Debug ingest: Worker ingest + PII anonymization + encrypted R2 storage #34

Open
opened 2026-07-01 04:01:32 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-01 04:01:32 +00:00 (Migrated from github.com)

Part of #11.

Context

Server side of bug reporting. Lives in separate infrastructure (not the Android app
repo). Receives reports from #33.

Scope

  • Cloudflare Worker HTTPS endpoint accepting a report payload, with size/rate limiting
    and basic abuse protection.
  • Best-effort PII anonymization/redaction pass (email addresses, tokens, names, IPs)
    before storage.
  • Store each report in a Cloudflare R2 bucket encrypted at rest; document the
    encryption scheme and key custody.
  • Lifecycle so unreviewed reports are picked up by the weekly job (#35).
  • Document the data flow + privacy posture (referenced by F-Droid #16 and the README #20).

Acceptance criteria

  • A POST from the app is accepted, scrubbed, and stored encrypted in R2.
  • Stored objects are not readable without the documented key.

Open questions

  • Encryption scheme (Worker-side envelope encryption vs. R2 SSE) and who holds the keys.
  • Where the Worker source lives; secrets stored in Cloudflare, never in the app.

Dependencies

Consumes #33; feeds #35.

Part of #11. ## Context Server side of bug reporting. Lives in **separate infrastructure** (not the Android app repo). Receives reports from #33. ## Scope - [ ] Cloudflare Worker HTTPS endpoint accepting a report payload, with size/rate limiting and basic abuse protection. - [ ] Best-effort PII anonymization/redaction pass (email addresses, tokens, names, IPs) before storage. - [ ] Store each report in a Cloudflare R2 bucket **encrypted at rest**; document the encryption scheme and key custody. - [ ] Lifecycle so unreviewed reports are picked up by the weekly job (#35). - [ ] Document the data flow + privacy posture (referenced by F-Droid #16 and the README #20). ## Acceptance criteria - A POST from the app is accepted, scrubbed, and stored encrypted in R2. - Stored objects are not readable without the documented key. ## Open questions - Encryption scheme (Worker-side envelope encryption vs. R2 SSE) and who holds the keys. - Where the Worker source lives; secrets stored in Cloudflare, never in the app. ## Dependencies Consumes #33; feeds #35.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#34