Problem/Motivation

Other Drupal modules can query the suppression policy but lack a documented notification contract for newly accepted events or effective suppression changes. CRM, membership and workflow integrations otherwise need to poll or depend on private tables.

Proposed resolution

Design an opt-in typed notification API with a transactional outbox or equivalent durable handoff. Keep authoritative intake and suppression updates synchronous; deliver integration work after commit through bounded workers.

Acceptance criteria

  • Define minimal versioned event DTOs, event identity, source context and which changes emit notifications; do not expose raw webhook bodies or credentials.
  • Ensure a duplicate webhook and a rolled-back transaction create no additional logical notifications.
  • Document at-least-once delivery and consumer idempotency; do not promise exactly-once external side effects.
  • Provide bounded retry/backoff, inspectable failed deliveries, controlled replay and retention; subscriber failure must not undo accepted suppression evidence.
  • Test crash boundaries between commit and dispatch, duplicate worker execution and replay.
  • Provide an example subscriber for a site workflow; optional ECA/Rules adapters can be separate follow-up work after the contract is established.

Scope and dependencies

Optional follow-up after stable release; not a blocker for #3621224: Complete the 1.0.0 stable release verification gates. Builds on #3621126: Add a shared suppression decision service with a stable extension API; the completed original issue remains fixed.

Comments

jmcerda created an issue. See original summary.

  • jmcerda committed 8b45b099 on 1.x
    Issue #3621232: Report lock contention when dispatch stops mid-batch
    
    If...

  • jmcerda committed e2e709f1 on 1.x
    Issue #3621232: Merge existing Settings when setting the webhook secret...

  • jmcerda committed 86541b1c on 1.x
    Issue #3621232: Load one outbox page and refresh the worker lock per row...

  • jmcerda committed f53f2922 on 1.x
    Issue #3621232: Drop no-op FOR UPDATE and hide the integration test...

  • jmcerda committed 4ce7035c on 1.x
    Issue #3621232: Do not construct integration events when the outbox is...

  • jmcerda committed 2fbf8581 on 1.x
    Issue #3621232: Reject incomplete outbox payloads without undefined-key...

  • jmcerda committed 11c1d4e2 on 1.x
    Issue #3621232: Clamp outbox backoff and preserve Drupal @placeholders...

  • jmcerda committed dc16195a on 1.x
    Issue #3621232: Roll back the enqueue savepoint on duplicate outbox rows...

  • jmcerda committed 33927e36 on 1.x
    Issue #3621232: Fail unreadable outbox payloads immediately and document...

  • jmcerda committed 91697aa8 on 1.x
    Issue #3621232: Add opt-in durable integration events after committed...
jmcerda’s picture

Status: Active » Fixed

Merged to 1.x. Opt-in transactional outbox delivers typed v1 events after unique webhooks and suppression changes commit. Intake stays synchronous. Delivery is at-least-once after commit; subscribers must be idempotent. Duplicate webhooks and rolled-back transactions create no extra notifications. Subscriber failure does not undo suppression. Drush inspect omits recipients. Disabled by default.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.