Add an authenticated admin API to the ingest Worker so the single maintainer
can review the pending queue and pull a report before Friday's publish run.
Endpoints (on the existing handler):
GET /v1/admin/reports list pending report ids
POST /v1/admin/reports/{id}/remove mark a report removed
DELETE /v1/admin/reports/{id} remove alias
Remove calls lifecycle.MarkRemoved (#10), transitioning pending -> removed so
#13's ListPending excludes it from the next publish. Codes: 200 list/remove,
404 unknown id, 401 missing/bad/unset-secret token, 405 wrong method.
Auth: shared-secret Bearer token compared with crypto/subtle.ConstantTimeCompare,
fail-closed when the secret is unset. Injected via handler.New's new AdminBackend
arg: the dev server and tests wire a memory-backed lifecycle.Manager + ADMIN_TOKEN
env; the Worker reads ADMIN_TOKEN from Secrets Store and builds an R2-backed
Manager per request. Choice documented in docs/decisions/admin-auth.md.
Tests: Go httptest unit tests (list, remove+exclusion, 404, 401 incl. fail-closed,
405) and a Bruno api-tests flow (seed, authed list/remove, exclusion, no/bad
token 401). wrangler.jsonc gains only the ADMIN_TOKEN secret binding; worker
triggers untouched (owned by #13).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
106 lines
4.1 KiB
Go
106 lines
4.1 KiB
Go
// Package handler holds the core, transport-agnostic HTTP handlers for the
|
|
// LibreMail bug-report ingest Worker.
|
|
//
|
|
// It intentionally carries no build constraints, so it compiles and is
|
|
// unit-tested with the standard Go toolchain on the host, and is reused
|
|
// verbatim by both the local dev server (cmd/devserver) and the Cloudflare
|
|
// Worker Wasm entrypoint (worker). Keeping the request logic here means the same
|
|
// http.Handler runs unchanged on the dev server and in the deployed Worker.
|
|
package handler
|
|
|
|
import (
|
|
"encoding/json"
|
|
"net/http"
|
|
|
|
"github.com/JMR-dev/LibreMail-Bug-Report-Ingest/internal/ingest"
|
|
)
|
|
|
|
// serviceName identifies this service in responses.
|
|
const serviceName = "libremail-bug-report-ingest"
|
|
|
|
// New returns an http.Handler serving the ingest Worker's endpoints:
|
|
//
|
|
// GET / -> 200, JSON service/status/message
|
|
// GET /healthz -> 200, JSON {"status":"ok"}
|
|
// POST /v1/reports -> 202 on accept; 400/413/415/405/503 per the ingest contract
|
|
// GET /v1/admin/reports -> 200 list of pending report ids (authenticated, #11)
|
|
// POST /v1/admin/reports/{id}/remove -> 200 remove a pending report (authenticated, #11)
|
|
// DELETE /v1/admin/reports/{id} -> 200 remove a pending report (authenticated alias, #11)
|
|
//
|
|
// Any other path returns 404. On the health/hello endpoints any non-GET method
|
|
// returns 405; on /v1/reports any non-POST method returns 405 (Allow: POST); on
|
|
// the admin routes a wrong method returns 405 (Allow header from the mux).
|
|
//
|
|
// sink is the storage backend for accepted reports (scrub + encrypt + R2, #9).
|
|
// It is injected so the deployed Worker supplies the real R2/Secrets-Store sink
|
|
// while cmd/devserver and tests supply an in-memory one. A nil sink defaults to
|
|
// ingest.NopSink, which enforces the full HTTP contract but discards bodies.
|
|
//
|
|
// admin is the maintainer admin API backend (#11): the lifecycle Manager plus the
|
|
// shared-secret token, injected the same way. A nil admin registers the admin
|
|
// routes but fails every request closed with 401, so the endpoints' shape is
|
|
// always present and can never be silently left unauthenticated.
|
|
func New(sink ingest.Sink, admin AdminBackend) http.Handler {
|
|
if admin == nil {
|
|
admin = denyAllBackend{}
|
|
}
|
|
mux := http.NewServeMux()
|
|
mux.HandleFunc("/healthz", healthz)
|
|
mux.Handle("/v1/reports", ingest.NewHandler(sink))
|
|
(&adminAPI{backend: admin}).register(mux)
|
|
mux.HandleFunc("/", root)
|
|
return mux
|
|
}
|
|
|
|
// root handles the service root. Because "/" is the catch-all pattern in the
|
|
// mux, it also rejects unknown paths with 404.
|
|
func root(w http.ResponseWriter, r *http.Request) {
|
|
if r.URL.Path != "/" {
|
|
writeJSON(w, http.StatusNotFound, response{Status: "error", Error: "not found"})
|
|
return
|
|
}
|
|
if !isGet(w, r) {
|
|
return
|
|
}
|
|
writeJSON(w, http.StatusOK, response{
|
|
Service: serviceName,
|
|
Status: "ok",
|
|
Message: "hello from the LibreMail bug-report ingest Worker",
|
|
})
|
|
}
|
|
|
|
// healthz is a liveness/readiness probe endpoint.
|
|
func healthz(w http.ResponseWriter, r *http.Request) {
|
|
if !isGet(w, r) {
|
|
return
|
|
}
|
|
writeJSON(w, http.StatusOK, response{Status: "ok"})
|
|
}
|
|
|
|
// isGet reports whether the request method is GET. If not, it writes a 405 with
|
|
// an Allow header and returns false.
|
|
func isGet(w http.ResponseWriter, r *http.Request) bool {
|
|
if r.Method != http.MethodGet {
|
|
w.Header().Set("Allow", http.MethodGet)
|
|
writeJSON(w, http.StatusMethodNotAllowed, response{Status: "error", Error: "method not allowed"})
|
|
return false
|
|
}
|
|
return true
|
|
}
|
|
|
|
// response is the JSON body shape returned by every endpoint. Empty fields are
|
|
// omitted so success and error bodies stay minimal.
|
|
type response struct {
|
|
Service string `json:"service,omitempty"`
|
|
Status string `json:"status"`
|
|
Message string `json:"message,omitempty"`
|
|
Error string `json:"error,omitempty"`
|
|
}
|
|
|
|
// writeJSON writes body as JSON with the given status code.
|
|
func writeJSON(w http.ResponseWriter, status int, body response) {
|
|
w.Header().Set("Content-Type", "application/json; charset=utf-8")
|
|
w.WriteHeader(status)
|
|
_ = json.NewEncoder(w).Encode(body)
|
|
}
|