fix(backend): report ingest correctness: 500 on a refused report, 413 on oversize, global body cap (closes #23)
check / check (push) Successful in 10s
check / check (push) Successful in 10s
A report the buffer refuses now returns 500 instead of a false `ok`. Reports reach disk later, so a failed disk write is still answered 200 and shows in the log, and at shutdown as a failed stop with a non-zero exit. An over-limit body returns 413; malformed JSON stays 400. A MaxBodyBytes middleware caps every route at 1 MiB; a route group can only lower that limit. The raw geo blob is no longer logged; client_id, timestamp and decode error text are cut to 128 bytes before logging. Panic recovery logs the panic value and stack through slog. Model: opus-5-5
This commit was merged in pull request #58.
This commit is contained in:
@@ -23,6 +23,16 @@ latest run passes.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-28: report ingest correctness (issue #23): a storage failure now
|
||||
returns 500 instead of a false `ok`; oversize bodies return 413 (distinguished
|
||||
from malformed JSON, which stays 400); a `MaxBodyBytes` middleware caps every
|
||||
route, not just the report route; the raw attacker-controlled `geo` blob is no
|
||||
longer logged (only its length), and `client_id`, `timestamp` and decode error
|
||||
text are length-bounded before logging; a `decodeJSON` handler helper was
|
||||
added; panic recovery now routes the stack through slog instead of chi's
|
||||
plain-text stderr; and writing a report file now returns its error, so a
|
||||
failed final flush on shutdown makes the process exit non-zero instead of
|
||||
losing the buffered reports silently
|
||||
- 2026-09-21: shutdown lifecycle correctness. The process now shuts down through
|
||||
fx instead of `os.Exit`, so every component's `OnStop` runs and buffered
|
||||
reports are flushed to disk on `SIGTERM` — previously a full flush window of
|
||||
|
||||
Reference in New Issue
Block a user