Repository navigation
feat: webhook_dispatcher telemetry + email_sender_service signing/timeouts (#520–#523) - #583
Merged
1 commit merged intoSep 26, 2026
Merged
1 commit merged into
1 commit merged into
Conversation
…eouts Add Winston pipeline tracing for webhook_dispatcher (Goldii-locks#520), supertest route coverage (Goldii-locks#521), HMAC signature checks for email_sender_service outbound webhooks (Goldii-locks#522), and connection timeout handling (Goldii-locks#523).
|
@success-OG Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
godamongstmen897
pushed a commit
that referenced
this pull request
Sep 26, 2026
#575 and #583 each created src/utils/email_sender_service.ts with disjoint exports (payload schema formatting vs outbound signing and timeouts); keep both in one module. #581 and #583 each created __tests__/webhook_dispatcher.test.ts for different modules (src/indexer vs src/utils); #583's test moves to webhook_dispatcher_signing.test.ts. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PJM5SuF3hAuKGMpPBz7Rwr
f39bed4
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements four self-contained issues for webhook dispatch telemetry/testing and email alert outbound hardening.
#520 — Add debug telemetry statements within
webhook_dispatchersrc/utils/webhook_dispatcher.tsas the webhook event notification service.traceId:handler entered(route, body keys, contract id)response sent(status, success)started/completed(ledger range, delivered/failed counts)src/routes/webhooks.tsnow delegates subscribe/unsubscribe through the dispatcher and returnstraceIdin successful responses.__tests__/webhook_dispatcher.test.tsassert the required tracking indicators are present in logger metadata.#521 — Add supertest verification validations for
webhook_dispatcher__tests__/webhook_dispatcher_supertest.test.tscovering:POST /api/webhooks/subscribe(200 success, missing fields, invalidevent_types,*event types)POST /api/webhooks/unsubscribe(200, 404, 400)traceIdpresenceafterAll)#522 — Implement signature checks within
email_sender_servicesrc/utils/email_sender_service.tswith:signOutgoingWebhook()— HMAC-SHA256 over the canonical JSON bodyverifyWebhookSignature()— timing-safe client-side verification of bare hex orsha256=<hex>headerssendEmailAlert()— attachesX-Webhook-Signatureon outbound alert webhooksEMAIL_WEBHOOK_SECRET(documented in.env.example).#523 — Configure call timeout exceptions for
email_sender_serviceAbortControllerwith a configurable timeout (EMAIL_SENDER_TIMEOUT_MS, default 5000ms).call timeout threshold exceeded), and throwEmailSenderTimeoutError.__tests__/email_sender_service.test.ts.Test plan
npm test -- --testPathPatterns='webhook_dispatcher|email_sender_service|webhooks.test' --forceExit— 4 suites / 38 tests passedEMAIL_WEBHOOK_SECRETand verify a receiver can validateX-Webhook-SignatureEMAIL_SENDER_TIMEOUT_MSagainst a slow endpoint and confirm timeout warning + exceptionNotes
/api/webhookspaths and response shapes are preserved; successful responses additionally includetraceId.feat/520-523for a single reviewable PR.Closes #520
Closes #521
Closes #522
Closes #523
Made with Cursor