check / check (push) Successful in 45s
A buffer failure on POST /api/v1/reports now returns 500 instead of a false `ok`, so clients can retry. Decode errors split: an over-limit body returns 413 (via errors.As on `*http.MaxBytesError`), malformed JSON stays 400. A new MaxBodyBytes middleware (1 MiB default) caps every route — rejecting an oversized Content-Length up front and capping the read otherwise — so the health check and future routes are bounded too. The raw attacker-controlled geo blob is no longer logged, only its length; client_id and timestamp are length-bounded before logging. A decodeJSON handler helper is added. Panic recovery is now a local middleware routing the stack through slog as structured JSON. Storage failure uses 500: a full buffer or write error is server-side and retryable. Model: opus-4-8
11 lines
325 B
Go
11 lines
325 B
Go
package handlers
|
|
|
|
import "log/slog"
|
|
|
|
// NewForTest builds a Handlers around a report sink and logger,
|
|
// bypassing the fx graph so handler behaviour (including the
|
|
// storage failure path) is exercisable in unit tests.
|
|
func NewForTest(buf reportAppender, log *slog.Logger) *Handlers {
|
|
return &Handlers{buf: buf, log: log}
|
|
}
|