Add internal/ingest implementing POST /v1/reports, wired into the core build-tag-free handler so the same route serves on the dev server and the Cloudflare Worker. Response contract (ADR #6 §2.4): - 202 Accepted for valid JSON within the 256 KiB cap ({"status":"accepted"}) - 413 for oversized bodies (Content-Length fast path AND a MaxBytesReader hard cap, so a missing/lying Content-Length cannot bypass the limit) - 415 when Content-Type is not application/json - 400 for malformed JSON or failed schema validation (generic error body, never echoes request content) - 405 with Allow: POST for any non-POST method - 503 when the storage Sink fails Storage is decoupled behind a small Sink interface (Store(ctx, raw)) with a NopSink default and a MemorySink for tests, so PII scrubbing (#8) and encrypted R2 storage (#9) can slot in without touching the HTTP contract. Rate limiting (429) and volumetric shedding stay a Cloudflare-edge/Pulumi concern per #2 and are intentionally not implemented in the Worker. Tests: - Go unit tests (net/http/httptest) for every response code, including 413 via both Content-Length and an oversized streamed body, plus boundary, storage-failure, and no-content-echo cases. - Bruno API tests in OpenCollection YAML format under api-tests/, asserting the full contract against the local dev server via @usebruno/cli. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
28 lines
750 B
YAML
28 lines
750 B
YAML
info:
|
|
name: 400 - malformed JSON is rejected
|
|
type: http
|
|
seq: 4
|
|
|
|
http:
|
|
method: POST
|
|
url: "{{baseUrl}}/v1/reports"
|
|
headers:
|
|
- name: Content-Type
|
|
value: application/json
|
|
# Sent as a raw text body (so the bytes are transmitted verbatim) but declared
|
|
# as application/json, so the endpoint tries to parse it and fails -> 400.
|
|
body:
|
|
type: text
|
|
data: '{"appVersion": "1.0.0", "platform": "android", "report":'
|
|
|
|
runtime:
|
|
scripts:
|
|
- type: tests
|
|
code: |-
|
|
test("malformed JSON returns 400", function () {
|
|
expect(res.getStatus()).to.equal(400);
|
|
});
|
|
test("400 body carries a generic error string", function () {
|
|
expect(res.getBody().error).to.be.a("string");
|
|
});
|