Failure scenario
- Enable outbound webhooks and start with one configured target.
- Through the advertised CRUD API, create a second target, update the configured target's URL/events, or delete it.
- Restart Odin cleanly.
The API mutates only the in-memory dispatcher. No route writes the target collection to config or another durable store. Startup reconstructs the dispatcher exclusively from config.outbound_webhooks.targets, so created targets disappear and updates/deletions of configured targets revert after every restart. The API returns successful 201/200 responses even though the change is not durable.
Sites
src/web/api/integrations.py:665-690 creates only an in-memory target.
src/web/api/integrations.py:692-717 updates only the in-memory target.
src/web/api/integrations.py:719-727 deletes only the in-memory target.
src/discord/wiring.py:535-554 rebuilds all targets from startup config and has no replay of API changes.
Expected result
Persist successful CRUD mutations transactionally to the canonical outbound-webhook target configuration (including protected secret handling), or explicitly replace the durable-looking CRUD API with a clearly documented ephemeral operation and prevent false persistence expectations.
Failure scenario
The API mutates only the in-memory dispatcher. No route writes the target collection to config or another durable store. Startup reconstructs the dispatcher exclusively from
config.outbound_webhooks.targets, so created targets disappear and updates/deletions of configured targets revert after every restart. The API returns successful201/200responses even though the change is not durable.Sites
src/web/api/integrations.py:665-690creates only an in-memory target.src/web/api/integrations.py:692-717updates only the in-memory target.src/web/api/integrations.py:719-727deletes only the in-memory target.src/discord/wiring.py:535-554rebuilds all targets from startup config and has no replay of API changes.Expected result
Persist successful CRUD mutations transactionally to the canonical outbound-webhook target configuration (including protected secret handling), or explicitly replace the durable-looking CRUD API with a clearly documented ephemeral operation and prevent false persistence expectations.