#7 Ingest HTTPS endpoint: accept report POST, size limit
Add internal/ingest implementing POST /v1/reports, wired into the core build-tag-free handler so the same route serves on the dev server and the Cloudflare Worker. Response contract (ADR #6 §2.4): - 202 Accepted for valid JSON within the 256 KiB cap ({"status":"accepted"}) - 413 for oversized bodies (Content-Length fast path AND a MaxBytesReader hard cap, so a missing/lying Content-Length cannot bypass the limit) - 415 when Content-Type is not application/json - 400 for malformed JSON or failed schema validation (generic error body, never echoes request content) - 405 with Allow: POST for any non-POST method - 503 when the storage Sink fails Storage is decoupled behind a small Sink interface (Store(ctx, raw)) with a NopSink default and a MemorySink for tests, so PII scrubbing (#8) and encrypted R2 storage (#9) can slot in without touching the HTTP contract. Rate limiting (429) and volumetric shedding stay a Cloudflare-edge/Pulumi concern per #2 and are intentionally not implemented in the Worker. Tests: - Go unit tests (net/http/httptest) for every response code, including 413 via both Content-Length and an oversized streamed body, plus boundary, storage-failure, and no-content-echo cases. - Bruno API tests in OpenCollection YAML format under api-tests/, asserting the full contract against the local dev server via @usebruno/cli. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,5 @@
|
||||
name: local
|
||||
|
||||
variables:
|
||||
- name: baseUrl
|
||||
value: http://localhost:8787
|
||||
@@ -0,0 +1,27 @@
|
||||
info:
|
||||
name: 400 - malformed JSON is rejected
|
||||
type: http
|
||||
seq: 4
|
||||
|
||||
http:
|
||||
method: POST
|
||||
url: "{{baseUrl}}/v1/reports"
|
||||
headers:
|
||||
- name: Content-Type
|
||||
value: application/json
|
||||
# Sent as a raw text body (so the bytes are transmitted verbatim) but declared
|
||||
# as application/json, so the endpoint tries to parse it and fails -> 400.
|
||||
body:
|
||||
type: text
|
||||
data: '{"appVersion": "1.0.0", "platform": "android", "report":'
|
||||
|
||||
runtime:
|
||||
scripts:
|
||||
- type: tests
|
||||
code: |-
|
||||
test("malformed JSON returns 400", function () {
|
||||
expect(res.getStatus()).to.equal(400);
|
||||
});
|
||||
test("400 body carries a generic error string", function () {
|
||||
expect(res.getBody().error).to.be.a("string");
|
||||
});
|
||||
@@ -0,0 +1,11 @@
|
||||
opencollection: "1.0.0"
|
||||
|
||||
info:
|
||||
name: LibreMail Bug-Report Ingest API tests
|
||||
# Contract tests for POST /v1/reports (GitHub issue #7).
|
||||
# Run against the local dev server (cmd/devserver) on http://localhost:8787,
|
||||
# which serves the exact same http.Handler as the deployed Cloudflare Worker.
|
||||
#
|
||||
# This collection is authored in the OpenCollection YAML format (the presence
|
||||
# of this opencollection.yml file selects the "yml" format in @usebruno/cli),
|
||||
# per the maintainer's requirement to avoid the .bru format.
|
||||
@@ -0,0 +1,33 @@
|
||||
info:
|
||||
name: 413 - oversized report is rejected
|
||||
type: http
|
||||
seq: 2
|
||||
|
||||
http:
|
||||
method: POST
|
||||
url: "{{baseUrl}}/v1/reports"
|
||||
headers:
|
||||
- name: Content-Type
|
||||
value: application/json
|
||||
body:
|
||||
type: json
|
||||
data: "{{oversizedReport}}"
|
||||
|
||||
runtime:
|
||||
scripts:
|
||||
# Build a payload larger than the 256 KiB cap at run time so this file stays
|
||||
# small. The before-request script runs before body interpolation, so the
|
||||
# {{oversizedReport}} placeholder above is replaced with this ~300 KiB body.
|
||||
- type: before-request
|
||||
code: |-
|
||||
const filler = "x".repeat(300 * 1024); // 300 KiB, over the 256 KiB cap
|
||||
bru.setVar("oversizedReport", JSON.stringify({
|
||||
appVersion: "1.0.0",
|
||||
platform: "android",
|
||||
report: filler
|
||||
}));
|
||||
- type: tests
|
||||
code: |-
|
||||
test("body larger than 256 KiB returns 413", function () {
|
||||
expect(res.getStatus()).to.equal(413);
|
||||
});
|
||||
@@ -0,0 +1,33 @@
|
||||
info:
|
||||
name: 202 - valid report is accepted
|
||||
type: http
|
||||
seq: 1
|
||||
|
||||
http:
|
||||
method: POST
|
||||
url: "{{baseUrl}}/v1/reports"
|
||||
headers:
|
||||
- name: Content-Type
|
||||
value: application/json
|
||||
body:
|
||||
type: json
|
||||
data: |-
|
||||
{
|
||||
"appVersion": "1.4.2 (142)",
|
||||
"platform": "android",
|
||||
"osVersion": "Android 14",
|
||||
"device": "Pixel 7",
|
||||
"clientTimestamp": "2026-07-02T12:34:56Z",
|
||||
"report": "NullPointerException in SyncService\n at line 42\n<attached logs>"
|
||||
}
|
||||
|
||||
runtime:
|
||||
scripts:
|
||||
- type: tests
|
||||
code: |-
|
||||
test("valid JSON report within the size limit returns 202", function () {
|
||||
expect(res.getStatus()).to.equal(202);
|
||||
});
|
||||
test("202 body reports accepted status", function () {
|
||||
expect(res.getBody().status).to.equal("accepted");
|
||||
});
|
||||
@@ -0,0 +1,27 @@
|
||||
info:
|
||||
name: 415 - non-JSON content type is rejected
|
||||
type: http
|
||||
seq: 3
|
||||
|
||||
http:
|
||||
method: POST
|
||||
url: "{{baseUrl}}/v1/reports"
|
||||
headers:
|
||||
- name: Content-Type
|
||||
value: text/plain
|
||||
body:
|
||||
type: text
|
||||
data: |-
|
||||
{
|
||||
"appVersion": "1.0.0",
|
||||
"platform": "android",
|
||||
"report": "body is valid JSON but the Content-Type is not application/json"
|
||||
}
|
||||
|
||||
runtime:
|
||||
scripts:
|
||||
- type: tests
|
||||
code: |-
|
||||
test("Content-Type other than application/json returns 415", function () {
|
||||
expect(res.getStatus()).to.equal(415);
|
||||
});
|
||||
@@ -0,0 +1,19 @@
|
||||
info:
|
||||
name: 405 - non-POST method is rejected
|
||||
type: http
|
||||
seq: 5
|
||||
|
||||
http:
|
||||
method: GET
|
||||
url: "{{baseUrl}}/v1/reports"
|
||||
|
||||
runtime:
|
||||
scripts:
|
||||
- type: tests
|
||||
code: |-
|
||||
test("a non-POST method returns 405", function () {
|
||||
expect(res.getStatus()).to.equal(405);
|
||||
});
|
||||
test("405 advertises the allowed method via the Allow header", function () {
|
||||
expect(res.getHeader("allow")).to.equal("POST");
|
||||
});
|
||||
Reference in New Issue
Block a user