Implement the storage path: for each accepted report, scrub PII (#8), encrypt with AES-256-GCM (ADR #5), and write only ciphertext to R2, wired in as the real ingest Sink replacing NopSink. - internal/crypto: AES-256-GCM in the exact ADR #5 wire format (magic "LMB1" || version || key_id BE16 || nonce(12) || ct || tag(16); the 7-byte header is the GCM AAD). Provider-independent framing shared by a host crypto/aes+crypto/cipher impl (tests, devserver) and a Wasm SubtleCrypto impl (syscall/js, //go:build js && wasm) per the TinyGo constraint; both produce byte-identical frames. Versioned keyring with key_id rotation; ParseKeyring reads the Secrets Store JSON secret. - internal/storage: ObjectStore interface with an in-memory fake (tests, devserver) and a Wasm R2Store (syumai/workers R2 binding). Sink ties scrub -> Seal -> Put under a unique reports/<ts>-<rand> key. WorkerSink loads the keyring from Secrets Store (BUGREPORT_ENC_KEYRING), cached for the isolate lifetime. - handler.New now takes an injectable ingest.Sink; the Worker uses the real R2/Secrets-Store sink, the devserver a memory + throwaway-key sink. - wrangler.jsonc: add REPORTS_BUCKET (R2) and BUGREPORT_ENC_KEYRING (Secrets Store) bindings. Tests (host, no TinyGo): encrypt/decrypt roundtrip; ciphertext != plaintext; wrong key + tamper (ct/tag/nonce/header-AAD) fail; exact wire layout plus a known-answer vector; key_id rotation with retained keys; full sink path (PII scrubbed then encrypted, readback requires the key and yields the scrubbed content). Existing ingest/handler behavior preserved (202 on valid POST). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
46 lines
2.0 KiB
Go
46 lines
2.0 KiB
Go
// Package storage persists accepted LibreMail bug-reports as encrypted-at-rest
|
|
// objects, implementing the storage half of the ingest pipeline: for each
|
|
// accepted report it scrubs PII (internal/scrub, #8), encrypts the scrubbed
|
|
// bytes with AES-256-GCM (internal/crypto, ADR #5), and writes only the opaque
|
|
// ciphertext frame to the object store. The store never sees plaintext or the
|
|
// key.
|
|
//
|
|
// The package follows the repo's build-tag pattern so it is host-testable
|
|
// without TinyGo or the Workers runtime:
|
|
//
|
|
// - The ObjectStore interface, MemoryStore, and the Sink (scrub+encrypt+put)
|
|
// carry no build constraints and are unit-tested with `go test`.
|
|
// - The real R2-backed store (R2Store) and the Worker sink that loads the
|
|
// keyring from Cloudflare Secrets Store live behind //go:build js && wasm and
|
|
// are compiled by the Wasm Worker build in CI.
|
|
package storage
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
)
|
|
|
|
// ErrNotFound is returned by ObjectStore.Get when no object exists at the key.
|
|
var ErrNotFound = errors.New("storage: object not found")
|
|
|
|
// Binding names wired in wrangler.jsonc and provisioned by infra (#2).
|
|
const (
|
|
// BucketBinding is the R2 bucket binding name (the JS var the Worker reads).
|
|
// The bound bucket is "libremail-bug-reports" (infra defaultR2BucketName).
|
|
BucketBinding = "REPORTS_BUCKET"
|
|
// KeyringBinding is the Cloudflare Secrets Store binding holding the JSON
|
|
// keyring secret, named per ADR #5.
|
|
KeyringBinding = "BUGREPORT_ENC_KEYRING"
|
|
)
|
|
|
|
// ObjectStore is the seam for the opaque object backend. Implementations only
|
|
// ever handle already-encrypted frames.
|
|
//
|
|
// - Put writes data (a sealed frame) at key, overwriting any existing object.
|
|
// - Get reads the bytes back, or returns ErrNotFound. Get exists mainly for the
|
|
// future publish job (#35) and for tests; the ingest path is write-only.
|
|
type ObjectStore interface {
|
|
Put(ctx context.Context, key string, data []byte) error
|
|
Get(ctx context.Context, key string) ([]byte, error)
|
|
}
|