Files
picpeak/backend/migrations/core/082_add_webhooks.js
T
Paul Nothaft c488f481ca feat: outbound webhooks for event/photo lifecycle (#327)
PicPeak POSTs lifecycle notifications to admin-configured URLs. Each
delivery is signed HMAC-SHA256 in the X-PicPeak-Signature header.
Verified end-to-end: 1/1 Playwright spec, 8/8 backend integration
tests, full UI click-through via Chrome DevTools.

Schema (migration 082)
- webhooks: id, name, url, secret (plaintext — required to compute HMAC
  for every outbound POST), secret_preview, events[], active, filter,
  template, created_by, timestamps, last_success_at/last_failure_at.
- webhook_deliveries: webhook_id (FK CASCADE), event_type, payload,
  attempt_count, status (pending|success|failed), response_status,
  response_body (truncated to 1KB), latency_ms, next_retry_at,
  last_error, created_at, completed_at. Composite index
  (status, next_retry_at) serves the worker's hot-path query.

Service + worker
- webhookService.fire(eventType, data) — non-throwing entry point used
  by lifecycle hooks. Looks up active webhooks subscribed to the event
  and applies their per-webhook filter (dot-path equality predicate)
  before enqueueing one webhook_deliveries row per match. Filter and
  template logic ship in this commit; admin surfaces in the follow-up.
- webhookDeliveryWorker — setInterval(5s) poller; fetches up to 5
  pending rows; per delivery: re-validates URL via networkValidation
  (DNS-rebinding mitigation, opt-out via WEBHOOK_ALLOW_PRIVATE_URLS),
  signs body with HMAC-SHA256, POSTs with 10s timeout, records outcome.
  Backoff schedule: 1m → 5m → 30m → 2h → 12h, max 5 attempts. Response
  body truncated to 1KB before storage. If a webhook has a template,
  the rendered string replaces the JSON envelope as the request body
  (signature is computed over the bytes actually sent).

Lifecycle wiring
- adminEvents.js POST /events → event.created (+ event.published when
  not draft); POST /:id/publish → event.published.
- routes/events.js (legacy public POST) → event.created + event.published.
- routes/v1/events.js (#322 API) → event.created + event.published on
  create, photo.uploaded on photo POST.
- archiveService.archiveEvent() → event.archived. Per-photo
  photo.deleted intentionally NOT fired during cascade — receivers
  infer from event.archived to avoid flooding (issue spec).
- expirationChecker.handleExpiredEvent() → event.expired BEFORE the
  cascading archive (so receivers see expired→archived in order).
- adminPhotos.js — photo.uploaded on each batch row, photo.deleted on
  single + bulk delete.
- photoProcessor.js — photo.uploaded for guest uploads + auto-import
  (covers all entry paths).
- fileWatcher.js — photo.uploaded on add, photo.deleted on unlink
  (local mode only).

Admin endpoints (mirrors adminApiTokens.js pattern)
- /api/admin/webhooks: GET list, POST create (returns plaintext secret
  exactly once), GET :id, PUT :id, DELETE :id, POST :id/test (synthetic
  fire), GET :id/deliveries (paginated, filter by status), GET
  :id/deliveries/:deliveryId, POST :id/deliveries/:deliveryId/replay.

Frontend
- Settings → Webhooks tab (mirrors API Tokens layout): name + URL +
  event checkboxes + "Advanced" expander for filter (JSON) and template.
  Plaintext secret shown once on creation with a Copy button. Active/
  Disabled toggle button per row.
- /admin/webhooks/:id/deliveries — operational debug surface. Table
  with timestamp/event/status/attempts/HTTP/latency. Status filter chips
  (all/pending/success/failed). Row click → slide-over with payload +
  signature + response body. Replay button on failed rows. Send-test-event
  dialog. Auto-refresh every 10s.

Dev infrastructure
- dev/webhook-receiver/ — tiny node:alpine HTTP server (~100 LOC) that
  records every POST to an in-memory ring buffer. Exposes GET /requests
  for the E2E spec to assert deliveries landed with the right HMAC.
  Sibling pattern to MinIO. Reachable from the backend at
  http://webhook-receiver:8888 inside the picpeak network.

Tests
- backend/__tests__/integration/webhookDelivery.test.js (8/8) —
  signature verification, headers, retry/backoff, max-attempts → failed,
  response truncation, disabled-mid-flight, SSRF block, start/stop
  idempotency.
- tests/e2e/webhooks-roundtrip.spec.ts (1/1) — create webhook → trigger
  event.published → assert receiver got POST with valid HMAC → visit
  deliveries page → row visible with status=success → API test event →
  API replay → disable webhook → assert no new delivery.

Docs
- README §"Webhooks" — event catalog, payload shape, HMAC verification
  in Node + Python + bash, retry semantics, SSRF protection.
- .env.example — WEBHOOK_ALLOW_PRIVATE_URLS, WEBHOOK_DELIVERY_INTERVAL_MS,
  WEBHOOK_DELIVERY_CONCURRENCY, WEBHOOK_HTTP_TIMEOUT_MS,
  WEBHOOK_MAX_ATTEMPTS.

Out of scope for v1 (per issue): webhook templates' code-eval (the
${dot.path} substitution that ships is pure string replacement, no
expression engine — see follow-up commit), per-webhook rate limiting
beyond the global concurrency cap, synchronous "ask before delete"
webhooks.

Spanning files
- App.tsx pulls in this commit with both the AnalyticsBootstrap
  (#325 dedup) and the WebhookDeliveriesPage route registration.
  Splitting via git add -p was forfeit for sanity; the single 92-line
  diff is honest about both contributions.
- adminEvents.js diff bundles the webhook fires AND the
  allow_presigned_download field plumbing (#328 follow-up). Same
  reasoning.
- The new webhookService/Worker/adminWebhooks files include the filter
  and template logic from the follow-up — they were authored in one
  pass; splitting them post-hoc would have produced fragile partial
  files. The follow-up commit covers the migration and the UI for these.
2026-04-28 10:07:39 +02:00

81 lines
3.8 KiB
JavaScript

/**
* #327 — outbound webhooks (push API) for the event/photo lifecycle.
*
* Two tables:
* webhooks — admin-managed subscriptions (URL + events + secret)
* webhook_deliveries — single source of truth for the delivery worker
* (audit log + retry queue in one).
*/
exports.up = async function up(knex) {
if (!(await knex.schema.hasTable('webhooks'))) {
await knex.schema.createTable('webhooks', (table) => {
table.increments('id').primary();
table.string('name', 100).notNullable();
// Validated via networkValidation.validateExternalUrl on create + per
// delivery (DNS-rebinding mitigation).
table.string('url', 2048).notNullable();
// Plaintext signing secret (`whsec_<random>`). Stored unencrypted
// because we need to recompute HMAC-SHA256 over every outbound body
// — a hash would make the secret unrecoverable. Same posture as
// SMTP passwords stored in app_settings; protect the DB. The
// plaintext is also returned to the admin once on create so they can
// configure the receiver to verify signatures.
table.string('secret', 100).notNullable();
// First 8 chars of the secret for the admin UI so operators can
// tell which webhook is which without revealing the full secret.
table.string('secret_preview', 16).nullable();
// JSON array of subscribed event types
// (e.g. ["event.published","photo.uploaded"]).
table.jsonb('events').notNullable().defaultTo('[]');
table.boolean('active').notNullable().defaultTo(true);
table.integer('created_by').notNullable()
.references('id').inTable('admin_users').onDelete('CASCADE');
table.timestamp('created_at').defaultTo(knex.fn.now());
table.timestamp('updated_at').defaultTo(knex.fn.now());
table.timestamp('last_success_at').nullable();
table.timestamp('last_failure_at').nullable();
// Index for the delivery worker's "find subscriptions for this event"
// query — small set, but keeps the lookup constant-time as it grows.
table.index('active', 'webhooks_active_idx');
});
}
if (!(await knex.schema.hasTable('webhook_deliveries'))) {
await knex.schema.createTable('webhook_deliveries', (table) => {
table.increments('id').primary();
table.integer('webhook_id').notNullable()
.references('id').inTable('webhooks').onDelete('CASCADE');
table.string('event_type', 64).notNullable();
// Full signed payload (the JSON body that was POSTed).
table.jsonb('payload').notNullable();
table.integer('attempt_count').notNullable().defaultTo(0);
// pending → success | failed. pending rows with next_retry_at <= NOW()
// are picked up by the worker.
table.string('status', 16).notNullable().defaultTo('pending');
table.integer('response_status').nullable();
// Truncated to 1KB before storage so a verbose receiver can't blow
// up the row size.
table.text('response_body').nullable();
table.text('last_error').nullable();
table.integer('latency_ms').nullable();
table.timestamp('next_retry_at').nullable();
table.timestamp('created_at').defaultTo(knex.fn.now());
table.timestamp('completed_at').nullable();
// Worker hot-path query: WHERE status='pending' AND next_retry_at <= NOW()
// ORDER BY next_retry_at LIMIT N. This composite index serves it directly.
table.index(['status', 'next_retry_at'], 'webhook_deliveries_status_retry_idx');
table.index('webhook_id', 'webhook_deliveries_webhook_idx');
});
}
};
exports.down = async function down(knex) {
if (await knex.schema.hasTable('webhook_deliveries')) {
await knex.schema.dropTable('webhook_deliveries');
}
if (await knex.schema.hasTable('webhooks')) {
await knex.schema.dropTable('webhooks');
}
};