Introduces the webhook egress foundation — a new WebhookSubscription table, admin-gated CRUD under /api/v1/webhooks, and the shared delivery client that both the test-ping route and the upcoming worker will use. No worker yet; this commit is API + model + client only. Simple-mode enum (AttackerDetail / DeckyStatus / SystemStatus) expands to bus-topic patterns at the router layer; storage is always the raw pattern list. Advanced mode lets admins supply raw NATS-style patterns directly. Filter-at-subscribe: the worker (next commit) will subscribe to the union of patterns across enabled subscriptions. Delivery client handles HMAC-SHA256 signing (X-DECNET-Signature), retry on 429/5xx/network errors with jittered backoff, no-retry on 4xx. Secrets never leave the server on GET/LIST — only the create response carries the secret for copy-out. CRUD routes publish WEBHOOK_SUBSCRIPTIONS_CHANGED on the bus after every mutation so the (future) worker can hot-reload. Opens DEBT-037 for the deferred items (circuit breaker, dead-letter, batch delivery, payload templates, secret-at-rest).
19 lines
662 B
Python
19 lines
662 B
Python
"""Webhook subscription CRUD.
|
|
|
|
Admin-gated management of external-egress webhook subscriptions. The
|
|
actual delivery happens in the `decnet webhook` worker, which watches
|
|
the DB + bus and POSTs matching events out. This module is the API
|
|
surface operators use to configure destinations.
|
|
|
|
Mounted under `/api/v1/webhooks` by the main api router.
|
|
"""
|
|
from fastapi import APIRouter
|
|
|
|
from .api_manage_webhooks import router as manage_webhooks_router
|
|
from .api_test_webhook import router as test_webhook_router
|
|
|
|
webhooks_router = APIRouter(prefix="/webhooks")
|
|
|
|
webhooks_router.include_router(manage_webhooks_router)
|
|
webhooks_router.include_router(test_webhook_router)
|