webhooks

package
v0.0.0-...-51ec7a6 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 23, 2026 License: Apache-2.0 Imports: 12 Imported by: 0

Documentation

Overview

Package webhooks provides bounded, engine-scoped HTTP webhook ingress. It routes exact request bytes to an engine-owned verifier and acceptor but deliberately does not parse, persist, deduplicate, or enqueue deliveries.

Index

Constants

View Source
const (
	DefaultMaxBodyBytes           int64 = 256 * 1024
	DefaultHandlerTimeout               = 5 * time.Second
	DefaultMaxConcurrentBodyReads       = 64
	MaxResponseBodyBytes                = 64 * 1024
)
View Source
const (
	OutcomeAccepted = "accepted"
	OutcomeRejected = "rejected"
	OutcomeFailed   = "failed"
)

Variables

View Source
var (
	ErrFrozen         = errors.New("webhook scope is frozen")
	ErrAdmissionPanic = errors.New("webhook admission check panicked")
	ErrVerifierPanic  = errors.New("webhook verifier panicked")
	ErrAcceptorPanic  = errors.New("webhook acceptor panicked")
)

Functions

func Reject

func Reject(statusCode int, err error) error

Reject returns a safe HTTP rejection. The wrapped error is used only for matching inside this package and is never written to the provider response or passed to observers.

Types

type AcceptFunc

type AcceptFunc func(context.Context) (Response, error)

AcceptFunc captures the verified, engine-owned source identity and performs durable acceptance. A verifier must return it only after authenticating the exact request bytes.

type AdmitFunc

type AdmitFunc func(context.Context, Metadata) error

AdmitFunc performs a cheap check before Soro reads the request body. It may reject abusive traffic but cannot authenticate a delivery; Verify still owns provider authentication over the exact body bytes.

type Definition

type Definition struct {
	Name         string
	Path         string
	ContentTypes []string
	MaxBodyBytes int64
	Timeout      time.Duration
	Admit        AdmitFunc
	Verify       VerifyFunc
}

Definition declares one POST endpoint relative to an engine's API mount. Zero limits use the package defaults.

type Metadata

type Metadata struct {
	Method     string
	URL        *url.URL
	Host       string
	Header     http.Header
	PathValues map[string]string
	RemoteAddr string
	ReceivedAt time.Time
}

Metadata is the detached request metadata available before Soro reads the body. It is suitable for cheap per-address or per-path admission checks. Path values are routing hints only and must not be trusted as source identity.

func (Metadata) PathValue

func (metadata Metadata) PathValue(name string) string

type Observation

type Observation struct {
	Engine     string
	Endpoint   string
	StatusCode int
	Outcome    string
	BodyBytes  int64
	Duration   time.Duration
}

type Observer

type Observer func(context.Context, Observation)

type Option

type Option func(*settings)

func WithClock

func WithClock(clock func() time.Time) Option

func WithMaxConcurrentBodyReads

func WithMaxConcurrentBodyReads(limit int) Option

func WithObserver

func WithObserver(observer Observer) Option

type Registry

type Registry struct {
	// contains filtered or unexported fields
}

Registry owns webhook routes installed on a host HTTP mux.

func New

func New(mux *http.ServeMux, options ...Option) (*Registry, error)

func (*Registry) Routes

func (registry *Registry) Routes() []Route

func (*Registry) Scope

func (registry *Registry) Scope(owner, prefix string) (*Scope, error)

type Request

type Request struct {
	Method     string
	URL        *url.URL
	Host       string
	Header     http.Header
	Body       []byte
	PathValues map[string]string
	RemoteAddr string
	ReceivedAt time.Time
}

Request is the detached transport evidence supplied to an engine. Body is the exact bounded byte sequence read from the HTTP request; Soro does not decompress or parse it before verification.

func (Request) PathValue

func (request Request) PathValue(name string) string

type Response

type Response struct {
	StatusCode int
	Header     http.Header
	Body       []byte
}

type Route

type Route struct {
	Engine       string
	Name         string
	Method       string
	Path         string
	ContentTypes []string
	MaxBodyBytes int64
	Timeout      time.Duration
}

type Scope

type Scope struct {
	// contains filtered or unexported fields
}

func (*Scope) Freeze

func (scope *Scope) Freeze()

func (*Scope) Frozen

func (scope *Scope) Frozen() bool

func (*Scope) Owner

func (scope *Scope) Owner() string

func (*Scope) Prefix

func (scope *Scope) Prefix() string

func (*Scope) Register

func (scope *Scope) Register(definition Definition) error

type VerifyFunc

type VerifyFunc func(context.Context, Request) (AcceptFunc, error)

VerifyFunc authenticates a request and returns the only function allowed to accept it. This keeps provider-specific identities and secrets inside the owning engine without an untyped shared claims container.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL