Skip to content

Build core form ingestion and durable webhook delivery - #1

Merged
quangshuynh merged 6 commits into
mainfrom
feat/core-ingestion
Aug 24, 2026
Merged

quangshuynh merged 6 commits into
mainfrom
feat/core-ingestion

Conversation

@quangshuynh

Copy link
Copy Markdown
Member

Summary

Builds the initial Hymical Forms backend from ingestion through durable webhook delivery.

Included

  • HTML form ingestion
  • persisted endpoints and submissions
  • configurable validation limits
  • PostgreSQL-backed persistence
  • idempotent submission handling
  • signed HMAC-SHA256 webhooks
  • transactional delivery outbox
  • separate webhook worker
  • bounded exponential retries
  • worker leases and crash recovery
  • delivery attempt history
  • SSRF protections for obvious private/local targets
  • automated tests, Ruff, mypy, and CI

Reliability guarantees

  • submissions are persisted before 202 Accepted
  • webhook work is created atomically with the submission
  • idempotent retries do not create duplicate submissions or delivery jobs
  • webhook delivery is at-least-once
  • failed deliveries retry with bounded exponential backoff
  • abandoned worker claims become eligible again after lease expiry

Current limitations

  • no authentication or API keys
  • one webhook destination per endpoint
  • no failed-delivery replay API
  • no database migrations yet
  • PostgreSQL worker concurrency is not yet exercised live in CI
  • SSRF protection does not yet resolve and pin hostnames
  • no dashboard or frontend

@quangshuynh
quangshuynh merged commit 54a5ea3 into main Aug 24, 2026
3 checks passed
@quangshuynh
quangshuynh deleted the feat/core-ingestion branch August 24, 2026 22:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant