Convoy v26.7.6 — two bugs in HTTP source verifier/provider handling
Bug 1: Cannot attach a verifier to a source created without one (HTTP PUT /sources)
Repro: POST a source with no verifier (type defaults to noop). Later PUT the same source
with verifier: {type: hmac, hmac: {...}} → HTTP 400 an error occurred while updating source.
Server log: failed to update source verifier ... source verifier not found.
Cause: internal/sources/impl.go (updateSource) only runs UPDATE on source_verifiers
and returns source verifier not found when RowsAffected() == 0 — there is no INSERT
branch when the source has no verifier row (noop-created sources have source_verifier_id NULL).
Workaround: seed the verifier row + link sources.source_verifier_id directly in SQL.
Expected: PUT should INSERT a verifier row when none exists (or the POST should persist
the verifier when supplied).
Bug 2: provider field silently not persisted via PUT source
Repro: PUT /sources/{uid} with "provider": "github" → 202 Source updated successfully,
response echoes the provider — but the provider column remains empty (verified via psql).
Impact: sources created without provider cannot gain provider-based verifiers
(NewGithubVerifier is only selected when source.Provider == github).
Expected: persist provider on update (or reject with a validation error).
Environment: Docker getconvoy/convoy:v26.7.6-amd64, Postgres 16, single project.
Convoy v26.7.6 — two bugs in HTTP source verifier/provider handling
Bug 1: Cannot attach a verifier to a source created without one (HTTP PUT /sources)
Repro: POST a source with no
verifier(type defaults to noop). Later PUT the same sourcewith
verifier: {type: hmac, hmac: {...}}→ HTTP 400an error occurred while updating source.Server log:
failed to update source verifier ... source verifier not found.Cause:
internal/sources/impl.go(updateSource) only runs UPDATE onsource_verifiersand returns
source verifier not foundwhenRowsAffected() == 0— there is no INSERTbranch when the source has no verifier row (noop-created sources have
source_verifier_id NULL).Workaround: seed the verifier row + link
sources.source_verifier_iddirectly in SQL.Expected: PUT should INSERT a verifier row when none exists (or the POST should persist
the verifier when supplied).
Bug 2:
providerfield silently not persisted via PUT sourceRepro: PUT /sources/{uid} with
"provider": "github"→ 202Source updated successfully,response echoes the provider — but the
providercolumn remains empty (verified via psql).Impact: sources created without provider cannot gain provider-based verifiers
(
NewGithubVerifieris only selected whensource.Provider == github).Expected: persist
provideron update (or reject with a validation error).Environment: Docker
getconvoy/convoy:v26.7.6-amd64, Postgres 16, single project.