# 2. Webhooks & Event Notifications — Test Cases

User Type: **Training Institute**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: webhooks_event_notifications.md — every feature, sub-feature, and rule covered

## Test Execution Policy

- Zero tolerance: any deviation from the documented behavior is a defect.
- Every failed test is logged with a Bug ID, the feature, the sub-feature, the expected vs actual result, and the severity; 100% of bugs are fixed before the group passes.
- 100% pass rate is required for the group to be marked complete.

## Coverage Matrix

| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 2.1 | Webhook configuration | TC-TI-7-02-001 |
| 2.1 | Register an endpoint URL | TC-TI-7-02-002 |
| 2.1 | Select event types to receive | TC-TI-7-02-003 |
| 2.1 | Signed HTTP POSTs sent on events | TC-TI-7-02-004 |
| 2.1 | Configured webhooks list | TC-TI-7-02-005 |
| 2.1 | Webhook status shown | TC-TI-7-02-006 |
| 2.1 | Configuration available on web and mobile | TC-TI-7-02-007 |
| 2.1 | Configuration event logging (created, updated) | TC-TI-7-02-008 |
| 2.1 | Audit logging of the webhook configuration | TC-TI-7-02-009 |
| 2.1 | Rule: The webhook payload is signed for verification. | TC-TI-7-02-001 |
| 2.1 | Rule: An unreachable endpoint is marked as failing. | TC-TI-7-02-002 |
| 2.1 | Rule: Configuration events (created, updated) are logged with the account and the timestamp. | TC-TI-7-02-003 |
| 2.1 | Rule: The webhook configuration is audit-logged with the account and the timestamp. | TC-TI-7-02-004 |
| 2.2 | Webhook delivery log | TC-TI-7-02-010 |
| 2.2 | Success or failure per delivery | TC-TI-7-02-011 |
| 2.2 | Automatic retries for failures | TC-TI-7-02-012 |
| 2.2 | Retry schedule shown | TC-TI-7-02-013 |
| 2.2 | Manual resend of a failed delivery | TC-TI-7-02-014 |
| 2.2 | Delivery payload viewable | TC-TI-7-02-015 |
| 2.2 | Delivery available on web and mobile | TC-TI-7-02-016 |
| 2.2 | Delivery event logging (delivered, retried) | TC-TI-7-02-017 |
| 2.2 | Audit logging of the webhook delivery and retries | TC-TI-7-02-018 |
| 2.2 | Rule: The retries follow an exponential backoff. | TC-TI-7-02-010 |
| 2.2 | Rule: A delivery that exhausts retries is marked as dead. | TC-TI-7-02-011 |
| 2.2 | Rule: Delivery events (delivered, retried) are logged with the account and the timestamp. | TC-TI-7-02-012 |
| 2.2 | Rule: The webhook delivery and retries is audit-logged with the account and the timestamp. | TC-TI-7-02-013 |
| 2.3 | Webhook security settings | TC-TI-7-02-019 |
| 2.3 | Signing secret for verification | TC-TI-7-02-020 |
| 2.3 | IP allowlist for the sender | TC-TI-7-02-021 |
| 2.3 | Rotate the signing secret | TC-TI-7-02-022 |
| 2.3 | Secret shown only once | TC-TI-7-02-023 |
| 2.3 | Security available on web and mobile | TC-TI-7-02-024 |
| 2.3 | Security event logging (secret rotated) | TC-TI-7-02-025 |
| 2.3 | Audit logging of the webhook security | TC-TI-7-02-026 |
| 2.3 | Rule: The secret is shown only once at creation or rotation. | TC-TI-7-02-019 |
| 2.3 | Rule: A rotation invalidates the previous secret. | TC-TI-7-02-020 |
| 2.3 | Rule: Security events (secret rotated) are logged with the account and the timestamp. | TC-TI-7-02-021 |
| 2.3 | Rule: The webhook security is audit-logged with the account and the timestamp. | TC-TI-7-02-022 |

## 2.1 Webhook Configuration

### TC-TI-7-02-001 — Webhook configuration
**Type:** Positive
**Covers:** 2.1 → Webhook configuration; Rule: The webhook payload is signed for verification.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Webhook configuration.
2. Observe the result and verify the full behavior: Webhook configuration.
**Expected Result:** Webhook configuration — delivered exactly as documented.
**Priority:** Critical

### TC-TI-7-02-002 — Register an endpoint URL
**Type:** Positive
**Covers:** 2.1 → Register an endpoint URL; Rule: An unreachable endpoint is marked as failing.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Register an endpoint URL.
2. Observe the result and verify the full behavior: Register an endpoint URL.
**Expected Result:** Register an endpoint URL — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-003 — Select event types to receive
**Type:** Positive
**Covers:** 2.1 → Select event types to receive; Rule: Configuration events (created, updated) are logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Select event types to receive.
2. Observe the result and verify the full behavior: Select event types to receive.
**Expected Result:** Select event types to receive — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-004 — Signed HTTP POSTs sent on events
**Type:** Positive
**Covers:** 2.1 → Signed HTTP POSTs sent on events; Rule: The webhook configuration is audit-logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Signed HTTP POSTs sent on events.
2. Observe the result and verify the full behavior: Signed HTTP POSTs sent on events.
**Expected Result:** Signed HTTP POSTs sent on events — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-005 — Configured webhooks list
**Type:** Positive
**Covers:** 2.1 → Configured webhooks list
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Configured webhooks list.
2. Observe the result and verify the full behavior: Configured webhooks list.
**Expected Result:** Configured webhooks list — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-006 — Webhook status shown
**Type:** Positive
**Covers:** 2.1 → Webhook status shown
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Webhook status shown.
2. Observe the result and verify the full behavior: Webhook status shown.
**Expected Result:** Webhook status shown — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-007 — Configuration available on web and mobile
**Type:** Positive
**Covers:** 2.1 → Configuration available on web and mobile
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Configuration available on web and mobile.
2. Observe the result and verify the full behavior: Configuration available on web and mobile.
**Expected Result:** Configuration available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-008 — Configuration event logging (created, updated)
**Type:** Positive
**Covers:** 2.1 → Configuration event logging (created, updated)
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Configuration event logging (created, updated).
2. Observe the result and verify the full behavior: Configuration event logging (created, updated).
**Expected Result:** Configuration event logging (created, updated) — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-009 — Audit logging of the webhook configuration
**Type:** Positive
**Covers:** 2.1 → Audit logging of the webhook configuration
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, perform the webhook configuration action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The webhook configuration action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical


## 2.2 Webhook Delivery & Retries

### TC-TI-7-02-010 — Webhook delivery log
**Type:** Positive
**Covers:** 2.2 → Webhook delivery log; Rule: The retries follow an exponential backoff.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Webhook delivery log.
2. Observe the result and verify the full behavior: Webhook delivery log.
**Expected Result:** Webhook delivery log — delivered exactly as documented.
**Priority:** Critical

### TC-TI-7-02-011 — Success or failure per delivery
**Type:** Positive
**Covers:** 2.2 → Success or failure per delivery; Rule: A delivery that exhausts retries is marked as dead.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Success or failure per delivery.
2. Observe the result and verify the full behavior: Success or failure per delivery.
**Expected Result:** Success or failure per delivery — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-012 — Automatic retries for failures
**Type:** Positive
**Covers:** 2.2 → Automatic retries for failures; Rule: Delivery events (delivered, retried) are logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Automatic retries for failures.
2. Observe the result and verify the full behavior: Automatic retries for failures.
**Expected Result:** Automatic retries for failures — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-013 — Retry schedule shown
**Type:** Positive
**Covers:** 2.2 → Retry schedule shown; Rule: The webhook delivery and retries is audit-logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Retry schedule shown.
2. Observe the result and verify the full behavior: Retry schedule shown.
**Expected Result:** Retry schedule shown — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-014 — Manual resend of a failed delivery
**Type:** Positive
**Covers:** 2.2 → Manual resend of a failed delivery
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Manual resend of a failed delivery.
2. Observe the result and verify the full behavior: Manual resend of a failed delivery.
**Expected Result:** Manual resend of a failed delivery — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-015 — Delivery payload viewable
**Type:** Positive
**Covers:** 2.2 → Delivery payload viewable
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Delivery payload viewable.
2. Observe the result and verify the full behavior: Delivery payload viewable.
**Expected Result:** Delivery payload viewable — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-016 — Delivery available on web and mobile
**Type:** Positive
**Covers:** 2.2 → Delivery available on web and mobile
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Delivery available on web and mobile.
2. Observe the result and verify the full behavior: Delivery available on web and mobile.
**Expected Result:** Delivery available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-017 — Delivery event logging (delivered, retried)
**Type:** Positive
**Covers:** 2.2 → Delivery event logging (delivered, retried)
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Delivery event logging (delivered, retried).
2. Observe the result and verify the full behavior: Delivery event logging (delivered, retried).
**Expected Result:** Delivery event logging (delivered, retried) — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-018 — Audit logging of the webhook delivery and retries
**Type:** Positive
**Covers:** 2.2 → Audit logging of the webhook delivery and retries
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, perform the webhook delivery and retries action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The webhook delivery and retries action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical


## 2.3 Webhook Security

### TC-TI-7-02-019 — Webhook security settings
**Type:** Positive
**Covers:** 2.3 → Webhook security settings; Rule: The secret is shown only once at creation or rotation.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Webhook security settings.
2. Observe the result and verify the full behavior: Webhook security settings.
**Expected Result:** Webhook security settings — delivered exactly as documented.
**Priority:** Critical

### TC-TI-7-02-020 — Signing secret for verification
**Type:** Positive
**Covers:** 2.3 → Signing secret for verification; Rule: A rotation invalidates the previous secret.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Signing secret for verification.
2. Observe the result and verify the full behavior: Signing secret for verification.
**Expected Result:** Signing secret for verification — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-021 — IP allowlist for the sender
**Type:** Positive
**Covers:** 2.3 → IP allowlist for the sender; Rule: Security events (secret rotated) are logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: IP allowlist for the sender.
2. Observe the result and verify the full behavior: IP allowlist for the sender.
**Expected Result:** IP allowlist for the sender — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-022 — Rotate the signing secret
**Type:** Positive
**Covers:** 2.3 → Rotate the signing secret; Rule: The webhook security is audit-logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Rotate the signing secret.
2. Observe the result and verify the full behavior: Rotate the signing secret.
**Expected Result:** Rotate the signing secret — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-023 — Secret shown only once
**Type:** Positive
**Covers:** 2.3 → Secret shown only once
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Secret shown only once.
2. Observe the result and verify the full behavior: Secret shown only once.
**Expected Result:** Secret shown only once — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-024 — Security available on web and mobile
**Type:** Positive
**Covers:** 2.3 → Security available on web and mobile
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Security available on web and mobile.
2. Observe the result and verify the full behavior: Security available on web and mobile.
**Expected Result:** Security available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-025 — Security event logging (secret rotated)
**Type:** Positive
**Covers:** 2.3 → Security event logging (secret rotated)
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Security event logging (secret rotated).
2. Observe the result and verify the full behavior: Security event logging (secret rotated).
**Expected Result:** Security event logging (secret rotated) — delivered exactly as documented.
**Priority:** High

### TC-TI-7-02-026 — Audit logging of the webhook security
**Type:** Positive
**Covers:** 2.3 → Audit logging of the webhook security
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, perform the webhook security action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The webhook security action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical
