Build image / build-and-push (push) Successful in 5s
PATCH and DELETE /journal/:id were never registered. Both handlers existed, were covered by service-level tests, and were completely unreachable — my edit to the router anchored on a string that only exists on another branch, so it silently did nothing. Registered, and covered by an API-level test that walks the whole lifecycle through the router, because that is the only kind of test that could have caught it. Anything addressed by its own id now has one. An entry about a plop was invisible under its bed's filter. Naming only a planting left object_id null, so "notes about this bed" silently excluded every note written about something growing IN the bed — the two filters disagreed about what an entry is about, which is precisely the question the reader is asking. The parent object is now derived from the planting. checkJournalTarget flattened every store error to ErrInvalidInput, so a real database failure surfaced as a 400 telling the caller their request was bad, and never reached the logs. Only "no such row" is a bad reference now; anything else passes through. ListJournalEntries repeated the column scan order inline, one column different from scanJournalEntry — the classic way for a shared column list to drift out of step with its readers. Both now build from journalScanTargets, with the list appending the joined author name. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
160 lines
6.6 KiB
Go
160 lines
6.6 KiB
Go
// Package api wires pansy's HTTP surface: a gin engine with structured logging
|
|
// and panic recovery, the versioned JSON API under /api/v1, and (via spa.go) the
|
|
// embedded single-page-app fallback. Handlers stay thin — decode, call the
|
|
// service layer, encode — so all business logic and permission checks live in
|
|
// internal/service (added by later issues).
|
|
package api
|
|
|
|
import (
|
|
"log/slog"
|
|
"net/http"
|
|
|
|
"github.com/gin-gonic/gin"
|
|
sloggin "github.com/samber/slog-gin"
|
|
|
|
"gitea.stevedudenhoeffer.com/steve/pansy/internal/config"
|
|
"gitea.stevedudenhoeffer.com/steve/pansy/internal/service"
|
|
)
|
|
|
|
// handlers carries the dependencies shared by every HTTP handler. Handlers stay
|
|
// thin: decode the request, call a service method, encode the result.
|
|
type handlers struct {
|
|
cfg *config.Config
|
|
svc *service.Service
|
|
oidc *oidcClient // nil unless OIDC is configured (see config.OIDCReady)
|
|
}
|
|
|
|
// New builds the gin engine with the standard middleware stack and registers the
|
|
// API routes against the given service. The embedded SPA fallback is registered
|
|
// separately by the caller via RegisterSPA (see spa.go) so the API can be built
|
|
// and tested without a web build present.
|
|
func New(cfg *config.Config, svc *service.Service) *gin.Engine {
|
|
gin.SetMode(gin.ReleaseMode)
|
|
|
|
r := gin.New()
|
|
r.Use(sloggin.New(slog.Default()), gin.Recovery())
|
|
|
|
if err := r.SetTrustedProxies(cfg.TrustedProxies); err != nil {
|
|
// Do not leave gin's trust-everyone default active on a parse failure —
|
|
// that would let any client spoof X-Forwarded-For. Fall back to trusting
|
|
// no proxies, which is also the behavior when none are configured.
|
|
slog.Error("api: invalid trusted proxies, trusting none", "error", err)
|
|
_ = r.SetTrustedProxies(nil)
|
|
}
|
|
|
|
h := &handlers{cfg: cfg, svc: svc}
|
|
|
|
v1 := r.Group("/api/v1")
|
|
// CSRF defense for every state-changing API call (no-op unless PANSY_BASE_URL
|
|
// is set; see csrfGuard).
|
|
v1.Use(h.csrfGuard())
|
|
v1.GET("/healthz", healthz)
|
|
|
|
// Auth endpoints are exempt from requireAuth (you can't be logged in yet);
|
|
// /me is the one that needs a session. Feature routers in later issues attach
|
|
// h.requireAuth() to their own protected groups.
|
|
auth := v1.Group("/auth")
|
|
auth.POST("/register", h.register)
|
|
auth.POST("/login", h.login)
|
|
auth.POST("/logout", h.logout)
|
|
auth.GET("/providers", h.providers)
|
|
auth.GET("/me", h.requireAuth(), h.me)
|
|
|
|
// OIDC routes exist only when OIDC can actually be offered, so an unconfigured
|
|
// instance 404s them (matching what /auth/providers advertises). Provider
|
|
// discovery is lazy (first request), so a briefly-unreachable IdP doesn't stop
|
|
// the server — or local auth — from starting.
|
|
switch {
|
|
case cfg.OIDCReady():
|
|
h.oidc = newOIDCClient(cfg)
|
|
auth.GET("/oidc/login", h.oidcLogin)
|
|
auth.GET("/oidc/callback", h.oidcCallback)
|
|
case cfg.OIDC.Enabled():
|
|
slog.Warn("api: OIDC is configured but PANSY_BASE_URL is unset; OIDC disabled (an absolute redirect URI is required)")
|
|
}
|
|
|
|
// Feature resources sit behind requireAuth, which resolves the session cookie
|
|
// to the actor the service layer's permission checks key off.
|
|
gardens := v1.Group("/gardens", h.requireAuth())
|
|
gardens.GET("", h.listGardens)
|
|
gardens.POST("", h.createGarden)
|
|
gardens.GET("/:id", h.getGarden)
|
|
gardens.PATCH("/:id", h.updateGarden)
|
|
gardens.DELETE("/:id", h.deleteGarden)
|
|
gardens.POST("/:id/copy", h.copyGarden) // duplicate a garden the actor owns
|
|
gardens.GET("/:id/full", h.getGardenFull) // one-shot editor load
|
|
gardens.GET("/:id/history", h.getGardenHistory) // change sets, newest first
|
|
gardens.POST("/:id/objects", h.createObject)
|
|
// The grow journal hangs off a garden even for entries about one bed or one
|
|
// plop, so it inherits the ordinary garden-role check.
|
|
gardens.GET("/:id/journal", h.listJournal)
|
|
gardens.POST("/:id/journal", h.createJournalEntry)
|
|
|
|
// Sharing (owner-managed; a recipient may remove their own share).
|
|
gardens.GET("/:id/shares", h.listShares)
|
|
gardens.POST("/:id/shares", h.addShare)
|
|
gardens.PATCH("/:id/shares/:userId", h.updateShare)
|
|
gardens.DELETE("/:id/shares/:userId", h.removeShare)
|
|
|
|
// Public read-only share link (owner-managed): GET reports state, POST
|
|
// enables/rotates, DELETE disables. The link itself is served unauthenticated
|
|
// below.
|
|
gardens.GET("/:id/share-link", h.getShareLink)
|
|
gardens.POST("/:id/share-link", h.createShareLink)
|
|
gardens.DELETE("/:id/share-link", h.deleteShareLink)
|
|
|
|
// Objects are addressed by their own id; the service resolves the owning
|
|
// garden for the permission check.
|
|
objects := v1.Group("/objects", h.requireAuth())
|
|
objects.PATCH("/:id", h.updateObject)
|
|
objects.DELETE("/:id", h.deleteObject)
|
|
objects.POST("/:id/plantings", h.createPlanting) // place a plop in this object
|
|
|
|
// Plantings ("plops") are addressed by their own id; the service resolves the
|
|
// owning object/garden for the permission check.
|
|
plantings := v1.Group("/plantings", h.requireAuth())
|
|
plantings.PATCH("/:id", h.updatePlanting)
|
|
plantings.DELETE("/:id", h.deletePlanting)
|
|
|
|
// Undo. A change set is addressed by its own id; the service resolves the
|
|
// owning garden for the permission check, same as objects and plantings.
|
|
changeSets := v1.Group("/change-sets", h.requireAuth())
|
|
changeSets.POST("/:id/revert", h.revertChangeSet)
|
|
|
|
// Journal entries are addressed by their own id; the service resolves the
|
|
// owning garden for the permission check, same as objects and plantings.
|
|
journal := v1.Group("/journal", h.requireAuth())
|
|
journal.PATCH("/:id", h.updateJournalEntry)
|
|
journal.DELETE("/:id", h.deleteJournalEntry)
|
|
|
|
// Plant catalog: built-ins (seeded, read-only) plus the actor's own rows.
|
|
plants := v1.Group("/plants", h.requireAuth())
|
|
plants.GET("", h.listPlants)
|
|
plants.POST("", h.createPlant)
|
|
plants.PATCH("/:id", h.updatePlant)
|
|
plants.DELETE("/:id", h.deletePlant)
|
|
|
|
// Seed lots: what the actor bought, and what's left. Private to the buyer,
|
|
// so these hang off the session actor rather than off a garden.
|
|
seedLots := v1.Group("/seed-lots", h.requireAuth())
|
|
seedLots.GET("", h.listSeedLots)
|
|
seedLots.POST("", h.createSeedLot)
|
|
seedLots.GET("/:id", h.getSeedLot)
|
|
seedLots.PATCH("/:id", h.updateSeedLot)
|
|
seedLots.DELETE("/:id", h.deleteSeedLot)
|
|
|
|
// Public, unauthenticated read of a garden by its share token. Deliberately
|
|
// NOT behind requireAuth: the token is the capability, so a logged-out visitor
|
|
// opens a shared link without being redirected to /login or OIDC. Only GET,
|
|
// only the read-only /full payload — never a mutation.
|
|
public := v1.Group("/public")
|
|
public.GET("/gardens/:token", h.getPublicGarden)
|
|
|
|
return r
|
|
}
|
|
|
|
// healthz is a liveness probe: always returns {"ok": true} when the server is up.
|
|
func healthz(c *gin.Context) {
|
|
c.JSON(http.StatusOK, gin.H{"ok": true})
|
|
}
|