Add an authenticated admin API to the ingest Worker so the single maintainer
can review the pending queue and pull a report before Friday's publish run.
Endpoints (on the existing handler):
GET /v1/admin/reports list pending report ids
POST /v1/admin/reports/{id}/remove mark a report removed
DELETE /v1/admin/reports/{id} remove alias
Remove calls lifecycle.MarkRemoved (#10), transitioning pending -> removed so
#13's ListPending excludes it from the next publish. Codes: 200 list/remove,
404 unknown id, 401 missing/bad/unset-secret token, 405 wrong method.
Auth: shared-secret Bearer token compared with crypto/subtle.ConstantTimeCompare,
fail-closed when the secret is unset. Injected via handler.New's new AdminBackend
arg: the dev server and tests wire a memory-backed lifecycle.Manager + ADMIN_TOKEN
env; the Worker reads ADMIN_TOKEN from Secrets Store and builds an R2-backed
Manager per request. Choice documented in docs/decisions/admin-auth.md.
Tests: Go httptest unit tests (list, remove+exclusion, 404, 401 incl. fail-closed,
405) and a Bruno api-tests flow (seed, authed list/remove, exclusion, no/bad
token 401). wrangler.jsonc gains only the ADMIN_TOKEN secret binding; worker
triggers untouched (owned by #13).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
67 lines
2.3 KiB
Go
67 lines
2.3 KiB
Go
//go:build js && wasm
|
|
|
|
package main
|
|
|
|
// workerAdminBackend is the production handler.AdminBackend for the maintainer
|
|
// admin API (#11) in the Cloudflare Worker.
|
|
//
|
|
// The admin secret and the R2 bucket binding are only available inside a request
|
|
// on the Workers runtime (the Secrets Store get() is async and per-request; the
|
|
// R2 binding resolves from the request context), so — unlike the dev server,
|
|
// which injects a ready Manager + token at startup — this backend resolves both
|
|
// lazily on each call. The token is read from Secrets Store (AdminTokenBinding)
|
|
// and the lifecycle Manager is built over a fresh R2-backed store per operation.
|
|
// This mirrors how WorkerSink loads its keyring lazily.
|
|
//
|
|
// Compiled only into the js/wasm Worker; excluded from host builds and tests.
|
|
|
|
import (
|
|
"context"
|
|
|
|
"github.com/JMR-dev/LibreMail-Bug-Report-Ingest/internal/lifecycle"
|
|
"github.com/JMR-dev/LibreMail-Bug-Report-Ingest/internal/storage"
|
|
)
|
|
|
|
type workerAdminBackend struct{}
|
|
|
|
// AdminToken reads the shared admin secret from Cloudflare Secrets Store. A load
|
|
// failure (unbound/empty binding) returns an error, which the handler surfaces as
|
|
// 503; the handler independently fails closed (401) on an empty secret value.
|
|
func (workerAdminBackend) AdminToken(context.Context) (string, error) {
|
|
tok, err := storage.ReadSecret(storage.AdminTokenBinding)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
return string(tok), nil
|
|
}
|
|
|
|
// ListPending builds an R2-backed lifecycle Manager for this request and returns
|
|
// the pending report ids.
|
|
func (workerAdminBackend) ListPending(ctx context.Context) ([]string, error) {
|
|
mgr, err := managerForRequest()
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return mgr.ListPending(ctx)
|
|
}
|
|
|
|
// MarkRemoved builds an R2-backed lifecycle Manager for this request and
|
|
// transitions the report pending -> removed.
|
|
func (workerAdminBackend) MarkRemoved(ctx context.Context, id string) error {
|
|
mgr, err := managerForRequest()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
return mgr.MarkRemoved(ctx, id)
|
|
}
|
|
|
|
// managerForRequest resolves the R2 bucket binding (available within a request)
|
|
// and wraps it in a lifecycle Manager.
|
|
func managerForRequest() (*lifecycle.Manager, error) {
|
|
store, err := storage.NewR2Store(storage.BucketBinding)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return lifecycle.New(store), nil
|
|
}
|