Files
LibreMail-Bug-Report-Ingest/internal/handler/handler.go
T
JMR-devandClaude Opus 4.8 bd7fe21d97 #9 Encrypted-at-rest R2 storage for scrubbed reports
Implement the storage path: for each accepted report, scrub PII (#8),
encrypt with AES-256-GCM (ADR #5), and write only ciphertext to R2, wired
in as the real ingest Sink replacing NopSink.

- internal/crypto: AES-256-GCM in the exact ADR #5 wire format
  (magic "LMB1" || version || key_id BE16 || nonce(12) || ct || tag(16);
  the 7-byte header is the GCM AAD). Provider-independent framing shared by
  a host crypto/aes+crypto/cipher impl (tests, devserver) and a Wasm
  SubtleCrypto impl (syscall/js, //go:build js && wasm) per the TinyGo
  constraint; both produce byte-identical frames. Versioned keyring with
  key_id rotation; ParseKeyring reads the Secrets Store JSON secret.
- internal/storage: ObjectStore interface with an in-memory fake (tests,
  devserver) and a Wasm R2Store (syumai/workers R2 binding). Sink ties
  scrub -> Seal -> Put under a unique reports/<ts>-<rand> key. WorkerSink
  loads the keyring from Secrets Store (BUGREPORT_ENC_KEYRING), cached for
  the isolate lifetime.
- handler.New now takes an injectable ingest.Sink; the Worker uses the real
  R2/Secrets-Store sink, the devserver a memory + throwaway-key sink.
- wrangler.jsonc: add REPORTS_BUCKET (R2) and BUGREPORT_ENC_KEYRING
  (Secrets Store) bindings.

Tests (host, no TinyGo): encrypt/decrypt roundtrip; ciphertext != plaintext;
wrong key + tamper (ct/tag/nonce/header-AAD) fail; exact wire layout plus a
known-answer vector; key_id rotation with retained keys; full sink path (PII
scrubbed then encrypted, readback requires the key and yields the scrubbed
content). Existing ingest/handler behavior preserved (202 on valid POST).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 15:08:21 -05:00

93 lines
3.2 KiB
Go

// Package handler holds the core, transport-agnostic HTTP handlers for the
// LibreMail bug-report ingest Worker.
//
// It intentionally carries no build constraints, so it compiles and is
// unit-tested with the standard Go toolchain on the host, and is reused
// verbatim by both the local dev server (cmd/devserver) and the Cloudflare
// Worker Wasm entrypoint (worker). Keeping the request logic here means the same
// http.Handler runs unchanged on the dev server and in the deployed Worker.
package handler
import (
"encoding/json"
"net/http"
"github.com/JMR-dev/LibreMail-Bug-Report-Ingest/internal/ingest"
)
// serviceName identifies this service in responses.
const serviceName = "libremail-bug-report-ingest"
// New returns an http.Handler serving the ingest Worker's endpoints:
//
// GET / -> 200, JSON service/status/message
// GET /healthz -> 200, JSON {"status":"ok"}
// POST /v1/reports -> 202 on accept; 400/413/415/405/503 per the ingest contract
//
// Any other path returns 404. On the health/hello endpoints any non-GET method
// returns 405; on /v1/reports any non-POST method returns 405 (Allow: POST).
//
// sink is the storage backend for accepted reports (scrub + encrypt + R2, #9).
// It is injected so the deployed Worker supplies the real R2/Secrets-Store sink
// while cmd/devserver and tests supply an in-memory one. A nil sink defaults to
// ingest.NopSink, which enforces the full HTTP contract but discards bodies.
func New(sink ingest.Sink) http.Handler {
mux := http.NewServeMux()
mux.HandleFunc("/healthz", healthz)
mux.Handle("/v1/reports", ingest.NewHandler(sink))
mux.HandleFunc("/", root)
return mux
}
// root handles the service root. Because "/" is the catch-all pattern in the
// mux, it also rejects unknown paths with 404.
func root(w http.ResponseWriter, r *http.Request) {
if r.URL.Path != "/" {
writeJSON(w, http.StatusNotFound, response{Status: "error", Error: "not found"})
return
}
if !isGet(w, r) {
return
}
writeJSON(w, http.StatusOK, response{
Service: serviceName,
Status: "ok",
Message: "hello from the LibreMail bug-report ingest Worker",
})
}
// healthz is a liveness/readiness probe endpoint.
func healthz(w http.ResponseWriter, r *http.Request) {
if !isGet(w, r) {
return
}
writeJSON(w, http.StatusOK, response{Status: "ok"})
}
// isGet reports whether the request method is GET. If not, it writes a 405 with
// an Allow header and returns false.
func isGet(w http.ResponseWriter, r *http.Request) bool {
if r.Method != http.MethodGet {
w.Header().Set("Allow", http.MethodGet)
writeJSON(w, http.StatusMethodNotAllowed, response{Status: "error", Error: "method not allowed"})
return false
}
return true
}
// response is the JSON body shape returned by every endpoint. Empty fields are
// omitted so success and error bodies stay minimal.
type response struct {
Service string `json:"service,omitempty"`
Status string `json:"status"`
Message string `json:"message,omitempty"`
Error string `json:"error,omitempty"`
}
// writeJSON writes body as JSON with the given status code.
func writeJSON(w http.ResponseWriter, status int, body response) {
w.Header().Set("Content-Type", "application/json; charset=utf-8")
w.WriteHeader(status)
_ = json.NewEncoder(w).Encode(body)
}