check / check (push) Failing after 1s
A buffer failure on POST /api/v1/reports now returns 500 instead of a
false {"status":"ok"}, so clients can retry. Decode errors are split:
an over-limit body returns 413 (via errors.As on *http.MaxBytesError),
malformed JSON stays 400. A new MaxBodyBytes middleware caps every
route (1 MiB default; rejects an oversized Content-Length up-front and
caps the read otherwise), replacing the per-route reader so the health
check and future routes are bounded too. The raw attacker-controlled
geo blob is no longer logged — only its byte length — and client_id and
timestamp are length-bounded before logging. A decodeJSON handler helper
is added per the HTTP server conventions. Panic recovery is now a local
middleware that routes the stack through slog as structured JSON rather
than chi's plain-text stderr. Error bodies still leak nothing internal.
Chosen failure code for a storage failure: 500, since a full buffer or
write error is server-side and retryable, not the client's fault.
Model: opus-4-8
94 lines
2.0 KiB
Go
94 lines
2.0 KiB
Go
// Package handlers implements HTTP request handlers for the
|
|
// netwatch-server API.
|
|
package handlers
|
|
|
|
import (
|
|
"context"
|
|
"encoding/json"
|
|
"log/slog"
|
|
"net/http"
|
|
|
|
"sneak.berlin/go/netwatch/internal/globals"
|
|
"sneak.berlin/go/netwatch/internal/healthcheck"
|
|
"sneak.berlin/go/netwatch/internal/logger"
|
|
"sneak.berlin/go/netwatch/internal/reportbuf"
|
|
|
|
"go.uber.org/fx"
|
|
)
|
|
|
|
const jsonContentType = "application/json; charset=utf-8"
|
|
|
|
// reportAppender is the subset of the report buffer the handlers
|
|
// depend on. Defining it here keeps the storage failure path
|
|
// exercisable with a stub in tests.
|
|
type reportAppender interface {
|
|
Append(v any) error
|
|
}
|
|
|
|
// Params defines the dependencies for Handlers.
|
|
type Params struct {
|
|
fx.In
|
|
|
|
Buffer *reportbuf.Buffer
|
|
Globals *globals.Globals
|
|
Healthcheck *healthcheck.Healthcheck
|
|
Logger *logger.Logger
|
|
}
|
|
|
|
// Handlers provides HTTP handler factories for all endpoints.
|
|
type Handlers struct {
|
|
buf reportAppender
|
|
hc *healthcheck.Healthcheck
|
|
log *slog.Logger
|
|
params *Params
|
|
}
|
|
|
|
// New creates a Handlers instance.
|
|
func New(
|
|
lc fx.Lifecycle,
|
|
params Params,
|
|
) (*Handlers, error) {
|
|
s := new(Handlers)
|
|
s.buf = params.Buffer
|
|
s.params = ¶ms
|
|
s.log = params.Logger.Get()
|
|
s.hc = params.Healthcheck
|
|
|
|
lc.Append(fx.Hook{
|
|
OnStart: func(_ context.Context) error {
|
|
return nil
|
|
},
|
|
})
|
|
|
|
return s, nil
|
|
}
|
|
|
|
func (s *Handlers) respondJSON(
|
|
w http.ResponseWriter,
|
|
_ *http.Request,
|
|
data any,
|
|
status int,
|
|
) {
|
|
w.Header().Set("Content-Type", jsonContentType)
|
|
w.WriteHeader(status)
|
|
|
|
if data != nil {
|
|
err := json.NewEncoder(w).Encode(data)
|
|
if err != nil {
|
|
s.log.Error("json encode error", "error", err)
|
|
}
|
|
}
|
|
}
|
|
|
|
// decodeJSON decodes the request body into v. The body is
|
|
// expected to already be bounded by the body-size middleware, so
|
|
// a caller can distinguish an over-limit body from malformed
|
|
// JSON by testing the returned error for *http.MaxBytesError.
|
|
func (s *Handlers) decodeJSON(
|
|
_ http.ResponseWriter,
|
|
r *http.Request,
|
|
v any,
|
|
) error {
|
|
return json.NewDecoder(r.Body).Decode(v)
|
|
}
|