Public read-only share link (no login / no OIDC) (#41) (#43)
Build image / build-and-push (push) Successful in 8s
Build image / build-and-push (push) Successful in 8s
Per-garden public read-only link: unauthenticated GET /api/v1/public/gardens/:token (no requireAuth, no OIDC), owner-only enable/rotate/disable, and a /g/$token page rendering GardenCanvas read-only. Review fixes: redact plant owner ids, Cache-Control: no-store, 400 on malformed body, shared resetTransient store action. Closes #41. Co-authored-by: Steve Dudenhoeffer <[email protected]>
This commit was merged in pull request #43.
This commit is contained in:
@@ -90,6 +90,13 @@ func New(cfg *config.Config, svc *service.Service) *gin.Engine {
|
||||
gardens.PATCH("/:id/shares/:userId", h.updateShare)
|
||||
gardens.DELETE("/:id/shares/:userId", h.removeShare)
|
||||
|
||||
// Public read-only share link (owner-managed): GET reports state, POST
|
||||
// enables/rotates, DELETE disables. The link itself is served unauthenticated
|
||||
// below.
|
||||
gardens.GET("/:id/share-link", h.getShareLink)
|
||||
gardens.POST("/:id/share-link", h.createShareLink)
|
||||
gardens.DELETE("/:id/share-link", h.deleteShareLink)
|
||||
|
||||
// Objects are addressed by their own id; the service resolves the owning
|
||||
// garden for the permission check.
|
||||
objects := v1.Group("/objects", h.requireAuth())
|
||||
@@ -110,6 +117,13 @@ func New(cfg *config.Config, svc *service.Service) *gin.Engine {
|
||||
plants.PATCH("/:id", h.updatePlant)
|
||||
plants.DELETE("/:id", h.deletePlant)
|
||||
|
||||
// Public, unauthenticated read of a garden by its share token. Deliberately
|
||||
// NOT behind requireAuth: the token is the capability, so a logged-out visitor
|
||||
// opens a shared link without being redirected to /login or OIDC. Only GET,
|
||||
// only the read-only /full payload — never a mutation.
|
||||
public := v1.Group("/public")
|
||||
public.GET("/gardens/:token", h.getPublicGarden)
|
||||
|
||||
return r
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user