All checks were successful
CI / build-test (push) Successful in 1m28s
- Protect `/webhook` endpoint using the `Authorization` header - Update `README.md` with setup instructions and examples for authentication - Warn when `WEBHOOK_SECRET` is not configured - Add tests for valid, missing, and invalid token scenarios - Update `docker-compose.yml` to support `WEBHOOK_SECRET` configuration
72 lines
1.6 KiB
Go
72 lines
1.6 KiB
Go
package main
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"log"
|
|
"net/http"
|
|
"os"
|
|
"os/signal"
|
|
"syscall"
|
|
"time"
|
|
|
|
diun "awesomeProject/pkg/diunwebhook"
|
|
)
|
|
|
|
func main() {
|
|
if err := diun.InitDB("./diun.db"); err != nil {
|
|
log.Fatalf("InitDB: %v", err)
|
|
}
|
|
|
|
secret := os.Getenv("WEBHOOK_SECRET")
|
|
if secret == "" {
|
|
log.Println("WARNING: WEBHOOK_SECRET not set — webhook endpoint is unprotected")
|
|
} else {
|
|
diun.SetWebhookSecret(secret)
|
|
log.Println("Webhook endpoint protected with token authentication")
|
|
}
|
|
|
|
port := os.Getenv("PORT")
|
|
if port == "" {
|
|
port = "8080"
|
|
}
|
|
|
|
mux := http.NewServeMux()
|
|
mux.HandleFunc("/webhook", diun.WebhookHandler)
|
|
mux.HandleFunc("/api/updates/", diun.DismissHandler)
|
|
mux.HandleFunc("/api/updates", diun.UpdatesHandler)
|
|
mux.HandleFunc("/api/tags", diun.TagsHandler)
|
|
mux.HandleFunc("/api/tags/", diun.TagByIDHandler)
|
|
mux.HandleFunc("/api/tag-assignments", diun.TagAssignmentHandler)
|
|
mux.Handle("/", http.FileServer(http.Dir("./frontend/dist")))
|
|
|
|
srv := &http.Server{
|
|
Addr: ":" + port,
|
|
Handler: mux,
|
|
ReadTimeout: 10 * time.Second,
|
|
WriteTimeout: 10 * time.Second,
|
|
IdleTimeout: 60 * time.Second,
|
|
}
|
|
|
|
stop := make(chan os.Signal, 1)
|
|
signal.Notify(stop, syscall.SIGINT, syscall.SIGTERM)
|
|
|
|
go func() {
|
|
log.Printf("Listening on :%s", port)
|
|
if err := srv.ListenAndServe(); err != nil && !errors.Is(err, http.ErrServerClosed) {
|
|
log.Fatalf("ListenAndServe: %v", err)
|
|
}
|
|
}()
|
|
|
|
<-stop
|
|
|
|
ctx, cancel := context.WithTimeout(context.Background(), 15*time.Second)
|
|
defer cancel()
|
|
|
|
if err := srv.Shutdown(ctx); err != nil {
|
|
log.Printf("Shutdown error: %v", err)
|
|
} else {
|
|
log.Println("Server stopped cleanly")
|
|
}
|
|
}
|