This repo had no version control prior to this commit. The import is a
straight snapshot of the working tree at 2026-05-03; the deployed
binary on fihelvop01 was being rebuilt from this source via `make
build` + scp into place, with no upstream review path.
The snapshot already includes one in-flight fix made on 2026-05-03 to
internal/service/persona.go:GetSelfModel — the handler queried
`source` and `strength` columns plus an `is_active = true` filter on
persona.persona_commitments, none of which exist on that table (its
shape is session-bound commitments with `status`, `commitment_meta`,
etc.). The query returned a 500 every time SynapseHub bootstrapped a
persona's self-model, dropping the IdentityConstraints / Commitments /
ConscienceStandards layer from the assembled prompt. The patched
query reads existing columns only (commitment_text, commitment_type),
filters on `status='active'`, and synthesises Source="learned" /
Strength=1.0 to keep the SelfModel response shape stable for callers.
Verified live: `GET /api/v1/personas/70f7cfd9-.../self-model` now
returns 200 with `{identityConstraints:[],commitments:[],
conscienceStandards:[]}` instead of 500.
Future changes go through PRs against this repo — no more bin-only
deploys.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
38 lines
835 B
Go
38 lines
835 B
Go
package middleware
|
|
|
|
import (
|
|
"crypto/subtle"
|
|
|
|
"github.com/gofiber/fiber/v2"
|
|
|
|
"github.com/gosec/gsc-ops-api/pkg/types"
|
|
)
|
|
|
|
const APIKeyHeader = "X-API-Key"
|
|
|
|
// APIKey validates the X-API-Key header against configured keys
|
|
func APIKey(validKeys []string) fiber.Handler {
|
|
return func(c *fiber.Ctx) error {
|
|
key := c.Get(APIKeyHeader)
|
|
if key == "" {
|
|
apiErr := types.NewUnauthorized("Missing API key")
|
|
return c.Status(apiErr.Status).JSON(types.NewErrorResponse(apiErr, GetRequestID(c)))
|
|
}
|
|
|
|
valid := false
|
|
for _, vk := range validKeys {
|
|
if subtle.ConstantTimeCompare([]byte(key), []byte(vk)) == 1 {
|
|
valid = true
|
|
break
|
|
}
|
|
}
|
|
|
|
if !valid {
|
|
apiErr := types.NewUnauthorized("Invalid API key")
|
|
return c.Status(apiErr.Status).JSON(types.NewErrorResponse(apiErr, GetRequestID(c)))
|
|
}
|
|
|
|
return c.Next()
|
|
}
|
|
}
|