Closes the gaps and the one security finding from the second end-to-end
CLI test (E2E_STASH_REPORT.md), plus the H1 boot-regression found while
re-reviewing those fixes.
Security
- S6: reserved-path validation (`check_reserved`) now case-folds before
comparing, so `/API/v2/x`, `/HEALTHZ`, `/Admin/x` are rejected like
their lowercase forms. Request-time matching stays case-sensitive.
- S10: "public route != public data" callout in sdk-shape.md (script_gate
skips authz when the principal is anonymous).
Observability / features
- G1: trigger executions now write `execution_logs`. Migration 0043 adds
a `source` column (CHECK mirrors ExecutionSource/OutboxSourceKind,
DEFAULT 'http' backfills history); a shared `build_execution_log` helper
in executor-core; dispatcher logging for outbox triggers + queue
consumers (skips sync-HTTP rows the orchestrator already logs). `pic
logs` gains a source column + `--source` filter.
- G5: dev-only in-memory email capture under PICLOUD_DEV_MODE with no SMTP
(email::send succeeds locally), readable at GET /api/v1/admin/dev/emails
(Owner/Admin only; route mounted only in capture mode).
- G6: generalized the Rhai in-place-mutation footgun note (trim/replace/
make_upper/make_lower/crop/truncate/pad return ()).
- G2/G3/G4 (CLI): `pic members`, `pic files`, `pic queues`, read-only
`pic kv` (+ new kv_api.rs); `pic deploy --timeout/--memory/--kind/
--sandbox`; first-class `pic triggers create-{docs,files,pubsub,queue,
email}` wrappers. All new client path segments percent-encoded via seg().
H1 regression fix (found in re-review)
- The S6 change also runs in `compile_routes`, which compiles every stored
route at boot and on each route CRUD. A single stored route the new
validation rejects (creatable while the S6 gap existed) made the whole
compile Err and aborted startup. `compile_routes` is now lenient: it
skips an un-compilable row with a warning instead of bricking boot
(route creation still validates separately). Migration 0044 sweeps
pre-existing reserved-path routes on upgrade (WHERE mirrors
check_reserved exactly). Added regression tests for both.
Verified: cargo fmt, clippy --all-targets --all-features -D warnings, the
schema_snapshot test, and the new S6/lenient-compile unit tests all pass;
boot-resilience and G1/G5 confirmed live.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
49 lines
1.6 KiB
Rust
49 lines
1.6 KiB
Rust
//! `GET /api/v1/admin/dev/emails` — dev-only inspection of mail captured
|
|
//! by the in-memory email sink (G5).
|
|
//!
|
|
//! Mounted **only** when the email service is running in dev-capture mode
|
|
//! (`PICLOUD_DEV_MODE=true` and no SMTP relay configured). In every other
|
|
//! configuration the route does not exist, so there is no production
|
|
//! surface here. Capture is instance-wide (the SMTP transport seam can't
|
|
//! see a script's `app_id`), so the endpoint is instance-wide too and is
|
|
//! restricted to instance Owners/Admins.
|
|
|
|
use std::sync::Arc;
|
|
|
|
use axum::extract::State;
|
|
use axum::http::StatusCode;
|
|
use axum::response::Json;
|
|
use axum::routing::get;
|
|
use axum::{Extension, Router};
|
|
use picloud_shared::{InstanceRole, Principal};
|
|
|
|
use crate::email_service::{CapturedEmail, DevEmailSink};
|
|
|
|
#[derive(Clone)]
|
|
pub struct DevEmailState {
|
|
pub sink: Arc<DevEmailSink>,
|
|
}
|
|
|
|
/// Build the dev-email router. Callers mount this only when dev-capture
|
|
/// mode is active (i.e. they hold a `Some(sink)`).
|
|
pub fn dev_emails_router(state: DevEmailState) -> Router {
|
|
Router::new()
|
|
.route("/dev/emails", get(list_dev_emails))
|
|
.with_state(state)
|
|
}
|
|
|
|
async fn list_dev_emails(
|
|
Extension(principal): Extension<Principal>,
|
|
State(state): State<DevEmailState>,
|
|
) -> Result<Json<Vec<CapturedEmail>>, StatusCode> {
|
|
// Instance-wide data → require an instance Owner/Admin. A Member
|
|
// (app-scoped) principal has no business reading every app's mail.
|
|
if !matches!(
|
|
principal.instance_role,
|
|
InstanceRole::Owner | InstanceRole::Admin
|
|
) {
|
|
return Err(StatusCode::FORBIDDEN);
|
|
}
|
|
Ok(Json(state.sink.snapshot()))
|
|
}
|