Add an authenticated admin API to the ingest Worker so the single maintainer
can review the pending queue and pull a report before Friday's publish run.
Endpoints (on the existing handler):
GET /v1/admin/reports list pending report ids
POST /v1/admin/reports/{id}/remove mark a report removed
DELETE /v1/admin/reports/{id} remove alias
Remove calls lifecycle.MarkRemoved (#10), transitioning pending -> removed so
#13's ListPending excludes it from the next publish. Codes: 200 list/remove,
404 unknown id, 401 missing/bad/unset-secret token, 405 wrong method.
Auth: shared-secret Bearer token compared with crypto/subtle.ConstantTimeCompare,
fail-closed when the secret is unset. Injected via handler.New's new AdminBackend
arg: the dev server and tests wire a memory-backed lifecycle.Manager + ADMIN_TOKEN
env; the Worker reads ADMIN_TOKEN from Secrets Store and builds an R2-backed
Manager per request. Choice documented in docs/decisions/admin-auth.md.
Tests: Go httptest unit tests (list, remove+exclusion, 404, 401 incl. fail-closed,
405) and a Bruno api-tests flow (seed, authed list/remove, exclusion, no/bad
token 401). wrangler.jsonc gains only the ADMIN_TOKEN secret binding; worker
triggers untouched (owned by #13).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
30 lines
1.2 KiB
Go
30 lines
1.2 KiB
Go
//go:build js && wasm
|
|
|
|
// Command worker is the Cloudflare Workers (Wasm) entrypoint.
|
|
//
|
|
// It is compiled only for the js/wasm target by TinyGo (see the "Build & run
|
|
// locally" section of the README). The build constraint above keeps this file
|
|
// out of host builds and `go test ./...`, so the standard Go toolchain never
|
|
// needs the Workers runtime. It wires the shared core handler into the
|
|
// syumai/workers adapter, which bridges Go's net/http model to the Workers
|
|
// fetch event.
|
|
package main
|
|
|
|
import (
|
|
"github.com/syumai/workers"
|
|
|
|
"github.com/JMR-dev/LibreMail-Bug-Report-Ingest/internal/handler"
|
|
"github.com/JMR-dev/LibreMail-Bug-Report-Ingest/internal/storage"
|
|
)
|
|
|
|
func main() {
|
|
// The real storage Sink (#9): scrub -> AES-256-GCM encrypt -> R2 put, with the
|
|
// keyring loaded from Cloudflare Secrets Store on first request. Bindings
|
|
// (REPORTS_BUCKET, BUGREPORT_ENC_KEYRING) are declared in wrangler.jsonc.
|
|
//
|
|
// The maintainer admin API (#11) is wired with workerAdminBackend, which reads
|
|
// the admin shared secret (ADMIN_TOKEN) from Secrets Store and drives the
|
|
// lifecycle Manager over R2 per request (see admin.go).
|
|
workers.Serve(handler.New(storage.NewWorkerSink(), workerAdminBackend{}))
|
|
}
|