fix: guard webhook canary enqueue semantics - #241
Conversation
Co-authored-by: giscebot <286264155+giscebot@users.noreply.github.com>
0c19ec5 to
3fae7bc
Compare
giscebot
left a comment
There was a problem hiding this comment.
Approved. I checked the canary gate ordering, bot/self-trigger suppression, non-actionable payload handling before canonical-event claiming, cross-transport identities for failed workflows and commit comments, the SQLite/policy/schema/docs compatibility path, operator authorization, and the dashboard audit links and filters.
Validated at 3fae7bc: 409 Python tests, 62 dashboard tests, production dashboard build, and diff check; CI is green on Python 3.11, Python 3.12, and dashboard.
Non-blocking follow-up: the coverage query applies julianday() to created_at, so a future high-volume ingest_receipts table may need a source/created_at index plus index-friendly comparisons. That does not block the current guarded rollout.
Summary
botLoginswebhookCanaryReposfrom the transport-wideenabledReposgate so a one-repo webhook canary cannot deny IMAP work elsewhere#commitcomment-<id>anchors%hwebhook policy paths defensively and fix the systemd environment exampleSafety fixes
The canary now fails closed unless a repository appears in
webhookCanaryRepos. The existingenabledReposfield keeps its original transport-wide meaning, so IMAP remains unchanged when the webhook canary is narrow.Configured bot identities are observational only and cannot self-trigger webhook work. Coverage excludes old IMAP history, source-specific
email:*fallbacks, unsupported event identities, and deliveries still inside the grace window.Validation
python -m pytest -q— 409 passednpm test -- --run— 62 passednpm run build— passedok, 0 foreign-key violationsRollout
Keep
GITHUB_AGENT_BRIDGE_WEBHOOK_MODE=shadowuntil this lands. Then configure one explicitwebhookCanaryReposentry and switch only the webhook service/dashboard tocanary. Rollback is configuration-only: return the mode toshadow.Requested by: @ecarreras
Follow-up for #233 post-merge audit.