The undo substrate. The agent is going to act freely — "empty the garlic bed and plant cucumbers" runs without a confirmation prompt — and that is only a defensible default if the result is easy to roll back. So undo lands before the agent write path, not after it. The unit of undo is the OPERATION, not the row. A change set groups the row-level revisions it produced; revert replays their inverses. Emptying a bed and replanting it touches one object and many plantings, and undoing half of that is worse than useless. Two properties shape the rest: Revert is itself a change set (reverts_id names its target), so history is append-only and an undo can be undone. git revert, not git reset. Revert is version-guarded per entity. Every snapshot carries the row's version; if something edited that row after the change set being reverted, restoring the old snapshot would silently discard the newer edit, so it is reported as a conflict and left alone while the rest of the change set still reverts. The auto-scope is what keeps this invasive but shallow. Service mutations call record(), which joins the change set on the context if one is open and otherwise opens a single-op one on the spot. REST handlers needed no edits at all and every UI mutation lands in history for free; only the agent wraps a whole turn. Multi-row operations (FillRegion, ClearObject) pass all their changes in one record call, so a 12-plop fill is one change set with 12 revisions and one undo. Revisions are buffered and written with their change set in a single transaction, so an operation that fails partway leaves no half-recorded history. Recording is best-effort after the fact: the row is already written, so failing the caller there would report a failure that didn't happen and invite a duplicate retry. A gap is logged loudly instead. Two sharp edges handled explicitly rather than by luck: Deleting an object cascades its plantings away at the FK level, where the service never sees them. deleteObjectRecording snapshots them first, or the delete would be listed in history and not actually be undoable. Restoring deleted rows reuses their ids, and a restored plop needs its object back first. planRevert runs three explicit passes — restore parents then children, then updates, then delete created children before their parents — instead of trusting reverse-seq ordering to happen to be right. Garden deletion stays out of scope, as designed: the cascade is invisible to the service and ON DELETE CASCADE would take the history with it. The history UI will say so rather than pretend otherwise. Closes #48 Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
141 lines
5.7 KiB
Go
141 lines
5.7 KiB
Go
// Package api wires pansy's HTTP surface: a gin engine with structured logging
|
|
// and panic recovery, the versioned JSON API under /api/v1, and (via spa.go) the
|
|
// embedded single-page-app fallback. Handlers stay thin — decode, call the
|
|
// service layer, encode — so all business logic and permission checks live in
|
|
// internal/service (added by later issues).
|
|
package api
|
|
|
|
import (
|
|
"log/slog"
|
|
"net/http"
|
|
|
|
"github.com/gin-gonic/gin"
|
|
sloggin "github.com/samber/slog-gin"
|
|
|
|
"gitea.stevedudenhoeffer.com/steve/pansy/internal/config"
|
|
"gitea.stevedudenhoeffer.com/steve/pansy/internal/service"
|
|
)
|
|
|
|
// handlers carries the dependencies shared by every HTTP handler. Handlers stay
|
|
// thin: decode the request, call a service method, encode the result.
|
|
type handlers struct {
|
|
cfg *config.Config
|
|
svc *service.Service
|
|
oidc *oidcClient // nil unless OIDC is configured (see config.OIDCReady)
|
|
}
|
|
|
|
// New builds the gin engine with the standard middleware stack and registers the
|
|
// API routes against the given service. The embedded SPA fallback is registered
|
|
// separately by the caller via RegisterSPA (see spa.go) so the API can be built
|
|
// and tested without a web build present.
|
|
func New(cfg *config.Config, svc *service.Service) *gin.Engine {
|
|
gin.SetMode(gin.ReleaseMode)
|
|
|
|
r := gin.New()
|
|
r.Use(sloggin.New(slog.Default()), gin.Recovery())
|
|
|
|
if err := r.SetTrustedProxies(cfg.TrustedProxies); err != nil {
|
|
// Do not leave gin's trust-everyone default active on a parse failure —
|
|
// that would let any client spoof X-Forwarded-For. Fall back to trusting
|
|
// no proxies, which is also the behavior when none are configured.
|
|
slog.Error("api: invalid trusted proxies, trusting none", "error", err)
|
|
_ = r.SetTrustedProxies(nil)
|
|
}
|
|
|
|
h := &handlers{cfg: cfg, svc: svc}
|
|
|
|
v1 := r.Group("/api/v1")
|
|
// CSRF defense for every state-changing API call (no-op unless PANSY_BASE_URL
|
|
// is set; see csrfGuard).
|
|
v1.Use(h.csrfGuard())
|
|
v1.GET("/healthz", healthz)
|
|
|
|
// Auth endpoints are exempt from requireAuth (you can't be logged in yet);
|
|
// /me is the one that needs a session. Feature routers in later issues attach
|
|
// h.requireAuth() to their own protected groups.
|
|
auth := v1.Group("/auth")
|
|
auth.POST("/register", h.register)
|
|
auth.POST("/login", h.login)
|
|
auth.POST("/logout", h.logout)
|
|
auth.GET("/providers", h.providers)
|
|
auth.GET("/me", h.requireAuth(), h.me)
|
|
|
|
// OIDC routes exist only when OIDC can actually be offered, so an unconfigured
|
|
// instance 404s them (matching what /auth/providers advertises). Provider
|
|
// discovery is lazy (first request), so a briefly-unreachable IdP doesn't stop
|
|
// the server — or local auth — from starting.
|
|
switch {
|
|
case cfg.OIDCReady():
|
|
h.oidc = newOIDCClient(cfg)
|
|
auth.GET("/oidc/login", h.oidcLogin)
|
|
auth.GET("/oidc/callback", h.oidcCallback)
|
|
case cfg.OIDC.Enabled():
|
|
slog.Warn("api: OIDC is configured but PANSY_BASE_URL is unset; OIDC disabled (an absolute redirect URI is required)")
|
|
}
|
|
|
|
// Feature resources sit behind requireAuth, which resolves the session cookie
|
|
// to the actor the service layer's permission checks key off.
|
|
gardens := v1.Group("/gardens", h.requireAuth())
|
|
gardens.GET("", h.listGardens)
|
|
gardens.POST("", h.createGarden)
|
|
gardens.GET("/:id", h.getGarden)
|
|
gardens.PATCH("/:id", h.updateGarden)
|
|
gardens.DELETE("/:id", h.deleteGarden)
|
|
gardens.POST("/:id/copy", h.copyGarden) // duplicate a garden the actor owns
|
|
gardens.GET("/:id/full", h.getGardenFull) // one-shot editor load
|
|
gardens.GET("/:id/history", h.getGardenHistory) // change sets, newest first
|
|
gardens.POST("/:id/objects", h.createObject)
|
|
|
|
// Sharing (owner-managed; a recipient may remove their own share).
|
|
gardens.GET("/:id/shares", h.listShares)
|
|
gardens.POST("/:id/shares", h.addShare)
|
|
gardens.PATCH("/:id/shares/:userId", h.updateShare)
|
|
gardens.DELETE("/:id/shares/:userId", h.removeShare)
|
|
|
|
// Public read-only share link (owner-managed): GET reports state, POST
|
|
// enables/rotates, DELETE disables. The link itself is served unauthenticated
|
|
// below.
|
|
gardens.GET("/:id/share-link", h.getShareLink)
|
|
gardens.POST("/:id/share-link", h.createShareLink)
|
|
gardens.DELETE("/:id/share-link", h.deleteShareLink)
|
|
|
|
// Objects are addressed by their own id; the service resolves the owning
|
|
// garden for the permission check.
|
|
objects := v1.Group("/objects", h.requireAuth())
|
|
objects.PATCH("/:id", h.updateObject)
|
|
objects.DELETE("/:id", h.deleteObject)
|
|
objects.POST("/:id/plantings", h.createPlanting) // place a plop in this object
|
|
|
|
// Plantings ("plops") are addressed by their own id; the service resolves the
|
|
// owning object/garden for the permission check.
|
|
plantings := v1.Group("/plantings", h.requireAuth())
|
|
plantings.PATCH("/:id", h.updatePlanting)
|
|
plantings.DELETE("/:id", h.deletePlanting)
|
|
|
|
// Undo. A change set is addressed by its own id; the service resolves the
|
|
// owning garden for the permission check, same as objects and plantings.
|
|
changeSets := v1.Group("/change-sets", h.requireAuth())
|
|
changeSets.POST("/:id/revert", h.revertChangeSet)
|
|
|
|
// Plant catalog: built-ins (seeded, read-only) plus the actor's own rows.
|
|
plants := v1.Group("/plants", h.requireAuth())
|
|
plants.GET("", h.listPlants)
|
|
plants.POST("", h.createPlant)
|
|
plants.PATCH("/:id", h.updatePlant)
|
|
plants.DELETE("/:id", h.deletePlant)
|
|
|
|
// Public, unauthenticated read of a garden by its share token. Deliberately
|
|
// NOT behind requireAuth: the token is the capability, so a logged-out visitor
|
|
// opens a shared link without being redirected to /login or OIDC. Only GET,
|
|
// only the read-only /full payload — never a mutation.
|
|
public := v1.Group("/public")
|
|
public.GET("/gardens/:token", h.getPublicGarden)
|
|
|
|
return r
|
|
}
|
|
|
|
// healthz is a liveness probe: always returns {"ok": true} when the server is up.
|
|
func healthz(c *gin.Context) {
|
|
c.JSON(http.StatusOK, gin.H{"ok": true})
|
|
}
|