wavelet init

This commit is contained in:
ryan
2026-06-18 15:24:48 +08:00
parent d6a7011885
commit 99738bbc17
714 changed files with 139987 additions and 0 deletions
+112
View File
@@ -0,0 +1,112 @@
// Copyright 2025 linux.do
// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
// Package router 提供 HTTP 路由注册与服务启动
package router
import (
"context"
"net/http"
"strconv"
"strings"
"time"
"github.com/Rain-kl/Wavelet/internal/common/response"
"github.com/Rain-kl/Wavelet/internal/config"
"github.com/Rain-kl/Wavelet/internal/model"
"github.com/Rain-kl/Wavelet/internal/repository"
"github.com/Rain-kl/Wavelet/pkg/logger"
otel_trace "github.com/Rain-kl/Wavelet/pkg/trace"
"github.com/gin-gonic/gin"
"go.opentelemetry.io/otel/codes"
"go.opentelemetry.io/otel/trace"
)
func loggerMiddleware() gin.HandlerFunc {
return func(c *gin.Context) {
// 初始化 Trace
ctx, span := otel_trace.Start(c.Request.Context(), "LoggerMiddleware")
defer span.End()
// 开始计时
start := time.Now()
// 记录请求路径和 Query
path := c.Request.URL.Path
raw := c.Request.URL.RawQuery
if raw != "" {
path = path + "?" + raw
}
// 执行请求
c.Next()
// 停止计时
end := time.Now()
latency := end.Sub(start)
// 打印日志
// 排除健康检查接口
healthPath := config.Config.App.APIPrefix + "/health"
if c.Request.URL.Path != healthPath {
logger.InfoF(
ctx,
"[LoggerMiddleware] %s %s\nStartTime: %s\nEndTime: %s\nLatency: %d\nClientIP: %s\nResponse: %d %d",
c.Request.Method,
path,
start.Format(time.RFC3339),
end.Format(time.RFC3339),
latency.Milliseconds(),
c.ClientIP(),
c.Writer.Status(),
c.Writer.Size(),
)
}
// 设置 Span 状态
if c.Writer.Status() >= http.StatusBadRequest {
span := trace.SpanFromContext(ctx)
span.SetStatus(codes.Error, strconv.Itoa(c.Writer.Status()))
}
}
}
func isOriginAllowed(ctx context.Context, origin string) bool {
sc, err := repository.GetSystemConfigByKey(ctx, model.ConfigKeyServerAddress)
if err != nil || sc.Value == "" {
return false
}
allowedOrigins := strings.Split(sc.Value, ",")
for _, allowed := range allowedOrigins {
allowed = strings.TrimRight(strings.TrimSpace(allowed), "/")
if allowed != "" && strings.EqualFold(allowed, origin) {
return true
}
}
return false
}
func corsMiddleware() gin.HandlerFunc {
return func(c *gin.Context) {
origin := c.Request.Header.Get("Origin")
if origin != "" && isOriginAllowed(c.Request.Context(), origin) {
c.Writer.Header().Set("Access-Control-Allow-Origin", origin)
c.Writer.Header().Set("Access-Control-Allow-Credentials", "true")
c.Writer.Header().Set("Access-Control-Allow-Headers", "Content-Type, Content-Length, Accept-Encoding, X-CSRF-Token, Authorization, accept, origin, Cache-Control, X-Requested-With, X-Access-Token, X-Cap-Token")
c.Writer.Header().Set("Access-Control-Allow-Methods", "POST, OPTIONS, GET, PUT, DELETE, PATCH")
}
if c.Request.Method == "OPTIONS" {
c.AbortWithStatus(http.StatusNoContent)
return
}
c.Next()
}
}
// errorHandlerMiddleware 委托给 response.ErrorHandlerMiddleware,保持路由层单一入口。
func errorHandlerMiddleware() gin.HandlerFunc {
return response.ErrorHandlerMiddleware()
}
+128
View File
@@ -0,0 +1,128 @@
// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
package router
import (
"context"
"net/http"
"net/http/httptest"
"testing"
"github.com/Rain-kl/Wavelet/internal/model"
"github.com/Rain-kl/Wavelet/internal/repository"
"github.com/Rain-kl/Wavelet/internal/testhelper"
"github.com/gin-gonic/gin"
)
func TestCORSMiddleware(t *testing.T) {
dbConn, _, cleanup := testhelper.SetupTestEnvironment(t)
defer cleanup()
gin.SetMode(gin.TestMode)
clearConfigCache := func() {
if err := repository.InvalidateAllSystemConfigCaches(context.Background()); err != nil {
t.Fatalf("InvalidateAllSystemConfigCaches() error = %v", err)
}
}
t.Run("missing server_address configuration returns no CORS headers", func(t *testing.T) {
clearConfigCache()
// Ensure it's empty in DB
if err := dbConn.Model(&model.SystemConfig{}).Where("key = ?", model.ConfigKeyServerAddress).Update("value", "").Error; err != nil {
t.Fatalf("failed to update config: %v", err)
}
clearConfigCache()
r := gin.New()
r.Use(corsMiddleware())
r.GET("/test", func(c *gin.Context) {
c.String(http.StatusOK, "ok")
})
req, _ := http.NewRequest(http.MethodGet, "/test", nil)
req.Header.Set("Origin", "http://attacker.com")
w := httptest.NewRecorder()
r.ServeHTTP(w, req)
if w.Code != http.StatusOK {
t.Fatalf("expected 200 OK, got %d", w.Code)
}
if val := w.Header().Get("Access-Control-Allow-Origin"); val != "" {
t.Errorf("expected empty Access-Control-Allow-Origin header, got %q", val)
}
if val := w.Header().Get("Access-Control-Allow-Credentials"); val != "" {
t.Errorf("expected empty Access-Control-Allow-Credentials header, got %q", val)
}
})
t.Run("matching server_address allows origin and sets credential headers", func(t *testing.T) {
clearConfigCache()
if err := dbConn.Model(&model.SystemConfig{}).Where("key = ?", model.ConfigKeyServerAddress).Update("value", "https://trusted.com, http://localhost:3000/").Error; err != nil {
t.Fatalf("failed to update config: %v", err)
}
clearConfigCache()
r := gin.New()
r.Use(corsMiddleware())
r.GET("/test", func(c *gin.Context) {
c.String(http.StatusOK, "ok")
})
// Test trusted origin 1
req1, _ := http.NewRequest(http.MethodGet, "/test", nil)
req1.Header.Set("Origin", "https://trusted.com")
w1 := httptest.NewRecorder()
r.ServeHTTP(w1, req1)
if w1.Code != http.StatusOK {
t.Fatalf("expected 200 OK, got %d", w1.Code)
}
if val := w1.Header().Get("Access-Control-Allow-Origin"); val != "https://trusted.com" {
t.Errorf("expected Access-Control-Allow-Origin 'https://trusted.com', got %q", val)
}
if val := w1.Header().Get("Access-Control-Allow-Credentials"); val != "true" {
t.Errorf("expected Access-Control-Allow-Credentials 'true', got %q", val)
}
// Test trusted origin 2 (trimmed trailing slash)
req2, _ := http.NewRequest(http.MethodGet, "/test", nil)
req2.Header.Set("Origin", "http://localhost:3000")
w2 := httptest.NewRecorder()
r.ServeHTTP(w2, req2)
if w2.Code != http.StatusOK {
t.Fatalf("expected 200 OK, got %d", w2.Code)
}
if val := w2.Header().Get("Access-Control-Allow-Origin"); val != "http://localhost:3000" {
t.Errorf("expected Access-Control-Allow-Origin 'http://localhost:3000', got %q", val)
}
})
t.Run("non-matching origin is denied CORS headers", func(t *testing.T) {
clearConfigCache()
if err := dbConn.Model(&model.SystemConfig{}).Where("key = ?", model.ConfigKeyServerAddress).Update("value", "https://trusted.com").Error; err != nil {
t.Fatalf("failed to update config: %v", err)
}
clearConfigCache()
r := gin.New()
r.Use(corsMiddleware())
r.GET("/test", func(c *gin.Context) {
c.String(http.StatusOK, "ok")
})
req, _ := http.NewRequest(http.MethodGet, "/test", nil)
req.Header.Set("Origin", "https://attacker.com")
w := httptest.NewRecorder()
r.ServeHTTP(w, req)
if w.Code != http.StatusOK {
t.Fatalf("expected 200 OK, got %d", w.Code)
}
if val := w.Header().Get("Access-Control-Allow-Origin"); val != "" {
t.Errorf("expected empty Access-Control-Allow-Origin header, got %q", val)
}
})
}
+14
View File
@@ -0,0 +1,14 @@
// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
// Package root registers custom business routes and frontend serving.
package root
import (
"github.com/gin-gonic/gin"
)
// RegisterCustomRootRoutes registers custom business routes that belong to the root path.
func RegisterCustomRootRoutes(_ *gin.Engine) {
// Add custom root routes here
}
+32
View File
@@ -0,0 +1,32 @@
// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
package root
import (
_ "github.com/Rain-kl/Wavelet/docs" // Swagger documentation generation setup
publicconfig "github.com/Rain-kl/Wavelet/internal/apps/config"
"github.com/Rain-kl/Wavelet/internal/apps/health"
"github.com/Rain-kl/Wavelet/internal/apps/upload"
"github.com/Rain-kl/Wavelet/internal/config"
"github.com/gin-gonic/gin"
swaggerFiles "github.com/swaggo/files"
ginSwagger "github.com/swaggo/gin-swagger"
)
// RegisterDefaultRootRoutes registers default routes that belong to the root path.
func RegisterDefaultRootRoutes(r *gin.Engine) {
// 1. Serve files by ID
r.GET("/f/:id", upload.ServeFileByID)
// 2. Dynamic robots.txt serving
r.GET("/robots.txt", publicconfig.GetRobotsTXT)
// 3. Swagger routes (Non-production only)
if !config.Config.App.IsProduction() {
r.GET(config.Config.App.APIPrefix+"/swagger/*any", ginSwagger.WrapHandler(swaggerFiles.Handler))
}
// 4. Health check
r.GET(config.Config.App.APIPrefix+"/health", health.Health)
}
+110
View File
@@ -0,0 +1,110 @@
//go:build embed_frontend
// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
package root
import (
"embed"
"io"
"io/fs"
"net/http"
"strings"
"github.com/gin-gonic/gin"
)
//go:embed all:dist
var frontendFS embed.FS
func serveFileDirect(c *gin.Context, subFS fs.FS, filePath string) bool {
file, err := subFS.Open(filePath)
if err != nil {
return false
}
defer file.Close()
stat, err := file.Stat()
if err != nil {
return false
}
if stat.IsDir() {
return false
}
seeker, ok := file.(io.ReadSeeker)
if !ok {
return false
}
// 使用 http.ServeContent 直接输出文件内容,不进行路径规范化重定向
http.ServeContent(c.Writer, c.Request, filePath, stat.ModTime(), seeker)
return true
}
func init() {
RegisterFrontend = func(r *gin.Engine) {
subFS, err := fs.Sub(frontendFS, "dist")
if err != nil {
panic(err)
}
r.NoRoute(func(c *gin.Context) {
path := c.Request.URL.Path
// API 接口路由或文件服务路由 -> 直接返回,由 Gin 处理标准 404
if strings.HasPrefix(path, "/api/") || strings.HasPrefix(path, "/f/") {
return
}
// 只处理 GET 和 HEAD 请求
if c.Request.Method != http.MethodGet && c.Request.Method != http.MethodHead {
c.JSON(http.StatusMethodNotAllowed, gin.H{"error_msg": "Method not allowed"})
return
}
// 移除开头的斜杠以在嵌入文件系统中查找
cleanPath := strings.TrimPrefix(path, "/")
// 1. 根路径 -> 直接输出 index.html
if cleanPath == "" {
if serveFileDirect(c, subFS, "index.html") {
return
}
}
// 2. 精确匹配(如果对应的文件存在,直接输出)
if serveFileDirect(c, subFS, cleanPath) {
return
}
// 如果是个目录(例如请求了 "/login",同时 dist 目录下存在一个叫 "login" 的文件夹目录),
// 则查找是否有对应的 ".html" 文件(例如 "login.html")并进行输出。
if cleanPath != "" {
htmlPath := cleanPath + ".html"
if serveFileDirect(c, subFS, htmlPath) {
return
}
}
// 3. Next.js Clean URLs 兜底逻辑(例如访问 /settings/security -> 实际映射输出 settings/security.html)
if !strings.Contains(cleanPath, ".") {
htmlPath := cleanPath + ".html"
if serveFileDirect(c, subFS, htmlPath) {
return
}
indexPath := cleanPath + "/index.html"
if serveFileDirect(c, subFS, indexPath) {
return
}
}
// 4. 单页应用(SPA)前端路由兜底:返回 index.html
if serveFileDirect(c, subFS, "index.html") {
return
}
})
}
}
+26
View File
@@ -0,0 +1,26 @@
// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
// Package root registers custom business routes and frontend serving.
package root
import (
"github.com/gin-gonic/gin"
)
// RegisterFrontend is a package-level variable overridden by frontend.go when built with embed_frontend.
var RegisterFrontend = func(_ *gin.Engine) {
// No-op by default
}
// RegisterRootRoutes registers custom business routes that belong to the root path.
func RegisterRootRoutes(r *gin.Engine) {
// 1. Default root routes (/f/:id, /robots.txt, and /swagger/*any)
RegisterDefaultRootRoutes(r)
// 2. Register custom serving
RegisterCustomRootRoutes(r)
// 3. Register frontend serving
RegisterFrontend(r)
}
+122
View File
@@ -0,0 +1,122 @@
// Copyright 2025 linux.do
// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
package router
import (
"context"
"errors"
"log"
"net/http"
"os"
"os/signal"
"strconv"
"syscall"
"time"
"github.com/Rain-kl/Wavelet/internal/apps/risk_control"
router_root "github.com/Rain-kl/Wavelet/internal/router/root"
v1 "github.com/Rain-kl/Wavelet/internal/router/v1"
"github.com/Rain-kl/Wavelet/internal/apps/oauth"
"github.com/Rain-kl/Wavelet/internal/config"
otel_trace "github.com/Rain-kl/Wavelet/pkg/trace"
"github.com/gin-contrib/sessions"
"github.com/gin-contrib/sessions/redis"
"github.com/gin-gonic/gin"
"go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin"
)
// Serve 启动 HTTP API 服务
func Serve() {
// 运行模式
if config.Config.App.IsProduction() {
gin.SetMode(gin.ReleaseMode)
}
// 初始化路由
r := gin.New()
r.Use(gin.Recovery())
r.Use(corsMiddleware())
cfg := config.Config.Redis
addrs := cfg.Addrs
sessionAddr := "localhost:6379"
if len(addrs) > 0 {
sessionAddr = addrs[0]
}
sessionStore, err := redis.NewStoreWithDB(
cfg.MinIdleConn,
"tcp",
sessionAddr,
cfg.Username,
cfg.Password,
strconv.Itoa(cfg.DB),
[]byte(config.Config.App.SessionSecret),
)
if err != nil {
log.Fatalf("[API] init session store failed: %v\n", err)
}
// 设置 Session Redis Key 前缀
if cfg.KeyPrefix != "" {
if err := redis.SetKeyPrefix(sessionStore, cfg.KeyPrefix+"session:"); err != nil {
log.Printf("[API] set session key prefix failed: %v\n", err)
}
}
sessionStore.Options(oauth.GetSessionOptions(config.Config.App.SessionAge))
r.Use(sessions.Sessions(config.Config.App.SessionCookieName, sessionStore))
// 补充中间件
r.Use(otelgin.Middleware(config.Config.App.AppName), errorHandlerMiddleware(), loggerMiddleware(), risk_control.RiskControlMiddleware())
registerRoutes(r)
srv := &http.Server{
Addr: config.Config.App.Addr,
Handler: r,
ReadHeaderTimeout: 10 * time.Second,
}
go func() {
log.Printf("[API] server starting on %s\n", config.Config.App.Addr)
if err := srv.ListenAndServe(); err != nil && !errors.Is(err, http.ErrServerClosed) {
log.Fatalf("[API] server failed: %v\n", err)
}
}()
quit := make(chan os.Signal, 1)
signal.Notify(quit, syscall.SIGINT, syscall.SIGTERM)
<-quit
shutdownCtx, cancel := context.WithTimeout(context.Background(), time.Duration(config.Config.App.GracefulShutdownTimeout)*time.Second)
otel_trace.Shutdown(shutdownCtx)
if err := srv.Shutdown(shutdownCtx); err != nil {
log.Printf("[API] server forced to shutdown: %v\n", err)
cancel()
os.Exit(1)
}
cancel()
log.Println("[API] server exited")
}
func registerRoutes(r *gin.Engine) {
// Register custom root routes, Swagger, and frontend serving
router_root.RegisterRootRoutes(r)
apiGroup := r.Group(config.Config.App.APIPrefix)
{
// API V1
apiV1Router := apiGroup.Group("/v1")
{
v1.RegisterV1Routes(apiV1Router, apiGroup)
}
}
}
+217
View File
@@ -0,0 +1,217 @@
// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
// Package v1 contains router registrations for API V1
package v1
import (
"github.com/Rain-kl/Wavelet/internal/apps/admin"
admin_auth_source "github.com/Rain-kl/Wavelet/internal/apps/admin/auth_source"
admin_cache "github.com/Rain-kl/Wavelet/internal/apps/admin/cache"
admin_db_manage "github.com/Rain-kl/Wavelet/internal/apps/admin/db_manage"
admin_logs "github.com/Rain-kl/Wavelet/internal/apps/admin/logs"
admin_push "github.com/Rain-kl/Wavelet/internal/apps/admin/push"
admin_status "github.com/Rain-kl/Wavelet/internal/apps/admin/status"
"github.com/Rain-kl/Wavelet/internal/apps/admin/system_config"
admin_task "github.com/Rain-kl/Wavelet/internal/apps/admin/task"
admin_template "github.com/Rain-kl/Wavelet/internal/apps/admin/template"
admin_updater "github.com/Rain-kl/Wavelet/internal/apps/admin/updater"
admin_user "github.com/Rain-kl/Wavelet/internal/apps/admin/user"
"github.com/Rain-kl/Wavelet/internal/apps/oauth"
"github.com/Rain-kl/Wavelet/internal/apps/upload"
"github.com/gin-gonic/gin"
)
// RegisterAdminRoutes registers all admin-related routes with sub-group categorizations.
func RegisterAdminRoutes(apiV1Router *gin.RouterGroup) {
adminRouter := apiV1Router.Group("/admin")
adminRouter.Use(oauth.LoginRequired(), admin.LoginAdminRequired())
{
// 1. Diagnostics & Infrastructure Management
registerAdminDiagnosticRoutes(adminRouter)
// 2. Identity & Access Management (IAM)
registerAdminIAMRoutes(adminRouter)
// 3. System Configuration & Templates Settings
registerAdminConfigRoutes(adminRouter)
// 4. Storage & Asset Management
registerAdminStorageRoutes(adminRouter)
// 5. Task Orchestration & Automation
registerAdminTaskRoutes(adminRouter)
// 6. Messaging & Push Notifications
registerAdminPushRoutes(adminRouter)
}
}
// registerAdminDiagnosticRoutes registers infrastructure, system status, caching, database, and logs diagnostics.
func registerAdminDiagnosticRoutes(adminRouter *gin.RouterGroup) {
// System status
adminRouter.GET("/status", admin_status.GetSystemStatus)
// Database basic info & backup export
adminRouter.GET("/db-info", admin_status.GetDatabaseInfo)
adminRouter.GET("/db-export", admin_status.ExportDatabase)
// Database management & interactive browser
dbManage := adminRouter.Group("/db-manage")
{
dbManage.GET("/overview", admin_db_manage.GetDBOverview)
dbManage.GET("/tables", admin_db_manage.ListDBTables)
dbManage.GET("/table-data", admin_db_manage.GetDBTableData)
dbManage.POST("/query", admin_db_manage.ExecuteSQL)
}
// Cache management (TTL, LRU eviction and clear operations)
cache := adminRouter.Group("/cache")
{
cache.GET("/status", admin_cache.GetCacheStatus)
cache.POST("/config", admin_cache.UpdateCacheConfig)
cache.POST("/clear", admin_cache.ClearCache)
}
// Application updater
update := adminRouter.Group("/update")
{
update.GET("", admin_updater.GetUpdateStatus)
update.POST("/apply", admin_updater.ApplyUpdate)
}
// System & access logs analytics
logs := adminRouter.Group("/logs")
{
logs.GET("", admin_logs.GetLogs)
logs.GET("/access", admin_logs.GetAccessLogs)
logs.GET("/analytics", admin_logs.GetLogsAnalytics)
logs.GET("/ws", admin_logs.HandleLogWebSocket)
}
}
// registerAdminIAMRoutes registers Identity & Access Management endpoints (Users & Auth Sources).
func registerAdminIAMRoutes(adminRouter *gin.RouterGroup) {
// Users management
users := adminRouter.Group("/users")
{
users.GET("", admin_user.ListUsers)
users.POST("", admin_user.CreateUser)
users.GET("/:id", admin_user.GetUser)
users.PUT("/:id/status", admin_user.UpdateUserStatus)
users.DELETE("/:id", admin_user.DeleteUser)
}
// Authentication Sources (LDAP, OAuth sources, etc.)
authSources := adminRouter.Group("/auth-sources")
{
authSources.GET("", admin_auth_source.ListAuthSources)
authSources.POST("", admin_auth_source.CreateAuthSource)
authSources.PUT("/:id", admin_auth_source.UpdateAuthSource)
authSources.PUT("/:id/toggle", admin_auth_source.ToggleAuthSource)
authSources.DELETE("/:id", admin_auth_source.DeleteAuthSource)
}
}
// registerAdminConfigRoutes registers system configurations and template settings.
func registerAdminConfigRoutes(adminRouter *gin.RouterGroup) {
// System configs
configs := adminRouter.Group("/system-configs")
{
configs.GET("", system_config.ListSystemConfigs)
configs.POST("", system_config.CreateSystemConfig)
configs.POST("/smtp/test", system_config.TestSMTP)
keyGroup := configs.Group("/:key")
{
keyGroup.GET("", system_config.GetSystemConfig)
keyGroup.PUT("", system_config.UpdateSystemConfig)
}
}
// Email/Notification Templates
templates := adminRouter.Group("/templates")
{
templates.GET("", admin_template.ListTemplates)
templates.POST("", admin_template.CreateTemplate)
keyGroup := templates.Group("/:key")
{
keyGroup.GET("", admin_template.GetTemplate)
keyGroup.PUT("", admin_template.UpdateTemplate)
keyGroup.DELETE("", admin_template.DeleteTemplate)
}
}
}
// registerAdminStorageRoutes registers file and asset storage administration.
func registerAdminStorageRoutes(adminRouter *gin.RouterGroup) {
uploads := adminRouter.Group("/uploads")
{
uploads.GET("", upload.ListFiles)
uploads.GET("/stats", upload.GetFileStats)
uploads.DELETE("/:id", upload.DeleteFile)
uploads.GET("/download/:id", upload.DownloadFile)
uploads.POST("/download/batch", upload.BatchDownloadFiles)
uploads.GET("/types", upload.GetDistinctUploadTypes)
}
}
// registerAdminTaskRoutes registers task orchestrations, execution logs and schedules.
func registerAdminTaskRoutes(adminRouter *gin.RouterGroup) {
tasks := adminRouter.Group("/tasks")
{
// Task dispatch & metadata
tasks.GET("/types", admin_task.ListTaskTypes)
tasks.POST("/dispatch", admin_task.DispatchTask)
// Task execution logs & manual retry
executions := tasks.Group("/executions")
{
executions.GET("", admin_task.ListTaskExecutions)
executions.GET("/:id", admin_task.GetTaskExecution)
executions.POST("/:id/retry", admin_task.RetryTask)
}
// Cron scheduler settings
schedules := tasks.Group("/schedules")
{
schedules.GET("", admin_task.ListSchedules)
schedules.POST("", admin_task.CreateSchedule)
schedules.PUT("/:id", admin_task.UpdateSchedule)
schedules.DELETE("/:id", admin_task.DeleteSchedule)
}
}
}
// registerAdminPushRoutes registers messaging channels and push notification events.
func registerAdminPushRoutes(adminRouter *gin.RouterGroup) {
push := adminRouter.Group("/push")
{
// Push Events
events := push.Group("/events")
{
events.GET("", admin_push.ListEvents)
events.GET("/builtin", admin_push.ListBuiltInEvents)
events.POST("", admin_push.CreateEvent)
events.PUT("/:id", admin_push.UpdateEvent)
events.DELETE("/:id", admin_push.DeleteEvent)
events.POST("/:id/toggle", admin_push.ToggleEvent)
}
// Delivery histories and diagnostics test
push.GET("/histories", admin_push.ListHistories)
push.POST("/test", admin_push.TestPush)
// Message Channels CRUD
channels := push.Group("/channels")
{
channels.GET("/definitions", admin_push.ListChannelDefinitions)
channels.GET("", admin_push.ListChannels)
channels.POST("", admin_push.CreateChannel)
channels.PUT("/:id", admin_push.UpdateChannel)
channels.DELETE("/:id", admin_push.DeleteChannel)
channels.POST("/test", admin_push.TestChannel)
}
}
}
+18
View File
@@ -0,0 +1,18 @@
// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
// Package v1 contains router registrations for API V1
package v1
import (
"github.com/Rain-kl/Wavelet/internal/apps/custom"
"github.com/gin-gonic/gin"
)
// RegisterCustomRoutes registers custom business routes to keep routing clean and stable.
func RegisterCustomRoutes(apiV1Router *gin.RouterGroup) {
customRouter := apiV1Router.Group("/custom")
{
customRouter.GET("/hello", custom.Hello)
}
}
+95
View File
@@ -0,0 +1,95 @@
// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
// Package v1 contains router registrations for API V1
package v1
import (
capApp "github.com/Rain-kl/Wavelet/internal/apps/cap"
publicconfig "github.com/Rain-kl/Wavelet/internal/apps/config"
"github.com/Rain-kl/Wavelet/internal/apps/oauth"
"github.com/Rain-kl/Wavelet/internal/apps/upload"
"github.com/Rain-kl/Wavelet/internal/apps/user"
"github.com/gin-gonic/gin"
)
// RegisterUserRoutes registers all user-related, oauth, upload, and public routes.
func RegisterUserRoutes(apiV1Router *gin.RouterGroup, apiGroup *gin.RouterGroup) {
// 1. CAPTCHA
registerCaptchaRoutes(apiGroup)
// 2. Config (public)
registerConfigRoutes(apiV1Router)
// 3. OAuth
registerOAuthRoutes(apiV1Router)
// 4. User
registerUserRoutes(apiV1Router)
// 5. Upload
registerUploadRoutes(apiV1Router)
}
func registerCaptchaRoutes(apiGroup *gin.RouterGroup) {
capGroup := apiGroup.Group("/cap")
{
capGroup.POST("/challenge", capApp.Challenge)
capGroup.POST("/redeem", capApp.Redeem)
}
}
func registerConfigRoutes(apiV1Router *gin.RouterGroup) {
configRouter := apiV1Router.Group("/config")
{
configRouter.GET("/public", publicconfig.GetPublicConfig)
}
}
func registerOAuthRoutes(apiV1Router *gin.RouterGroup) {
apiV1Router.GET("/oauth/sources", oauth.GetLoginSources)
apiV1Router.GET("/oauth/login", oauth.GetLoginURL)
apiV1Router.GET("/oauth/:source/authorize", oauth.Authorize)
apiV1Router.GET("/oauth/logout", oauth.Logout)
apiV1Router.POST("/oauth/callback", oauth.Callback)
apiV1Router.GET("/oauth/user-info", oauth.LoginRequired(), oauth.UserInfo)
apiV1Router.GET("/user-info", oauth.LoginRequired(), oauth.UserInfo)
apiV1Router.GET("/oauth/external-accounts", oauth.LoginRequired(), oauth.ListExternalAccounts)
apiV1Router.POST("/oauth/external-accounts/:id/delete", oauth.LoginRequired(), oauth.DeleteExternalAccount)
}
func registerUserRoutes(apiV1Router *gin.RouterGroup) {
userRouter := apiV1Router.Group("/user")
{
userRouter.POST("/login", capApp.VerifyMiddleware(capApp.GetDefaultManager(), "login"), user.Login)
userRouter.POST("/register", capApp.VerifyMiddleware(capApp.GetDefaultManager(), "register"), user.Register)
userRouter.POST("/send-email-code", capApp.VerifyMiddleware(capApp.GetDefaultManager(), "send_email_code"), user.SendEmailCode)
userRouter.GET("/logout", user.Logout)
userRouter.GET("/self", oauth.LoginRequired(), oauth.UserInfo)
userRouter.POST("/change-password", oauth.LoginRequired(), user.ChangePassword)
userRouter.PUT("/profile", oauth.LoginRequired(), user.UpdateProfile)
// Access Token
tokenRouter := userRouter.Group("/access-tokens")
tokenRouter.Use(oauth.LoginRequired(), oauth.DisallowTokenAuth())
{
tokenRouter.GET("", user.ListAccessTokens)
tokenRouter.POST("", user.CreateAccessToken)
tokenRouter.DELETE("/:id", user.DeleteAccessToken)
tokenRouter.POST("/:id/rotate", user.RotateAccessToken)
}
}
}
func registerUploadRoutes(apiV1Router *gin.RouterGroup) {
uploadRouter := apiV1Router.Group("/upload")
uploadRouter.Use(oauth.LoginRequired())
{
uploadRouter.POST("", upload.UploadFile)
uploadRouter.GET("/my", upload.ListMyFiles)
uploadRouter.DELETE("/:id", upload.DeleteMyFile)
uploadRouter.PUT("/:id", upload.UpdateMyFile)
uploadRouter.GET("/download/:id", upload.DownloadFile)
uploadRouter.POST("/download/batch", upload.BatchDownloadFiles)
}
}
+21
View File
@@ -0,0 +1,21 @@
// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
// Package v1 contains router registrations for API V1
package v1
import (
"github.com/gin-gonic/gin"
)
// RegisterV1Routes registers all routes under API V1.
func RegisterV1Routes(apiV1Router *gin.RouterGroup, apiGroup *gin.RouterGroup) {
// 1. User & Public routes (OAuth, User, Upload, CAPTCHA, Health, Config)
RegisterUserRoutes(apiV1Router, apiGroup)
// 2. Admin routes
RegisterAdminRoutes(apiV1Router)
// 3. Register custom business routes
RegisterCustomRoutes(apiV1Router)
}