Files
inbuxa-server/crates
jcoffey-dev 6945714aa9
ci / fork-checks (pull_request) Successful in 45s
ci / build (pull_request) Successful in 5m42s
Stop webhooks sending every event, message content included
A webhook has a level (info by default) that nothing read: its events
were chosen by its list and policy alone. With the default policy,
exclude, and nothing listed, that meant every event type, including
smtp.raw-input (the raw SMTP bytes, DATA included) and the model's
reply to the spam classifier. The docs suggest a webhook to pass the
audit log to a SIEM; set up that way it would have received whole
messages. Found by the personal-data catalog investigation (finding 1).

Now an include list is sent as named, whatever each event's level:
naming an event is the choice. Otherwise a webhook gets only events at
or above its level, as a tracer does, and never a protocol's raw input
or output (IMAP, SMTP, POP3, ManageSieve, delivery, milter), which
carries whole messages and credentials; those go out only when named.

Tested: unit tests for the rule (level, raw I/O only when named, a
named event below the level, custom event levels, a webhook's own
errors); the telemetry system test, whose webhook names debug-level
connection events and still receives them.
2026-09-28 06:38:37 -07:00
..
2026-09-22 16:57:06 -07:00
2026-09-22 16:31:25 -07:00
2026-09-22 16:57:06 -07:00
2026-09-22 16:57:06 -07:00
2026-09-28 00:15:33 -07:00