From 12b4c3e54c04357a86b52fd105566f00370cb79d Mon Sep 17 00:00:00 2001 From: ryan Date: Sun, 30 Aug 2026 16:39:40 +0800 Subject: [PATCH 1/2] fix(cap): keep only /api/v1/cap routes Drop the unversioned /api/cap aliases so Challenge and Redeem exist only under /api/v1/cap. --- backend/plugins/domain/cap/handlers.go | 5 +++-- backend/plugins/domain/cap/plugin.go | 6 +----- backend/plugins/domain/cap/plugin_captcha_contract_test.go | 7 +++++-- 3 files changed, 9 insertions(+), 9 deletions(-) diff --git a/backend/plugins/domain/cap/handlers.go b/backend/plugins/domain/cap/handlers.go index 3be401c9..fe211ddb 100644 --- a/backend/plugins/domain/cap/handlers.go +++ b/backend/plugins/domain/cap/handlers.go @@ -20,7 +20,8 @@ import ( // @Param request body challengeRequest false "可选范围限制参数" // @Success 200 {object} response.Any{data=cap.ChallengeResponse} "成功返回 PoW 难题" // @Failure 500 {object} response.Any "内部服务错误" -// @Router /api/cap/challenge [post] +// @Router /api/v1/cap/challenge [get] +// @Router /api/v1/cap/challenge [post] func Challenge(c *gin.Context) { var req challengeRequest _ = c.ShouldBind(&req) // 允许不传 body,默认使用 login scope @@ -54,7 +55,7 @@ func Challenge(c *gin.Context) { // @Success 200 {object} response.Any{data=cap.RedeemResponse} "核销成功,返回 X-Cap-Token" // @Failure 400 {object} response.Any "参数错误或核销失败" // @Failure 500 {object} response.Any "内部服务错误" -// @Router /api/cap/redeem [post] +// @Router /api/v1/cap/redeem [post] func Redeem(c *gin.Context) { var req redeemRequest if err := c.ShouldBindJSON(&req); err != nil { diff --git a/backend/plugins/domain/cap/plugin.go b/backend/plugins/domain/cap/plugin.go index c9ecf749..2c4703dc 100644 --- a/backend/plugins/domain/cap/plugin.go +++ b/backend/plugins/domain/cap/plugin.go @@ -86,11 +86,7 @@ func (p *Plugin) Apply(ctx *core.Context) error { capGroup.POST("/challenge", Challenge) capGroup.POST("/redeem", Redeem) } - - legacy := ctx.Router().Group("/api/cap") - legacy.POST("/challenge", Challenge) - legacy.POST("/redeem", Redeem) - ctx.Router().RegisterWhitelist("/api/cap/challenge", "/api/cap/redeem") + ctx.Router().RegisterWhitelist("/api/v1/cap/challenge", "/api/v1/cap/redeem") // Register Settings Schemas ctx.Settings().Register(extpoints.SettingSchema{ diff --git a/backend/plugins/domain/cap/plugin_captcha_contract_test.go b/backend/plugins/domain/cap/plugin_captcha_contract_test.go index 2eb104f8..7577a31d 100644 --- a/backend/plugins/domain/cap/plugin_captcha_contract_test.go +++ b/backend/plugins/domain/cap/plugin_captcha_contract_test.go @@ -34,15 +34,18 @@ func TestApplyRegistersUnversionedCapRoutes(t *testing.T) { t.Fatal(err) } want := map[string]bool{ + "GET /api/v1/cap/challenge": false, "POST /api/v1/cap/challenge": false, - "POST /api/cap/challenge": false, - "POST /api/cap/redeem": false, + "POST /api/v1/cap/redeem": false, } for _, rd := range ctx.Router().Routes() { key := rd.Method + " " + rd.Path if _, ok := want[key]; ok { want[key] = true } + if key == "POST /api/cap/challenge" || key == "POST /api/cap/redeem" { + t.Errorf("legacy route must not exist: %s", key) + } } for key, ok := range want { if !ok { From 6553ac778274e7e3eaf48581a92dc02308e1e187 Mon Sep 17 00:00:00 2001 From: ryan Date: Sun, 30 Aug 2026 16:41:07 +0800 Subject: [PATCH 2/2] fix(system): expose only GET /api/healthz Remove /healthz and /api/health so the process advertises a single probe at /api/healthz with {status: ok}. --- backend/plugins/domain/auth/plugin.go | 2 +- .../domain/system/health_route_test.go | 54 +++++++------------ backend/plugins/domain/system/plugin.go | 17 +----- 3 files changed, 21 insertions(+), 52 deletions(-) diff --git a/backend/plugins/domain/auth/plugin.go b/backend/plugins/domain/auth/plugin.go index 2e98a15e..b836bb1d 100644 --- a/backend/plugins/domain/auth/plugin.go +++ b/backend/plugins/domain/auth/plugin.go @@ -134,7 +134,7 @@ func (p *Plugin) Apply(ctx *core.Context) error { "/api/v1/user/send-email-code", "/api/v1/cap/challenge", "/api/v1/cap/redeem", - "/healthz", + "/api/healthz", "/metrics", } RegisterWhitelist(publicEndpoints...) diff --git a/backend/plugins/domain/system/health_route_test.go b/backend/plugins/domain/system/health_route_test.go index a0e08e9a..98ad95e1 100644 --- a/backend/plugins/domain/system/health_route_test.go +++ b/backend/plugins/domain/system/health_route_test.go @@ -15,56 +15,40 @@ import ( "github.com/gin-gonic/gin" ) -func TestHealthRouteReturnsOKNil(t *testing.T) { +func TestHealthzIsTheOnlyHealthRoute(t *testing.T) { gin.SetMode(gin.TestMode) ctx := core.NewContext(context.Background()) if err := New().Apply(ctx); err != nil { t.Fatal(err) } - healthHandler := routeHandler(t, ctx, "GET", "/api/health") - routeHandler(t, ctx, "GET", "/healthz") - if !ctx.Router().IsWhitelisted("/api/health") { - t.Fatal("GET /api/health is not whitelisted") + var hasHealthz bool + for _, rd := range ctx.Router().Routes() { + key := rd.Method + " " + rd.Path + switch key { + case "GET /api/healthz": + hasHealthz = true + case "GET /healthz", "GET /api/health": + t.Errorf("removed health route still registered: %s", key) + } + } + if !hasHealthz { + t.Fatal("GET /api/healthz missing") + } + if !ctx.Router().IsWhitelisted("/api/healthz") { + t.Fatal("GET /api/healthz not whitelisted") } + handler := routeHandler(t, ctx, "GET", "/api/healthz") w := httptest.NewRecorder() c, _ := gin.CreateTestContext(w) - c.Request = httptest.NewRequest(http.MethodGet, "/api/health", nil) - healthHandler(c) + c.Request = httptest.NewRequest(http.MethodGet, "/api/healthz", nil) + handler(c) if w.Code != http.StatusOK { t.Fatalf("status = %d, want %d", w.Code, http.StatusOK) } - var body struct { - ErrorMsg string `json:"error_msg"` - Data any `json:"data"` - } - if err := json.Unmarshal(w.Body.Bytes(), &body); err != nil { - t.Fatal(err) - } - if body.ErrorMsg != "" { - t.Fatalf("error_msg = %q, want empty", body.ErrorMsg) - } - if body.Data != nil { - t.Fatalf("data = %#v, want null", body.Data) - } -} - -func TestHealthzRouteUnchanged(t *testing.T) { - gin.SetMode(gin.TestMode) - ctx := core.NewContext(context.Background()) - if err := New().Apply(ctx); err != nil { - t.Fatal(err) - } - - handler := routeHandler(t, ctx, "GET", "/healthz") - w := httptest.NewRecorder() - c, _ := gin.CreateTestContext(w) - c.Request = httptest.NewRequest(http.MethodGet, "/healthz", nil) - handler(c) - var body map[string]any if err := json.Unmarshal(w.Body.Bytes(), &body); err != nil { t.Fatal(err) diff --git a/backend/plugins/domain/system/plugin.go b/backend/plugins/domain/system/plugin.go index 71763b86..b03f98e8 100644 --- a/backend/plugins/domain/system/plugin.go +++ b/backend/plugins/domain/system/plugin.go @@ -50,14 +50,10 @@ func (p *Plugin) Apply(ctx *core.Context) error { appName := ctx.Config().String("app.app_name", "Wavelet") // 1. Health check - ctx.Router().GET("/healthz", func(c *gin.Context) { - c.JSON(http.StatusOK, gin.H{"status": "ok"}) - }) ctx.Router().GET("/api/healthz", func(c *gin.Context) { c.JSON(http.StatusOK, gin.H{"status": "ok"}) }) - ctx.Router().GET("/api/health", Health) - ctx.Router().RegisterWhitelist("/api/health") + ctx.Router().RegisterWhitelist("/api/healthz") // 2. Public config ctx.Router().GET("/api/v1/config/public", func(c *gin.Context) { @@ -90,14 +86,3 @@ func (p *Plugin) Apply(ctx *core.Context) error { return nil } - -// Health 健康检查 -// @Summary 健康检查 -// @Description 检查服务是否正常运行,可用于负载均衡存活探测 -// @Tags health -// @Produce json -// @Success 200 {object} response.Any{data=string} "服务正常" -// @Router /api/health [get] -func Health(c *gin.Context) { - c.JSON(http.StatusOK, response.OKNil()) -}