Implement the storage path: for each accepted report, scrub PII (#8),
encrypt with AES-256-GCM (ADR #5), and write only ciphertext to R2, wired
in as the real ingest Sink replacing NopSink.
- internal/crypto: AES-256-GCM in the exact ADR #5 wire format
(magic "LMB1" || version || key_id BE16 || nonce(12) || ct || tag(16);
the 7-byte header is the GCM AAD). Provider-independent framing shared by
a host crypto/aes+crypto/cipher impl (tests, devserver) and a Wasm
SubtleCrypto impl (syscall/js, //go:build js && wasm) per the TinyGo
constraint; both produce byte-identical frames. Versioned keyring with
key_id rotation; ParseKeyring reads the Secrets Store JSON secret.
- internal/storage: ObjectStore interface with an in-memory fake (tests,
devserver) and a Wasm R2Store (syumai/workers R2 binding). Sink ties
scrub -> Seal -> Put under a unique reports/<ts>-<rand> key. WorkerSink
loads the keyring from Secrets Store (BUGREPORT_ENC_KEYRING), cached for
the isolate lifetime.
- handler.New now takes an injectable ingest.Sink; the Worker uses the real
R2/Secrets-Store sink, the devserver a memory + throwaway-key sink.
- wrangler.jsonc: add REPORTS_BUCKET (R2) and BUGREPORT_ENC_KEYRING
(Secrets Store) bindings.
Tests (host, no TinyGo): encrypt/decrypt roundtrip; ciphertext != plaintext;
wrong key + tamper (ct/tag/nonce/header-AAD) fail; exact wire layout plus a
known-answer vector; key_id rotation with retained keys; full sink path (PII
scrubbed then encrypted, readback requires the key and yields the scrubbed
content). Existing ingest/handler behavior preserved (202 on valid POST).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>