refactor(webpush): use RequireExperimentWithDevBypass middleware (#22525)

Replace manual experiment checks in web-push handlers with the
`RequireExperimentWithDevBypass` middleware on the route group, matching
the pattern used by OAuth2, Agents, and MCP experiments.

## Changes

- **`coderd/coderd.go`**: Add `RequireExperimentWithDevBypass`
middleware to `/webpush` route group
- **`coderd/webpush.go`**: Remove inline
`api.Experiments.Enabled(codersdk.ExperimentWebPush)` checks from all
three handlers
- **`cli/server.go`**: Gate webpush dispatcher initialization with
`buildinfo.IsDev()` fallback so dev builds always init the real
dispatcher
- **`coderd/webpush_test.go`**: Remove experiment enablement from tests
(dev bypass handles it)

Net effect: -26 lines removed, +5 added.

Created using whatchamacallits (Opus 4.6 Max)
This commit is contained in:
Cian Johnston
2026-03-03 09:49:04 +00:00
committed by GitHub
parent e563766722
commit 517cb0ce73
4 changed files with 5 additions and 26 deletions
-15
View File
@@ -28,11 +28,6 @@ import (
func (api *API) postUserWebpushSubscription(rw http.ResponseWriter, r *http.Request) {
ctx := r.Context()
user := httpmw.UserParam(r)
if !api.Experiments.Enabled(codersdk.ExperimentWebPush) {
httpapi.ResourceNotFound(rw)
return
}
var req codersdk.WebpushSubscription
if !httpapi.Read(ctx, rw, r, &req) {
return
@@ -77,11 +72,6 @@ func (api *API) deleteUserWebpushSubscription(rw http.ResponseWriter, r *http.Re
ctx := r.Context()
user := httpmw.UserParam(r)
if !api.Experiments.Enabled(codersdk.ExperimentWebPush) {
httpapi.ResourceNotFound(rw)
return
}
var req codersdk.DeleteWebpushSubscription
if !httpapi.Read(ctx, rw, r, &req) {
return
@@ -137,11 +127,6 @@ func (api *API) postUserPushNotificationTest(rw http.ResponseWriter, r *http.Req
ctx := r.Context()
user := httpmw.UserParam(r)
if !api.Experiments.Enabled(codersdk.ExperimentWebPush) {
httpapi.ResourceNotFound(rw)
return
}
// We need to authorize the user to send a push notification to themselves.
if !api.Authorize(r, policy.ActionCreate, rbac.ResourceNotificationMessage.WithOwner(user.ID.String())) {
httpapi.Forbidden(rw)