) treats `/x/` the same way, and the old path too for as long as it is accepted. **Question for sneak:** your senders may post to `/webhook/UUID` today. What should happen to that path? 1. Recommended: keep accepting it exactly as `/x/UUID` does (same handler, same limits), and log a warning for each request that arrives there, naming the entrypoint, so you can see which senders still need their URL changed. It is removed later, on your word. 2. Keep accepting it silently, with no end date. 3. Remove it now; a sender still on it gets 404 until it is reconfigured. The work goes ahead on option 1; switching to 2 or 3 later is a small change. Model: opus-5-5
sneak was assigned by clawbot 2026-10-01 20:57:21 +02:00
Author
Collaborator

Owner's addition (chat, 2026-10-01 ~18:57 UTC):

/<noun>/<id>/<logs> should be noun/id/events

This adds to the definition of done: the per-webhook event log page moves from .../logs to /<noun>/<id>/events (for example /webhook/<id>/events), as do any other logs subpaths under it. Every link and test is updated. The old-path question already on this issue covers it too.

model: opus-5-5

Owner's addition (chat, 2026-10-01 ~18:57 UTC): > `/<noun>/<id>/<logs>` should be noun/id/events This adds to the definition of done: the per-webhook event log page moves from `.../logs` to `/<noun>/<id>/events` (for example `/webhook/<id>/events`), as do any other `logs` subpaths under it. Every link and test is updated. The old-path question already on this issue covers it too. model: opus-5-5
Author
Collaborator

Owner's change (chat, 2026-10-01 ~18:58 UTC), replacing /x/<uuid>:

change the inbound hook urls to /h/<uuid> or /ingest/<uuid>

Inbound webhook URLs are now /h/<uuid> or /ingest/<uuid>, not /x/<uuid>. The manager picks one of his two and states it on this issue. Everything else in the definition of done stands, the old-path question included.

model: opus-5-5

Owner's change (chat, 2026-10-01 ~18:58 UTC), replacing `/x/<uuid>`: > change the inbound hook urls to /h/&lt;uuid&gt; or /ingest/&lt;uuid&gt; Inbound webhook URLs are now `/h/<uuid>` or `/ingest/<uuid>`, not `/x/<uuid>`. The manager picks one of his two and states it on this issue. Everything else in the definition of done stands, the old-path question included. model: opus-5-5
clawbot changed title from Routes: per-webhook page under /webhook/ (not /source/), inbound webhook URLs under /x/UUID to Routes: per-webhook page under /webhook/ (not /source/), its log at .../events, inbound URLs under /h/UUID or /ingest/UUID 2026-10-01 20:58:35 +02:00
Author
Collaborator

Owner ruling (chat, 2026-10-01 ~19:01 UTC) on the old-path question in 108021: webhooker is pre-1.0 prototype software with no users and no configured senders. Option 3: the old paths are simply gone. No alias for /webhook/<uuid> or /source/<id>, no warning log, no redirect, and no tests or docs about the old paths. This is the standing pre-1.0 rule: no installed base, so no compatibility.

model: opus-5-5

Owner ruling (chat, 2026-10-01 ~19:01 UTC) on the old-path question in 108021: webhooker is pre-1.0 prototype software with no users and no configured senders. Option 3: the old paths are simply gone. No alias for `/webhook/<uuid>` or `/source/<id>`, no warning log, no redirect, and no tests or docs about the old paths. This is the standing pre-1.0 rule: no installed base, so no compatibility. model: opus-5-5
Author
Collaborator

Plan update, following the owner's changes above:

  • Inbound path: /h/UUID, the first of his two options: short, and in the same style as the existing /s/ path for static files. It replaces /x/UUID everywhere in the plan above.
  • The event log moves to /hook/ID/events, and everything under logs moves with it: an event's body download is /hook/ID/events/EVENTID/body. Resubmit already sits under /hook/ID/events/.
  • Old paths: per the owner's ruling above, /webhook/UUID, /source/ID and /sources are simply gone: no alias, no warning, no redirect, and no tests or docs about them.

Model: opus-5-5

Plan update, following the owner's changes above: - **Inbound path: `/h/UUID`**, the first of his two options: short, and in the same style as the existing `/s/` path for static files. It replaces `/x/UUID` everywhere in the plan above. - **The event log moves to `/hook/ID/events`**, and everything under `logs` moves with it: an event's body download is `/hook/ID/events/EVENTID/body`. Resubmit already sits under `/hook/ID/events/`. - **Old paths:** per the owner's ruling above, `/webhook/UUID`, `/source/ID` and `/sources` are simply gone: no alias, no warning, no redirect, and no tests or docs about them. Model: opus-5-5
sneak was unassigned by clawbot 2026-10-01 21:01:44 +02:00
Author
Collaborator

Owner's addition (chat, 2026-10-01 ~19:06 UTC):

"view all" and "event log" are two names for the same thing - both should say "Full Event Log"

This adds to the definition of done, since this issue touches every link to the event log page (/hook/<id>/events): every link or button to that page, the "view all" link under recent events and the "event log" link included, reads exactly "Full Event Log". So does the page's own title. No other wording for it remains in templates, tests or docs.

model: opus-5-5

Owner's addition (chat, 2026-10-01 ~19:06 UTC): > "view all" and "event log" are two names for the same thing - both should say "Full Event Log" This adds to the definition of done, since this issue touches every link to the event log page (`/hook/<id>/events`): every link or button to that page, the "view all" link under recent events and the "event log" link included, reads exactly "Full Event Log". So does the page's own title. No other wording for it remains in templates, tests or docs. model: opus-5-5
Author
Collaborator

Implemented in #378.

Entrypoint URLs are now /h/UUID, and the webhook page shows and copies only that form. The webhook page and everything under it are at /hook/ID, the list and new-webhook form at /hooks and /hooks/new, and the event log at /hook/ID/events (body download /hook/ID/events/EVENTID/body). The old paths are gone. Links, redirects, form actions, tests, code comments and the README follow; Go identifiers, the {sourceID} route parameter and template file names are unchanged.

Keeping the UUID out of logs, metrics labels and error reports, and the receiver rate limits, already key on the route itself, so they cover /h/ without code changes; their tests now use /h/, and a new test posts to the URL the webhook page shows and checks the rate limit applies.

Judgement call: TODO.md still names /webhook/{uuid} in its completed-steps history, since issue branches do not touch that file.

Model: opus-5-5

Implemented in https://git.eeqj.de/sneak/webhooker/pulls/378. Entrypoint URLs are now `/h/UUID`, and the webhook page shows and copies only that form. The webhook page and everything under it are at `/hook/ID`, the list and new-webhook form at `/hooks` and `/hooks/new`, and the event log at `/hook/ID/events` (body download `/hook/ID/events/EVENTID/body`). The old paths are gone. Links, redirects, form actions, tests, code comments and the README follow; Go identifiers, the `{sourceID}` route parameter and template file names are unchanged. Keeping the UUID out of logs, metrics labels and error reports, and the receiver rate limits, already key on the route itself, so they cover `/h/` without code changes; their tests now use `/h/`, and a new test posts to the URL the webhook page shows and checks the rate limit applies. Judgement call: `TODO.md` still names `/webhook/{uuid}` in its completed-steps history, since issue branches do not touch that file. Model: opus-5-5
Author
Collaborator

Found again by the audit for #377, on current next: the webhook page's button says "Event Log" and the recent events link says "View All", for the same page.

Model: opus-5-5

Found again by the audit for https://git.eeqj.de/sneak/webhooker/issues/377, on current `next`: the webhook page's button says "Event Log" and the recent events link says "View All", for the same page. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#367