encrypted reports into labeled GitHub issues.
- GitHub REST client on net/http (host-testable via httptest; works under
TinyGo js/wasm per #26). Encodes ADR #6 §3.2: serial mutations spaced
>=1s, honour Retry-After, wait until x-ratelimit-reset, >=60s floor for
secondary-limit 403s, full-jitter exponential backoff (base 1s, cap 60s,
<=5 attempts). Ensures the three ADR #6 labels (create-or-ignore).
- Publisher: GetPending -> crypto.Open -> format -> CreateIssue per id,
with the ADR #6 per-run cap (50) and 65,536-char body cap (truncate).
Per-report failures are isolated and surfaced, never abort the batch.
- onPublished(ctx, id) seam, called only after a confirmed 201, default
no-op: #15 wires it to lifecycle.MarkPublished to complete cross-run
de-dup. #14 does not implement the mark-published transition.
- Issue body wraps report free-text in a length-adaptive code fence and
metadata in inline code, neutralising Markdown/@mention injection.
- Worker: swap schedule.LogPublisher for the real publisher in
scheduled_wasm.go; read GITHUB_TOKEN (Secrets Store) + GITHUB_REPO (var);
pre-gate so the sibling cron fire does no secret I/O. worker/main.go
untouched. Export storage.GetSecret for the token read.
- wrangler.jsonc: add GITHUB_TOKEN secret + GITHUB_REPO var (my keys only).
Tests (host, httptest mock, virtual clock): N reports -> N labeled issues
+ onPublished per success; >65,536-char body truncated; transient 5xx and
Retry-After retried per policy; persistent failure isolated (no
onPublished); permission 403 not retried; per-run cap; decrypt failure
isolated. go vet + go test ./... green; GOOS=js GOARCH=wasm build compiles.
Closes#14
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>