Files
LibreMail-Bug-Report-Ingest/api-tests/admin-list-excludes-removed.yml
JMR-devandClaude Opus 4.8 047391d01c #11 Manual review/removal path for maintainers
Add an authenticated admin API to the ingest Worker so the single maintainer
can review the pending queue and pull a report before Friday's publish run.

Endpoints (on the existing handler):
  GET    /v1/admin/reports              list pending report ids
  POST   /v1/admin/reports/{id}/remove  mark a report removed
  DELETE /v1/admin/reports/{id}         remove alias

Remove calls lifecycle.MarkRemoved (#10), transitioning pending -> removed so
#13's ListPending excludes it from the next publish. Codes: 200 list/remove,
404 unknown id, 401 missing/bad/unset-secret token, 405 wrong method.

Auth: shared-secret Bearer token compared with crypto/subtle.ConstantTimeCompare,
fail-closed when the secret is unset. Injected via handler.New's new AdminBackend
arg: the dev server and tests wire a memory-backed lifecycle.Manager + ADMIN_TOKEN
env; the Worker reads ADMIN_TOKEN from Secrets Store and builds an R2-backed
Manager per request. Choice documented in docs/decisions/admin-auth.md.

Tests: Go httptest unit tests (list, remove+exclusion, 404, 401 incl. fail-closed,
405) and a Bruno api-tests flow (seed, authed list/remove, exclusion, no/bad
token 401). wrangler.jsonc gains only the ADMIN_TOKEN secret binding; worker
triggers untouched (owned by #13).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 15:56:59 -05:00

25 lines
712 B
YAML

info:
name: "admin: removed report is excluded from the pending list"
# Re-list after the remove: the removed id must no longer appear, proving it is
# excluded from the next weekly publish run (the ticket's acceptance criterion).
type: http
seq: 9
http:
method: GET
url: "{{baseUrl}}/v1/admin/reports"
headers:
- name: Authorization
value: "Bearer {{adminToken}}"
runtime:
scripts:
- type: tests
code: |-
test("list returns 200", function () {
expect(res.getStatus()).to.equal(200);
});
test("the removed id is no longer pending", function () {
expect(res.getBody().reports).to.not.include(bru.getVar("removeId"));
});