You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Added
Gzip compression: HTTP responses are now gzip-compressed via tower-httpCompressionLayer, reducing bandwidth for API and metrics responses.
Full JSON Schema validation: Replaced manual schema validation with the jsonschema crate (Draft 2020-12). Now supports enum, pattern, minLength, maxLength, and all standard JSON Schema keywords.
Local replay mode: qhook replay-local <file.jsonl> replays exported events (from qhook export events) to a running server. Supports --target, --token, and stdin (-).
Paddle webhook verification: verify: paddle checks Paddle-Signature header (ts=...;h1=... format, HMAC-SHA256) with 5-minute replay protection.
MySQL support: database.driver: mysql for MySQL/MariaDB backends via sqlx AnyPool. Adapts FOR UPDATE SKIP LOCKED, INSERT IGNORE, and VARCHAR(255) primary keys for MySQL compatibility.
llms.txt: AI agent discoverability file at docs/llms.txt following the llms.txt specification.
Compliance documentation: PCI DSS 4.0 and SOC 2 compliance framing guide (docs/guides/compliance.md) with audit trail mapping tables.
insta snapshot tests: 21 snapshot tests for config validation error messages, default config template, Prometheus metrics format, and API response formats.
Event inspection API: GET /api/events, GET /api/events/{id}/jobs, GET /api/jobs, GET /api/jobs/{id}/attempts with filtering, cursor-based pagination, and has_more support.
Filtered replay: replay-local now supports --source, --event-type, --since, --until, --status filters. Event type supports prefix matching with *.
Benchmark suite: criterion-based benchmarks for config parsing, filter evaluation, ULID generation, signature verification, and SQLite event insertion.
MCP server: TypeScript MCP server (mcp-server/) wrapping qhook's REST API for AI agent integration (Claude Code, Claude Desktop).
Changed
Per-destination rate limiting: Switched from semaphore-hold to GCRA-based rate limiting via the governor crate. Provides smoother, more accurate per-handler rate limiting.