hub: check a pasted Cloudflare token's reach before saving it (R-138 option C, decision 190)

On create and edit, a non-empty cf_api_token is checked with Cloudflare (GET /zones): it is saved only when
the token sees exactly one zone and the customer's domain is that zone or a name under it. More zones, another
zone, no zone, or Cloudflare not answering -> the form re-renders with one sentence and nothing is saved (the
previous token stays). An unchanged token on an unchanged domain and an empty token (HTTP-01) make no call.
The token is never logged and never in a sentence or error. Tests use a fake Cloudflare (httptest).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-08 14:25:58 +02:00
parent e1ff3210eb
commit 700a2d06fe
5 changed files with 461 additions and 0 deletions
+2
View File
@@ -124,6 +124,8 @@ type Server struct {
// beforeCreateSave is a TEST seam: called in handleConfigCreate after the duplicate check, before the
// save. nil in production.
beforeCreateSave func(customerID string)
// cfAPIBase is a TEST seam for the Cloudflare token reach check (R-138 option C): "" = the real API.
cfAPIBase string
}
// New creates a new web server.