#9 Encrypted-at-rest R2 storage for scrubbed reports
Implement the storage path: for each accepted report, scrub PII (#8), encrypt with AES-256-GCM (ADR #5), and write only ciphertext to R2, wired in as the real ingest Sink replacing NopSink. - internal/crypto: AES-256-GCM in the exact ADR #5 wire format (magic "LMB1" || version || key_id BE16 || nonce(12) || ct || tag(16); the 7-byte header is the GCM AAD). Provider-independent framing shared by a host crypto/aes+crypto/cipher impl (tests, devserver) and a Wasm SubtleCrypto impl (syscall/js, //go:build js && wasm) per the TinyGo constraint; both produce byte-identical frames. Versioned keyring with key_id rotation; ParseKeyring reads the Secrets Store JSON secret. - internal/storage: ObjectStore interface with an in-memory fake (tests, devserver) and a Wasm R2Store (syumai/workers R2 binding). Sink ties scrub -> Seal -> Put under a unique reports/<ts>-<rand> key. WorkerSink loads the keyring from Secrets Store (BUGREPORT_ENC_KEYRING), cached for the isolate lifetime. - handler.New now takes an injectable ingest.Sink; the Worker uses the real R2/Secrets-Store sink, the devserver a memory + throwaway-key sink. - wrangler.jsonc: add REPORTS_BUCKET (R2) and BUGREPORT_ENC_KEYRING (Secrets Store) bindings. Tests (host, no TinyGo): encrypt/decrypt roundtrip; ciphertext != plaintext; wrong key + tamper (ct/tag/nonce/header-AAD) fail; exact wire layout plus a known-answer vector; key_id rotation with retained keys; full sink path (PII scrubbed then encrypted, readback requires the key and yields the scrubbed content). Existing ingest/handler behavior preserved (202 on valid POST). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
committed by
Jason Ross
co-authored by
Claude Opus 4.8
parent
3d320a8cea
commit
bd7fe21d97
+20
-1
@@ -5,6 +5,11 @@
|
||||
// so `go run ./cmd/devserver` works with the standard Go toolchain and exercises
|
||||
// the exact same handler that the deployed Wasm Worker serves. It listens on
|
||||
// :8787 by default (matching wrangler dev's default port); override with ADDR.
|
||||
//
|
||||
// The ingest path is wired with the real scrub+encrypt storage Sink (#9) backed
|
||||
// by an in-memory object store and a throwaway per-run AES-256 key, so a POST
|
||||
// /v1/reports exercises the full pipeline locally. Stored objects live only for
|
||||
// the process lifetime.
|
||||
package main
|
||||
|
||||
import (
|
||||
@@ -12,7 +17,9 @@ import (
|
||||
"net/http"
|
||||
"os"
|
||||
|
||||
"github.com/JMR-dev/LibreMail-Bug-Report-Ingest/internal/crypto"
|
||||
"github.com/JMR-dev/LibreMail-Bug-Report-Ingest/internal/handler"
|
||||
"github.com/JMR-dev/LibreMail-Bug-Report-Ingest/internal/storage"
|
||||
)
|
||||
|
||||
func main() {
|
||||
@@ -21,8 +28,20 @@ func main() {
|
||||
addr = ":8787"
|
||||
}
|
||||
|
||||
// A throwaway keyring: a single random key generated at startup. Reports are
|
||||
// scrubbed, encrypted under it, and held in memory; nothing is persisted.
|
||||
key, err := crypto.GenerateKey()
|
||||
if err != nil {
|
||||
log.Fatalf("devserver: generate key: %v", err)
|
||||
}
|
||||
keyring, err := crypto.NewKeyring(1, map[uint16][]byte{1: key})
|
||||
if err != nil {
|
||||
log.Fatalf("devserver: build keyring: %v", err)
|
||||
}
|
||||
sink := storage.NewSink(storage.NewMemoryStore(), keyring)
|
||||
|
||||
log.Printf("devserver listening on %s (try GET / and GET /healthz)", addr)
|
||||
if err := http.ListenAndServe(addr, handler.New()); err != nil {
|
||||
if err := http.ListenAndServe(addr, handler.New(sink)); err != nil {
|
||||
log.Fatalf("devserver: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user