Applied the fixes warranted by the adversarial review of PR #21 (all findings graded in the gadfly store): Store (highest impact): - buildDSN always merges busy_timeout/journal_mode/foreign_keys pragmas into the DSN, even for file: URIs or paths with a query string — the prior passthrough silently disabled FK enforcement for those PANSY_DB values. Also escape '#' in the path and tighten in-memory detection to an exact ':memory:' token or mode=memory param (no substring misfire). - migrate.go: detect duplicate migration versions with a clear error; wrap appliedVersions' rows.Err() with the store: prefix. API: - SetTrustedProxies failure now falls back to trust-none instead of leaving gin's trust-everyone default (X-Forwarded-For spoofing). - SPA: 404 embedded directories (was a directory listing), 404 bare /api, add X-Content-Type-Options: nosniff, cache index.html bytes once at startup, single fs.Stat existence check, shared writeAPIError helper. - Move gin.SetMode out of package init() into New(). Config: validate PANSY_PORT range (fall back to 8080 with a warning). Web: - api.ts: serialize the request body before the fetch try so a JSON.stringify failure isn't misreported as a network error. - AppShell: move state-specific/conflicting utilities into active/inactiveProps so concatenated Tailwind classes don't collide. Tests: added store DSN-pragma/memory-detection cases and SPA directory-404 case. go build/vet/test clean (CGO off); web tsc + build clean; re-verified in a browser (SPA, deep links, /assets 404, nav). Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01JdQpdYYsTgtkJBxbcpAszi
46 lines
1.5 KiB
Go
46 lines
1.5 KiB
Go
// Package api wires pansy's HTTP surface: a gin engine with structured logging
|
|
// and panic recovery, the versioned JSON API under /api/v1, and (via spa.go) the
|
|
// embedded single-page-app fallback. Handlers stay thin — decode, call the
|
|
// service layer, encode — so all business logic and permission checks live in
|
|
// internal/service (added by later issues).
|
|
package api
|
|
|
|
import (
|
|
"log/slog"
|
|
"net/http"
|
|
|
|
"github.com/gin-gonic/gin"
|
|
sloggin "github.com/samber/slog-gin"
|
|
|
|
"gitea.stevedudenhoeffer.com/steve/pansy/internal/config"
|
|
)
|
|
|
|
// New builds the gin engine with the standard middleware stack and registers the
|
|
// API routes. The embedded SPA fallback is registered separately by the caller
|
|
// via RegisterSPA (see spa.go) so the API can be built and tested without a web
|
|
// build present.
|
|
func New(cfg *config.Config) *gin.Engine {
|
|
gin.SetMode(gin.ReleaseMode)
|
|
|
|
r := gin.New()
|
|
r.Use(sloggin.New(slog.Default()), gin.Recovery())
|
|
|
|
if err := r.SetTrustedProxies(cfg.TrustedProxies); err != nil {
|
|
// Do not leave gin's trust-everyone default active on a parse failure —
|
|
// that would let any client spoof X-Forwarded-For. Fall back to trusting
|
|
// no proxies, which is also the behavior when none are configured.
|
|
slog.Error("api: invalid trusted proxies, trusting none", "error", err)
|
|
_ = r.SetTrustedProxies(nil)
|
|
}
|
|
|
|
v1 := r.Group("/api/v1")
|
|
v1.GET("/healthz", healthz)
|
|
|
|
return r
|
|
}
|
|
|
|
// healthz is a liveness probe: always returns {"ok": true} when the server is up.
|
|
func healthz(c *gin.Context) {
|
|
c.JSON(http.StatusOK, gin.H{"ok": true})
|
|
}
|