(request: Request, env: CloudflareEnv)
| 94 | owner, |
| 95 | findingId: parsedPayload.data.findingId, |
| 96 | }); |
| 97 | try { |
| 98 | await env.MANUAL_ANALYSIS_QUEUE.sendBatch([ |
| 99 | { body: { ...parsedPayload.data, commandId: command.id }, contentType: 'json' }, |
| 100 | ]); |
| 101 | } catch (error) { |
| 102 | await markSecurityAgentCommandQueueAdmissionFailed(db, command.id, 'Queue admission failed'); |
| 103 | throw error; |
| 104 | } |
| 105 | return Response.json({ success: true, accepted: true, commandId: command.id }, { status: 202 }); |
| 106 | } |
| 107 | |
| 108 | if (request.method === 'POST' && url.pathname === '/internal/remediation/start') { |
| 109 | const internalSecret = await env.INTERNAL_API_SECRET.get(); |
| 110 | const authHeader = request.headers.get('x-internal-api-key'); |
| 111 | if (!authHeader || !internalSecret || !timingSafeEqual(authHeader, internalSecret)) { |
| 112 | return Response.json({ error: 'Unauthorized' }, { status: 401 }); |
| 113 | } |
| 114 | |
| 115 | let payload: unknown; |
| 116 | try { |
| 117 | payload = await request.json(); |
| 118 | } catch { |
| 119 | return Response.json({ error: 'Invalid JSON body' }, { status: 400 }); |
| 120 | } |
| 121 | const parsedPayload = ManualRemediationStartRequestSchema.safeParse(payload); |
| 122 | if (!parsedPayload.success) { |
| 123 | return Response.json( |
| 124 | { error: 'Invalid remediation command', issues: parsedPayload.error.issues }, |
| 125 | { status: 400 } |
| 126 | ); |
| 127 | } |
| 128 | |
| 129 | const result = await startManualRemediation({ env, request: parsedPayload.data }); |
| 130 | if (!result.admitted) { |
| 131 | return Response.json( |
| 132 | { success: false, accepted: false, admitted: false, reason: result.reason }, |
| 133 | { status: result.reason === 'finding_not_found' ? 404 : 409 } |
| 134 | ); |
| 135 | } |
| 136 | return Response.json( |
| 137 | { |
| 138 | success: true, |
| 139 | accepted: true, |
| 140 | admitted: true, |
| 141 | remediationId: result.remediationId, |
| 142 | attemptId: result.attemptId, |
| 143 | attemptNumber: result.attemptNumber, |
| 144 | }, |
| 145 | { status: 202 } |
| 146 | ); |
| 147 | } |
| 148 | |
| 149 | if (request.method === 'POST' && url.pathname === '/internal/remediation/cancel') { |
| 150 | const internalSecret = await env.INTERNAL_API_SECRET.get(); |
| 151 | const authHeader = request.headers.get('x-internal-api-key'); |
| 152 | if (!authHeader || !internalSecret || !timingSafeEqual(authHeader, internalSecret)) { |
| 153 | return Response.json({ error: 'Unauthorized' }, { status: 401 }); |
no test coverage detected