Compare commits
2 Commits
46248a2838
...
93be4d2846
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
93be4d2846 | ||
| c378690977 |
@@ -3,6 +3,11 @@
|
|||||||
# stage of the Dockerfile.
|
# stage of the Dockerfile.
|
||||||
.git/
|
.git/
|
||||||
bin/
|
bin/
|
||||||
|
# Third-party browser assets are fetched and hash-verified inside the build by
|
||||||
|
# script/fetch-assets. Excluding any host copy keeps a developer's working tree
|
||||||
|
# from supplying the bytes that get shipped. The script and its
|
||||||
|
# static/vendor.sha256 manifest stay in the context.
|
||||||
|
static/js/alpine.min.js
|
||||||
*.md
|
*.md
|
||||||
LICENSE
|
LICENSE
|
||||||
.editorconfig
|
.editorconfig
|
||||||
|
|||||||
5
.gitignore
vendored
5
.gitignore
vendored
@@ -45,3 +45,8 @@ temp/
|
|||||||
|
|
||||||
# CI cache barrier, written into the build context by the check workflow
|
# CI cache barrier, written into the build context by the check workflow
|
||||||
.ci-fingerprint
|
.ci-fingerprint
|
||||||
|
|
||||||
|
# Third-party browser assets, fetched and hash-verified by
|
||||||
|
# script/fetch-assets against static/vendor.sha256. Not committed:
|
||||||
|
# REPO_POLICIES.md forbids minified bundles in version control.
|
||||||
|
/static/js/alpine.min.js
|
||||||
19
Dockerfile
19
Dockerfile
@@ -19,9 +19,14 @@ RUN go mod download
|
|||||||
# .dockerignore.
|
# .dockerignore.
|
||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
# Run formatting check and linter
|
# Run formatting check and linter. golangci-lint is invoked directly rather
|
||||||
|
# than through `make lint`: this stage is already the pinned linter image, and
|
||||||
|
# script/lint is a wrapper that builds Dockerfile.lint, so calling it here
|
||||||
|
# would need a docker daemon inside the build. Keep these steps in step with
|
||||||
|
# Dockerfile.lint, including --network=none (see its header for why).
|
||||||
RUN make fmt-check
|
RUN make fmt-check
|
||||||
RUN make lint
|
RUN --network=none golangci-lint config verify --config .golangci.yml
|
||||||
|
RUN --network=none golangci-lint run --config .golangci.yml ./...
|
||||||
|
|
||||||
# Build stage
|
# Build stage
|
||||||
# golang:1.26.1-bookworm (Debian-based), 2026-03-17
|
# golang:1.26.1-bookworm (Debian-based), 2026-03-17
|
||||||
@@ -32,7 +37,7 @@ FROM golang:1.26.1-bookworm@sha256:4465644228bc2857a954b092167e12aa59c006a349228
|
|||||||
# Depend on lint stage passing
|
# Depend on lint stage passing
|
||||||
COPY --from=lint /src/go.sum /dev/null
|
COPY --from=lint /src/go.sum /dev/null
|
||||||
|
|
||||||
RUN apt-get update && apt-get install -y --no-install-recommends make && rm -rf /var/lib/apt/lists/*
|
RUN apt-get update && apt-get install -y --no-install-recommends make curl ca-certificates && rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
WORKDIR /build
|
WORKDIR /build
|
||||||
|
|
||||||
@@ -44,6 +49,14 @@ RUN go mod download
|
|||||||
# the lint stage above.
|
# the lint stage above.
|
||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
|
# Fetch the third-party browser assets the UI serves. They are not committed
|
||||||
|
# (REPO_POLICIES.md forbids minified bundles in version control) and
|
||||||
|
# .dockerignore keeps any host copy out of the build context, so this step is
|
||||||
|
# the only way they enter the image. Each download is checked against a
|
||||||
|
# hardcoded sha256 and the build fails on mismatch; make test re-checks the
|
||||||
|
# hashes against the bytes go:embed actually put in the binary.
|
||||||
|
RUN script/fetch-assets
|
||||||
|
|
||||||
# Run tests and build
|
# Run tests and build
|
||||||
RUN make test
|
RUN make test
|
||||||
RUN make build
|
RUN make build
|
||||||
|
|||||||
37
Dockerfile.lint
Normal file
37
Dockerfile.lint
Normal file
@@ -0,0 +1,37 @@
|
|||||||
|
# Lint-only image, built by script/lint. golangci-lint is never installed on
|
||||||
|
# the host: the repo is COPYed into the pinned image and linted as a build
|
||||||
|
# step, so a successful build IS a clean lint. This works even when the docker
|
||||||
|
# daemon is remote and bind mounts are impossible.
|
||||||
|
#
|
||||||
|
# script/lint passes --no-cache-filter=lint. Without it an unchanged tree
|
||||||
|
# replays the lint stage from cache and the build succeeds in under a second
|
||||||
|
# having run no linter at all. Do not drop that flag.
|
||||||
|
#
|
||||||
|
# The lint steps run with --network=none. `golangci-lint config verify` is
|
||||||
|
# documented as fetching its JSON schema over HTTPS, which would make linting
|
||||||
|
# depend on an unpinned remote artifact; this pinned image resolves the schema
|
||||||
|
# without any network, and --network=none enforces that rather than trusting
|
||||||
|
# it. It also proves no linter reaches out at analysis time. If a future image
|
||||||
|
# bump makes either step need the network, this build fails loudly instead of
|
||||||
|
# quietly acquiring an unpinned dependency.
|
||||||
|
|
||||||
|
# golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07
|
||||||
|
# Using Debian-based image because mattn/go-sqlite3 (CGO) does not
|
||||||
|
# compile on Alpine musl (off64_t is a glibc type).
|
||||||
|
FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS deps
|
||||||
|
|
||||||
|
WORKDIR /src
|
||||||
|
|
||||||
|
# Copy go mod files first for better layer caching. This stage is cacheable;
|
||||||
|
# only the lint stage below is forced to re-execute.
|
||||||
|
COPY go.mod go.sum ./
|
||||||
|
RUN go mod download
|
||||||
|
|
||||||
|
FROM deps AS lint
|
||||||
|
|
||||||
|
COPY . .
|
||||||
|
|
||||||
|
# `run` silently ignores config keys it does not recognize, so a typo would
|
||||||
|
# disable a setting without a word. `config verify` is what catches that.
|
||||||
|
RUN --network=none golangci-lint config verify --config .golangci.yml
|
||||||
|
RUN --network=none golangci-lint run --config .golangci.yml ./...
|
||||||
5
Makefile
5
Makefile
@@ -1,4 +1,4 @@
|
|||||||
.PHONY: bootstrap setup test lint fmt fmt-check check build run dev deps docker clean hooks css
|
.PHONY: bootstrap setup assets test lint fmt fmt-check check build run dev deps docker clean hooks css
|
||||||
|
|
||||||
# Default target
|
# Default target
|
||||||
.DEFAULT_GOAL := check
|
.DEFAULT_GOAL := check
|
||||||
@@ -9,6 +9,9 @@ bootstrap:
|
|||||||
setup:
|
setup:
|
||||||
@script/setup
|
@script/setup
|
||||||
|
|
||||||
|
assets:
|
||||||
|
@script/fetch-assets
|
||||||
|
|
||||||
test:
|
test:
|
||||||
@script/test
|
@script/test
|
||||||
|
|
||||||
|
|||||||
74
README.md
74
README.md
@@ -12,8 +12,10 @@ with retry support, logging, and observability. Category: infrastructure
|
|||||||
### Prerequisites
|
### Prerequisites
|
||||||
|
|
||||||
- Go 1.26+
|
- Go 1.26+
|
||||||
- golangci-lint v2.11+
|
- Docker (for linting and for containerized deployment)
|
||||||
- Docker (for containerized deployment)
|
|
||||||
|
golangci-lint is not a prerequisite and must not be installed on the host:
|
||||||
|
`make lint` runs the pinned linter image via `Dockerfile.lint`.
|
||||||
|
|
||||||
### Quick Start
|
### Quick Start
|
||||||
|
|
||||||
@@ -40,8 +42,9 @@ make docker
|
|||||||
```bash
|
```bash
|
||||||
make bootstrap # Install all dependencies (idempotent)
|
make bootstrap # Install all dependencies (idempotent)
|
||||||
make setup # Bootstrap + install git pre-commit hook
|
make setup # Bootstrap + install git pre-commit hook
|
||||||
|
make assets # Fetch + verify third-party browser assets
|
||||||
make fmt # Format code (gofmt + goimports)
|
make fmt # Format code (gofmt + goimports)
|
||||||
make lint # Run golangci-lint
|
make lint # Run golangci-lint in Docker (Dockerfile.lint)
|
||||||
make test # Run tests with race detection
|
make test # Run tests with race detection
|
||||||
make check # test + lint + fmt-check (CI gate)
|
make check # test + lint + fmt-check (CI gate)
|
||||||
make build # Build binary to bin/webhooker
|
make build # Build binary to bin/webhooker
|
||||||
@@ -247,8 +250,10 @@ them. We provide:
|
|||||||
- `script/setup` — make a fresh clone ready for development
|
- `script/setup` — make a fresh clone ready for development
|
||||||
(bootstrap, then install-precommit)
|
(bootstrap, then install-precommit)
|
||||||
- `script/projectname` — output the project name ("webhooker")
|
- `script/projectname` — output the project name ("webhooker")
|
||||||
|
- `script/fetch-assets` — download the third-party browser assets into
|
||||||
|
`static/`, verifying each against its pinned sha256
|
||||||
- `script/test` — run the test suite
|
- `script/test` — run the test suite
|
||||||
- `script/lint` — run golangci-lint
|
- `script/lint` — run golangci-lint in Docker (see Linting below)
|
||||||
- `script/fmt` — format all code (writes)
|
- `script/fmt` — format all code (writes)
|
||||||
- `script/fmt-check` — check formatting (read-only)
|
- `script/fmt-check` — check formatting (read-only)
|
||||||
- `script/check` — run test, lint, and fmt-check
|
- `script/check` — run test, lint, and fmt-check
|
||||||
@@ -260,6 +265,27 @@ them. We provide:
|
|||||||
- `script/install-precommit` — install the git pre-commit hook that
|
- `script/install-precommit` — install the git pre-commit hook that
|
||||||
runs `script/precommit`
|
runs `script/precommit`
|
||||||
|
|
||||||
|
## Third-party browser assets
|
||||||
|
|
||||||
|
The web UI serves one third-party script, Alpine.js. It is **not** committed:
|
||||||
|
a minified bundle in the tree is unreviewable, and `REPO_POLICIES.md` bars
|
||||||
|
both committed build artifacts and unpinned external references.
|
||||||
|
|
||||||
|
Instead `script/fetch-assets` downloads it from a pinned URL, checks the
|
||||||
|
download against a hardcoded sha256, and installs it under `static/`. The
|
||||||
|
sha256 of every installed asset is recorded in `static/vendor.sha256`, and
|
||||||
|
`static/vendor_test.go` re-hashes the bytes `go:embed` put in the binary
|
||||||
|
against that manifest — so the pin is enforced on what actually ships, not
|
||||||
|
merely written down. Any mismatch fails the build.
|
||||||
|
|
||||||
|
`make bootstrap` runs the fetch for local development, and the Dockerfile
|
||||||
|
runs it in the build stage; `.gitignore` and `.dockerignore` keep the
|
||||||
|
artifact out of both the repo and the build context.
|
||||||
|
|
||||||
|
To move to a new version: update the version, URL, and tarball sha256 in
|
||||||
|
`script/fetch-assets` and the asset sha256 in `static/vendor.sha256`, then
|
||||||
|
run `make assets && make check`.
|
||||||
|
|
||||||
## Rationale
|
## Rationale
|
||||||
|
|
||||||
Webhook integrations between services are inherently fragile. The
|
Webhook integrations between services are inherently fragile. The
|
||||||
@@ -1058,6 +1084,7 @@ webhooker/
|
|||||||
│ └── js/app.js # Client-side JavaScript (minimal bootstrap)
|
│ └── js/app.js # Client-side JavaScript (minimal bootstrap)
|
||||||
├── templates/ # Go HTML templates (base, index, login, etc.)
|
├── templates/ # Go HTML templates (base, index, login, etc.)
|
||||||
├── Dockerfile # Multi-stage: lint, build+test, then Alpine runtime
|
├── Dockerfile # Multi-stage: lint, build+test, then Alpine runtime
|
||||||
|
├── Dockerfile.lint # Lint-only image built by script/lint
|
||||||
├── Makefile # fmt, lint, test, check, build, docker targets
|
├── Makefile # fmt, lint, test, check, build, docker targets
|
||||||
├── go.mod / go.sum
|
├── go.mod / go.sum
|
||||||
└── .golangci.yml # Linter configuration
|
└── .golangci.yml # Linter configuration
|
||||||
@@ -1165,17 +1192,48 @@ downstream at form-parse time.
|
|||||||
- Container runs as non-root user (UID 1000)
|
- Container runs as non-root user (UID 1000)
|
||||||
- GORM soft deletes on all entities (data preserved for audit)
|
- GORM soft deletes on all entities (data preserved for audit)
|
||||||
|
|
||||||
|
### Linting
|
||||||
|
|
||||||
|
golangci-lint never runs on the host. `script/lint` builds
|
||||||
|
`Dockerfile.lint`, which copies the repo into the digest-pinned
|
||||||
|
golangci-lint image and lints as a build step, so a successful build is
|
||||||
|
a clean lint. A host binary would share one cache and one lock with
|
||||||
|
every other checkout on the machine, which has produced both invented
|
||||||
|
findings attributed to other worktrees and unearned passes.
|
||||||
|
|
||||||
|
Two properties are load-bearing:
|
||||||
|
|
||||||
|
- `script/lint` passes `--no-cache-filter=lint`. Without it an unchanged
|
||||||
|
tree replays the lint layer from cache and the build exits 0 in under
|
||||||
|
a second having linted nothing. The `deps` stage stays cacheable, so
|
||||||
|
module downloads are not repeated. Invalidation is scoped to the one
|
||||||
|
stage; never prune the shared build cache.
|
||||||
|
- Both lint steps use `RUN --network=none`. `golangci-lint config
|
||||||
|
verify` is documented as fetching its JSON schema over HTTPS, which
|
||||||
|
would be an unpinned remote dependency; the pinned image resolves the
|
||||||
|
schema without network access, and `--network=none` enforces that
|
||||||
|
instead of trusting it. Verify is worth keeping because
|
||||||
|
`golangci-lint run` silently ignores config keys it does not
|
||||||
|
recognize, so a typo would disable a setting with no warning.
|
||||||
|
|
||||||
### Docker
|
### Docker
|
||||||
|
|
||||||
The Dockerfile uses a multi-stage build:
|
The Dockerfile uses a multi-stage build:
|
||||||
|
|
||||||
1. **Builder stage** (Debian-based `golang:1.24`) — installs
|
1. **Lint stage** (`golangci/golangci-lint`) — copies source, runs
|
||||||
golangci-lint, downloads dependencies, copies source, runs `make
|
`make fmt-check`, `golangci-lint config verify`, and
|
||||||
check` (format verification, linting, tests, compilation).
|
`golangci-lint run`.
|
||||||
2. **Runtime stage** (`alpine:3.21`) — copies the binary, creates the
|
2. **Builder stage** (Debian-based `golang`) — downloads dependencies,
|
||||||
|
copies source, runs `make test` and `make build`, then relinks the
|
||||||
|
binary statically.
|
||||||
|
3. **Runtime stage** (`alpine:3.21`) — copies the binary, creates the
|
||||||
`/var/lib/webhooker` directory for all SQLite databases, runs as
|
`/var/lib/webhooker` directory for all SQLite databases, runs as
|
||||||
non-root user, exposes port 8080, includes a health check.
|
non-root user, exposes port 8080, includes a health check.
|
||||||
|
|
||||||
|
The lint stage invokes `golangci-lint` directly rather than `make lint`:
|
||||||
|
it is already the pinned linter image, and `make lint` would shell out
|
||||||
|
to another docker build from inside this one.
|
||||||
|
|
||||||
The builder uses Debian rather than Alpine because GORM's SQLite
|
The builder uses Debian rather than Alpine because GORM's SQLite
|
||||||
dialect pulls in CGO-dependent headers at compile time. The runtime
|
dialect pulls in CGO-dependent headers at compile time. The runtime
|
||||||
binary is statically linked and runs on Alpine.
|
binary is statically linked and runs on Alpine.
|
||||||
|
|||||||
50
internal/server/static_assets_test.go
Normal file
50
internal/server/static_assets_test.go
Normal file
@@ -0,0 +1,50 @@
|
|||||||
|
package server_test
|
||||||
|
|
||||||
|
import (
|
||||||
|
"net/http"
|
||||||
|
"regexp"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"github.com/stretchr/testify/assert"
|
||||||
|
"github.com/stretchr/testify/require"
|
||||||
|
|
||||||
|
"sneak.berlin/go/webhooker/templates"
|
||||||
|
)
|
||||||
|
|
||||||
|
// TestBaseTemplateScriptsAreServed walks every /s/ script the base
|
||||||
|
// template loads on each page and fetches it through the real router.
|
||||||
|
// Alpine.js is fetched at build time rather than committed, so nothing
|
||||||
|
// in the repo guarantees it is present: this is the check that the page
|
||||||
|
// still gets the JavaScript it asks for.
|
||||||
|
func TestBaseTemplateScriptsAreServed(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
// scriptSrc matches the src of every <script> tag pointing at the
|
||||||
|
// /s/ static mount.
|
||||||
|
scriptSrc := regexp.MustCompile(`<script[^>]+src="(/s/[^"]+)"`)
|
||||||
|
|
||||||
|
base, err := templates.Templates.ReadFile("base.html")
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
matches := scriptSrc.FindAllStringSubmatch(string(base), -1)
|
||||||
|
require.NotEmpty(t, matches, "base.html should load scripts from /s/")
|
||||||
|
|
||||||
|
env := newTestEnv(t)
|
||||||
|
|
||||||
|
for _, m := range matches {
|
||||||
|
src := m[1]
|
||||||
|
t.Run(src, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
w := env.get(src, nil)
|
||||||
|
|
||||||
|
require.Equalf(
|
||||||
|
t, http.StatusOK, w.Code,
|
||||||
|
"base.html loads %s but the server does not serve it", src,
|
||||||
|
)
|
||||||
|
assert.NotEmptyf(
|
||||||
|
t, w.Body.Bytes(), "%s is served but empty", src,
|
||||||
|
)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -3,19 +3,14 @@
|
|||||||
# this repo. Idempotent: every install is guarded by a check so already
|
# this repo. Idempotent: every install is guarded by a check so already
|
||||||
# installed tools are skipped. Base tooling comes from nix, apt, brew,
|
# installed tools are skipped. Base tooling comes from nix, apt, brew,
|
||||||
# or apk (detected in that order); assumes NOTHING is present (not git,
|
# or apk (detected in that order); assumes NOTHING is present (not git,
|
||||||
# make, or go). golangci-lint is packaged in nix, brew, and apk; on apt
|
# make, or go). golangci-lint is deliberately not installed: linting runs
|
||||||
# it is installed from a hash-verified GitHub release archive (never
|
# only in docker, via script/lint and Dockerfile.lint. Finishes by running
|
||||||
# curl | sh).
|
# script/fetch-assets, which installs the hash-pinned third-party browser
|
||||||
|
# assets the repo does not commit.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
# Pinned versions, 2026-08-07. Never "latest"; exact versions only.
|
|
||||||
GOLANGCI_LINT_VERSION="2.12.2"
|
|
||||||
# sha256 of golangci-lint-2.12.2-linux-<arch>.tar.gz release archives
|
|
||||||
GOLANGCI_LINT_SHA256_AMD64="8df580d2670fed8fa984aac0507099af8df275e665215f5c7a2ae3943893a553"
|
|
||||||
GOLANGCI_LINT_SHA256_ARM64="44cd40a8c76c86755375adfeea52cfd3533cb43d7bd647771e0ae065e166df3a"
|
|
||||||
|
|
||||||
PKGMGR=""
|
PKGMGR=""
|
||||||
SUDO=""
|
SUDO=""
|
||||||
|
|
||||||
@@ -56,52 +51,6 @@ missing() {
|
|||||||
! command -v "$1" >/dev/null 2>&1
|
! command -v "$1" >/dev/null 2>&1
|
||||||
}
|
}
|
||||||
|
|
||||||
# verify_sha256 <file> <expected-hash>
|
|
||||||
verify_sha256() {
|
|
||||||
if command -v sha256sum >/dev/null 2>&1; then
|
|
||||||
actual="$(sha256sum "$1" | cut -d' ' -f1)"
|
|
||||||
else
|
|
||||||
actual="$(shasum -a 256 "$1" | cut -d' ' -f1)"
|
|
||||||
fi
|
|
||||||
if [ "$actual" != "$2" ]; then
|
|
||||||
echo "bootstrap: sha256 mismatch for $1" >&2
|
|
||||||
echo " expected: $2" >&2
|
|
||||||
echo " actual: $actual" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
# apt has no golangci-lint package: install a pinned release archive
|
|
||||||
# from GitHub, verified by hardcoded sha256 (never curl | sh).
|
|
||||||
install_golangci_lint_release() {
|
|
||||||
case "$(uname -m)" in
|
|
||||||
x86_64) goarch="amd64"; sha="$GOLANGCI_LINT_SHA256_AMD64" ;;
|
|
||||||
aarch64|arm64) goarch="arm64"; sha="$GOLANGCI_LINT_SHA256_ARM64" ;;
|
|
||||||
*)
|
|
||||||
echo "bootstrap: unsupported architecture $(uname -m)" >&2
|
|
||||||
exit 1
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
if missing curl; then pkg_install curl curl curl curl; fi
|
|
||||||
name="golangci-lint-${GOLANGCI_LINT_VERSION}-linux-${goarch}"
|
|
||||||
tmp="$(mktemp -d)"
|
|
||||||
curl -fsSL -o "$tmp/$name.tar.gz" \
|
|
||||||
"https://github.com/golangci/golangci-lint/releases/download/v${GOLANGCI_LINT_VERSION}/${name}.tar.gz"
|
|
||||||
verify_sha256 "$tmp/$name.tar.gz" "$sha"
|
|
||||||
tar -xzf "$tmp/$name.tar.gz" -C "$tmp"
|
|
||||||
$SUDO install -m 0755 "$tmp/$name/golangci-lint" /usr/local/bin/golangci-lint
|
|
||||||
rm -rf "$tmp"
|
|
||||||
}
|
|
||||||
|
|
||||||
ensure_golangci_lint() {
|
|
||||||
if ! missing golangci-lint; then return 0; fi
|
|
||||||
detect_pkgmgr
|
|
||||||
case "$PKGMGR" in
|
|
||||||
apt) install_golangci_lint_release ;;
|
|
||||||
*) pkg_install golangci-lint golangci-lint golangci-lint golangci-lint ;;
|
|
||||||
esac
|
|
||||||
}
|
|
||||||
|
|
||||||
main() {
|
main() {
|
||||||
cd "$ROOT"
|
cd "$ROOT"
|
||||||
|
|
||||||
@@ -109,12 +58,22 @@ main() {
|
|||||||
if missing git; then pkg_install git git git git; fi
|
if missing git; then pkg_install git git git git; fi
|
||||||
if missing make; then pkg_install gnumake make make make; fi
|
if missing make; then pkg_install gnumake make make make; fi
|
||||||
|
|
||||||
# Go toolchain and linter
|
# Go toolchain
|
||||||
if missing go; then pkg_install go golang go go; fi
|
if missing go; then pkg_install go golang go go; fi
|
||||||
ensure_golangci_lint
|
|
||||||
|
# Not installed here: docker is platform-specific and out of scope for a
|
||||||
|
# package-manager bootstrap, but script/lint needs it.
|
||||||
|
if missing docker; then
|
||||||
|
echo "bootstrap: docker not found; script/lint requires it" >&2
|
||||||
|
fi
|
||||||
|
|
||||||
go mod download
|
go mod download
|
||||||
|
|
||||||
|
# Third-party browser assets are not committed; fetch and verify them
|
||||||
|
# so a fresh clone can build and test.
|
||||||
|
if missing curl; then pkg_install curl curl curl curl; fi
|
||||||
|
"$ROOT/script/fetch-assets"
|
||||||
|
|
||||||
echo "bootstrap complete"
|
echo "bootstrap complete"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
104
script/fetch-assets
Executable file
104
script/fetch-assets
Executable file
@@ -0,0 +1,104 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/fetch-assets: download the third-party browser assets the web UI
|
||||||
|
# ships and install them under static/. Minified bundles are not committed
|
||||||
|
# (REPO_POLICIES.md: no build artifacts in version control), so the build
|
||||||
|
# fetches them here. Every download is verified against a hardcoded sha256
|
||||||
|
# before it is installed, and any mismatch aborts. Idempotent: an asset
|
||||||
|
# already present with its pinned hash is left alone.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
|
# The sha256 of each installed asset lives in static/vendor.sha256, in
|
||||||
|
# sha256sum(1) format, with paths relative to static/. That file is the
|
||||||
|
# single source of truth: this script verifies against it, and
|
||||||
|
# static/vendor_test.go asserts the bytes embedded into the binary match
|
||||||
|
# it, so the hash cannot rot into a value nothing checks.
|
||||||
|
MANIFEST="static/vendor.sha256"
|
||||||
|
|
||||||
|
# Alpine.js 3.14.9, 2026-08-17. Fetched from registry.npmjs.org, the
|
||||||
|
# publisher of record; the jsDelivr and unpkg copies are mirrors of this
|
||||||
|
# same tarball. dist/cdn.min.js is the browser build Alpine publishes for
|
||||||
|
# a <script> tag.
|
||||||
|
ALPINE_VERSION="3.14.9"
|
||||||
|
ALPINE_URL="https://registry.npmjs.org/alpinejs/-/alpinejs-${ALPINE_VERSION}.tgz"
|
||||||
|
# sha256 of alpinejs-3.14.9.tgz
|
||||||
|
ALPINE_TARBALL_SHA256="97dad7c0c81e659cfc8e7700055da9770f8186187cb9a8a76efb57e00d5ce52a"
|
||||||
|
ALPINE_MEMBER="package/dist/cdn.min.js"
|
||||||
|
ALPINE_DEST="js/alpine.min.js"
|
||||||
|
|
||||||
|
sha256_of() {
|
||||||
|
if command -v sha256sum >/dev/null 2>&1; then
|
||||||
|
sha256sum "$1" | cut -d' ' -f1
|
||||||
|
else
|
||||||
|
shasum -a 256 "$1" | cut -d' ' -f1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# expected_sha256 <path-relative-to-static>
|
||||||
|
expected_sha256() {
|
||||||
|
awk -v want="$1" '$2 == want { print $1; found = 1 }
|
||||||
|
END { if (!found) exit 1 }' "$ROOT/$MANIFEST"
|
||||||
|
}
|
||||||
|
|
||||||
|
# verify <file> <expected-sha256> <what>
|
||||||
|
verify() {
|
||||||
|
actual="$(sha256_of "$1")"
|
||||||
|
if [ "$actual" != "$2" ]; then
|
||||||
|
echo "fetch-assets: sha256 mismatch for $3" >&2
|
||||||
|
echo " expected: $2" >&2
|
||||||
|
echo " actual: $actual" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# up_to_date <path-relative-to-static> <expected-sha256>
|
||||||
|
up_to_date() {
|
||||||
|
[ -f "$ROOT/static/$1" ] || return 1
|
||||||
|
[ "$(sha256_of "$ROOT/static/$1")" = "$2" ]
|
||||||
|
}
|
||||||
|
|
||||||
|
fetch_alpine() {
|
||||||
|
want="$(expected_sha256 "$ALPINE_DEST")"
|
||||||
|
|
||||||
|
if up_to_date "$ALPINE_DEST" "$want"; then
|
||||||
|
echo "fetch-assets: static/$ALPINE_DEST already at $want"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "fetch-assets: fetching Alpine.js $ALPINE_VERSION from $ALPINE_URL"
|
||||||
|
tmp="$(mktemp -d)"
|
||||||
|
trap 'rm -rf "$tmp"' EXIT INT TERM
|
||||||
|
curl -fsSL -o "$tmp/alpine.tgz" "$ALPINE_URL"
|
||||||
|
verify "$tmp/alpine.tgz" "$ALPINE_TARBALL_SHA256" "alpinejs-${ALPINE_VERSION}.tgz"
|
||||||
|
tar -xzOf "$tmp/alpine.tgz" "$ALPINE_MEMBER" >"$tmp/alpine.min.js"
|
||||||
|
verify "$tmp/alpine.min.js" "$want" "$ALPINE_MEMBER from alpinejs-${ALPINE_VERSION}.tgz"
|
||||||
|
|
||||||
|
mkdir -p "$(dirname "$ROOT/static/$ALPINE_DEST")"
|
||||||
|
cp "$tmp/alpine.min.js" "$ROOT/static/$ALPINE_DEST"
|
||||||
|
rm -rf "$tmp"
|
||||||
|
trap - EXIT INT TERM
|
||||||
|
echo "fetch-assets: installed static/$ALPINE_DEST ($want)"
|
||||||
|
}
|
||||||
|
|
||||||
|
# Re-check every manifest entry against what is now on disk, so an entry
|
||||||
|
# no script installs fails loudly instead of passing silently.
|
||||||
|
verify_manifest() {
|
||||||
|
while read -r want path; do
|
||||||
|
case "$want" in '' | '#'*) continue ;; esac
|
||||||
|
if [ ! -f "$ROOT/static/$path" ]; then
|
||||||
|
echo "fetch-assets: $MANIFEST lists static/$path, which is missing" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
verify "$ROOT/static/$path" "$want" "static/$path"
|
||||||
|
done <"$ROOT/$MANIFEST"
|
||||||
|
}
|
||||||
|
|
||||||
|
main() {
|
||||||
|
cd "$ROOT"
|
||||||
|
fetch_alpine
|
||||||
|
verify_manifest
|
||||||
|
echo "fetch-assets: all assets in $MANIFEST verified"
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
47
script/lint
47
script/lint
@@ -1,12 +1,55 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# script/lint: run the linter.
|
# script/lint: run the linter. golangci-lint is never installed locally: it
|
||||||
|
# runs via docker only, one way, everywhere — script/lint builds
|
||||||
|
# Dockerfile.lint, which COPYs the repo into the pinned golangci-lint image
|
||||||
|
# and lints as a build step. This works even when the docker daemon is remote
|
||||||
|
# and bind mounts are impossible, and it removes the host linter's shared
|
||||||
|
# cache, which has attributed other checkouts' findings to this one.
|
||||||
|
#
|
||||||
|
# --no-cache-filter=lint forces the lint stage to re-execute on every run; a
|
||||||
|
# cached lint stage exits 0 in under a second having linted nothing. The deps
|
||||||
|
# stage keeps its cache, so module downloads are not repeated.
|
||||||
|
# --progress=plain keeps the linter's own output visible on success, so a
|
||||||
|
# passing run shows the issue count rather than nothing.
|
||||||
|
# --output=type=cacheonly leaves no image behind to clean up.
|
||||||
|
#
|
||||||
|
# docker silently ignores --no-cache-filter for a stage name that does not
|
||||||
|
# match, so a rename or a typo would restore the cached false green with no
|
||||||
|
# warning and a fast exit 0. The flag is therefore not trusted: the build
|
||||||
|
# output is teed to a log and a run is only a pass if golangci-lint's own
|
||||||
|
# summary line ("N issues." / "N issues:") is in it. No summary, no lint,
|
||||||
|
# whatever the exit code says.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
main() {
|
main() {
|
||||||
cd "$ROOT"
|
cd "$ROOT"
|
||||||
golangci-lint run --config .golangci.yml ./...
|
|
||||||
|
log="$(mktemp -t webhooker-lint.XXXXXXXX)"
|
||||||
|
rcfile="$(mktemp -t webhooker-lint-rc.XXXXXXXX)"
|
||||||
|
trap 'rm -f "$log" "$rcfile"' EXIT INT TERM
|
||||||
|
|
||||||
|
# The pipeline's status is tee's, and POSIX sh has no pipefail, so the
|
||||||
|
# build's status travels via a file. Output still streams live.
|
||||||
|
{
|
||||||
|
docker build \
|
||||||
|
-f Dockerfile.lint \
|
||||||
|
--no-cache-filter=lint \
|
||||||
|
--progress=plain \
|
||||||
|
--output=type=cacheonly \
|
||||||
|
. 2>&1 && echo 0 >"$rcfile" || echo $? >"$rcfile"
|
||||||
|
} | tee "$log" >&2
|
||||||
|
|
||||||
|
rc="$(cat "$rcfile")"
|
||||||
|
[ "$rc" -eq 0 ] || exit "$rc"
|
||||||
|
|
||||||
|
if ! grep -qE '[0-9]+ issues[.:]' "$log"; then
|
||||||
|
echo "script/lint: golangci-lint printed no summary line; the linter" >&2
|
||||||
|
echo " did not run. Check that the stage named in --no-cache-filter" >&2
|
||||||
|
echo " still matches a stage in Dockerfile.lint." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
main "$@"
|
main "$@"
|
||||||
|
|||||||
5
static/js/alpine.min.js
vendored
5
static/js/alpine.min.js
vendored
File diff suppressed because one or more lines are too long
1
static/vendor.sha256
Normal file
1
static/vendor.sha256
Normal file
@@ -0,0 +1 @@
|
|||||||
|
3ed1eed252488921df65e363d6715deb04d7f92aaedb9e52199fdf73cb1e0ad3 js/alpine.min.js
|
||||||
92
static/vendor_test.go
Normal file
92
static/vendor_test.go
Normal file
@@ -0,0 +1,92 @@
|
|||||||
|
package static_test
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bufio"
|
||||||
|
"crypto/sha256"
|
||||||
|
"encoding/hex"
|
||||||
|
"os"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"github.com/stretchr/testify/require"
|
||||||
|
|
||||||
|
"sneak.berlin/go/webhooker/static"
|
||||||
|
)
|
||||||
|
|
||||||
|
const manifestPath = "vendor.sha256"
|
||||||
|
|
||||||
|
// fetchHint is appended to every failure here: the assets the manifest
|
||||||
|
// covers are fetched by the build, not committed, so a fresh clone that
|
||||||
|
// has not run script/fetch-assets fails this test and should be told why.
|
||||||
|
const fetchHint = "run `script/fetch-assets` (or `make assets`) to install " +
|
||||||
|
"the pinned third-party assets"
|
||||||
|
|
||||||
|
// TestVendoredAssetsMatchManifest asserts that every asset listed in
|
||||||
|
// static/vendor.sha256 is embedded in the binary with exactly the pinned
|
||||||
|
// bytes. script/fetch-assets verifies the same hashes at download time;
|
||||||
|
// this test verifies them again on what actually ships, so a build that
|
||||||
|
// skipped, cached, or subverted the fetch cannot produce a binary serving
|
||||||
|
// unpinned third-party JavaScript.
|
||||||
|
func TestVendoredAssetsMatchManifest(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
entries := readManifest(t)
|
||||||
|
require.NotEmpty(t, entries, "%s lists no assets", manifestPath)
|
||||||
|
|
||||||
|
for path, want := range entries {
|
||||||
|
t.Run(path, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
data, err := static.Static.ReadFile(path)
|
||||||
|
require.NoErrorf(
|
||||||
|
t, err,
|
||||||
|
"%s is listed in %s but is not embedded; %s",
|
||||||
|
path, manifestPath, fetchHint,
|
||||||
|
)
|
||||||
|
|
||||||
|
sum := sha256.Sum256(data)
|
||||||
|
got := hex.EncodeToString(sum[:])
|
||||||
|
require.Equalf(
|
||||||
|
t, want, got,
|
||||||
|
"embedded %s does not match its pinned sha256 in %s; %s",
|
||||||
|
path, manifestPath, fetchHint,
|
||||||
|
)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// readManifest parses static/vendor.sha256, which is in sha256sum(1)
|
||||||
|
// format with paths relative to static/.
|
||||||
|
func readManifest(t *testing.T) map[string]string {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
f, err := os.Open(manifestPath)
|
||||||
|
require.NoError(t, err, "opening %s", manifestPath)
|
||||||
|
|
||||||
|
defer func() { require.NoError(t, f.Close()) }()
|
||||||
|
|
||||||
|
entries := make(map[string]string)
|
||||||
|
scanner := bufio.NewScanner(f)
|
||||||
|
|
||||||
|
for scanner.Scan() {
|
||||||
|
line := strings.TrimSpace(scanner.Text())
|
||||||
|
if line == "" || strings.HasPrefix(line, "#") {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
|
||||||
|
fields := strings.Fields(line)
|
||||||
|
require.Lenf(
|
||||||
|
t, fields, 2,
|
||||||
|
"%s: malformed entry %q, want \"<sha256> <path>\"",
|
||||||
|
manifestPath, line,
|
||||||
|
)
|
||||||
|
|
||||||
|
sum, path := fields[0], fields[1]
|
||||||
|
require.Lenf(t, sum, 64, "%s: %q is not a sha256", manifestPath, sum)
|
||||||
|
entries[path] = sum
|
||||||
|
}
|
||||||
|
|
||||||
|
require.NoError(t, scanner.Err(), "reading %s", manifestPath)
|
||||||
|
|
||||||
|
return entries
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user