jcoffey-dev is traveling from Thursday 1 October through Sunday 4 October. Issues and pull requests are welcome, and will get an answer after that. Thanks for your patience.
The server side of the settings-reorg Webhooks item: Send test.
POST /api/webhook/test with {"webhookId": "…"} sends one sample event to a saved webhook, the way a real batch goes: the same URL, headers, HTTP sign-in, X-Signature HMAC, timeout and certificate setting.
The answer:{"sent": true, "status": 204, "ms": 84} on a 2xx; {"sent": false, "status": 403, …} on anything else; {"sent": false, "error": "…"} when nothing came back.
The sample is {"events":[{"id":"test-…","createdAt":…,"type":"webhook.test","data":{"details":"A test from inbuxa Admin. Nothing happened on the server."}}]}, in the real batch's shape. webhook.test is not a type the server raises, and an X-Inbuxa-Test: true header marks the request, so receivers can tell it apart.
Webhooks that are off work too, so one can be tried before it's switched on.
Access: server-level administrators with SysWebHookUpdate; tenants are refused, as with /api/directory/test. The request only goes where the saved webhook already sends.
Signing now lives in one sign() helper, shared with real deliveries.
Checked: two new tests in common against a local HTTP listener. The first checks that the signature matches the body's HMAC and that the test header and webhook.test type arrive, with a 204 back. The second checks that a 403 comes back as a status, and that a closed port comes back as an error. The http crate checks clean and the notice check is clean.
The admin's button follows in a separate PR.
The server side of the settings-reorg Webhooks item: *Send test*.
**`POST /api/webhook/test`** with `{"webhookId": "…"}` sends one sample event to a saved webhook, the way a real batch goes: the same URL, headers, HTTP sign-in, `X-Signature` HMAC, timeout and certificate setting.
- **The answer:** `{"sent": true, "status": 204, "ms": 84}` on a 2xx; `{"sent": false, "status": 403, …}` on anything else; `{"sent": false, "error": "…"}` when nothing came back.
- **The sample** is `{"events":[{"id":"test-…","createdAt":…,"type":"webhook.test","data":{"details":"A test from inbuxa Admin. Nothing happened on the server."}}]}`, in the real batch's shape. `webhook.test` is not a type the server raises, and an `X-Inbuxa-Test: true` header marks the request, so receivers can tell it apart.
- **Webhooks that are off work too**, so one can be tried before it's switched on.
- **Access:** server-level administrators with `SysWebHookUpdate`; tenants are refused, as with `/api/directory/test`. The request only goes where the saved webhook already sends.
- **Signing** now lives in one `sign()` helper, shared with real deliveries.
**Checked:** two new tests in `common` against a local HTTP listener. The first checks that the signature matches the body's HMAC and that the test header and `webhook.test` type arrive, with a 204 back. The second checks that a 403 comes back as a status, and that a closed port comes back as an error. The `http` crate checks clean and the notice check is clean.
The admin's button follows in a separate PR.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The server side of the settings-reorg Webhooks item: Send test.
POST /api/webhook/testwith{"webhookId": "…"}sends one sample event to a saved webhook, the way a real batch goes: the same URL, headers, HTTP sign-in,X-SignatureHMAC, timeout and certificate setting.{"sent": true, "status": 204, "ms": 84}on a 2xx;{"sent": false, "status": 403, …}on anything else;{"sent": false, "error": "…"}when nothing came back.{"events":[{"id":"test-…","createdAt":…,"type":"webhook.test","data":{"details":"A test from inbuxa Admin. Nothing happened on the server."}}]}, in the real batch's shape.webhook.testis not a type the server raises, and anX-Inbuxa-Test: trueheader marks the request, so receivers can tell it apart.SysWebHookUpdate; tenants are refused, as with/api/directory/test. The request only goes where the saved webhook already sends.sign()helper, shared with real deliveries.Checked: two new tests in
commonagainst a local HTTP listener. The first checks that the signature matches the body's HMAC and that the test header andwebhook.testtype arrive, with a 204 back. The second checks that a 403 comes back as a status, and that a closed port comes back as an error. Thehttpcrate checks clean and the notice check is clean.The admin's button follows in a separate PR.