Implement the storage path: for each accepted report, scrub PII (#8), encrypt with AES-256-GCM (ADR #5), and write only ciphertext to R2, wired in as the real ingest Sink replacing NopSink. - internal/crypto: AES-256-GCM in the exact ADR #5 wire format (magic "LMB1" || version || key_id BE16 || nonce(12) || ct || tag(16); the 7-byte header is the GCM AAD). Provider-independent framing shared by a host crypto/aes+crypto/cipher impl (tests, devserver) and a Wasm SubtleCrypto impl (syscall/js, //go:build js && wasm) per the TinyGo constraint; both produce byte-identical frames. Versioned keyring with key_id rotation; ParseKeyring reads the Secrets Store JSON secret. - internal/storage: ObjectStore interface with an in-memory fake (tests, devserver) and a Wasm R2Store (syumai/workers R2 binding). Sink ties scrub -> Seal -> Put under a unique reports/<ts>-<rand> key. WorkerSink loads the keyring from Secrets Store (BUGREPORT_ENC_KEYRING), cached for the isolate lifetime. - handler.New now takes an injectable ingest.Sink; the Worker uses the real R2/Secrets-Store sink, the devserver a memory + throwaway-key sink. - wrangler.jsonc: add REPORTS_BUCKET (R2) and BUGREPORT_ENC_KEYRING (Secrets Store) bindings. Tests (host, no TinyGo): encrypt/decrypt roundtrip; ciphertext != plaintext; wrong key + tamper (ct/tag/nonce/header-AAD) fail; exact wire layout plus a known-answer vector; key_id rotation with retained keys; full sink path (PII scrubbed then encrypted, readback requires the key and yields the scrubbed content). Existing ingest/handler behavior preserved (202 on valid POST). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
26 lines
980 B
Go
26 lines
980 B
Go
//go:build js && wasm
|
|
|
|
// Command worker is the Cloudflare Workers (Wasm) entrypoint.
|
|
//
|
|
// It is compiled only for the js/wasm target by TinyGo (see the "Build & run
|
|
// locally" section of the README). The build constraint above keeps this file
|
|
// out of host builds and `go test ./...`, so the standard Go toolchain never
|
|
// needs the Workers runtime. It wires the shared core handler into the
|
|
// syumai/workers adapter, which bridges Go's net/http model to the Workers
|
|
// fetch event.
|
|
package main
|
|
|
|
import (
|
|
"github.com/syumai/workers"
|
|
|
|
"github.com/JMR-dev/LibreMail-Bug-Report-Ingest/internal/handler"
|
|
"github.com/JMR-dev/LibreMail-Bug-Report-Ingest/internal/storage"
|
|
)
|
|
|
|
func main() {
|
|
// The real storage Sink (#9): scrub -> AES-256-GCM encrypt -> R2 put, with the
|
|
// keyring loaded from Cloudflare Secrets Store on first request. Bindings
|
|
// (REPORTS_BUCKET, BUGREPORT_ENC_KEYRING) are declared in wrangler.jsonc.
|
|
workers.Serve(handler.New(storage.NewWorkerSink()))
|
|
}
|