Skip to content

Bug: HTTP source cannot gain a verifier via PUT after noop creation, and provider field is not persisted (v26.7.6) #2861

Description

@MaggieT-creator

Convoy v26.7.6 — two bugs in HTTP source verifier/provider handling

Bug 1: Cannot attach a verifier to a source created without one (HTTP PUT /sources)

Repro: POST a source with no verifier (type defaults to noop). Later PUT the same source
with verifier: {type: hmac, hmac: {...}} → HTTP 400 an error occurred while updating source.
Server log: failed to update source verifier ... source verifier not found.

Cause: internal/sources/impl.go (updateSource) only runs UPDATE on source_verifiers
and returns source verifier not found when RowsAffected() == 0 — there is no INSERT
branch when the source has no verifier row (noop-created sources have source_verifier_id NULL).

Workaround: seed the verifier row + link sources.source_verifier_id directly in SQL.

Expected: PUT should INSERT a verifier row when none exists (or the POST should persist
the verifier when supplied).

Bug 2: provider field silently not persisted via PUT source

Repro: PUT /sources/{uid} with "provider": "github" → 202 Source updated successfully,
response echoes the provider — but the provider column remains empty (verified via psql).

Impact: sources created without provider cannot gain provider-based verifiers
(NewGithubVerifier is only selected when source.Provider == github).

Expected: persist provider on update (or reject with a validation error).

Environment: Docker getconvoy/convoy:v26.7.6-amd64, Postgres 16, single project.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions