Add an authenticated admin API to the ingest Worker so the single maintainer
can review the pending queue and pull a report before Friday's publish run.
Endpoints (on the existing handler):
GET /v1/admin/reports list pending report ids
POST /v1/admin/reports/{id}/remove mark a report removed
DELETE /v1/admin/reports/{id} remove alias
Remove calls lifecycle.MarkRemoved (#10), transitioning pending -> removed so
#13's ListPending excludes it from the next publish. Codes: 200 list/remove,
404 unknown id, 401 missing/bad/unset-secret token, 405 wrong method.
Auth: shared-secret Bearer token compared with crypto/subtle.ConstantTimeCompare,
fail-closed when the secret is unset. Injected via handler.New's new AdminBackend
arg: the dev server and tests wire a memory-backed lifecycle.Manager + ADMIN_TOKEN
env; the Worker reads ADMIN_TOKEN from Secrets Store and builds an R2-backed
Manager per request. Choice documented in docs/decisions/admin-auth.md.
Tests: Go httptest unit tests (list, remove+exclusion, 404, 401 incl. fail-closed,
405) and a Bruno api-tests flow (seed, authed list/remove, exclusion, no/bad
token 401). wrangler.jsonc gains only the ADMIN_TOKEN secret binding; worker
triggers untouched (owned by #13).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
31 lines
1016 B
YAML
31 lines
1016 B
YAML
info:
|
|
name: "admin: authenticated list of pending reports"
|
|
# GET /v1/admin/reports with a valid Bearer token returns the pending ids.
|
|
# Captures the first id into the `removeId` run variable for the remove test.
|
|
type: http
|
|
seq: 7
|
|
|
|
http:
|
|
method: GET
|
|
url: "{{baseUrl}}/v1/admin/reports"
|
|
headers:
|
|
- name: Authorization
|
|
value: "Bearer {{adminToken}}"
|
|
|
|
runtime:
|
|
scripts:
|
|
- type: tests
|
|
code: |-
|
|
test("authenticated list returns 200", function () {
|
|
expect(res.getStatus()).to.equal(200);
|
|
});
|
|
test("body has status ok and a reports array", function () {
|
|
expect(res.getBody().status).to.equal("ok");
|
|
expect(res.getBody().reports).to.be.an("array");
|
|
});
|
|
test("at least one pending report is listed (the seed)", function () {
|
|
expect(res.getBody().reports.length).to.be.at.least(1);
|
|
});
|
|
// Remember an id to remove in the next request.
|
|
bru.setVar("removeId", res.getBody().reports[0]);
|