fix: address code review findings

This commit is contained in:
2026-08-18 13:57:30 +03:00
parent 2cf9e20608
commit 48650d96cf
4 changed files with 31 additions and 11 deletions

View File

@@ -1,7 +1,7 @@
package main
import (
"crypto/hmac"
"crypto/subtle"
"encoding/json"
"fmt"
"net/http"
@@ -435,7 +435,7 @@ func adminAuth(hc *HandlerContext, w http.ResponseWriter, r *http.Request) bool
return false
}
providedAPIKey := r.Header.Get("X-Admin-Api-Key")
if !hmac.Equal([]byte(providedAPIKey), []byte(expectedAPIKey)) {
if subtle.ConstantTimeCompare([]byte(providedAPIKey), []byte(expectedAPIKey)) != 1 {
http.Error(w, "unauthorized", http.StatusUnauthorized)
return false
}

View File

@@ -39,6 +39,35 @@ func main() {
http.HandleFunc("/internal/admin/stations/", makeHandler(AdminStationStatus, handlerCtx))
http.HandleFunc("/metrics", makeHandler(MetricsHandler, handlerCtx))
// User preferences routes
http.HandleFunc("/v1/preferences/saved-cities", func(w http.ResponseWriter, r *http.Request) {
switch r.Method {
case http.MethodGet:
GetSavedCities(handlerCtx, w, r)
case http.MethodPost:
AddSavedCity(handlerCtx, w, r)
default:
http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
}
})
http.HandleFunc("/v1/preferences/saved-cities/", func(w http.ResponseWriter, r *http.Request) {
if r.Method == http.MethodDelete {
RemoveSavedCity(handlerCtx, w, r)
} else {
http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
}
})
http.HandleFunc("/v1/preferences/search-history", func(w http.ResponseWriter, r *http.Request) {
switch r.Method {
case http.MethodGet:
GetSearchHistory(handlerCtx, w, r)
case http.MethodPost:
AddSearchHistory(handlerCtx, w, r)
default:
http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
}
})
log.Println("Trip Planner API starting on :8080")
log.Fatal(http.ListenAndServe(":8080", nil))
}