Milestone: next into main #380

Open
clawbot wants to merge 6 commits from next into main
Collaborator

Milestone branch next, mergeable to main at every moment.

On the branch since main:

  • The image build downloads no browser asset: the Alpine.js npm tarball is committed in 3p/ and extracted at build time (#345).
  • The webhook page lists the 50 most recent events with time received, body size, processing time and, for a single HTTP target, its status (#347).
  • With TRUSTED_PROXIES unset, the RFC 1918 ranges are trusted as proxies, so behind upaas's proxy each client gets its own rate-limit bucket with nothing set (#333).
  • Usernames are limited to 1024 bytes, so no account can exist that cannot log in (#184).
  • The profile page no longer shows a fixed "Account Type: Standard User" row (#401).
  • The README and the blocklist's code comment state exactly what the default egress blocklist covers (#244).

To know before deploying: each webhook's event database gains a column with no migration, so existing event databases (the per-webhook files in DATA_DIR) must be removed and start empty. webhooker.db is kept; on its first start the users table is rebuilt to add the username limit, rows kept. If any client can reach webhooker, or the proxy in front of it, from an RFC 1918 source address, set TRUSTED_PROXIES to the proxy's address alone (the remoteIP field of the http request log line).

Landing here next, for the upaas deploy: the image stamping its real version instead of unknown (#366).

This description is updated as units land.

Model: opus-5-5

Milestone branch `next`, mergeable to `main` at every moment. On the branch since `main`: - The image build downloads no browser asset: the Alpine.js npm tarball is committed in `3p/` and extracted at build time (https://git.eeqj.de/sneak/webhooker/issues/345). - The webhook page lists the 50 most recent events with time received, body size, processing time and, for a single HTTP target, its status (https://git.eeqj.de/sneak/webhooker/issues/347). - With `TRUSTED_PROXIES` unset, the RFC 1918 ranges are trusted as proxies, so behind upaas's proxy each client gets its own rate-limit bucket with nothing set (https://git.eeqj.de/sneak/webhooker/issues/333). - Usernames are limited to 1024 bytes, so no account can exist that cannot log in (https://git.eeqj.de/sneak/webhooker/issues/184). - The profile page no longer shows a fixed "Account Type: Standard User" row (https://git.eeqj.de/sneak/webhooker/issues/401). - The README and the blocklist's code comment state exactly what the default egress blocklist covers (https://git.eeqj.de/sneak/webhooker/issues/244). To know before deploying: each webhook's event database gains a column with no migration, so existing event databases (the per-webhook files in `DATA_DIR`) must be removed and start empty. `webhooker.db` is kept; on its first start the `users` table is rebuilt to add the username limit, rows kept. If any client can reach webhooker, or the proxy in front of it, from an RFC 1918 source address, set `TRUSTED_PROXIES` to the proxy's address alone (the `remoteIP` field of the `http request` log line). Landing here next, for the upaas deploy: the image stamping its real version instead of `unknown` (https://git.eeqj.de/sneak/webhooker/issues/366). This description is updated as units land. Model: opus-5-5
clawbot self-assigned this 2026-10-01 21:39:25 +02:00
clawbot added 1 commit 2026-10-01 21:39:25 +02:00
Bound username length at creation (closes #184)
check / check (push) Successful in 4m8s
507980a347
Usernames are limited to 1024 bytes, so no account can exist that is unable to log in. The username rides in the session cookie, which browsers and securecookie refuse past about 4 KB, leaving room for roughly 2000 bytes of username; the limit is about half that.

User.BeforeSave returns ErrUsernameTooLong when a whole User is created or saved. A byte-counting check constraint on users.username catches every other write, including a column update. The limit appears in the constant and in the struct tag; a test fails if they disagree.

Model: opus-5-5
clawbot added 1 commit 2026-10-01 22:44:43 +02:00
The build no longer downloads Alpine.js. Its npm package tarball is committed as 3p/alpinejs-3.14.9.tgz, byte for byte the file script/fetch-assets downloaded, with the sha256 that script pinned. script/assets (make assets) extracts package/dist/cdn.min.js to the ignored static/js/alpine.min.js; script/test runs it, so make test, make check, the pre-commit hook and the Dockerfile get the file with no network access, and make build, run and dev run it too.

Removed: script/fetch-assets, its Dockerfile step, static/vendor.sha256 and static/vendor_test.go. The README describes the new flow.

Model: opus-5-5
clawbot added 1 commit 2026-10-01 23:24:43 +02:00
The profile page no longer shows the fixed "Account Type: Standard User" row. webhooker has one account, the administrator it creates, and no account types, so the row was untrue. The Account Information section now lists the username alone, and a test checks the row stays gone.

Model: opus-5-5
clawbot added 1 commit 2026-10-01 23:50:03 +02:00
The webhook page's list, now headed "50 Most Recent Events", shows the 50 newest events, limited in the query. Each row adds the time received (relative, UTC on hover), the body size, the processing time (slowest delivery, queued to final outcome, retries included, "in progress" while pending), and, when the webhook has exactly one HTTP target, that target's latest HTTP status, coloured by class.

Each event now records its body size in a new body_bytes column when it is stored, so the list never reads bodies; the list loads only the delivery and attempt columns it shows, and a failed load is an error, not an empty list.

An existing event database must be recreated: the column is added in place, with no migration.

Model: opus-5-5
clawbot added 1 commit 2026-10-02 00:21:38 +02:00
The README's egress section and the comment above blockedNetworks now state what the default blocklist covers: the IPv4 private and reserved ranges, IPv6 loopback, unique local and link-local addresses, and certain public addresses, each added only because it hands credentials, user data or bootstrap material to whatever can reach it without the caller presenting anything. That is the same material as the rule above alwaysBlockedNetworks, so a future candidate can be accepted or refused against one rule.

A provider's other public addresses, such as 161.26.0.0/16 and 166.8.0.0/14, are not refused. Docs and a comment only; the lists are unchanged.

Model: opus-5-5
clawbot added 1 commit 2026-10-02 00:41:38 +02:00
Unset or empty, TRUSTED_PROXIES now defaults to 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16, so a reverse proxy reaching webhooker from one of those ranges gets per-client rate-limit buckets with nothing set. A set value replaces the default entirely; an unparseable one still fails startup. The startup warning for an empty list is gone.

The README gives the default, one rule (if any client can reach webhooker, or the proxy in front of it, from an RFC 1918 source address, set the list to the proxy's address alone), and where to find that address: the remoteIP field of the http request log line. Loopback is not in the default.

Model: opus-5-5
Some checks are pending
check / check (push) Waiting to run
You are not authorized to merge this pull request.
This pull request can be merged automatically.
This branch is out-of-date with the base branch
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin next:next
git checkout next
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#380