9장. Route Handler와 외부 인터페이스
OAuth callback, webhook, health처럼 HTTP 계약이 필요한 경로는 Route Handler로 둔다. method, status, content type, authentication, rate limit, timeout, idempotency, error shape를 문서화한다.
Webhook은 signature, timestamp, replay window를 검증하고 원문 body 필요 여부를 확인한다. 성공 응답 뒤 비동기 처리한다고 해서 이벤트를 잃지 않도록 durable queue/outbox를 쓴다.