package main import ( "context" "errors" "log" "net/http" "os" "os/signal" "strings" "syscall" "time" ) // Config holds all runtime settings, sourced from environment variables. type Config struct { Token string AllowedOrigins []string DBPath string Port string } func envOr(key, def string) string { if v := os.Getenv(key); v != "" { return v } return def } func loadConfig() Config { c := Config{ Token: os.Getenv("API_TOKEN"), DBPath: envOr("DB_PATH", "/data/bookmarks.db"), Port: envOr("PORT", "8080"), } for _, o := range strings.Split(os.Getenv("ALLOWED_ORIGINS"), ",") { if o = strings.TrimSpace(o); o != "" { c.AllowedOrigins = append(c.AllowedOrigins, o) } } return c } // newRouter wires routes and middleware. CORS is the outermost layer so // preflight OPTIONS short-circuits before auth; /bookmarks* is auth-protected, // /healthz is public. func newRouter(store *Store, cfg Config) http.Handler { mux := http.NewServeMux() mux.HandleFunc("GET /healthz", healthz) h := &bookmarkHandler{store: store} protected := http.NewServeMux() protected.HandleFunc("GET /bookmarks", h.list) protected.HandleFunc("PUT /bookmarks/{key}", h.put) protected.HandleFunc("DELETE /bookmarks/{key}", h.delete) auth := withAuth(cfg.Token, protected) mux.Handle("/bookmarks", auth) mux.Handle("/bookmarks/", auth) return withCORS(cfg.AllowedOrigins, mux) } func main() { cfg := loadConfig() if cfg.Token == "" { log.Fatal("API_TOKEN is required") } store, err := OpenStore(cfg.DBPath) if err != nil { log.Fatalf("open store: %v", err) } defer store.Close() srv := &http.Server{ Addr: ":" + cfg.Port, Handler: newRouter(store, cfg), ReadHeaderTimeout: 10 * time.Second, } go func() { log.Printf("listening on :%s (db=%s, origins=%v)", cfg.Port, cfg.DBPath, cfg.AllowedOrigins) if err := srv.ListenAndServe(); err != nil && !errors.Is(err, http.ErrServerClosed) { log.Fatalf("serve: %v", err) } }() stop := make(chan os.Signal, 1) signal.Notify(stop, syscall.SIGINT, syscall.SIGTERM) <-stop log.Println("shutting down") ctx, cancel := context.WithTimeout(context.Background(), 10*time.Second) defer cancel() if err := srv.Shutdown(ctx); err != nil { log.Printf("shutdown: %v", err) } }