[BTAPI-80] Add alert-webhook receiver for wealthsimple-api dead-session alerts #94
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feature/BTAPI-80"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Ticket
BTAPI-80 Add alert-webhook receiver so wealthsimple-api can push dead-session alerts
Summary
POST /alert?token=...— a query-string-token-authenticated receiver (exempted from the standard bearer gate viaPUBLIC_PATHS, since wealthsimple-api's outbound alert-webhook sender, WSAPI-7, never sends anAuthorizationheader) that validates{ kind, body }against budget-tracker-api's fullAlertKindset and forwards intoNotifications.sendAlert, answering200 { delivered: true }on success or a genuine500if it reached zero devices.Config.alertWebhookToken(envALERT_WEBHOOK_TOKEN), compared with the existing timing-safematches()helper (now exported fromapi/bearer-auth), and a 30/min rate limiter mirroring/sync/wealthsimple's pattern.tokenquery param from request logs (api/create-app'spinoHttpserializer) — pino-http's default serializer logs the full URL and parsed query at info level on every request, including rejected ones, and no prior route carried a credential in the query string.CLAUDE.md,server/CLAUDE.md, andserver/lib/wealthsimple/CLAUDE.mdfor the newPUBLIC_PATHSentry (two → three) and the new endpoint, plusdocs/DEV-ENVIRONMENT.mdand a stale comment inapi/routes/log.alertSchema.body, a missing compile-time link betweenalertSchema's hand-copied kind literals andlib/models.ts'sAlertKind, a cross-file Bunmock.modulecollision in the route's own test, and a shared rate-limit counter across that test file's cases.🤖 Generated with Claude Code
mock.module('expo-server-sdk', ...) is process-wide in Bun, and lib/notifications/.test.ts already claims it for its own fixture — a second mock of that module silently lost the race depending on file order, which whole-suite verification (Step 8a) surfaced as a flaky failure. Swap Notifications.sendAlert directly instead, the same approach lib/wealthsimple/auth/.test.ts already documents and uses for this exact reason. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>