audit the whole app for stupid cases of missing functionality or basic things like this (like the stats panel at the top that i requested).
What is missing: most actions reload the page with no message saying what happened. That covers creating a webhook, saving a webhook or a target, adding or deleting an entrypoint or a target, activating or deactivating one, deleting a webhook, and signing out. In the audit, deleting a webhook landed on the webhook list with nothing to say it had worked. Deactivating a target changed only a small badge in its row. Only replay, resubmit and the password change report what they did (replayOutcome in internal/handlers/delivery_replay.go, resubmitOutcome in internal/handlers/event_resubmit.go, and the messages on the profile page).
Definition of done:
Each action listed above lands on its page with a one-line message saying what was done, for example "Webhook deleted.", "Target deactivated." or "Signed out.".
The message travels the way replay's does today: a fixed code in the redirect URL, mapped to fixed text. Nothing the user typed is echoed from the URL.
One template partial shows these messages, and the replay and resubmit messages too, on every page.
Tests: each action's redirect carries its code, and each page shows the message.
PRIORITY: from the owner's audit request of 1 October (#377), in the tier of #367 to #376.
Model: opus-5-5
Owner's request, https://git.eeqj.de/sneak/webhooker/issues/377 (chat, 2026-10-01):
> audit the whole app for stupid cases of missing functionality or basic things like this (like the stats panel at the top that i requested).
What is missing: most actions reload the page with no message saying what happened. That covers creating a webhook, saving a webhook or a target, adding or deleting an entrypoint or a target, activating or deactivating one, deleting a webhook, and signing out. In the audit, deleting a webhook landed on the webhook list with nothing to say it had worked. Deactivating a target changed only a small badge in its row. Only replay, resubmit and the password change report what they did (`replayOutcome` in `internal/handlers/delivery_replay.go`, `resubmitOutcome` in `internal/handlers/event_resubmit.go`, and the messages on the profile page).
Definition of done:
- Each action listed above lands on its page with a one-line message saying what was done, for example "Webhook deleted.", "Target deactivated." or "Signed out.".
- The message travels the way replay's does today: a fixed code in the redirect URL, mapped to fixed text. Nothing the user typed is echoed from the URL.
- One template partial shows these messages, and the replay and resubmit messages too, on every page.
- Tests: each action's redirect carries its code, and each page shows the message.
PRIORITY: from the owner's audit request of 1 October (https://git.eeqj.de/sneak/webhooker/issues/377), in the tier of https://git.eeqj.de/sneak/webhooker/issues/367 to https://git.eeqj.de/sneak/webhooker/issues/376.
Model: opus-5-5
clawbot
self-assigned this 2026-10-01 22:06:18 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Owner's request, #377 (chat, 2026-10-01):
What is missing: most actions reload the page with no message saying what happened. That covers creating a webhook, saving a webhook or a target, adding or deleting an entrypoint or a target, activating or deactivating one, deleting a webhook, and signing out. In the audit, deleting a webhook landed on the webhook list with nothing to say it had worked. Deactivating a target changed only a small badge in its row. Only replay, resubmit and the password change report what they did (
replayOutcomeininternal/handlers/delivery_replay.go,resubmitOutcomeininternal/handlers/event_resubmit.go, and the messages on the profile page).Definition of done:
PRIORITY: from the owner's audit request of 1 October (#377), in the tier of #367 to #376.
Model: opus-5-5