diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 00000000000..5d9d34dfdd2 --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,51 @@ +name: ci + +on: + pull_request: + branches: [main] + +jobs: + format: + name: Style + runs-on: ubuntu-latest + + steps: + - name: Check out code + uses: actions/checkout@v6 + + - name: Set up Go + uses: actions/setup-go@v6 + with: + go-version: "1.27.1" + + - name: Install staticcheck + run: go install honnef.co/go/tools/cmd/staticcheck@latest + + - name: Format + run: test -z $(go fmt ./...) + + - name: Staticcheck + run: staticcheck ./... + + + tests: + name: Tests + runs-on: ubuntu-latest + + steps: + - name: Check out code + uses: actions/checkout@v6 + + - name: Set up Go + uses: actions/setup-go@v6 + with: + go-version: "1.27.1" + + - name: Install gosec + run: go install github.com/securego/gosec/v2/cmd/gosec@latest + + - name: Gosec + run: gosec ./... + + - name: Finish + run: go test -v -coverprofile=coverage.out -covermode=atomic ./... diff --git a/README.md b/README.md index c2bec0368b7..ce582a0ad43 100644 --- a/README.md +++ b/README.md @@ -1,3 +1,6 @@ +![Tests Status](https://github.com/marioblnn/cicd/actions/workflows/ci.yml/badge.svg) + + # learn-cicd-starter (Notely) This repo contains the starter code for the "Notely" application for the "Learn CICD" course on [Boot.dev](https://boot.dev). @@ -18,6 +21,8 @@ Run the server: go build -o notely && ./notely ``` -*This starts the server in non-database mode.* It will serve a simple webpage at `http://localhost:8080`. +_This starts the server in non-database mode._ It will serve a simple webpage at `http://localhost:8080`. + +You do _not_ need to set up a database or any interactivity on the webpage yet. Instructions for that will come later in the course! -You do *not* need to set up a database or any interactivity on the webpage yet. Instructions for that will come later in the course! +Mario's version of Boot.dev's Notely app. diff --git a/internal/auth/get_api_key_test.go b/internal/auth/get_api_key_test.go new file mode 100644 index 00000000000..096019ebb27 --- /dev/null +++ b/internal/auth/get_api_key_test.go @@ -0,0 +1,75 @@ +package auth + +import ( + "errors" + "net/http" + "testing" +) + +func TestGetAPIKey(t *testing.T) { + tests := []struct { + name string + headers http.Header + expectedKey string + expectedErr error + }{ + { + name: "Valid API Key", + headers: http.Header{ + "Authorization": []string{"ApiKey my-secret-key-123"}, + }, + expectedKey: "my-secret-key-123", + expectedErr: nil, + }, + { + name: "No Authorization Header", + headers: http.Header{}, + expectedKey: "", + expectedErr: ErrNoAuthHeaderIncluded, + }, + { + name: "Empty Authorization Header", + headers: http.Header{ + "Authorization": []string{""}, + }, + expectedKey: "", + expectedErr: ErrNoAuthHeaderIncluded, + }, + { + name: "Malformed Header - Wrong Prefix", + headers: http.Header{ + "Authorization": []string{"Bearer my-secret-key-123"}, + }, + expectedKey: "", + expectedErr: errors.New("malformed authorization header"), + }, + { + name: "Malformed Header - Missing Key", + headers: http.Header{ + "Authorization": []string{"ApiKey"}, + }, + expectedKey: "", + expectedErr: errors.New("malformed authorization header"), + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + key, err := GetAPIKey(tt.headers) + + if key != tt.expectedKey { + t.Errorf("expected key %q, got %q", tt.expectedKey, key) + } + + if tt.expectedErr != nil { + if err == nil { + t.Errorf("expected error %q, got nil", tt.expectedErr.Error()) + } else if err.Error() != tt.expectedErr.Error() { + t.Errorf("expected error %q, got %q", tt.expectedErr.Error(), err.Error()) + } + } else if err != nil { + t.Errorf("expected no error, got %q", err.Error()) + } + }) + } +} diff --git a/json.go b/json.go index 1e6e7985e18..893e3b2ec3f 100644 --- a/json.go +++ b/json.go @@ -30,5 +30,9 @@ func respondWithJSON(w http.ResponseWriter, code int, payload interface{}) { return } w.WriteHeader(code) - w.Write(dat) + _, err = w.Write(dat) + if err != nil { + log.Printf("Error writing JSON response: %s", err) + return + } } diff --git a/main.go b/main.go index 19d7366c5f7..3d4ecfd2a77 100644 --- a/main.go +++ b/main.go @@ -7,6 +7,7 @@ import ( "log" "net/http" "os" + "strings" "github.com/go-chi/chi" "github.com/go-chi/cors" @@ -89,10 +90,12 @@ func main() { router.Mount("/v1", v1Router) srv := &http.Server{ - Addr: ":" + port, - Handler: router, + Addr: ":" + port, + Handler: router, + ReadHeaderTimeout: 5 * 60, } - - log.Printf("Serving on port: %s\n", port) + sanitizedPort := strings.ReplaceAll(port, "\n", "") + sanitizedPort = strings.ReplaceAll(sanitizedPort, "\r", "") + log.Printf("Serving on port: %s\n", sanitizedPort) log.Fatal(srv.ListenAndServe()) }