Files
ExploreDNS/web/api/server.go
T
Gary HansenandClaude Fable 5 111b8bf48e feat(web): harden server for public exposure
- hard per-traversal deadline (EXPLOREDNS_JOB_TIMEOUT, default 5m) so
  every job reaches a terminal state; timed-out jobs report error with
  any partial results instead of masquerading as complete
- cap concurrent traversals (EXPLOREDNS_MAX_JOBS, default 8) returning
  429 when saturated
- CORS off by default (the embedded SPA is same-origin); opt in via
  EXPLOREDNS_CORS_ORIGIN

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 21:50:29 +10:00

118 lines
3.1 KiB
Go

// Package api provides the HTTP API server for ExploreDNS.
//
// The server exposes DNS traversal as a REST service with:
// - POST /api/traverse — start an asynchronous traversal
// - GET /api/traverse/{id} — poll traversal status and results
// - GET /api/traverse/{id}/stream — Server-Sent Events for live progress
// - GET /api/health — health check
//
// Static frontend assets are embedded at compile time and served from /.
// Unknown paths fall back to index.html to support SPA client-side routing.
package api
import (
"context"
"embed"
"fmt"
"io/fs"
"log"
"net"
"net/http"
"os"
"time"
)
//go:embed static
var staticFiles embed.FS
// Server is the HTTP API server.
type Server struct {
addr string
srv *http.Server
cancel context.CancelFunc
}
// NewServer creates a new Server that listens on addr (e.g. ":8080").
func NewServer(addr string) *Server {
return &Server{addr: addr}
}
// Start builds the HTTP handler, begins listening, and returns when the
// server has accepted its first connection or the address is bound.
// Call Shutdown to stop gracefully.
func (s *Server) Start() error {
ctx, cancel := context.WithCancel(context.Background())
s.cancel = cancel
h := newHandler(ctx)
sub, err := fs.Sub(staticFiles, "static")
if err != nil {
return fmt.Errorf("static filesystem: %w", err)
}
h.registerStatic(sub)
s.srv = &http.Server{
Addr: s.addr,
Handler: corsMiddleware(h.mux),
ReadHeaderTimeout: 10 * time.Second,
ReadTimeout: 30 * time.Second,
WriteTimeout: 0, // SSE streams need no write timeout
IdleTimeout: 120 * time.Second,
}
ln, err := net.Listen("tcp", s.addr)
if err != nil {
return fmt.Errorf("listen %s: %w", s.addr, err)
}
s.addr = ln.Addr().String()
go func() {
if err := s.srv.Serve(ln); err != nil && err != http.ErrServerClosed {
log.Printf("api server: %v", err)
}
}()
return nil
}
// Addr returns the address the server is listening on. Valid after Start.
func (s *Server) Addr() string {
return s.addr
}
// Shutdown gracefully stops the server, waiting up to timeout for in-flight
// requests to complete.
func (s *Server) Shutdown(timeout time.Duration) error {
if s.cancel != nil {
s.cancel()
}
if s.srv == nil {
return nil
}
ctx, cancel := context.WithTimeout(context.Background(), timeout)
defer cancel()
return s.srv.Shutdown(ctx)
}
// corsMiddleware adds CORS headers for cross-origin API access. The
// embedded SPA is served same-origin and needs none, so CORS is off
// unless EXPLOREDNS_CORS_ORIGIN names an allowed origin (use "*" to
// restore the old allow-all behaviour for development).
func corsMiddleware(next http.Handler) http.Handler {
origin := os.Getenv("EXPLOREDNS_CORS_ORIGIN")
if origin == "" {
return next
}
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Access-Control-Allow-Origin", origin)
w.Header().Set("Access-Control-Allow-Methods", "GET, POST, OPTIONS")
w.Header().Set("Access-Control-Allow-Headers", "Content-Type")
if r.Method == http.MethodOptions {
w.WriteHeader(http.StatusNoContent)
return
}
next.ServeHTTP(w, r)
})
}