No page shows the server's settings #402

Open
opened 2026-10-01 22:06:27 +02:00 by clawbot · 2 comments
Collaborator

Owner's request, #377 (chat, 2026-10-01):

audit the whole app for stupid cases of missing functionality or basic things like this (like the stats panel at the top that i requested).

What is missing: how the running server behaves is set entirely in its environment. That includes the egress allowlist, the receiver rate limit, the session idle timeout, the retention sweep interval, the trusted proxies, whether metrics are served, and the data directory. None of it is visible in the UI; only the version appears, in the footer. Without a shell on the host, an operator cannot check why a target on their own network is refused, or how often old events are removed. There is no settings page at all.

Definition of done:

  • A read-only Settings page, linked from the navigation bar, lists every configuration value the server is running with. Each is shown by its variable name, with a plain description, as the README's configuration table has them.
  • Secrets (METRICS_PASSWORD and SENTRY_DSN) are shown only as "set" or "not set".
  • The page is behind the admin login, and nothing on it can be edited.
  • Tests: each listed value matches the loaded configuration, and no secret value appears in the page.

PRIORITY: from the owner's audit request of 1 October (#377), in the tier of #367 to #376.

Model: opus-5-5

Owner's request, https://git.eeqj.de/sneak/webhooker/issues/377 (chat, 2026-10-01): > audit the whole app for stupid cases of missing functionality or basic things like this (like the stats panel at the top that i requested). What is missing: how the running server behaves is set entirely in its environment. That includes the egress allowlist, the receiver rate limit, the session idle timeout, the retention sweep interval, the trusted proxies, whether metrics are served, and the data directory. None of it is visible in the UI; only the version appears, in the footer. Without a shell on the host, an operator cannot check why a target on their own network is refused, or how often old events are removed. There is no settings page at all. Definition of done: - A read-only Settings page, linked from the navigation bar, lists every configuration value the server is running with. Each is shown by its variable name, with a plain description, as the README's configuration table has them. - Secrets (`METRICS_PASSWORD` and `SENTRY_DSN`) are shown only as "set" or "not set". - The page is behind the admin login, and nothing on it can be edited. - Tests: each listed value matches the loaded configuration, and no secret value appears in the page. PRIORITY: from the owner's audit request of 1 October (https://git.eeqj.de/sneak/webhooker/issues/377), in the tier of https://git.eeqj.de/sneak/webhooker/issues/367 to https://git.eeqj.de/sneak/webhooker/issues/376. Model: opus-5-5
clawbot self-assigned this 2026-10-01 22:06:27 +02:00
Author
Collaborator

Plan. The issue body is the brief. A read-only page at /settings, behind the admin login with the other pages and linked from the navigation bar, lists every value of the loaded configuration by its variable name, with the description the README's Configuration table gives it. Secret values (METRICS_PASSWORD, SENTRY_DSN, and any other credential the configuration holds) show only "set" or "not set". The page reads the configuration the server started with; nothing on it can be edited. It rebases onto #378 if that lands first (both touch the navigation bar).

Model: opus-5-5

Plan. The issue body is the brief. A read-only page at `/settings`, behind the admin login with the other pages and linked from the navigation bar, lists every value of the loaded configuration by its variable name, with the description the README's Configuration table gives it. Secret values (`METRICS_PASSWORD`, `SENTRY_DSN`, and any other credential the configuration holds) show only "set" or "not set". The page reads the configuration the server started with; nothing on it can be edited. It rebases onto https://git.eeqj.de/sneak/webhooker/pulls/378 if that lands first (both touch the navigation bar). Model: opus-5-5
Author
Collaborator

Built in #409: a read-only Settings page at /settings, behind the login and linked from the navigation bar, listing every field of the loaded configuration by its variable name, with the README's description and the value the server started with. METRICS_PASSWORD and SENTRY_DSN show only as "set" or "not set". Tests check each shown value against the configuration and that neither secret value appears in the page.

Judgement call: METRICS_USERNAME is shown as its value, since a username alone grants nothing and this issue names only the two above as secrets.

Not rebased over #378, which was still open; whichever lands second resolves the navigation bar, routes and README.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/webhooker/pulls/409: a read-only Settings page at `/settings`, behind the login and linked from the navigation bar, listing every field of the loaded configuration by its variable name, with the README's description and the value the server started with. `METRICS_PASSWORD` and `SENTRY_DSN` show only as "set" or "not set". Tests check each shown value against the configuration and that neither secret value appears in the page. Judgement call: `METRICS_USERNAME` is shown as its value, since a username alone grants nothing and this issue names only the two above as secrets. Not rebased over https://git.eeqj.de/sneak/webhooker/pulls/378, which was still open; whichever lands second resolves the navigation bar, routes and README. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#402