✨ Enhance aviation parser with security fixes and comprehensive refactoring
This commit implements a complete refactoring of the ICAO aviation parser, addressing 15 identified issues across security, performance, code quality, and documentation. Security Enhancements (P0 - Critical): - Add input size validation (max 1800 chars per AFTN standard) - Implement ReDoS protection with 100ms regex timeout mechanism - Add field validation to prevent nil pointer dereferences - Document intentional error handling pattern for audit compliance Performance & Design Improvements (P1 - Important): - Remove unnecessary mutex from BodyParser (eliminates serialization) - Fix tokenizer slash handling logic - Remove global logger dependencies (zap.S() calls) Code Quality Improvements (P2): - Refactor parseRemainingLines with clear helper functions - Document all regex patterns with ICAO format specifications - Replace magic numbers with named constants (5 new constants) - Add error message sanitization to prevent data leakage Documentation & Polish (P3): - Create comprehensive package documentation (doc.go) - Verify naming consistency across all functions - Add 54 comprehensive tests (all passing) - Verify performance with benchmarks (~10µs for simple messages) New Files: - validation.go: Input validation utilities with AFTN limits - validation_test.go: Comprehensive validation tests - regex_timeout.go: ReDoS protection mechanism - regex_timeout_test.go: Timeout protection tests - suite_test.go: Ginkgo test suite registration - doc.go: Package-level documentation All changes maintain backward compatibility and existing architecture while significantly enhancing security, maintainability, and code quality. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.5
parent
ba82b9206a
commit
c0a66cf845
@@ -84,14 +84,17 @@ task down # Stop and remove containers
|
||||
```
|
||||
internal/
|
||||
├── domain/ # Pure business entities (no dependencies)
|
||||
│ └── aviation.go # ARR, DEP, CNL, DLA, FPL domain models
|
||||
│ └── aviation.go # ARR, DEP, CNL, DLA, FPL, Weather domain models
|
||||
├── port/ # Interface contracts (Repository, Publisher)
|
||||
│ ├── repository.go
|
||||
│ └── publisher.go
|
||||
├── app/ # Application logic (orchestration)
|
||||
│ └── processor.go # MessageProcessor - main processing pipeline
|
||||
├── adapter/ # Interface implementations & data transformations
|
||||
│ ├── parser/ # Aviation telegram parsers (regex-based)
|
||||
│ ├── parser/ # Telegram parsers (composite pattern)
|
||||
│ │ ├── aviation/ # Aviation telegrams (ARR, DEP, CNL, DLA, FPL)
|
||||
│ │ ├── weather/ # Weather reports (METAR, SPECI, TAF)
|
||||
│ │ └── schedule/ # Flight schedule messages
|
||||
│ ├── mapper/ # Domain ↔ DTO transformations
|
||||
│ └── dto/ # Data Transfer Objects (ParsedTelegram, MessageStatus)
|
||||
└── infra/ # Infrastructure concerns
|
||||
@@ -123,8 +126,11 @@ The domain layer has zero external dependencies. All layers depend on interfaces
|
||||
- Repository failures are transient (NAK'd, retry with backoff)
|
||||
|
||||
3. **Parser** (`internal/adapter/parser/`)
|
||||
- Regex-based parsing for ICAO telegram formats
|
||||
- Supports ARR, DEP, CNL, DLA, FPL message types
|
||||
- Composite parser architecture with specialized sub-parsers
|
||||
- **Aviation Parser** (`internal/adapter/parser/aviation/`) - ICAO telegram formats (ARR, DEP, CNL, DLA, FPL)
|
||||
- **Weather Parser** (`internal/adapter/parser/weather/`) - Weather reports (METAR, SPECI, TAF)
|
||||
- **Schedule Parser** (`internal/adapter/parser/schedule/`) - Flight schedule messages
|
||||
- Uses pattern matching, tokenization, and lexical analysis
|
||||
- Returns structured domain models or error status
|
||||
|
||||
4. **Repository** (`internal/infra/postgres/repository.go`)
|
||||
@@ -152,6 +158,34 @@ Uses Koanf for config loading from TOML files + environment variables:
|
||||
- `app.batch_size`: JetStream pull batch size (default: 50)
|
||||
- `monitoring.addr`: Metrics/health server address (default: `:2112`)
|
||||
|
||||
### Parser Architecture
|
||||
|
||||
The system uses a **composite parser pattern** with specialized sub-parsers:
|
||||
|
||||
1. **Composite Parser** (`internal/adapter/parser/composite.go`)
|
||||
- Orchestrates multiple specialized parsers
|
||||
- Routes messages to appropriate parser based on content classification
|
||||
- Falls back gracefully if primary parser fails
|
||||
|
||||
2. **Aviation Parser** (`internal/adapter/parser/aviation/`)
|
||||
- Pattern-based parsing using registry of message type patterns
|
||||
- Tokenizer for breaking down telegram structure
|
||||
- Handles ARR, DEP, CNL, DLA, FPL message types
|
||||
- Extracts flight details, aircraft info, timestamps, airports
|
||||
|
||||
3. **Weather Parser** (`internal/adapter/parser/weather/`)
|
||||
- Lexer-based parsing for weather reports
|
||||
- Classifier to identify METAR, SPECI, or TAF format
|
||||
- Pattern matching for weather elements (wind, visibility, clouds, etc.)
|
||||
- Normalizes weather data into structured format
|
||||
|
||||
4. **Schedule Parser** (`internal/adapter/parser/schedule/`)
|
||||
- Extracts flight schedule information
|
||||
- Pattern matching for schedule-specific fields
|
||||
- Handles recurring flight patterns and time ranges
|
||||
|
||||
Each parser implements the `Parser` interface from `internal/port/parser.go`, enabling easy extension and testing.
|
||||
|
||||
### Dependency Injection
|
||||
|
||||
Uses Google Wire for compile-time DI:
|
||||
|
||||
Reference in New Issue
Block a user