Files
LibreMail-Bug-Report-Ingest/internal/storage/store.go
T
JMR-devandClaude Opus 4.8 bd7fe21d97 #9 Encrypted-at-rest R2 storage for scrubbed reports
Implement the storage path: for each accepted report, scrub PII (#8),
encrypt with AES-256-GCM (ADR #5), and write only ciphertext to R2, wired
in as the real ingest Sink replacing NopSink.

- internal/crypto: AES-256-GCM in the exact ADR #5 wire format
  (magic "LMB1" || version || key_id BE16 || nonce(12) || ct || tag(16);
  the 7-byte header is the GCM AAD). Provider-independent framing shared by
  a host crypto/aes+crypto/cipher impl (tests, devserver) and a Wasm
  SubtleCrypto impl (syscall/js, //go:build js && wasm) per the TinyGo
  constraint; both produce byte-identical frames. Versioned keyring with
  key_id rotation; ParseKeyring reads the Secrets Store JSON secret.
- internal/storage: ObjectStore interface with an in-memory fake (tests,
  devserver) and a Wasm R2Store (syumai/workers R2 binding). Sink ties
  scrub -> Seal -> Put under a unique reports/<ts>-<rand> key. WorkerSink
  loads the keyring from Secrets Store (BUGREPORT_ENC_KEYRING), cached for
  the isolate lifetime.
- handler.New now takes an injectable ingest.Sink; the Worker uses the real
  R2/Secrets-Store sink, the devserver a memory + throwaway-key sink.
- wrangler.jsonc: add REPORTS_BUCKET (R2) and BUGREPORT_ENC_KEYRING
  (Secrets Store) bindings.

Tests (host, no TinyGo): encrypt/decrypt roundtrip; ciphertext != plaintext;
wrong key + tamper (ct/tag/nonce/header-AAD) fail; exact wire layout plus a
known-answer vector; key_id rotation with retained keys; full sink path (PII
scrubbed then encrypted, readback requires the key and yields the scrubbed
content). Existing ingest/handler behavior preserved (202 on valid POST).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 15:08:21 -05:00

46 lines
2.0 KiB
Go

// Package storage persists accepted LibreMail bug-reports as encrypted-at-rest
// objects, implementing the storage half of the ingest pipeline: for each
// accepted report it scrubs PII (internal/scrub, #8), encrypts the scrubbed
// bytes with AES-256-GCM (internal/crypto, ADR #5), and writes only the opaque
// ciphertext frame to the object store. The store never sees plaintext or the
// key.
//
// The package follows the repo's build-tag pattern so it is host-testable
// without TinyGo or the Workers runtime:
//
// - The ObjectStore interface, MemoryStore, and the Sink (scrub+encrypt+put)
// carry no build constraints and are unit-tested with `go test`.
// - The real R2-backed store (R2Store) and the Worker sink that loads the
// keyring from Cloudflare Secrets Store live behind //go:build js && wasm and
// are compiled by the Wasm Worker build in CI.
package storage
import (
"context"
"errors"
)
// ErrNotFound is returned by ObjectStore.Get when no object exists at the key.
var ErrNotFound = errors.New("storage: object not found")
// Binding names wired in wrangler.jsonc and provisioned by infra (#2).
const (
// BucketBinding is the R2 bucket binding name (the JS var the Worker reads).
// The bound bucket is "libremail-bug-reports" (infra defaultR2BucketName).
BucketBinding = "REPORTS_BUCKET"
// KeyringBinding is the Cloudflare Secrets Store binding holding the JSON
// keyring secret, named per ADR #5.
KeyringBinding = "BUGREPORT_ENC_KEYRING"
)
// ObjectStore is the seam for the opaque object backend. Implementations only
// ever handle already-encrypted frames.
//
// - Put writes data (a sealed frame) at key, overwriting any existing object.
// - Get reads the bytes back, or returns ErrNotFound. Get exists mainly for the
// future publish job (#35) and for tests; the ingest path is write-only.
type ObjectStore interface {
Put(ctx context.Context, key string, data []byte) error
Get(ctx context.Context, key string) ([]byte, error)
}