Exactly-once delivery is covering processing in this scenario. Because of that it is not covered in tests and schemas.
REST endpoint was just added to create entire use case. But you are right, if in this part of the system something will go wrong you will have duplicate message. But it’s rather at least once publish rather at least once delivery. Message will be delivered once, but published twice :)