The event log never shows an event's request headers or the entrypoint it arrived at #389

Open
opened 2026-10-01 22:06:20 +02:00 by clawbot · 0 comments
Collaborator

Owner's request, #377 (chat, 2026-10-01):

audit the whole app for stupid cases of missing functionality or basic things like this (like the stats panel at the top that i requested).

What is missing: the receiver stores each event's complete request headers and the entrypoint it arrived at (Event.Headers and Event.EntrypointID), but no page shows either. The event log shows only the method, event ID, content type and body; eventLogColumns in internal/handlers/event_log_view.go does not even load the other two.

So when a webhook has more than one entrypoint, the operator cannot tell which sender sent an event. The operator also cannot see the headers that carry an event's meaning: in the audit that was X-Shop-Event: order.created, and the same goes for the sender's user agent and any signature header.

The query string is a separate gap, #312.

Definition of done:

  • An expanded event in the event log shows the entrypoint it arrived at. That is the entrypoint's description, "Entrypoint" when it has none, or "deleted entrypoint". The entrypoint's URL and UUID are never shown here.
  • It also shows the full request headers, one per line, HTML-escaped, behind the admin login like the body.
  • The per-event page from #369 shows the same two things, through the same rendering, whichever of the two lands second.
  • Tests: two events that arrive at two different entrypoints show their own entrypoint and headers.

PRIORITY: from the owner's audit request of 1 October (#377), in the tier of #367 to #376.

Model: opus-5-5

Owner's request, https://git.eeqj.de/sneak/webhooker/issues/377 (chat, 2026-10-01): > audit the whole app for stupid cases of missing functionality or basic things like this (like the stats panel at the top that i requested). What is missing: the receiver stores each event's complete request headers and the entrypoint it arrived at (`Event.Headers` and `Event.EntrypointID`), but no page shows either. The event log shows only the method, event ID, content type and body; `eventLogColumns` in `internal/handlers/event_log_view.go` does not even load the other two. So when a webhook has more than one entrypoint, the operator cannot tell which sender sent an event. The operator also cannot see the headers that carry an event's meaning: in the audit that was `X-Shop-Event: order.created`, and the same goes for the sender's user agent and any signature header. The query string is a separate gap, https://git.eeqj.de/sneak/webhooker/issues/312. Definition of done: - An expanded event in the event log shows the entrypoint it arrived at. That is the entrypoint's description, "Entrypoint" when it has none, or "deleted entrypoint". The entrypoint's URL and UUID are never shown here. - It also shows the full request headers, one per line, HTML-escaped, behind the admin login like the body. - The per-event page from https://git.eeqj.de/sneak/webhooker/issues/369 shows the same two things, through the same rendering, whichever of the two lands second. - Tests: two events that arrive at two different entrypoints show their own entrypoint and headers. PRIORITY: from the owner's audit request of 1 October (https://git.eeqj.de/sneak/webhooker/issues/377), in the tier of https://git.eeqj.de/sneak/webhooker/issues/367 to https://git.eeqj.de/sneak/webhooker/issues/376. Model: opus-5-5
clawbot self-assigned this 2026-10-01 22:06:20 +02:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#389