Issue #3621122: Validate webhook payloads and imported settings

Malformed authenticated payloads can currently create blank rows or throw field-type errors. This change validates one JSON object, bounds body reads to 1 MiB, validates extracted strings and provider IDs, and rejects conflicting recipients before identity or persistence. Unknown metadata remains compatible. Configuration schema limits match the form and an import validator enforces them.

Depends on !1 (closed); the branch contains its event-identity foundation. Review the validation commit 3567cca separately until !1 (closed) merges.

Validation on PostgreSQL: Drupal 10.3/PHP 8.3 and Drupal 11/PHP 8.4 each passed the 28-test suite (114 assertions), followed by the added config-import subscriber test (1 assertion) on each version. Drupal/DrupalPractice PHPCS and git diff --check pass. Manual findings review checked bounded reads, validation before writes, Unicode, large IDs, secret-free error responses and import dispatch. No unresolved findings within this slice. GitLab automated review and pipelines are not configured.

Merge request reports

Loading
Loading