- CORS config is now actually applied to the router (the middleware
existed but was never wired); preflight returns 204 for allowed
origins and 403 with no CORS headers for disallowed ones.
- /readyz runs real dependency checks (queue, auth database) and
returns 503 with per-component detail when not ready; exported
handlers support dedicated health listeners.
- Optional server.tls (cert_file/key_file) for REST and gRPC, validated
at config load.
- 5xx responses no longer echo internal error details; not-found and
already-sent map to 404/409 on cancel/retry.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Store SHA-256 digests (key_hash + key_preview) instead of raw keys, in
both the in-memory store and Postgres; migrate legacy plaintext rows in
place and drop the plaintext column.
- Fix TEXT[] scans that failed at runtime (missing pq.Array) in
GetKey/ListKeys/LoadAllKeys.
- Load persisted keys at startup (InitializeFromDatabase was never called)
and fall back to the database on cache miss, so issued keys survive
restarts.
- Make HybridKeyStore.CreateKey genuinely write-through: cache is only
updated after a successful DB write.
- Guard nil database backend (auth enabled without DB previously panicked
on key creation) and degrade to in-memory operation.
- Persist bootstrap admin keys when a database is configured.
- Record real audit-log details as JSON and log audit failures instead of
silently dropping them; add DB pool limits and ping timeout.
- Sentinel errors matched with errors.Is; unit tests for hashing,
write-through ordering, DB fallback, and nil-DB operation.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Use typed context key for auth context to prevent collisions (auth.go)
- Eliminate nested locking in CheckRateLimit to prevent potential deadlock (auth.go)
- Add 1MB request body size limit middleware to prevent DoS (router.go)
- Return proper gRPC status codes instead of nil errors on failures (handler.go)
- Use key name instead of raw API key in admin URL paths to prevent secret leakage (keys.go, router.go, keystore_db.go, keystore_hybrid.go)
- Enforce RBAC authorization in service Send/SendBatch for both REST and gRPC (service.go)
- Pin runtime Docker image to alpine:3.21 for reproducible builds (Dockerfile)
- Enable readOnlyRootFilesystem with /tmp emptyDir in k8s deployment (deployment.yaml)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
After conflict resolution from rebase, some imports were accidentally
removed and the CORS middleware function was eliminated but still
referenced by tests. This commit:
- Adds fmt import to api/rest/keys.go (used for error messages)
- Adds gorilla/mux import to cmd/server/main.go (used for router type)
- Restores newCORSMiddleware function to api/rest/router.go for test compatibility
- Formats code with gofmt