Add updated-from entity snapshot to updated webhooks

Update webhook events now carry a top-level "updatedFrom" field
alongside "data", containing a full snapshot of the entity as it was
before the update. This lets subscribers diff old vs new state (for
example the prior membership role on user:updated) without tracking
prior state themselves. It is a complete snapshot with the same shape as
"data", not a partial diff, so consumers select whatever fields they
need. The field is omitted for non-update events.

The webhook_data table gains a nullable updated_from JSONB column, and
webhook.InsertUpdateData enqueues both snapshots; InsertData delegates to
it with a nil updatedFrom so non-update callers are unaffected. Each
*:updated emission site snapshots the entity right after load, before
mutation: obligation, third-party, user (org and SCIM flows), document,
document-version, and document-version-approval-quorum. The document
emit helpers gained an optional updatedFrom argument threaded through to
the payload.

For document-version-approval-quorum:updated the snapshot requires an
extra query, so it is now gated behind the same subscription-existence
check the emitter uses: when no subscriber is configured the load is
skipped entirely rather than running (and potentially failing the
approval) for an event nobody receives.

Add integration tests (against a real Postgres, skipped when none is
reachable) covering the updated_from round-trip, the SQL NULL behavior
when no snapshot is provided, and the no-op when no subscription matches,
plus a unit test asserting updatedFrom is omitted from the payload when
absent.

Document the new field in the probod and n8n changelogs and the n8n
README.

Signed-off-by: Sacha Al Himdani <sacha@probo.com>
This commit is contained in:
Sacha Al Himdani
2026-07-15 10:34:17 +02:00
parent 68338fb4ae
commit 944bcb7380
15 changed files with 428 additions and 19 deletions

View File

@@ -293,6 +293,8 @@ func (s *OrganizationService) UpdateMembership(
}
}
previousUser := webhooktypes.NewUser(profile, &membership)
membership.Role = role
membership.UpdatedAt = time.Now()
@@ -300,7 +302,7 @@ func (s *OrganizationService) UpdateMembership(
return fmt.Errorf("cannot update membership: %w", err)
}
if err := webhook.InsertData(ctx, tx, scope, organizationID, coredata.WebhookEventTypeUserUpdated, webhooktypes.NewUser(profile, &membership)); err != nil {
if err := webhook.InsertUpdateData(ctx, tx, scope, organizationID, coredata.WebhookEventTypeUserUpdated, webhooktypes.NewUser(profile, &membership), previousUser); err != nil {
return fmt.Errorf("cannot insert webhook event: %w", err)
}
@@ -439,6 +441,8 @@ func (s *OrganizationService) ArchiveUser(
return fmt.Errorf("cannot delete requested signatures: %w", err)
}
previousUser := webhooktypes.NewUser(&profile, membership)
now := time.Now()
if profile.State != coredata.ProfileStateInactive {
@@ -455,7 +459,7 @@ func (s *OrganizationService) ArchiveUser(
return fmt.Errorf("cannot update membership: %w", err)
}
if err := webhook.InsertData(ctx, tx, scope, profile.OrganizationID, coredata.WebhookEventTypeUserUpdated, webhooktypes.NewUser(&profile, membership)); err != nil {
if err := webhook.InsertUpdateData(ctx, tx, scope, profile.OrganizationID, coredata.WebhookEventTypeUserUpdated, webhooktypes.NewUser(&profile, membership), previousUser); err != nil {
return fmt.Errorf("cannot insert webhook event: %w", err)
}
@@ -1099,6 +1103,8 @@ func (s *OrganizationService) UpdateUser(ctx context.Context, req *UpdateUserReq
return fmt.Errorf("cannot load profile: %w", err)
}
previousProfile := *profile
if profile.Source != coredata.ProfileSourceSCIM {
profile.FullName = req.FullName
profile.Kind = req.Kind
@@ -1130,7 +1136,10 @@ func (s *OrganizationService) UpdateUser(ctx context.Context, req *UpdateUserReq
membership := &coredata.Membership{}
var webhookPayload *webhooktypes.User
var (
webhookPayload *webhooktypes.User
previousUser *webhooktypes.User
)
if err := membership.LoadByIdentityIDAndOrganizationID(ctx, conn, scope, profile.IdentityID, profile.OrganizationID); err != nil {
if !errors.Is(err, coredata.ErrResourceNotFound) {
@@ -1138,16 +1147,20 @@ func (s *OrganizationService) UpdateUser(ctx context.Context, req *UpdateUserReq
}
webhookPayload = webhooktypes.NewUser(profile, nil)
previousUser = webhooktypes.NewUser(&previousProfile, nil)
} else {
webhookPayload = webhooktypes.NewUser(profile, membership)
previousUser = webhooktypes.NewUser(&previousProfile, membership)
}
if err := webhook.InsertData(ctx,
if err := webhook.InsertUpdateData(
ctx,
conn,
scope,
profile.OrganizationID,
coredata.WebhookEventTypeUserUpdated,
webhookPayload,
previousUser,
); err != nil {
return fmt.Errorf("cannot insert webhook event: %w", err)
}

View File

@@ -190,6 +190,8 @@ func (s *Service) CreateUser(
eventType := coredata.WebhookEventTypeUserUpdated
profile = &coredata.MembershipProfile{}
var previousProfile *coredata.MembershipProfile
if err := profile.LoadByIdentityIDAndOrganizationID(
ctx,
tx,
@@ -214,6 +216,9 @@ func (s *Service) CreateUser(
*externalIdPtr,
config.OrganizationID,
); err == nil {
snapshot := *profile
previousProfile = &snapshot
// Migrate the existing membership to the new identity
// so the user's role is preserved.
oldIdentityID := profile.IdentityID
@@ -270,6 +275,11 @@ func (s *Service) CreateUser(
eventType = coredata.WebhookEventTypeUserCreated
}
} else {
if previousProfile == nil {
snapshot := *profile
previousProfile = &snapshot
}
if profile.Source == coredata.ProfileSourceSCIM {
return scimerrors.ScimErrorUniqueness
}
@@ -340,7 +350,12 @@ func (s *Service) CreateUser(
}
}
if err := webhook.InsertData(ctx, tx, scope, config.OrganizationID, eventType, webhooktypes.NewUser(profile, membership)); err != nil {
var previousUser any
if eventType == coredata.WebhookEventTypeUserUpdated && previousProfile != nil {
previousUser = webhooktypes.NewUser(previousProfile, membership)
}
if err := webhook.InsertUpdateData(ctx, tx, scope, config.OrganizationID, eventType, webhooktypes.NewUser(profile, membership), previousUser); err != nil {
return fmt.Errorf("cannot insert webhook event: %w", err)
}
@@ -517,6 +532,10 @@ func (s *Service) updateUser(
return fmt.Errorf("cannot load membership: %w", err)
}
previousProfile := *profile
previousMembership := *membership
previousUser := webhooktypes.NewUser(&previousProfile, &previousMembership)
shouldReactivate := attrs.Active != nil && *attrs.Active && profile.State == coredata.ProfileStateInactive
shouldDeactivate := attrs.Active != nil && !*attrs.Active && profile.State == coredata.ProfileStateActive
@@ -785,7 +804,7 @@ func (s *Service) updateUser(
}
}
if err := webhook.InsertData(ctx, tx, scope, config.OrganizationID, coredata.WebhookEventTypeUserUpdated, webhooktypes.NewUser(profile, membership)); err != nil {
if err := webhook.InsertUpdateData(ctx, tx, scope, config.OrganizationID, coredata.WebhookEventTypeUserUpdated, webhooktypes.NewUser(profile, membership), previousUser); err != nil {
return fmt.Errorf("cannot insert webhook event: %w", err)
}
@@ -931,6 +950,8 @@ func (s *Service) deactivateProfileInTx(
return nil
}
previousUser := webhooktypes.NewUser(profile, membership)
now := time.Now()
profile.State = coredata.ProfileStateInactive
profile.UpdatedAt = now
@@ -964,7 +985,7 @@ func (s *Service) deactivateProfileInTx(
}
}
if err := webhook.InsertData(ctx, tx, scope, config.OrganizationID, coredata.WebhookEventTypeUserUpdated, webhooktypes.NewUser(profile, membership)); err != nil {
if err := webhook.InsertUpdateData(ctx, tx, scope, config.OrganizationID, coredata.WebhookEventTypeUserUpdated, webhooktypes.NewUser(profile, membership), previousUser); err != nil {
return fmt.Errorf("cannot insert webhook event: %w", err)
}