docs+test(notifications): api-reference, changeset, switch click in browser test

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
Devvyn
2026-10-02 22:34:46 +08:00
co-authored by Claude Sonnet 5.5
parent 0ff57ce304
commit d68a173a23
3 changed files with 26 additions and 3 deletions
+5
View File
@@ -0,0 +1,5 @@
---
"aicodeman": minor
---
Webhook notifications. Settings → Notifications → "Webhook" posts the same events as Web Push (permission prompts, questions, errors, idle) to ntfy, Slack, Discord or any JSON URL, so a headless server can reach a phone with no browser open. Off by default. The URL is a bearer secret: it is stored in its own 0600 file, never returned by the API, and the routes (`GET`/`PUT /api/webhook`, `POST /api/webhook/test`) are admin only in multi-user mode. Delivery refuses link-local and cloud-metadata targets, does not follow redirects, times out after 5 s, dedupes repeats, and neutralises `@everyone`/Slack control characters in agent-supplied text.