The three delete prompts on the webhook page now name what is being deleted and say what is lost, per #400:
webhook: Delete webhook "Orders"?, then that its stored events, with their number, and their deliveries are deleted, and that any archive files it wrote are kept;
entrypoint: named by its description, or by its URL when it has none; senders using its URL get an error from now on, and the URL cannot be restored;
target: nothing more is delivered to it, and its past deliveries stay in the event log.
They stay the browser's own prompts in each form's submit handler, so they work without the page's scripts. Each name goes into the prompt through the template's escaping for script text, so a quote, a backslash or a closing script tag in a name shows as typed and cannot break the prompt.
What the diff does not show: the number is the stored-events figure the statistics pane already reads (its "Within retention" events), so there is no new query; when the statistics cannot be read, the prompt leaves the number out. The handler's comment on the unvalidated base URL now names the entrypoint prompt as a second place it is shown as text.
Judgement call: the number is written in parentheses, "its stored events (42)", so the sentence reads right for a single event too.
Judgement call: "any archive files it wrote are kept" rather than "its archive files are kept", since a webhook without a database target has none.
Model: opus-5-5
The three delete prompts on the webhook page now name what is being deleted and say what is lost, per https://git.eeqj.de/sneak/webhooker/issues/400:
- webhook: `Delete webhook "Orders"?`, then that its stored events, with their number, and their deliveries are deleted, and that any archive files it wrote are kept;
- entrypoint: named by its description, or by its URL when it has none; senders using its URL get an error from now on, and the URL cannot be restored;
- target: nothing more is delivered to it, and its past deliveries stay in the event log.
They stay the browser's own prompts in each form's submit handler, so they work without the page's scripts. Each name goes into the prompt through the template's escaping for script text, so a quote, a backslash or a closing script tag in a name shows as typed and cannot break the prompt.
What the diff does not show: the number is the stored-events figure the statistics pane already reads (its "Within retention" events), so there is no new query; when the statistics cannot be read, the prompt leaves the number out. The handler's comment on the unvalidated base URL now names the entrypoint prompt as a second place it is shown as text.
- Judgement call: the number is written in parentheses, "its stored events (42)", so the sentence reads right for a single event too.
- Judgement call: "any archive files it wrote are kept" rather than "its archive files are kept", since a webhook without a database target has none.
Model: opus-5-5
internal/handlers/source_detail_test.go line 305, in TestHandleSourceDetail_DeletePromptsNameWhatIsLost: the event totals are seeded with no events removed by retention, so the webhook's lifetime count and its stored count are the same number. A prompt showing the lifetime count, which includes events retention has already deleted, passes this test. Acceptable: seed totals where retention has removed some events (for example 5 events, 2 removed) and assert the prompt shows the stored count, 3, the same figure as the statistics pane's "Within retention" events.
internal/handlers/source_detail_test.go line 342, TestHandleSourceDetail_DeletePromptKeepsQuotesInName: only a quote and a backslash are tested. The PR says a closing script tag in a name is safe too, and a newline left unescaped would end the prompt's script text, so the form would submit without asking. Neither is tested. Acceptable: the test's name also contains </script> and a newline, and the test asserts each reaches the prompt escaped (<\/script> and \n).
Model: opus-5-5
Review: needs rework.
1. `internal/handlers/source_detail_test.go` line 305, in `TestHandleSourceDetail_DeletePromptsNameWhatIsLost`: the event totals are seeded with no events removed by retention, so the webhook's lifetime count and its stored count are the same number. A prompt showing the lifetime count, which includes events retention has already deleted, passes this test. Acceptable: seed totals where retention has removed some events (for example 5 events, 2 removed) and assert the prompt shows the stored count, 3, the same figure as the statistics pane's "Within retention" events.
2. `internal/handlers/source_detail_test.go` line 342, `TestHandleSourceDetail_DeletePromptKeepsQuotesInName`: only a quote and a backslash are tested. The PR says a closing script tag in a name is safe too, and a newline left unescaped would end the prompt's script text, so the form would submit without asking. Neither is tested. Acceptable: the test's name also contains </script> and a newline, and the test asserts each reaches the prompt escaped (`<\/script>` and `\n`).
Model: opus-5-5
The webhook, entrypoint and target delete prompts on the webhook page
now name the item and say what deleting it loses: the webhook's stored
events (with the count from the statistics pane) and their deliveries,
while its archive files are kept; an entrypoint's URL, which stops
working for good; a target's future deliveries, while its past ones
stay in the event log. They stay the browser's own prompts, so they
work without the page's scripts, and each name is escaped for the
script so quotes and backslashes show as typed.
Model: opus-5-5
TestHandleSourceDetail_DeletePromptsNameWhatIsLost now seeds 5 events with 2 removed by retention and expects the prompt to show 3; it fails when the prompt shows the lifetime count.
TestHandleSourceDetail_DeletePromptKeepsQuotesInName now also puts a closing script tag and a newline in the name and expects them in the prompt as <\/script> and \n; it fails when the newline is left unescaped.
Deviation: the closing script tag is asserted as the template actually writes it, with its angle brackets escaped as well as its slash.
Judgement call: the template cannot write an unescaped newline into the prompt, so I showed that failure by temporarily turning the escaped newline back into a raw one in the rendered page.
Model: opus-5-5
Reworked:
1. `TestHandleSourceDetail_DeletePromptsNameWhatIsLost` now seeds 5 events with 2 removed by retention and expects the prompt to show 3; it fails when the prompt shows the lifetime count.
2. `TestHandleSourceDetail_DeletePromptKeepsQuotesInName` now also puts a closing script tag and a newline in the name and expects them in the prompt as `<\/script>` and `\n`; it fails when the newline is left unescaped.
- Deviation: the closing script tag is asserted as the template actually writes it, with its angle brackets escaped as well as its slash.
- Judgement call: the template cannot write an unescaped newline into the prompt, so I showed that failure by temporarily turning the escaped newline back into a raw one in the rendered page.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The three delete prompts on the webhook page now name what is being deleted and say what is lost, per #400:
Delete webhook "Orders"?, then that its stored events, with their number, and their deliveries are deleted, and that any archive files it wrote are kept;They stay the browser's own prompts in each form's submit handler, so they work without the page's scripts. Each name goes into the prompt through the template's escaping for script text, so a quote, a backslash or a closing script tag in a name shows as typed and cannot break the prompt.
What the diff does not show: the number is the stored-events figure the statistics pane already reads (its "Within retention" events), so there is no new query; when the statistics cannot be read, the prompt leaves the number out. The handler's comment on the unvalidated base URL now names the entrypoint prompt as a second place it is shown as text.
Model: opus-5-5
Review: needs rework.
internal/handlers/source_detail_test.goline 305, inTestHandleSourceDetail_DeletePromptsNameWhatIsLost: the event totals are seeded with no events removed by retention, so the webhook's lifetime count and its stored count are the same number. A prompt showing the lifetime count, which includes events retention has already deleted, passes this test. Acceptable: seed totals where retention has removed some events (for example 5 events, 2 removed) and assert the prompt shows the stored count, 3, the same figure as the statistics pane's "Within retention" events.internal/handlers/source_detail_test.goline 342,TestHandleSourceDetail_DeletePromptKeepsQuotesInName: only a quote and a backslash are tested. The PR says a closing script tag in a name is safe too, and a newline left unescaped would end the prompt's script text, so the form would submit without asking. Neither is tested. Acceptable: the test's name also contains </script> and a newline, and the test asserts each reaches the prompt escaped (<\/script>and\n).Model: opus-5-5
8adb7cd043tof1304da780Reworked:
TestHandleSourceDetail_DeletePromptsNameWhatIsLostnow seeds 5 events with 2 removed by retention and expects the prompt to show 3; it fails when the prompt shows the lifetime count.TestHandleSourceDetail_DeletePromptKeepsQuotesInNamenow also puts a closing script tag and a newline in the name and expects them in the prompt as<\/script>and\n; it fails when the newline is left unescaped.Model: opus-5-5
Review passed: both findings of the previous review are fixed.
Model: opus-5-5