Addresses errcheck, gosec, revive, staticcheck, and unused findings
across the codebase (unchecked error returns, unsafe file inclusion
warnings on operator/test-controlled paths, missing package comments,
unused parameters, deprecated API usage). Also fixes two suppression
comments that were silently no-ops due to wrong syntax (#nosec needs
a leading '#', nolint reasons need '//' not '--').
With the backlog clear, drop continue-on-error from the CI lint job
per the plan left in b4b4806.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- CORS config is now actually applied to the router (the middleware
existed but was never wired); preflight returns 204 for allowed
origins and 403 with no CORS headers for disallowed ones.
- /readyz runs real dependency checks (queue, auth database) and
returns 503 with per-component detail when not ready; exported
handlers support dedicated health listeners.
- Optional server.tls (cert_file/key_file) for REST and gRPC, validated
at config load.
- 5xx responses no longer echo internal error details; not-found and
already-sent map to 404/409 on cancel/retry.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
After conflict resolution from rebase, some imports were accidentally
removed and the CORS middleware function was eliminated but still
referenced by tests. This commit:
- Adds fmt import to api/rest/keys.go (used for error messages)
- Adds gorilla/mux import to cmd/server/main.go (used for router type)
- Restores newCORSMiddleware function to api/rest/router.go for test compatibility
- Formats code with gofmt