A delivery left in `retrying` whose target type was edited to a fire-and-forget or unknown type was skipped forever by both restart recovery and the retry sweep. Both paths now record a result row and mark it `failed`.
4.7 KiB
Workflow
- branch (from
main) - do the work in Next Step
- move Next Step to the top of Completed Steps
- move the top item of Future Steps into Next Step
- commit (
TODO.mdchanges in the same commit as the work) - merge to
mainif the branch is not protected, otherwise open a PR - push
Status
pre-1.0. No git tags exist. main (4f5ecb1) is a working webhook proxy
with auth, CSRF/SSRF protections, login rate limiting, Slack target,
event retention (#63), the database archiving target (#43), the admin
password change flow (#65), policy compliance (#6), and pinned lint
tooling (#55). Note: TODO.md was deliberately deleted from this repo in
f9a9569 (2026-03-01, #6); its content was folded into the README TODO
section, which this draft reconstructs as of 2026-07-06.
Next Step
Implement automatic event retention cleanup based on retention_days: a periodic maintenance job that deletes Events, Deliveries, and DeliveryResults older than the parent webhook's retention_days from each per-webhook event database. The field exists on the Webhook model and the README promises the behavior, but nothing enforces it, so event databases currently grow without bound.
Completed Steps
- 2026-08-09 Restart recovery and the 60s retry sweep terminally fail an
orphaned
retryingdelivery whose target type no longer supports retries, recording aDeliveryResultwith the reason instead of leaving the delivery stuck forever (#82) - 2026-08-09 Root the delivery engine's worker pool and the retention
reaper's sweep loop at
context.Background()rather than the fxOnStarthook context (#97), which carries fx's 15s start timeout and killed both roughly fifteen seconds after boot: the proxy silently stopped delivering webhooks entirely, and the reaper never ran a single sweep under its default one-hour interval - 2026-08-09 Archive writer lifecycle (#89): deleting a webhook (or its
last
databasetarget) evicts the cached archive writer and closes its handle while deliberately leavingarchive-{webhookID}.dbon disk, and a newArchiveSweeperprunes idle archives on the existingRETENTION_SWEEP_INTERVALwithout ever creating an archive file - 2026-08-07 Update golangci-lint to v2.12.2 (Docker image digest in
Dockerfile, release-archive sha256 pins inscript/bootstrap), adopt the canonical.golangci.yml(v2linters.settingslayout solll/funlen/cyclop/duplthresholds actually apply), and fix all newly surfaced lint findings - 2026-07-07 Adopted scripts-to-rule-them-all:
script/entrypoints, Makefile shims, README Entrypoints section - 2026-03-25 pin golangci-lint Docker image for linting (#55)
- 2026-03-18 CSRF middleware detects TLS per-request, fixing login over plain HTTP and behind reverse proxies (#54)
- 2026-03-17 root path redirects based on auth state (#52)
- 2026-03-17 CSRF protection, SSRF prevention for HTTP delivery targets with DNS rebinding defense, and per-IP login rate limiting (#42)
- 2026-03-17 Slack target type for incoming webhook notifications (#47)
- 2026-03-17 Dockerfile absolute paths and static linking (#49); absolute dev DATA_DIR default and clarified env docs (#46)
- 2026-03-05 security headers middleware, session regeneration on login, request body size limits (#41)
- 2026-03-04 tests for delivery, middleware, and session packages (#32); removed globals.Buildarch (#31)
- 2026-03-04 1.0 MVP merge: Webhook/Entrypoint/Target rename, core delivery engine with bounded worker pool and circuit breaker, parallel fan-out, per-webhook event databases, management UI (#16)
- 2026-03-01 repo brought to REPO_POLICIES standards; TODO.md folded into README (#6)
Future Steps
- Manual event redelivery from the web UI (replay is a core promised capability in the README rationale)
- Delivery status and retry management UI
- Per-webhook rate limiting in the receiver handler (per-webhook config plus handler enforcement; global limits must not apply to receiver endpoints)
- Webhook signature verification for GitHub and Stripe HMAC formats
- API key authentication for programmatic access (APIKey model exists; Bearer token middleware does not)
- REST API v1
- CRUD for webhooks, entrypoints, targets
- event viewing and filtering endpoints
- event redelivery endpoint
- OpenAPI specification
- Analytics dashboard: success rates, response times, volume
- Session expiration tuning and a remember-me option
- Password change and reset flow
- Later, nice to have
- email delivery target type
- SNS and S3 delivery targets
- data transformations (e.g. webhook to Slack message formatting)
- JSONL file delivery with periodic S3 upload
- webhook event search and filtering
- multi-user with role-based access control