BUG: Webhook system reliability issues causing missed updates in v1.7.31 (replay protection, instance matching, SSE) #62
Closed
opened 2026-05-28 10:39:42 +01:00 by Gandalf
·
0 comments
No Branch/Tag Specified
main
release/1.7.38
develop
release/1.7.37
release/1.7.36
release/1.7.35
release/1.7.34
release/1.7.33
release/1.7.32
release/1.7.31
release/1.7.30
release/1.7.29
release/1.7.28
release/1.7.27
release/1.7.26
release/1.7.25
release/1.7.24
release/1.7.23
release/1.7.22
release/1.7.21
release/1.7.20
release/1.7.19
release/1.7.18
release/1.7.17
release/1.7.16
release/1.7.15
release/1.7.14
release/1.7.13
release/1.7.12
release/1.7.11
release/1.7.10
release/1.7.9
release/1.7.8
release/1.7.7
release/1.7.6
release/1.7.5
release/1.7.4
release/1.7.3
release/1.6.0
release/1.5.5
release/1.5.3
release/1.5.2
release/1.5.0a
release/1.4.0
release/1.3.1a
release/1.3.1
release/1.3.0
release/v1.2.2
release/v1.2.1
release/v1.2.0
release/1.1.2
release/1.1.1
release/1.1.0
release/1.0.0
release/0.2.0
release/v0.1.5
release/0.1.4
release/0.1.3
release/0.1
v1.7.38
v1.7.37
v1.7.36
v1.7.35
v1.7.34
v1.7.33
v1.7.32
v1.7.31
v1.7.30
v1.7.29
v1.7.28
v1.7.27
v1.7.26
v1.7.25
v1.7.24
v1.7.23
v1.7.22
v1.7.21
v1.7.20
v1.7.19
v1.7.18
v1.7.17
v1.7.16
v1.7.15
v1.7.14
v1.7.13
v1.7.12
v1.7.11
v1.7.10
v1.7.9
v1.7.8
v1.7.7
v1.7.6
v1.7.5
v1.7.4
v1.7.3
v1.6.0
v1.5.5
v1.5.3
v1.5.2
v1.5.1
v1.5.0a
v1.4.0
v1.3.1a
v1.3.1
v1.2.2
v1.2.1
v1.2.0
v1.1.2
v1.1.1
v1.1.0
v1.0.0
v0.2.0
v0.1.5
v0.1.4
v0.1.3
v0.1.2
v0.1.1
v0.1.0
Labels
Clear labels
Area/Docker
Area/Download Clients
Area/Frontend
Area/History
Area/Logging
Area/Matching
Area/Proxy
Area/SSE
Area/Webhooks
Compat/Breaking
Compat/Non-Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Docker image and container packaging
Download client integrations
Client-side UI and build tooling
History and completed downloads views
Log streaming, file handling, and debug infrastructure
Matching and correlation logic
Upstream service proxy routes
Server-Sent Events and real-time streaming
Webhook processing and reliability
Breaking change that won't be backward compatible
Non-breaking compatibility change
Something is not working
Documentation changes
Improve existing functionality
New functionality
This is security issue
Issue or pull request related to testing
Priority
Critical
1
The priority is critical
Priority
High
2
The priority is high
Priority
Low
4
The priority is low
Priority
Medium
3
The priority is medium
Reviewed
Confirmed
1
Issue has been confirmed
Reviewed
Duplicate
2
This issue or pull request already exists
Reviewed
Invalid
3
Invalid issue
Reviewed
Won't Fix
3
This issue won't be fixed
Status
Abandoned
3
Somebody has started to work on this but abandoned work
Status
Blocked
1
Something is blocking this issue or pull request
Status
Need More Info
2
Feedback is required to reproduce issue or to continue work
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Gandalf/sofarr#62
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Related to: Season pack queue handling (#61) – webhooks are the primary trigger for queue refreshes that feed the broken season pack data path.
Description:
Webhooks from Sonarr, Radarr, and Ombi frequently fail to trigger real-time dashboard/SSE updates ("not working again" in v1.7.31). This regressed or became more noticeable after the poller/SSE test expansions and frontend changes in this release, even though no direct webhook logic was modified.
Detailed Investigation Findings (release/1.7.31)
1. Overly Strict Replay Protection (
server/routes/webhook.js)isReplay(eventType, instanceName, eventDate)uses a simple key:`${eventType}:${instanceName || ''}:${eventDate}`(or`${requestId}-${eventDate}`for Ombi).datewith sub-second variations, timezone differences, or identical values for rapid events (e.g., Grab → Download).200 { received: true, duplicate: true }and completely skipprocessWebhookEvent()+pollAllServices()(SSE broadcast).eventDate(e.g., to minute precision) and no content-hash fallback.2. Brittle Instance Resolution
const inst = sonarrInstances.find(i => i.name === instanceName || i.id === instanceName) || sonarrInstances[0];instanceNamefrom *arr often doesn't exactly match configurednameorid→ falls back to first instance.cache.updateWebhookMetrics()and incorrect cache keys for multi-instance users.3. Ombi-Specific Fragility (despite query-param secret fix in commit
7b9c895)validatePayload().extractRequestedUser()logic inprocessWebhookEvent('ombi', ...)can fail silently on certain payloads/Ombi versions, leavingpoll:ombi-requestsstale.4. Fire-and-Forget + SSE Dependency
processWebhookEvent(...).catch(err => log...)only logs.await pollAllServices()(which triggers SSE to all connected clients) can fail without user-visible feedback.5. Interaction with Poller & Queue Refresh
arrRetrieverRegistry.getQueuesByType()→PollingSonarrRetriever.getQueue()(which has the season pack bug tracked in #61).Impact:
Proposed Solution / Fix Plan:
Replay Protection Hardening (High Priority)
eventDateto minute precision or use a stable content hash of key fields (eventType + title + downloadId).?force=truequery param for testing/admin bypass.Instance Matching Improvements
Ombi Hardening
validatePayloadOmbi()version.Observability
/api/statusor new debug endpoint.pollAllServices()errors are caught and logged with context.Cross-Dependency Note
Suggested Labels:
Kind/Bug, Priority: High, Area/Webhooks, Area/SSE, Compat/Non-Breaking
Affected Versions: v1.7.27 – v1.7.31 (replay protection introduced earlier; became painful with increased webhook usage and poller changes).