fix(api): align upload permissions and mount robots and swagger routes

This commit is contained in:
ryan
2026-08-30 17:53:42 +08:00
parent 7c5c196ede
commit 374289bfda
10 changed files with 6718 additions and 110 deletions
+2538 -34
View File
File diff suppressed because it is too large Load Diff
+2538 -34
View File
File diff suppressed because it is too large Load Diff
+1567 -33
View File
File diff suppressed because it is too large Load Diff
+4
View File
@@ -170,6 +170,10 @@ func (p *Plugin) Apply(ctx *core.Context) error {
adminRouter := ctx.Router().Group("/api/v1/admin", loginMW, adminMW)
handler.RegisterRoutes(adminRouter)
// Register robots.txt public route
ctx.Router().GET("/robots.txt", handler.GetRobotsTXT)
ctx.Router().RegisterWhitelist("/robots.txt")
// 2. Register Background Tasks
logSwitchHandler := &service.LogDBSwitchHandler{}
ctx.Task().Register(service.LogDBSwitchTask, func(c context.Context, payload []byte) error {
@@ -23,6 +23,14 @@ func TestAdminPluginUnit(t *testing.T) {
// Verify routes
routes := ctx.Router().Routes()
assert.NotEmpty(t, routes)
var hasRobots bool
for _, r := range routes {
if r.Path == "/robots.txt" && r.Method == "GET" {
hasRobots = true
break
}
}
assert.True(t, hasRobots, "admin plugin must register /robots.txt")
// Verify tasks
_, ok := ctx.Tasks().Get("admin:system_cleanup")
+3 -4
View File
@@ -112,6 +112,7 @@ func (p *Plugin) Apply(ctx *core.Context) error {
return err
}
loginMW := authSvc.RequireAuthMiddleware().(gin.HandlerFunc)
adminMW := authSvc.RequireAdminMiddleware().(gin.HandlerFunc)
// 0a. Register migrations
ctx.Migrations().Register("upload", uploadMigrations)
@@ -123,16 +124,14 @@ func (p *Plugin) Apply(ctx *core.Context) error {
uploadGroup := ctx.Router().Group("/api/v1/upload", loginMW)
{
uploadGroup.POST("", handler.UploadFile)
uploadGroup.GET("", handler.ListFiles)
uploadGroup.DELETE("/:id", handler.DeleteFile)
uploadGroup.POST("/batch-download", handler.BatchDownloadFiles)
uploadGroup.DELETE("/:id", handler.DeleteMyFile)
uploadGroup.GET("/my", handler.ListMyFiles)
uploadGroup.PUT("/:id", handler.UpdateMyFile)
uploadGroup.GET("/download/:id", handler.DownloadFile)
uploadGroup.POST("/download/batch", handler.BatchDownloadFiles)
}
adminUploadGroup := ctx.Router().Group("/api/v1/admin/uploads", loginMW)
adminUploadGroup := ctx.Router().Group("/api/v1/admin/uploads", loginMW, adminMW)
{
adminUploadGroup.GET("", handler.ListFiles)
adminUploadGroup.GET("/stats", handler.GetFileStats)
+12 -2
View File
@@ -23,6 +23,10 @@ func (stubAuthService) RequireAuthMiddleware() any {
return gin.HandlerFunc(func(c *gin.Context) { c.Next() })
}
func (stubAuthService) RequireAdminMiddleware() any {
return gin.HandlerFunc(func(c *gin.Context) { c.Next() })
}
func TestUserUploadRoutes(t *testing.T) {
gin.SetMode(gin.TestMode)
ctx := core.NewContext(context.Background())
@@ -34,12 +38,18 @@ func TestUserUploadRoutes(t *testing.T) {
}
want := []string{
"POST /api/v1/upload",
"DELETE /api/v1/upload/:id",
"GET /api/v1/upload/my",
"PUT /api/v1/upload/:id",
"GET /api/v1/upload/download/:id",
"POST /api/v1/upload/download/batch",
"GET /api/v1/upload",
"POST /api/v1/upload/batch-download",
"GET /api/v1/admin/uploads",
"GET /api/v1/admin/uploads/stats",
"DELETE /api/v1/admin/uploads/:id",
"GET /api/v1/admin/uploads/download/:id",
"POST /api/v1/admin/uploads/download/batch",
"GET /api/v1/admin/uploads/types",
}
found := make(map[string]bool, len(want))
for _, rd := range ctx.Router().Routes() {
@@ -4,9 +4,12 @@
package driver_http
import (
"testing"
"Wavelet/core"
"Wavelet/core/extpoints"
"context"
"net/http"
"net/http/httptest"
"testing"
)
func TestBuildEngineDefaultRedirectsTrailingSlash(t *testing.T) {
@@ -111,3 +114,29 @@ func bindAppConfig(t *testing.T, values map[string]any, env map[string]string) h
}
func boolPtr(v bool) *bool { return &v }
func TestDriverHTTPSwaggerMount(t *testing.T) {
ctx := core.NewContext(t.Context())
ctx.Config().SetSource(core.NewMapSource(map[string]any{"app.env": "development"}))
if err := ctx.Config().Resolve(); err != nil {
t.Fatal(err)
}
p := New(WithAddr("127.0.0.1:0"))
if err := p.Apply(ctx); err != nil {
t.Fatal(err)
}
startCtx, cancel := context.WithCancel(t.Context())
defer cancel()
if err := p.Start(startCtx); err != nil {
t.Fatal(err)
}
defer func() { _ = p.Stop(t.Context()) }()
w := httptest.NewRecorder()
req, _ := http.NewRequestWithContext(t.Context(), http.MethodGet, "/swagger/index.html", nil)
req.RequestURI = "/swagger/index.html"
p.Engine().ServeHTTP(w, req)
if w.Code != http.StatusOK {
t.Fatalf("expected 200 for /swagger/index.html, got %d (body: %s)", w.Code, w.Body.String())
}
}
@@ -17,7 +17,7 @@ const indexFile = "index.html"
// serverOwnedPrefixes are backend-owned namespaces. A miss there must keep Gin's default
// 404 instead of silently returning the frontend shell, which would mask broken API links.
var serverOwnedPrefixes = []string{"/api/", "/f/"}
var serverOwnedPrefixes = []string{"/api/", "/f/", "/swagger/"}
// registerFrontend mounts assets as the NoRoute fallback so client-side routes resolve.
// It is a no-op when assets is nil, i.e. the binary was built without the embed_frontend tag.
@@ -7,6 +7,7 @@ package driver_http
import (
"Wavelet/core"
"Wavelet/core/contracts"
_ "Wavelet/docs" // swagger documentation registration
"Wavelet/pkg/util"
"context"
"errors"
@@ -17,6 +18,8 @@ import (
"time"
"github.com/gin-gonic/gin"
swaggerFiles "github.com/swaggo/files"
ginSwagger "github.com/swaggo/gin-swagger"
)
const (
@@ -207,6 +210,19 @@ func (p *Plugin) Start(ctx context.Context) error {
}
}
// Mount Swagger in non-production environments
if p.coreCtx != nil {
var appCfg httpAppConfig
_ = p.coreCtx.Config().Bind("app", &appCfg)
if appCfg.Env != "production" && appCfg.Env != "prod" {
swaggerHandler := ginSwagger.WrapHandler(swaggerFiles.Handler)
p.engine.GET("/swagger/*any", swaggerHandler)
if appCfg.APIPrefix != "" {
p.engine.GET(appCfg.APIPrefix+"/swagger/*any", swaggerHandler)
}
}
}
registerFrontend(p.engine, frontendAssets())
p.server = &http.Server{