check / check (push) Successful in 54s
Adds a SecurityHeaders middleware and registers it globally, right after the request ID middleware, so every route gets the headers, including static files, /metrics and error responses. It sets Strict-Transport-Security (one year, includeSubDomains), a Content-Security-Policy with default-src 'self', no scripts and frame-ancestors 'none', X-Frame-Options DENY, X-Content-Type-Options nosniff, Referrer-Policy no-referrer and a Permissions-Policy that turns every listed feature off. HSTS is sent on every response, not only over TLS: the service runs behind a TLS-terminating proxy and REPO_POLICIES.md requires the application to send it. Referrer-Policy is stricter than the policy baseline because dashboard URLs can name internal hosts. model: claude-opus-4-8 (implementation); claude-fable-5 (commit message)
66 lines
1.4 KiB
Go
66 lines
1.4 KiB
Go
package server
|
|
|
|
import (
|
|
"net/http"
|
|
"time"
|
|
|
|
"github.com/go-chi/chi/v5"
|
|
chimw "github.com/go-chi/chi/v5/middleware"
|
|
"github.com/prometheus/client_golang/prometheus/promhttp"
|
|
|
|
"sneak.berlin/go/dnswatcher/static"
|
|
)
|
|
|
|
// requestTimeout is the maximum duration for handling a request.
|
|
const requestTimeout = 60 * time.Second
|
|
|
|
// SetupRoutes configures all HTTP routes.
|
|
func (s *Server) SetupRoutes() {
|
|
s.router = chi.NewRouter()
|
|
|
|
// Global middleware
|
|
s.router.Use(chimw.Recoverer)
|
|
s.router.Use(chimw.RequestID)
|
|
s.router.Use(s.mw.SecurityHeaders())
|
|
s.router.Use(s.mw.Logging())
|
|
s.router.Use(s.mw.CORS())
|
|
s.router.Use(chimw.Timeout(requestTimeout))
|
|
|
|
// Dashboard (read-only web UI)
|
|
s.router.Get("/", s.handlers.HandleDashboard())
|
|
|
|
// Static assets (embedded CSS/JS)
|
|
s.router.Mount(
|
|
"/s",
|
|
http.StripPrefix(
|
|
"/s",
|
|
http.FileServer(http.FS(static.Static)),
|
|
),
|
|
)
|
|
|
|
// Health check (standard well-known path)
|
|
s.router.Get(
|
|
"/.well-known/healthcheck",
|
|
s.handlers.HandleHealthCheck(),
|
|
)
|
|
|
|
// Legacy health check (keep for backward compatibility)
|
|
s.router.Get("/health", s.handlers.HandleHealthCheck())
|
|
|
|
// API v1 routes
|
|
s.router.Route("/api/v1", func(r chi.Router) {
|
|
r.Get("/status", s.handlers.HandleStatus())
|
|
})
|
|
|
|
// Metrics endpoint (optional, with basic auth)
|
|
if s.params.Config.MetricsUsername != "" {
|
|
s.router.Group(func(r chi.Router) {
|
|
r.Use(s.mw.MetricsAuth())
|
|
r.Get(
|
|
"/metrics",
|
|
promhttp.Handler().ServeHTTP,
|
|
)
|
|
})
|
|
}
|
|
}
|