Stop webhooks sending every event, message content included #82

Merged
jcoffey-dev merged 1 commits from fix/webhook-event-levels into main 2026-09-28 13:44:52 +00:00
Owner

Personal-data catalog spec, finding 1 (fixed now, Settled 6).

A webhook's level was never read, so the default exclude policy with no events sent every event type, including smtp.raw-input (raw SMTP, DATA included) and the AI classifier's reply.

Now: an include list is sent as named, whatever each event's level. Otherwise, events at or above the webhook's level, as for a tracer, and never raw protocol I/O unless named.

Tested: unit tests for the rule; telemetry_tests (its webhook names debug-level events and still gets them).

Personal-data catalog spec, finding 1 (fixed now, Settled 6). A webhook's `level` was never read, so the default exclude policy with no events sent every event type, including `smtp.raw-input` (raw SMTP, DATA included) and the AI classifier's reply. Now: an include list is sent as named, whatever each event's level. Otherwise, events at or above the webhook's level, as for a tracer, and never raw protocol I/O unless named. Tested: unit tests for the rule; `telemetry_tests` (its webhook names debug-level events and still gets them).
jcoffey-dev added 1 commit 2026-09-28 13:38:42 +00:00
Stop webhooks sending every event, message content included
ci / fork-checks (pull_request) Successful in 45s
ci / build (pull_request) Successful in 5m42s
6945714aa9
A webhook has a level (info by default) that nothing read: its events
were chosen by its list and policy alone. With the default policy,
exclude, and nothing listed, that meant every event type, including
smtp.raw-input (the raw SMTP bytes, DATA included) and the model's
reply to the spam classifier. The docs suggest a webhook to pass the
audit log to a SIEM; set up that way it would have received whole
messages. Found by the personal-data catalog investigation (finding 1).

Now an include list is sent as named, whatever each event's level:
naming an event is the choice. Otherwise a webhook gets only events at
or above its level, as a tracer does, and never a protocol's raw input
or output (IMAP, SMTP, POP3, ManageSieve, delivery, milter), which
carries whole messages and credentials; those go out only when named.

Tested: unit tests for the rule (level, raw I/O only when named, a
named event below the level, custom event levels, a webhook's own
errors); the telemetry system test, whose webhook names debug-level
connection events and still receives them.
jcoffey-dev merged commit 09c55ba503 into main 2026-09-28 13:44:52 +00:00
jcoffey-dev deleted branch fix/webhook-event-levels 2026-09-28 13:44:52 +00:00
jcoffey-dev referenced this issue from a commit 2026-09-28 19:22:38 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: inbuxa/inbuxa-server#82