Where a newsletter's events go, and how a creator changes it. Commune hands every event it publishes to a delivery service that owns fan out, retries, signing and the delivery log, and a destination is one place that service sends them: an HTTPS endpoint, or a queue, stream or object store for a consumer that would rather not run a web server.
Reading the list is an operation here, and so is reading the delivery attempt log: what was handed to which destination, what came back, and asking for one to be handed over again.
Changing the destinations themselves is not. portal-session mints a link
into the delivery service's own portal, where a creator adds an endpoint,
disables one and rotates a signing secret. Asking for an attempt to be
replayed is the one write here, and is the same action as the portal's
retry button.
Needs webhooks throughout, since a destination is a private endpoint of
the creator's, the list of them says which systems a newsletter is wired
into, and the attempt log says what those systems were told and when.