init
This commit is contained in:
commit
b15b95781c
108 changed files with 14802 additions and 0 deletions
63
docs/agents/handoffs/05-api-keys-fix.md
Normal file
63
docs/agents/handoffs/05-api-keys-fix.md
Normal file
|
|
@ -0,0 +1,63 @@
|
|||
# Agent
|
||||
|
||||
Name: Agent 05 - API Keys And Access Control (fix round)
|
||||
|
||||
Stage: API Keys And Access Control
|
||||
|
||||
Date: 2026-04-14
|
||||
|
||||
## Scope
|
||||
|
||||
Fixed the validation findings for Agent 05 without expanding into the client API stage.
|
||||
|
||||
Completed in this fix round:
|
||||
|
||||
- added explicit anti-cache headers for the one-time raw API key reveal response so the secret-bearing HTML is marked non-cacheable;
|
||||
- changed the immediate post-create detail render to hydrate from the persisted API key record and persisted scope rows while still showing the raw key only on that one response;
|
||||
- extended HTTP integration coverage to verify:
|
||||
- the creation response includes anti-cache headers;
|
||||
- the creation response shows saved name, description, scope mode, permissions, and selected project or tag rules;
|
||||
- the raw key is present on the creation response and absent on later detail loads.
|
||||
|
||||
## Files Changed
|
||||
|
||||
- `/Users/delete/projects/update_server/internal/http/admin_api_keys.go`
|
||||
- `/Users/delete/projects/update_server/internal/http/api_keys_integration_test.go`
|
||||
- `/Users/delete/projects/update_server/docs/agents/handoffs/05-api-keys-fix.md`
|
||||
|
||||
## Database Changes
|
||||
|
||||
- no schema or migration changes were required;
|
||||
- the existing API key hash and scope storage model remains unchanged.
|
||||
|
||||
## API Or Route Changes
|
||||
|
||||
- no routes were added or removed;
|
||||
- `POST /admin/api-keys` now returns the one-time reveal page with explicit anti-cache headers:
|
||||
- `Cache-Control: no-store, private, max-age=0`
|
||||
- `Pragma: no-cache`
|
||||
- `Expires: 0`
|
||||
|
||||
## Commands And Tests Run
|
||||
|
||||
- `gofmt -w internal/http/admin_api_keys.go internal/http/api_keys_integration_test.go` - passed;
|
||||
- `GOCACHE=/tmp/go-build-agent05-fix GOMODCACHE=/tmp/go-mod-agent05-2 go test ./internal/http` - passed;
|
||||
- `GOCACHE=/tmp/go-build-agent05-fix-all GOMODCACHE=/tmp/go-mod-agent05-2 go test ./...` - passed;
|
||||
- `GOCACHE=/tmp/go-build-agent05-fix-build GOMODCACHE=/tmp/go-mod-agent05-2 go build -o /tmp/update-server-agent05-fix ./cmd/server` - passed;
|
||||
- `GOCACHE=/tmp/go-build-agent05-fix-build2 GOMODCACHE=/tmp/go-mod-agent05-2 go build -o /tmp/update-migrate-agent05-fix ./cmd/migrate` - passed.
|
||||
|
||||
## Known Limitations
|
||||
|
||||
- the one-time reveal still intentionally happens on the direct POST response rather than a redirect flow so the raw key never has to enter query strings or persistent storage;
|
||||
- CSRF protection is still not implemented for admin API key forms;
|
||||
- the client `/api/v1` endpoints still do not use the API key middleware yet; that remains for Agent 06.
|
||||
|
||||
## Recommended Next Step
|
||||
|
||||
Agent 06 should wire the existing API key middleware into the client `/api/v1` endpoints for accessible project listing, latest release lookup, and authenticated artifact download.
|
||||
|
||||
## Notes For Validator
|
||||
|
||||
- verify that the post-create response shows persisted saved values immediately, without requiring a manual refresh;
|
||||
- verify that the raw key appears only on the secret-bearing creation response and not on later `GET /admin/api-keys/{id}` detail loads;
|
||||
- verify the one-time reveal response includes the anti-cache headers listed above.
|
||||
Loading…
Add table
Add a link
Reference in a new issue