-
Notifications
You must be signed in to change notification settings - Fork 1
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
Encrypted Endpoint.secret_key has no documented APP_KEY-rotation runbook — a naive rotation permanently bricks every webhook signature
documentationImprovements or additions to documentationImprovements or additions to documentationStatus: Open.#168 In morcen/hooketh;Project-rename cleanup missed docker/validate.sh and DEVELOPMENT.md — both fail on first use
bugSomething isn't workingSomething isn't workingdocumentationImprovements or additions to documentationImprovements or additions to documentationStatus: Open.#167 In morcen/hooketh;SafeWebhookUrlTest's "unresolvable hostname" test performs a live DNS lookup, making a security-critical unit test network-dependent
enhancementNew feature or requestNew feature or requestStatus: Open.#165 In morcen/hooketh;RemoveTeamMemberTest's authorization test only checks the 403 status, never that the member was actually left in place
enhancementNew feature or requestNew feature or requestStatus: Open.#164 In morcen/hooketh;DeprecatedWebhookTriggerAuthTest only checks the controller's self-reported count, never that a Delivery/job was actually created
enhancementNew feature or requestNew feature or requestStatus: Open.#163 In morcen/hooketh;DEPLOYMENT.md documents a phantom APP_FORCE_HTTPS env var that the app never reads
documentationImprovements or additions to documentationImprovements or additions to documentationStatus: Open.#161 In morcen/hooketh;docker/setup.sh never seeds the database, contradicting README.md/CLAUDE.md which both imply make setup produces a working login
bugSomething isn't workingSomething isn't workingdocumentationImprovements or additions to documentationImprovements or additions to documentationStatus: Open.#160 In morcen/hooketh;DEPLOYMENT.md's suggested Docker HEALTHCHECK checks nothing meaningful
bugSomething isn't workingSomething isn't workingdocumentationImprovements or additions to documentationImprovements or additions to documentationStatus: Open.#159 In morcen/hooketh;DEPLOYMENT.md's standalone/cloud recipes point a load balancer directly at php-fpm with no reverse proxy — none of them will work
bugSomething isn't workingSomething isn't workingdocumentationImprovements or additions to documentationImprovements or additions to documentationStatus: Open.#155 In morcen/hooketh;Jetstream Teams feature is fully enabled in the UI but completely disconnected from the app's authorization model
enhancementNew feature or requestNew feature or requestStatus: Open.#153 In morcen/hooketh;Events/Edit.vue silently discards invalid JSON in Payload/Schema fields — independent instance of #98's bug
bugSomething isn't workingSomething isn't workingStatus: Open.#151 In morcen/hooketh;Events/Edit.vue receives endpoint-subscription data but never renders it — no way to manage an event's endpoints from the Edit page
bugSomething isn't workingSomething isn't workingStatus: Open.#150 In morcen/hooketh;