webhooks: add comment clarifying field usage
webhooks: expand auth configuration
The purpose of this change is to enable internal webhooks to be
configured in GQL webhook tables. A webhook subscription now includes
the auth method field which is appropriate, which is limited to either
OAUTH2 or INTERNAL. In the former case, the previous set of fields will
be valid, and in the latter case, the NodeID field will be valid. This
will allow us to register webhook subscriptions for internal use.
server: add @private directive glue code
auth: fix /query/api-meta.json route
This route does not need authentication.
Enforce complexity limit on webhook payload
Configure server to manage mail queue
This also sets up the recovery function for webhooks, so we get emailed
when we panic during a webhook query.
valid: accept format strings
valid: new module for input validation
webhooks: panic on nested webhook auth case
This is not strictly speaking necessary since we have a panic which
immediately follows the switch, but it is cleaner.
webhooks: correct error case log format
webhooks: test error from delivery attempt
webhooks: add query validation function
The new function tests a query against a GraphQL schema and returns any
validation errors if they are found. This is useful for determining if a
GraphQL query will pass validation when creating a new webhook.
webhooks: refactor exec code into separate func
server: add server reference to context
webhooks: initial prototype for GQL-native webhooks
.builds/alpine.yml: upgrade to 3.14
auth: s/OAuth2Token/BearerToken/g
This also makes some tweaks to the organization of the crypto module to
make it easier for us to add more keys in the future, which will be
necessary for the internal token redesign.
auth: allow /query/metrics w/o authentication
auth: fix user type on database insert