fix(api): align upload permissions and mount robots and swagger routes

This commit is contained in:
ryan
2026-08-30 17:53:42 +08:00
parent 7c5c196ede
commit 374289bfda
10 changed files with 6718 additions and 110 deletions
@@ -17,7 +17,7 @@ const indexFile = "index.html"
// serverOwnedPrefixes are backend-owned namespaces. A miss there must keep Gin's default
// 404 instead of silently returning the frontend shell, which would mask broken API links.
var serverOwnedPrefixes = []string{"/api/", "/f/"}
var serverOwnedPrefixes = []string{"/api/", "/f/", "/swagger/"}
// registerFrontend mounts assets as the NoRoute fallback so client-side routes resolve.
// It is a no-op when assets is nil, i.e. the binary was built without the embed_frontend tag.