Webhooks: send one sample event to a saved webhook #100

Merged
jcoffey-dev merged 1 commits from feature/webhook-test into main 2026-09-29 01:06:13 +00:00
Owner

The server side of the settings-reorg Webhooks item: Send test.

POST /api/webhook/test with {"webhookId": "…"} sends one sample event to a saved webhook, the way a real batch goes: the same URL, headers, HTTP sign-in, X-Signature HMAC, timeout and certificate setting.

  • The answer: {"sent": true, "status": 204, "ms": 84} on a 2xx; {"sent": false, "status": 403, …} on anything else; {"sent": false, "error": "…"} when nothing came back.
  • The sample is {"events":[{"id":"test-…","createdAt":…,"type":"webhook.test","data":{"details":"A test from inbuxa Admin. Nothing happened on the server."}}]}, in the real batch's shape. webhook.test is not a type the server raises, and an X-Inbuxa-Test: true header marks the request, so receivers can tell it apart.
  • Webhooks that are off work too, so one can be tried before it's switched on.
  • Access: server-level administrators with SysWebHookUpdate; tenants are refused, as with /api/directory/test. The request only goes where the saved webhook already sends.
  • Signing now lives in one sign() helper, shared with real deliveries.

Checked: two new tests in common against a local HTTP listener. The first checks that the signature matches the body's HMAC and that the test header and webhook.test type arrive, with a 204 back. The second checks that a 403 comes back as a status, and that a closed port comes back as an error. The http crate checks clean and the notice check is clean.

The admin's button follows in a separate PR.

The server side of the settings-reorg Webhooks item: *Send test*. **`POST /api/webhook/test`** with `{"webhookId": "…"}` sends one sample event to a saved webhook, the way a real batch goes: the same URL, headers, HTTP sign-in, `X-Signature` HMAC, timeout and certificate setting. - **The answer:** `{"sent": true, "status": 204, "ms": 84}` on a 2xx; `{"sent": false, "status": 403, …}` on anything else; `{"sent": false, "error": "…"}` when nothing came back. - **The sample** is `{"events":[{"id":"test-…","createdAt":…,"type":"webhook.test","data":{"details":"A test from inbuxa Admin. Nothing happened on the server."}}]}`, in the real batch's shape. `webhook.test` is not a type the server raises, and an `X-Inbuxa-Test: true` header marks the request, so receivers can tell it apart. - **Webhooks that are off work too**, so one can be tried before it's switched on. - **Access:** server-level administrators with `SysWebHookUpdate`; tenants are refused, as with `/api/directory/test`. The request only goes where the saved webhook already sends. - **Signing** now lives in one `sign()` helper, shared with real deliveries. **Checked:** two new tests in `common` against a local HTTP listener. The first checks that the signature matches the body's HMAC and that the test header and `webhook.test` type arrive, with a 204 back. The second checks that a 403 comes back as a status, and that a closed port comes back as an error. The `http` crate checks clean and the notice check is clean. The admin's button follows in a separate PR.
jcoffey-dev added 1 commit 2026-09-29 00:02:55 +00:00
Webhooks: send one sample event to a saved webhook
ci / fork-checks (pull_request) Successful in 52s
ci / build (pull_request) Successful in 18m39s
9e0aab6b6a
jcoffey-dev merged commit 15064d6fd5 into main 2026-09-29 01:06:13 +00:00
jcoffey-dev deleted branch feature/webhook-test 2026-09-29 01:06:13 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: inbuxa/inbuxa-server#100