From c13a79ca053e16993a4dcaff73fc090ba50c914f Mon Sep 17 00:00:00 2001 From: marioblnn Date: Tue, 1 Sep 2026 18:00:42 +0300 Subject: [PATCH 01/13] Readme changes --- README.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index c2bec0368b7..a41f90f6190 100644 --- a/README.md +++ b/README.md @@ -18,6 +18,8 @@ Run the server: go build -o notely && ./notely ``` -*This starts the server in non-database mode.* It will serve a simple webpage at `http://localhost:8080`. +_This starts the server in non-database mode._ It will serve a simple webpage at `http://localhost:8080`. -You do *not* need to set up a database or any interactivity on the webpage yet. Instructions for that will come later in the course! +You do _not_ need to set up a database or any interactivity on the webpage yet. Instructions for that will come later in the course! + +Mario's version of Boot.dev's Notely app. From 4199048cd04833f8f9f1c3c3c2b2727908def5e3 Mon Sep 17 00:00:00 2001 From: marioblnn Date: Sun, 6 Sep 2026 15:04:31 +0300 Subject: [PATCH 02/13] added CI test --- .github/ci.yml | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 .github/ci.yml diff --git a/.github/ci.yml b/.github/ci.yml new file mode 100644 index 00000000000..679535cc34d --- /dev/null +++ b/.github/ci.yml @@ -0,0 +1,22 @@ +name: ci + +on: + pull_request: + branches: [main] + +jobs: + tests: + name: Tests + runs-on: ubuntu-latest + + steps: + - name: Check out code + uses: actions/checkout@v6 + + - name: Set up Go + uses: actions/setup-go@v6 + with: + go-version: "1.27.1" + + - name: Force Failure + run: (exit 1) \ No newline at end of file From 112c1b7135488b60d3239fdd864b8507feffdf4b Mon Sep 17 00:00:00 2001 From: marioblnn Date: Sun, 6 Sep 2026 15:11:07 +0300 Subject: [PATCH 03/13] added ci tests in workflows --- .github/workflows/ci.yml | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 .github/workflows/ci.yml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 00000000000..2e1aaee2918 --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,22 @@ +name: ci + +on: + pull_request: + branches: [main] + +jobs: + tests: + name: Tests + runs-on: ubuntu-latest + + steps: + - name: Check out code + uses: actions/checkout@v6 + + - name: Set up Go + uses: actions/setup-go@v6 + with: + go-version: "1.27.1" + + - name: Force Failure + run: (exit 1) From d3df296dcad2a5552054471a7ef37ce80392ccb5 Mon Sep 17 00:00:00 2001 From: marioblnn Date: Mon, 7 Sep 2026 16:54:35 +0300 Subject: [PATCH 04/13] Changed CI test --- .github/ci.yml | 22 ---------------------- .github/workflows/ci.yml | 4 ++-- 2 files changed, 2 insertions(+), 24 deletions(-) delete mode 100644 .github/ci.yml diff --git a/.github/ci.yml b/.github/ci.yml deleted file mode 100644 index 679535cc34d..00000000000 --- a/.github/ci.yml +++ /dev/null @@ -1,22 +0,0 @@ -name: ci - -on: - pull_request: - branches: [main] - -jobs: - tests: - name: Tests - runs-on: ubuntu-latest - - steps: - - name: Check out code - uses: actions/checkout@v6 - - - name: Set up Go - uses: actions/setup-go@v6 - with: - go-version: "1.27.1" - - - name: Force Failure - run: (exit 1) \ No newline at end of file diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2e1aaee2918..5d688ebf426 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -18,5 +18,5 @@ jobs: with: go-version: "1.27.1" - - name: Force Failure - run: (exit 1) + - name: Finish + run: (exit 0) From 86176ebdbdc6fb00476901f991dc00bec65a9f25 Mon Sep 17 00:00:00 2001 From: marioblnn Date: Mon, 7 Sep 2026 19:07:51 +0300 Subject: [PATCH 05/13] added unit tests --- .github/workflows/ci.yml | 2 +- internal/auth/get_api_key_test.go | 75 +++++++++++++++++++++++++++++++ 2 files changed, 76 insertions(+), 1 deletion(-) create mode 100644 internal/auth/get_api_key_test.go diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 5d688ebf426..5972dfc3181 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -19,4 +19,4 @@ jobs: go-version: "1.27.1" - name: Finish - run: (exit 0) + run: go test ./.... \ No newline at end of file diff --git a/internal/auth/get_api_key_test.go b/internal/auth/get_api_key_test.go new file mode 100644 index 00000000000..fdaf9435d8a --- /dev/null +++ b/internal/auth/get_api_key_test.go @@ -0,0 +1,75 @@ +package auth + +import ( + "errors" + "net/http" + "testing" +) + +func TestGetAPIKey(t *testing.T) { + tests := []struct { + name string + headers http.Header + expectedKey string + expectedErr error + }{ + { + name: "Valid API Key", + headers: http.Header{ + "Authorization": []string{"ApiKey my-secret-key-123"}, + }, + expectedKey: "my-secret-key-123", + expectedErr: nil, + }, + { + name: "No Authorization Header", + headers: http.Header{}, + expectedKey: "", + expectedErr: ErrNoAuthHeaderIncluded, + }, + { + name: "Empty Authorization Header", + headers: http.Header{ + "Authorization": []string{""}, + }, + expectedKey: "", + expectedErr: ErrNoAuthHeaderIncluded, + }, + { + name: "Malformed Header - Wrong Prefix", + headers: http.Header{ + "Authorization": []string{"Bearer my-secret-key-123"}, + }, + expectedKey: "", + expectedErr: errors.New("malformed authorization header"), + }, + { + name: "Malformed Header - Missing Key", + headers: http.Header{ + "Authorization": []string{"ApiKey"}, + }, + expectedKey: "", + expectedErr: errors.New("malformed authorization header"), + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + key, err := GetAPIKey(tt.headers) + + if key != tt.expectedKey { + t.Errorf("expected key %q, got %q", tt.expectedKey, key) + } + + if tt.expectedErr != nil { + if err == nil { + t.Errorf("expected error %q, got nil", tt.expectedErr.Error()) + } else if err.Error() != tt.expectedErr.Error() { + t.Errorf("expected error %q, got %q", tt.expectedErr.Error(), err.Error()) + } + } else if err != nil { + t.Errorf("expected no error, got %q", err.Error()) + } + }) + } +} From 0928226c292052908de8c0b88cbbf0c77ccd2cd0 Mon Sep 17 00:00:00 2001 From: marioblnn Date: Mon, 7 Sep 2026 19:18:37 +0300 Subject: [PATCH 06/13] Code coverage impl --- .github/workflows/ci.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 5972dfc3181..4bcc749199f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -19,4 +19,4 @@ jobs: go-version: "1.27.1" - name: Finish - run: go test ./.... \ No newline at end of file + run: go test -v -coverprofile=coverage.out -covermode=atomic ./... From cf3dc4aca0f6dec4c8315db0b259a0ce6d78ddee Mon Sep 17 00:00:00 2001 From: marioblnn Date: Mon, 7 Sep 2026 19:32:36 +0300 Subject: [PATCH 07/13] readme changes --- README.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/README.md b/README.md index a41f90f6190..ce582a0ad43 100644 --- a/README.md +++ b/README.md @@ -1,3 +1,6 @@ +![Tests Status](https://github.com/marioblnn/cicd/actions/workflows/ci.yml/badge.svg) + + # learn-cicd-starter (Notely) This repo contains the starter code for the "Notely" application for the "Learn CICD" course on [Boot.dev](https://boot.dev). From 4ab904130df88c06f5dc3d94cfe10e7452ec7c6d Mon Sep 17 00:00:00 2001 From: marioblnn Date: Tue, 8 Sep 2026 13:40:49 +0300 Subject: [PATCH 08/13] Formatting checks --- .github/workflows/ci.yml | 17 ++++ internal/auth/get_api_key_test.go | 150 +++++++++++++++--------------- 2 files changed, 92 insertions(+), 75 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4bcc749199f..d16648cdcdf 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -5,6 +5,23 @@ on: branches: [main] jobs: + format: + name: Format + runs-on: ubuntu-latest + + steps: + - name: Check out code + uses: actions/checkout@v6 + + - name: Set up Go + uses: actions/setup-go@v6 + with: + go-version: "1.27.1" + + - name: Format + run: test -z $(go fmt ./...) + + tests: name: Tests runs-on: ubuntu-latest diff --git a/internal/auth/get_api_key_test.go b/internal/auth/get_api_key_test.go index fdaf9435d8a..096019ebb27 100644 --- a/internal/auth/get_api_key_test.go +++ b/internal/auth/get_api_key_test.go @@ -1,75 +1,75 @@ -package auth - -import ( - "errors" - "net/http" - "testing" -) - -func TestGetAPIKey(t *testing.T) { - tests := []struct { - name string - headers http.Header - expectedKey string - expectedErr error - }{ - { - name: "Valid API Key", - headers: http.Header{ - "Authorization": []string{"ApiKey my-secret-key-123"}, - }, - expectedKey: "my-secret-key-123", - expectedErr: nil, - }, - { - name: "No Authorization Header", - headers: http.Header{}, - expectedKey: "", - expectedErr: ErrNoAuthHeaderIncluded, - }, - { - name: "Empty Authorization Header", - headers: http.Header{ - "Authorization": []string{""}, - }, - expectedKey: "", - expectedErr: ErrNoAuthHeaderIncluded, - }, - { - name: "Malformed Header - Wrong Prefix", - headers: http.Header{ - "Authorization": []string{"Bearer my-secret-key-123"}, - }, - expectedKey: "", - expectedErr: errors.New("malformed authorization header"), - }, - { - name: "Malformed Header - Missing Key", - headers: http.Header{ - "Authorization": []string{"ApiKey"}, - }, - expectedKey: "", - expectedErr: errors.New("malformed authorization header"), - }, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - key, err := GetAPIKey(tt.headers) - - if key != tt.expectedKey { - t.Errorf("expected key %q, got %q", tt.expectedKey, key) - } - - if tt.expectedErr != nil { - if err == nil { - t.Errorf("expected error %q, got nil", tt.expectedErr.Error()) - } else if err.Error() != tt.expectedErr.Error() { - t.Errorf("expected error %q, got %q", tt.expectedErr.Error(), err.Error()) - } - } else if err != nil { - t.Errorf("expected no error, got %q", err.Error()) - } - }) - } -} +package auth + +import ( + "errors" + "net/http" + "testing" +) + +func TestGetAPIKey(t *testing.T) { + tests := []struct { + name string + headers http.Header + expectedKey string + expectedErr error + }{ + { + name: "Valid API Key", + headers: http.Header{ + "Authorization": []string{"ApiKey my-secret-key-123"}, + }, + expectedKey: "my-secret-key-123", + expectedErr: nil, + }, + { + name: "No Authorization Header", + headers: http.Header{}, + expectedKey: "", + expectedErr: ErrNoAuthHeaderIncluded, + }, + { + name: "Empty Authorization Header", + headers: http.Header{ + "Authorization": []string{""}, + }, + expectedKey: "", + expectedErr: ErrNoAuthHeaderIncluded, + }, + { + name: "Malformed Header - Wrong Prefix", + headers: http.Header{ + "Authorization": []string{"Bearer my-secret-key-123"}, + }, + expectedKey: "", + expectedErr: errors.New("malformed authorization header"), + }, + { + name: "Malformed Header - Missing Key", + headers: http.Header{ + "Authorization": []string{"ApiKey"}, + }, + expectedKey: "", + expectedErr: errors.New("malformed authorization header"), + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + key, err := GetAPIKey(tt.headers) + + if key != tt.expectedKey { + t.Errorf("expected key %q, got %q", tt.expectedKey, key) + } + + if tt.expectedErr != nil { + if err == nil { + t.Errorf("expected error %q, got nil", tt.expectedErr.Error()) + } else if err.Error() != tt.expectedErr.Error() { + t.Errorf("expected error %q, got %q", tt.expectedErr.Error(), err.Error()) + } + } else if err != nil { + t.Errorf("expected no error, got %q", err.Error()) + } + }) + } +} From 3d08feb0a8db6c9b7f5539809dd0ceb2c0484c58 Mon Sep 17 00:00:00 2001 From: marioblnn Date: Tue, 8 Sep 2026 13:43:55 +0300 Subject: [PATCH 09/13] Formatting ci test rename --- .github/workflows/ci.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d16648cdcdf..0d03155ff44 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -6,7 +6,7 @@ on: jobs: format: - name: Format + name: Style runs-on: ubuntu-latest steps: From fb0ba7ae38768186a658712e52b0ecbee814ef1c Mon Sep 17 00:00:00 2001 From: marioblnn Date: Tue, 8 Sep 2026 13:57:29 +0300 Subject: [PATCH 10/13] Static check --- .github/workflows/ci.yml | 8 +++++++- internal/auth/auth.go | 5 +++++ 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 0d03155ff44..2d1f2749f4d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -8,7 +8,7 @@ jobs: format: name: Style runs-on: ubuntu-latest - + steps: - name: Check out code uses: actions/checkout@v6 @@ -18,9 +18,15 @@ jobs: with: go-version: "1.27.1" + - name: Install staticcheck + run: go install honnef.co/go/tools/cmd/staticcheck@latest + - name: Format run: test -z $(go fmt ./...) + - name: Staticcheck + run: staticcheck ./... + tests: name: Tests diff --git a/internal/auth/auth.go b/internal/auth/auth.go index f969aacf638..6c20464f228 100644 --- a/internal/auth/auth.go +++ b/internal/auth/auth.go @@ -21,3 +21,8 @@ func GetAPIKey(headers http.Header) (string, error) { return splitAuth[1], nil } + +func unused() { + // this function does nothing + // and is called nowhere +} From 609510859d5b3e290a5b9b3ada57477f54817cc1 Mon Sep 17 00:00:00 2001 From: marioblnn Date: Tue, 8 Sep 2026 13:59:27 +0300 Subject: [PATCH 11/13] removed unused function --- internal/auth/auth.go | 5 ----- 1 file changed, 5 deletions(-) diff --git a/internal/auth/auth.go b/internal/auth/auth.go index 6c20464f228..f969aacf638 100644 --- a/internal/auth/auth.go +++ b/internal/auth/auth.go @@ -21,8 +21,3 @@ func GetAPIKey(headers http.Header) (string, error) { return splitAuth[1], nil } - -func unused() { - // this function does nothing - // and is called nowhere -} From 3b86c2368ee1bb4ab079f6d6c7cb146c4b202e7f Mon Sep 17 00:00:00 2001 From: marioblnn Date: Tue, 8 Sep 2026 15:01:26 +0300 Subject: [PATCH 12/13] Added gosec --- .github/workflows/ci.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2d1f2749f4d..5d9d34dfdd2 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -41,5 +41,11 @@ jobs: with: go-version: "1.27.1" + - name: Install gosec + run: go install github.com/securego/gosec/v2/cmd/gosec@latest + + - name: Gosec + run: gosec ./... + - name: Finish run: go test -v -coverprofile=coverage.out -covermode=atomic ./... From f8ffd71a6c5293bfbc0c4b2da41703986c400e72 Mon Sep 17 00:00:00 2001 From: marioblnn Date: Tue, 8 Sep 2026 15:16:21 +0300 Subject: [PATCH 13/13] security features impl --- json.go | 6 +++++- main.go | 11 +++++++---- 2 files changed, 12 insertions(+), 5 deletions(-) diff --git a/json.go b/json.go index 1e6e7985e18..893e3b2ec3f 100644 --- a/json.go +++ b/json.go @@ -30,5 +30,9 @@ func respondWithJSON(w http.ResponseWriter, code int, payload interface{}) { return } w.WriteHeader(code) - w.Write(dat) + _, err = w.Write(dat) + if err != nil { + log.Printf("Error writing JSON response: %s", err) + return + } } diff --git a/main.go b/main.go index 19d7366c5f7..3d4ecfd2a77 100644 --- a/main.go +++ b/main.go @@ -7,6 +7,7 @@ import ( "log" "net/http" "os" + "strings" "github.com/go-chi/chi" "github.com/go-chi/cors" @@ -89,10 +90,12 @@ func main() { router.Mount("/v1", v1Router) srv := &http.Server{ - Addr: ":" + port, - Handler: router, + Addr: ":" + port, + Handler: router, + ReadHeaderTimeout: 5 * 60, } - - log.Printf("Serving on port: %s\n", port) + sanitizedPort := strings.ReplaceAll(port, "\n", "") + sanitizedPort = strings.ReplaceAll(sanitizedPort, "\r", "") + log.Printf("Serving on port: %s\n", sanitizedPort) log.Fatal(srv.ListenAndServe()) }