mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-08 16:46:37 +08:00
fix(api): align upload permissions and mount robots and swagger routes
This commit is contained in:
@@ -170,6 +170,10 @@ func (p *Plugin) Apply(ctx *core.Context) error {
|
||||
adminRouter := ctx.Router().Group("/api/v1/admin", loginMW, adminMW)
|
||||
handler.RegisterRoutes(adminRouter)
|
||||
|
||||
// Register robots.txt public route
|
||||
ctx.Router().GET("/robots.txt", handler.GetRobotsTXT)
|
||||
ctx.Router().RegisterWhitelist("/robots.txt")
|
||||
|
||||
// 2. Register Background Tasks
|
||||
logSwitchHandler := &service.LogDBSwitchHandler{}
|
||||
ctx.Task().Register(service.LogDBSwitchTask, func(c context.Context, payload []byte) error {
|
||||
|
||||
@@ -23,6 +23,14 @@ func TestAdminPluginUnit(t *testing.T) {
|
||||
// Verify routes
|
||||
routes := ctx.Router().Routes()
|
||||
assert.NotEmpty(t, routes)
|
||||
var hasRobots bool
|
||||
for _, r := range routes {
|
||||
if r.Path == "/robots.txt" && r.Method == "GET" {
|
||||
hasRobots = true
|
||||
break
|
||||
}
|
||||
}
|
||||
assert.True(t, hasRobots, "admin plugin must register /robots.txt")
|
||||
|
||||
// Verify tasks
|
||||
_, ok := ctx.Tasks().Get("admin:system_cleanup")
|
||||
|
||||
@@ -112,6 +112,7 @@ func (p *Plugin) Apply(ctx *core.Context) error {
|
||||
return err
|
||||
}
|
||||
loginMW := authSvc.RequireAuthMiddleware().(gin.HandlerFunc)
|
||||
adminMW := authSvc.RequireAdminMiddleware().(gin.HandlerFunc)
|
||||
|
||||
// 0a. Register migrations
|
||||
ctx.Migrations().Register("upload", uploadMigrations)
|
||||
@@ -123,16 +124,14 @@ func (p *Plugin) Apply(ctx *core.Context) error {
|
||||
uploadGroup := ctx.Router().Group("/api/v1/upload", loginMW)
|
||||
{
|
||||
uploadGroup.POST("", handler.UploadFile)
|
||||
uploadGroup.GET("", handler.ListFiles)
|
||||
uploadGroup.DELETE("/:id", handler.DeleteFile)
|
||||
uploadGroup.POST("/batch-download", handler.BatchDownloadFiles)
|
||||
uploadGroup.DELETE("/:id", handler.DeleteMyFile)
|
||||
uploadGroup.GET("/my", handler.ListMyFiles)
|
||||
uploadGroup.PUT("/:id", handler.UpdateMyFile)
|
||||
uploadGroup.GET("/download/:id", handler.DownloadFile)
|
||||
uploadGroup.POST("/download/batch", handler.BatchDownloadFiles)
|
||||
}
|
||||
|
||||
adminUploadGroup := ctx.Router().Group("/api/v1/admin/uploads", loginMW)
|
||||
adminUploadGroup := ctx.Router().Group("/api/v1/admin/uploads", loginMW, adminMW)
|
||||
{
|
||||
adminUploadGroup.GET("", handler.ListFiles)
|
||||
adminUploadGroup.GET("/stats", handler.GetFileStats)
|
||||
|
||||
@@ -23,6 +23,10 @@ func (stubAuthService) RequireAuthMiddleware() any {
|
||||
return gin.HandlerFunc(func(c *gin.Context) { c.Next() })
|
||||
}
|
||||
|
||||
func (stubAuthService) RequireAdminMiddleware() any {
|
||||
return gin.HandlerFunc(func(c *gin.Context) { c.Next() })
|
||||
}
|
||||
|
||||
func TestUserUploadRoutes(t *testing.T) {
|
||||
gin.SetMode(gin.TestMode)
|
||||
ctx := core.NewContext(context.Background())
|
||||
@@ -34,12 +38,18 @@ func TestUserUploadRoutes(t *testing.T) {
|
||||
}
|
||||
|
||||
want := []string{
|
||||
"POST /api/v1/upload",
|
||||
"DELETE /api/v1/upload/:id",
|
||||
"GET /api/v1/upload/my",
|
||||
"PUT /api/v1/upload/:id",
|
||||
"GET /api/v1/upload/download/:id",
|
||||
"POST /api/v1/upload/download/batch",
|
||||
"GET /api/v1/upload",
|
||||
"POST /api/v1/upload/batch-download",
|
||||
"GET /api/v1/admin/uploads",
|
||||
"GET /api/v1/admin/uploads/stats",
|
||||
"DELETE /api/v1/admin/uploads/:id",
|
||||
"GET /api/v1/admin/uploads/download/:id",
|
||||
"POST /api/v1/admin/uploads/download/batch",
|
||||
"GET /api/v1/admin/uploads/types",
|
||||
}
|
||||
found := make(map[string]bool, len(want))
|
||||
for _, rd := range ctx.Router().Routes() {
|
||||
|
||||
Reference in New Issue
Block a user