mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-06 15:46:37 +08:00
wavelet init
This commit is contained in:
@@ -0,0 +1,112 @@
|
||||
// Copyright 2025 linux.do
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
// Package router 提供 HTTP 路由注册与服务启动
|
||||
package router
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net/http"
|
||||
"strconv"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/common/response"
|
||||
"github.com/Rain-kl/Wavelet/internal/config"
|
||||
"github.com/Rain-kl/Wavelet/internal/model"
|
||||
"github.com/Rain-kl/Wavelet/internal/repository"
|
||||
"github.com/Rain-kl/Wavelet/pkg/logger"
|
||||
otel_trace "github.com/Rain-kl/Wavelet/pkg/trace"
|
||||
"github.com/gin-gonic/gin"
|
||||
"go.opentelemetry.io/otel/codes"
|
||||
"go.opentelemetry.io/otel/trace"
|
||||
)
|
||||
|
||||
func loggerMiddleware() gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
// 初始化 Trace
|
||||
ctx, span := otel_trace.Start(c.Request.Context(), "LoggerMiddleware")
|
||||
defer span.End()
|
||||
|
||||
// 开始计时
|
||||
start := time.Now()
|
||||
|
||||
// 记录请求路径和 Query
|
||||
path := c.Request.URL.Path
|
||||
raw := c.Request.URL.RawQuery
|
||||
if raw != "" {
|
||||
path = path + "?" + raw
|
||||
}
|
||||
|
||||
// 执行请求
|
||||
c.Next()
|
||||
|
||||
// 停止计时
|
||||
end := time.Now()
|
||||
latency := end.Sub(start)
|
||||
|
||||
// 打印日志
|
||||
// 排除健康检查接口
|
||||
healthPath := config.Config.App.APIPrefix + "/health"
|
||||
if c.Request.URL.Path != healthPath {
|
||||
logger.InfoF(
|
||||
ctx,
|
||||
"[LoggerMiddleware] %s %s\nStartTime: %s\nEndTime: %s\nLatency: %d\nClientIP: %s\nResponse: %d %d",
|
||||
c.Request.Method,
|
||||
path,
|
||||
start.Format(time.RFC3339),
|
||||
end.Format(time.RFC3339),
|
||||
latency.Milliseconds(),
|
||||
c.ClientIP(),
|
||||
c.Writer.Status(),
|
||||
c.Writer.Size(),
|
||||
)
|
||||
}
|
||||
|
||||
// 设置 Span 状态
|
||||
if c.Writer.Status() >= http.StatusBadRequest {
|
||||
span := trace.SpanFromContext(ctx)
|
||||
span.SetStatus(codes.Error, strconv.Itoa(c.Writer.Status()))
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func isOriginAllowed(ctx context.Context, origin string) bool {
|
||||
sc, err := repository.GetSystemConfigByKey(ctx, model.ConfigKeyServerAddress)
|
||||
if err != nil || sc.Value == "" {
|
||||
return false
|
||||
}
|
||||
allowedOrigins := strings.Split(sc.Value, ",")
|
||||
for _, allowed := range allowedOrigins {
|
||||
allowed = strings.TrimRight(strings.TrimSpace(allowed), "/")
|
||||
if allowed != "" && strings.EqualFold(allowed, origin) {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func corsMiddleware() gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
origin := c.Request.Header.Get("Origin")
|
||||
if origin != "" && isOriginAllowed(c.Request.Context(), origin) {
|
||||
c.Writer.Header().Set("Access-Control-Allow-Origin", origin)
|
||||
c.Writer.Header().Set("Access-Control-Allow-Credentials", "true")
|
||||
c.Writer.Header().Set("Access-Control-Allow-Headers", "Content-Type, Content-Length, Accept-Encoding, X-CSRF-Token, Authorization, accept, origin, Cache-Control, X-Requested-With, X-Access-Token, X-Cap-Token")
|
||||
c.Writer.Header().Set("Access-Control-Allow-Methods", "POST, OPTIONS, GET, PUT, DELETE, PATCH")
|
||||
}
|
||||
|
||||
if c.Request.Method == "OPTIONS" {
|
||||
c.AbortWithStatus(http.StatusNoContent)
|
||||
return
|
||||
}
|
||||
|
||||
c.Next()
|
||||
}
|
||||
}
|
||||
|
||||
// errorHandlerMiddleware 委托给 response.ErrorHandlerMiddleware,保持路由层单一入口。
|
||||
func errorHandlerMiddleware() gin.HandlerFunc {
|
||||
return response.ErrorHandlerMiddleware()
|
||||
}
|
||||
@@ -0,0 +1,128 @@
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
package router
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"testing"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/model"
|
||||
"github.com/Rain-kl/Wavelet/internal/repository"
|
||||
"github.com/Rain-kl/Wavelet/internal/testhelper"
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
func TestCORSMiddleware(t *testing.T) {
|
||||
dbConn, _, cleanup := testhelper.SetupTestEnvironment(t)
|
||||
defer cleanup()
|
||||
|
||||
gin.SetMode(gin.TestMode)
|
||||
|
||||
clearConfigCache := func() {
|
||||
if err := repository.InvalidateAllSystemConfigCaches(context.Background()); err != nil {
|
||||
t.Fatalf("InvalidateAllSystemConfigCaches() error = %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
t.Run("missing server_address configuration returns no CORS headers", func(t *testing.T) {
|
||||
clearConfigCache()
|
||||
// Ensure it's empty in DB
|
||||
if err := dbConn.Model(&model.SystemConfig{}).Where("key = ?", model.ConfigKeyServerAddress).Update("value", "").Error; err != nil {
|
||||
t.Fatalf("failed to update config: %v", err)
|
||||
}
|
||||
clearConfigCache()
|
||||
|
||||
r := gin.New()
|
||||
r.Use(corsMiddleware())
|
||||
r.GET("/test", func(c *gin.Context) {
|
||||
c.String(http.StatusOK, "ok")
|
||||
})
|
||||
|
||||
req, _ := http.NewRequest(http.MethodGet, "/test", nil)
|
||||
req.Header.Set("Origin", "http://attacker.com")
|
||||
w := httptest.NewRecorder()
|
||||
r.ServeHTTP(w, req)
|
||||
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("expected 200 OK, got %d", w.Code)
|
||||
}
|
||||
if val := w.Header().Get("Access-Control-Allow-Origin"); val != "" {
|
||||
t.Errorf("expected empty Access-Control-Allow-Origin header, got %q", val)
|
||||
}
|
||||
if val := w.Header().Get("Access-Control-Allow-Credentials"); val != "" {
|
||||
t.Errorf("expected empty Access-Control-Allow-Credentials header, got %q", val)
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("matching server_address allows origin and sets credential headers", func(t *testing.T) {
|
||||
clearConfigCache()
|
||||
if err := dbConn.Model(&model.SystemConfig{}).Where("key = ?", model.ConfigKeyServerAddress).Update("value", "https://trusted.com, http://localhost:3000/").Error; err != nil {
|
||||
t.Fatalf("failed to update config: %v", err)
|
||||
}
|
||||
clearConfigCache()
|
||||
|
||||
r := gin.New()
|
||||
r.Use(corsMiddleware())
|
||||
r.GET("/test", func(c *gin.Context) {
|
||||
c.String(http.StatusOK, "ok")
|
||||
})
|
||||
|
||||
// Test trusted origin 1
|
||||
req1, _ := http.NewRequest(http.MethodGet, "/test", nil)
|
||||
req1.Header.Set("Origin", "https://trusted.com")
|
||||
w1 := httptest.NewRecorder()
|
||||
r.ServeHTTP(w1, req1)
|
||||
|
||||
if w1.Code != http.StatusOK {
|
||||
t.Fatalf("expected 200 OK, got %d", w1.Code)
|
||||
}
|
||||
if val := w1.Header().Get("Access-Control-Allow-Origin"); val != "https://trusted.com" {
|
||||
t.Errorf("expected Access-Control-Allow-Origin 'https://trusted.com', got %q", val)
|
||||
}
|
||||
if val := w1.Header().Get("Access-Control-Allow-Credentials"); val != "true" {
|
||||
t.Errorf("expected Access-Control-Allow-Credentials 'true', got %q", val)
|
||||
}
|
||||
|
||||
// Test trusted origin 2 (trimmed trailing slash)
|
||||
req2, _ := http.NewRequest(http.MethodGet, "/test", nil)
|
||||
req2.Header.Set("Origin", "http://localhost:3000")
|
||||
w2 := httptest.NewRecorder()
|
||||
r.ServeHTTP(w2, req2)
|
||||
|
||||
if w2.Code != http.StatusOK {
|
||||
t.Fatalf("expected 200 OK, got %d", w2.Code)
|
||||
}
|
||||
if val := w2.Header().Get("Access-Control-Allow-Origin"); val != "http://localhost:3000" {
|
||||
t.Errorf("expected Access-Control-Allow-Origin 'http://localhost:3000', got %q", val)
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("non-matching origin is denied CORS headers", func(t *testing.T) {
|
||||
clearConfigCache()
|
||||
if err := dbConn.Model(&model.SystemConfig{}).Where("key = ?", model.ConfigKeyServerAddress).Update("value", "https://trusted.com").Error; err != nil {
|
||||
t.Fatalf("failed to update config: %v", err)
|
||||
}
|
||||
clearConfigCache()
|
||||
|
||||
r := gin.New()
|
||||
r.Use(corsMiddleware())
|
||||
r.GET("/test", func(c *gin.Context) {
|
||||
c.String(http.StatusOK, "ok")
|
||||
})
|
||||
|
||||
req, _ := http.NewRequest(http.MethodGet, "/test", nil)
|
||||
req.Header.Set("Origin", "https://attacker.com")
|
||||
w := httptest.NewRecorder()
|
||||
r.ServeHTTP(w, req)
|
||||
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("expected 200 OK, got %d", w.Code)
|
||||
}
|
||||
if val := w.Header().Get("Access-Control-Allow-Origin"); val != "" {
|
||||
t.Errorf("expected empty Access-Control-Allow-Origin header, got %q", val)
|
||||
}
|
||||
})
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
// Package root registers custom business routes and frontend serving.
|
||||
package root
|
||||
|
||||
import (
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
// RegisterCustomRootRoutes registers custom business routes that belong to the root path.
|
||||
func RegisterCustomRootRoutes(_ *gin.Engine) {
|
||||
// Add custom root routes here
|
||||
}
|
||||
@@ -0,0 +1,32 @@
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
package root
|
||||
|
||||
import (
|
||||
_ "github.com/Rain-kl/Wavelet/docs" // Swagger documentation generation setup
|
||||
publicconfig "github.com/Rain-kl/Wavelet/internal/apps/config"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/health"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/upload"
|
||||
"github.com/Rain-kl/Wavelet/internal/config"
|
||||
"github.com/gin-gonic/gin"
|
||||
swaggerFiles "github.com/swaggo/files"
|
||||
ginSwagger "github.com/swaggo/gin-swagger"
|
||||
)
|
||||
|
||||
// RegisterDefaultRootRoutes registers default routes that belong to the root path.
|
||||
func RegisterDefaultRootRoutes(r *gin.Engine) {
|
||||
// 1. Serve files by ID
|
||||
r.GET("/f/:id", upload.ServeFileByID)
|
||||
|
||||
// 2. Dynamic robots.txt serving
|
||||
r.GET("/robots.txt", publicconfig.GetRobotsTXT)
|
||||
|
||||
// 3. Swagger routes (Non-production only)
|
||||
if !config.Config.App.IsProduction() {
|
||||
r.GET(config.Config.App.APIPrefix+"/swagger/*any", ginSwagger.WrapHandler(swaggerFiles.Handler))
|
||||
}
|
||||
|
||||
// 4. Health check
|
||||
r.GET(config.Config.App.APIPrefix+"/health", health.Health)
|
||||
}
|
||||
@@ -0,0 +1,110 @@
|
||||
//go:build embed_frontend
|
||||
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
package root
|
||||
|
||||
import (
|
||||
"embed"
|
||||
"io"
|
||||
"io/fs"
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
//go:embed all:dist
|
||||
var frontendFS embed.FS
|
||||
|
||||
func serveFileDirect(c *gin.Context, subFS fs.FS, filePath string) bool {
|
||||
file, err := subFS.Open(filePath)
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
defer file.Close()
|
||||
|
||||
stat, err := file.Stat()
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
|
||||
if stat.IsDir() {
|
||||
return false
|
||||
}
|
||||
|
||||
seeker, ok := file.(io.ReadSeeker)
|
||||
if !ok {
|
||||
return false
|
||||
}
|
||||
|
||||
// 使用 http.ServeContent 直接输出文件内容,不进行路径规范化重定向
|
||||
http.ServeContent(c.Writer, c.Request, filePath, stat.ModTime(), seeker)
|
||||
return true
|
||||
}
|
||||
|
||||
func init() {
|
||||
RegisterFrontend = func(r *gin.Engine) {
|
||||
subFS, err := fs.Sub(frontendFS, "dist")
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
|
||||
r.NoRoute(func(c *gin.Context) {
|
||||
path := c.Request.URL.Path
|
||||
|
||||
// API 接口路由或文件服务路由 -> 直接返回,由 Gin 处理标准 404
|
||||
if strings.HasPrefix(path, "/api/") || strings.HasPrefix(path, "/f/") {
|
||||
return
|
||||
}
|
||||
|
||||
// 只处理 GET 和 HEAD 请求
|
||||
if c.Request.Method != http.MethodGet && c.Request.Method != http.MethodHead {
|
||||
c.JSON(http.StatusMethodNotAllowed, gin.H{"error_msg": "Method not allowed"})
|
||||
return
|
||||
}
|
||||
|
||||
// 移除开头的斜杠以在嵌入文件系统中查找
|
||||
cleanPath := strings.TrimPrefix(path, "/")
|
||||
|
||||
// 1. 根路径 -> 直接输出 index.html
|
||||
if cleanPath == "" {
|
||||
if serveFileDirect(c, subFS, "index.html") {
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
// 2. 精确匹配(如果对应的文件存在,直接输出)
|
||||
if serveFileDirect(c, subFS, cleanPath) {
|
||||
return
|
||||
}
|
||||
|
||||
// 如果是个目录(例如请求了 "/login",同时 dist 目录下存在一个叫 "login" 的文件夹目录),
|
||||
// 则查找是否有对应的 ".html" 文件(例如 "login.html")并进行输出。
|
||||
if cleanPath != "" {
|
||||
htmlPath := cleanPath + ".html"
|
||||
if serveFileDirect(c, subFS, htmlPath) {
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
// 3. Next.js Clean URLs 兜底逻辑(例如访问 /settings/security -> 实际映射输出 settings/security.html)
|
||||
if !strings.Contains(cleanPath, ".") {
|
||||
htmlPath := cleanPath + ".html"
|
||||
if serveFileDirect(c, subFS, htmlPath) {
|
||||
return
|
||||
}
|
||||
indexPath := cleanPath + "/index.html"
|
||||
if serveFileDirect(c, subFS, indexPath) {
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
// 4. 单页应用(SPA)前端路由兜底:返回 index.html
|
||||
if serveFileDirect(c, subFS, "index.html") {
|
||||
return
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,26 @@
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
// Package root registers custom business routes and frontend serving.
|
||||
package root
|
||||
|
||||
import (
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
// RegisterFrontend is a package-level variable overridden by frontend.go when built with embed_frontend.
|
||||
var RegisterFrontend = func(_ *gin.Engine) {
|
||||
// No-op by default
|
||||
}
|
||||
|
||||
// RegisterRootRoutes registers custom business routes that belong to the root path.
|
||||
func RegisterRootRoutes(r *gin.Engine) {
|
||||
// 1. Default root routes (/f/:id, /robots.txt, and /swagger/*any)
|
||||
RegisterDefaultRootRoutes(r)
|
||||
|
||||
// 2. Register custom serving
|
||||
RegisterCustomRootRoutes(r)
|
||||
|
||||
// 3. Register frontend serving
|
||||
RegisterFrontend(r)
|
||||
}
|
||||
@@ -0,0 +1,122 @@
|
||||
// Copyright 2025 linux.do
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
package router
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"log"
|
||||
"net/http"
|
||||
"os"
|
||||
"os/signal"
|
||||
"strconv"
|
||||
"syscall"
|
||||
"time"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/risk_control"
|
||||
router_root "github.com/Rain-kl/Wavelet/internal/router/root"
|
||||
v1 "github.com/Rain-kl/Wavelet/internal/router/v1"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/oauth"
|
||||
"github.com/Rain-kl/Wavelet/internal/config"
|
||||
otel_trace "github.com/Rain-kl/Wavelet/pkg/trace"
|
||||
"github.com/gin-contrib/sessions"
|
||||
"github.com/gin-contrib/sessions/redis"
|
||||
"github.com/gin-gonic/gin"
|
||||
"go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin"
|
||||
)
|
||||
|
||||
// Serve 启动 HTTP API 服务
|
||||
func Serve() {
|
||||
// 运行模式
|
||||
if config.Config.App.IsProduction() {
|
||||
gin.SetMode(gin.ReleaseMode)
|
||||
}
|
||||
|
||||
// 初始化路由
|
||||
r := gin.New()
|
||||
r.Use(gin.Recovery())
|
||||
r.Use(corsMiddleware())
|
||||
|
||||
cfg := config.Config.Redis
|
||||
addrs := cfg.Addrs
|
||||
sessionAddr := "localhost:6379"
|
||||
if len(addrs) > 0 {
|
||||
sessionAddr = addrs[0]
|
||||
}
|
||||
|
||||
sessionStore, err := redis.NewStoreWithDB(
|
||||
cfg.MinIdleConn,
|
||||
"tcp",
|
||||
sessionAddr,
|
||||
cfg.Username,
|
||||
cfg.Password,
|
||||
strconv.Itoa(cfg.DB),
|
||||
[]byte(config.Config.App.SessionSecret),
|
||||
)
|
||||
if err != nil {
|
||||
log.Fatalf("[API] init session store failed: %v\n", err)
|
||||
}
|
||||
|
||||
// 设置 Session Redis Key 前缀
|
||||
if cfg.KeyPrefix != "" {
|
||||
if err := redis.SetKeyPrefix(sessionStore, cfg.KeyPrefix+"session:"); err != nil {
|
||||
log.Printf("[API] set session key prefix failed: %v\n", err)
|
||||
}
|
||||
}
|
||||
|
||||
sessionStore.Options(oauth.GetSessionOptions(config.Config.App.SessionAge))
|
||||
|
||||
r.Use(sessions.Sessions(config.Config.App.SessionCookieName, sessionStore))
|
||||
|
||||
// 补充中间件
|
||||
r.Use(otelgin.Middleware(config.Config.App.AppName), errorHandlerMiddleware(), loggerMiddleware(), risk_control.RiskControlMiddleware())
|
||||
|
||||
registerRoutes(r)
|
||||
|
||||
srv := &http.Server{
|
||||
Addr: config.Config.App.Addr,
|
||||
Handler: r,
|
||||
ReadHeaderTimeout: 10 * time.Second,
|
||||
}
|
||||
|
||||
go func() {
|
||||
log.Printf("[API] server starting on %s\n", config.Config.App.Addr)
|
||||
if err := srv.ListenAndServe(); err != nil && !errors.Is(err, http.ErrServerClosed) {
|
||||
log.Fatalf("[API] server failed: %v\n", err)
|
||||
}
|
||||
}()
|
||||
|
||||
quit := make(chan os.Signal, 1)
|
||||
signal.Notify(quit, syscall.SIGINT, syscall.SIGTERM)
|
||||
<-quit
|
||||
|
||||
shutdownCtx, cancel := context.WithTimeout(context.Background(), time.Duration(config.Config.App.GracefulShutdownTimeout)*time.Second)
|
||||
|
||||
otel_trace.Shutdown(shutdownCtx)
|
||||
|
||||
if err := srv.Shutdown(shutdownCtx); err != nil {
|
||||
log.Printf("[API] server forced to shutdown: %v\n", err)
|
||||
cancel()
|
||||
os.Exit(1)
|
||||
}
|
||||
cancel()
|
||||
|
||||
log.Println("[API] server exited")
|
||||
}
|
||||
|
||||
func registerRoutes(r *gin.Engine) {
|
||||
// Register custom root routes, Swagger, and frontend serving
|
||||
router_root.RegisterRootRoutes(r)
|
||||
|
||||
apiGroup := r.Group(config.Config.App.APIPrefix)
|
||||
{
|
||||
// API V1
|
||||
apiV1Router := apiGroup.Group("/v1")
|
||||
{
|
||||
v1.RegisterV1Routes(apiV1Router, apiGroup)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,217 @@
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
// Package v1 contains router registrations for API V1
|
||||
package v1
|
||||
|
||||
import (
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/admin"
|
||||
admin_auth_source "github.com/Rain-kl/Wavelet/internal/apps/admin/auth_source"
|
||||
admin_cache "github.com/Rain-kl/Wavelet/internal/apps/admin/cache"
|
||||
admin_db_manage "github.com/Rain-kl/Wavelet/internal/apps/admin/db_manage"
|
||||
admin_logs "github.com/Rain-kl/Wavelet/internal/apps/admin/logs"
|
||||
admin_push "github.com/Rain-kl/Wavelet/internal/apps/admin/push"
|
||||
admin_status "github.com/Rain-kl/Wavelet/internal/apps/admin/status"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/admin/system_config"
|
||||
admin_task "github.com/Rain-kl/Wavelet/internal/apps/admin/task"
|
||||
admin_template "github.com/Rain-kl/Wavelet/internal/apps/admin/template"
|
||||
admin_updater "github.com/Rain-kl/Wavelet/internal/apps/admin/updater"
|
||||
admin_user "github.com/Rain-kl/Wavelet/internal/apps/admin/user"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/oauth"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/upload"
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
// RegisterAdminRoutes registers all admin-related routes with sub-group categorizations.
|
||||
func RegisterAdminRoutes(apiV1Router *gin.RouterGroup) {
|
||||
adminRouter := apiV1Router.Group("/admin")
|
||||
adminRouter.Use(oauth.LoginRequired(), admin.LoginAdminRequired())
|
||||
{
|
||||
// 1. Diagnostics & Infrastructure Management
|
||||
registerAdminDiagnosticRoutes(adminRouter)
|
||||
|
||||
// 2. Identity & Access Management (IAM)
|
||||
registerAdminIAMRoutes(adminRouter)
|
||||
|
||||
// 3. System Configuration & Templates Settings
|
||||
registerAdminConfigRoutes(adminRouter)
|
||||
|
||||
// 4. Storage & Asset Management
|
||||
registerAdminStorageRoutes(adminRouter)
|
||||
|
||||
// 5. Task Orchestration & Automation
|
||||
registerAdminTaskRoutes(adminRouter)
|
||||
|
||||
// 6. Messaging & Push Notifications
|
||||
registerAdminPushRoutes(adminRouter)
|
||||
}
|
||||
}
|
||||
|
||||
// registerAdminDiagnosticRoutes registers infrastructure, system status, caching, database, and logs diagnostics.
|
||||
func registerAdminDiagnosticRoutes(adminRouter *gin.RouterGroup) {
|
||||
// System status
|
||||
adminRouter.GET("/status", admin_status.GetSystemStatus)
|
||||
|
||||
// Database basic info & backup export
|
||||
adminRouter.GET("/db-info", admin_status.GetDatabaseInfo)
|
||||
adminRouter.GET("/db-export", admin_status.ExportDatabase)
|
||||
|
||||
// Database management & interactive browser
|
||||
dbManage := adminRouter.Group("/db-manage")
|
||||
{
|
||||
dbManage.GET("/overview", admin_db_manage.GetDBOverview)
|
||||
dbManage.GET("/tables", admin_db_manage.ListDBTables)
|
||||
dbManage.GET("/table-data", admin_db_manage.GetDBTableData)
|
||||
dbManage.POST("/query", admin_db_manage.ExecuteSQL)
|
||||
}
|
||||
|
||||
// Cache management (TTL, LRU eviction and clear operations)
|
||||
cache := adminRouter.Group("/cache")
|
||||
{
|
||||
cache.GET("/status", admin_cache.GetCacheStatus)
|
||||
cache.POST("/config", admin_cache.UpdateCacheConfig)
|
||||
cache.POST("/clear", admin_cache.ClearCache)
|
||||
}
|
||||
|
||||
// Application updater
|
||||
update := adminRouter.Group("/update")
|
||||
{
|
||||
update.GET("", admin_updater.GetUpdateStatus)
|
||||
update.POST("/apply", admin_updater.ApplyUpdate)
|
||||
}
|
||||
|
||||
// System & access logs analytics
|
||||
logs := adminRouter.Group("/logs")
|
||||
{
|
||||
logs.GET("", admin_logs.GetLogs)
|
||||
logs.GET("/access", admin_logs.GetAccessLogs)
|
||||
logs.GET("/analytics", admin_logs.GetLogsAnalytics)
|
||||
logs.GET("/ws", admin_logs.HandleLogWebSocket)
|
||||
}
|
||||
}
|
||||
|
||||
// registerAdminIAMRoutes registers Identity & Access Management endpoints (Users & Auth Sources).
|
||||
func registerAdminIAMRoutes(adminRouter *gin.RouterGroup) {
|
||||
// Users management
|
||||
users := adminRouter.Group("/users")
|
||||
{
|
||||
users.GET("", admin_user.ListUsers)
|
||||
users.POST("", admin_user.CreateUser)
|
||||
users.GET("/:id", admin_user.GetUser)
|
||||
users.PUT("/:id/status", admin_user.UpdateUserStatus)
|
||||
users.DELETE("/:id", admin_user.DeleteUser)
|
||||
}
|
||||
|
||||
// Authentication Sources (LDAP, OAuth sources, etc.)
|
||||
authSources := adminRouter.Group("/auth-sources")
|
||||
{
|
||||
authSources.GET("", admin_auth_source.ListAuthSources)
|
||||
authSources.POST("", admin_auth_source.CreateAuthSource)
|
||||
authSources.PUT("/:id", admin_auth_source.UpdateAuthSource)
|
||||
authSources.PUT("/:id/toggle", admin_auth_source.ToggleAuthSource)
|
||||
authSources.DELETE("/:id", admin_auth_source.DeleteAuthSource)
|
||||
}
|
||||
}
|
||||
|
||||
// registerAdminConfigRoutes registers system configurations and template settings.
|
||||
func registerAdminConfigRoutes(adminRouter *gin.RouterGroup) {
|
||||
// System configs
|
||||
configs := adminRouter.Group("/system-configs")
|
||||
{
|
||||
configs.GET("", system_config.ListSystemConfigs)
|
||||
configs.POST("", system_config.CreateSystemConfig)
|
||||
configs.POST("/smtp/test", system_config.TestSMTP)
|
||||
|
||||
keyGroup := configs.Group("/:key")
|
||||
{
|
||||
keyGroup.GET("", system_config.GetSystemConfig)
|
||||
keyGroup.PUT("", system_config.UpdateSystemConfig)
|
||||
}
|
||||
}
|
||||
|
||||
// Email/Notification Templates
|
||||
templates := adminRouter.Group("/templates")
|
||||
{
|
||||
templates.GET("", admin_template.ListTemplates)
|
||||
templates.POST("", admin_template.CreateTemplate)
|
||||
|
||||
keyGroup := templates.Group("/:key")
|
||||
{
|
||||
keyGroup.GET("", admin_template.GetTemplate)
|
||||
keyGroup.PUT("", admin_template.UpdateTemplate)
|
||||
keyGroup.DELETE("", admin_template.DeleteTemplate)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// registerAdminStorageRoutes registers file and asset storage administration.
|
||||
func registerAdminStorageRoutes(adminRouter *gin.RouterGroup) {
|
||||
uploads := adminRouter.Group("/uploads")
|
||||
{
|
||||
uploads.GET("", upload.ListFiles)
|
||||
uploads.GET("/stats", upload.GetFileStats)
|
||||
uploads.DELETE("/:id", upload.DeleteFile)
|
||||
uploads.GET("/download/:id", upload.DownloadFile)
|
||||
uploads.POST("/download/batch", upload.BatchDownloadFiles)
|
||||
uploads.GET("/types", upload.GetDistinctUploadTypes)
|
||||
}
|
||||
}
|
||||
|
||||
// registerAdminTaskRoutes registers task orchestrations, execution logs and schedules.
|
||||
func registerAdminTaskRoutes(adminRouter *gin.RouterGroup) {
|
||||
tasks := adminRouter.Group("/tasks")
|
||||
{
|
||||
// Task dispatch & metadata
|
||||
tasks.GET("/types", admin_task.ListTaskTypes)
|
||||
tasks.POST("/dispatch", admin_task.DispatchTask)
|
||||
|
||||
// Task execution logs & manual retry
|
||||
executions := tasks.Group("/executions")
|
||||
{
|
||||
executions.GET("", admin_task.ListTaskExecutions)
|
||||
executions.GET("/:id", admin_task.GetTaskExecution)
|
||||
executions.POST("/:id/retry", admin_task.RetryTask)
|
||||
}
|
||||
|
||||
// Cron scheduler settings
|
||||
schedules := tasks.Group("/schedules")
|
||||
{
|
||||
schedules.GET("", admin_task.ListSchedules)
|
||||
schedules.POST("", admin_task.CreateSchedule)
|
||||
schedules.PUT("/:id", admin_task.UpdateSchedule)
|
||||
schedules.DELETE("/:id", admin_task.DeleteSchedule)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// registerAdminPushRoutes registers messaging channels and push notification events.
|
||||
func registerAdminPushRoutes(adminRouter *gin.RouterGroup) {
|
||||
push := adminRouter.Group("/push")
|
||||
{
|
||||
// Push Events
|
||||
events := push.Group("/events")
|
||||
{
|
||||
events.GET("", admin_push.ListEvents)
|
||||
events.GET("/builtin", admin_push.ListBuiltInEvents)
|
||||
events.POST("", admin_push.CreateEvent)
|
||||
events.PUT("/:id", admin_push.UpdateEvent)
|
||||
events.DELETE("/:id", admin_push.DeleteEvent)
|
||||
events.POST("/:id/toggle", admin_push.ToggleEvent)
|
||||
}
|
||||
|
||||
// Delivery histories and diagnostics test
|
||||
push.GET("/histories", admin_push.ListHistories)
|
||||
push.POST("/test", admin_push.TestPush)
|
||||
|
||||
// Message Channels CRUD
|
||||
channels := push.Group("/channels")
|
||||
{
|
||||
channels.GET("/definitions", admin_push.ListChannelDefinitions)
|
||||
channels.GET("", admin_push.ListChannels)
|
||||
channels.POST("", admin_push.CreateChannel)
|
||||
channels.PUT("/:id", admin_push.UpdateChannel)
|
||||
channels.DELETE("/:id", admin_push.DeleteChannel)
|
||||
channels.POST("/test", admin_push.TestChannel)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,18 @@
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
// Package v1 contains router registrations for API V1
|
||||
package v1
|
||||
|
||||
import (
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/custom"
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
// RegisterCustomRoutes registers custom business routes to keep routing clean and stable.
|
||||
func RegisterCustomRoutes(apiV1Router *gin.RouterGroup) {
|
||||
customRouter := apiV1Router.Group("/custom")
|
||||
{
|
||||
customRouter.GET("/hello", custom.Hello)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,95 @@
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
// Package v1 contains router registrations for API V1
|
||||
package v1
|
||||
|
||||
import (
|
||||
capApp "github.com/Rain-kl/Wavelet/internal/apps/cap"
|
||||
publicconfig "github.com/Rain-kl/Wavelet/internal/apps/config"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/oauth"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/upload"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/user"
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
// RegisterUserRoutes registers all user-related, oauth, upload, and public routes.
|
||||
func RegisterUserRoutes(apiV1Router *gin.RouterGroup, apiGroup *gin.RouterGroup) {
|
||||
// 1. CAPTCHA
|
||||
registerCaptchaRoutes(apiGroup)
|
||||
|
||||
// 2. Config (public)
|
||||
registerConfigRoutes(apiV1Router)
|
||||
|
||||
// 3. OAuth
|
||||
registerOAuthRoutes(apiV1Router)
|
||||
|
||||
// 4. User
|
||||
registerUserRoutes(apiV1Router)
|
||||
|
||||
// 5. Upload
|
||||
registerUploadRoutes(apiV1Router)
|
||||
}
|
||||
|
||||
func registerCaptchaRoutes(apiGroup *gin.RouterGroup) {
|
||||
capGroup := apiGroup.Group("/cap")
|
||||
{
|
||||
capGroup.POST("/challenge", capApp.Challenge)
|
||||
capGroup.POST("/redeem", capApp.Redeem)
|
||||
}
|
||||
}
|
||||
|
||||
func registerConfigRoutes(apiV1Router *gin.RouterGroup) {
|
||||
configRouter := apiV1Router.Group("/config")
|
||||
{
|
||||
configRouter.GET("/public", publicconfig.GetPublicConfig)
|
||||
}
|
||||
}
|
||||
|
||||
func registerOAuthRoutes(apiV1Router *gin.RouterGroup) {
|
||||
apiV1Router.GET("/oauth/sources", oauth.GetLoginSources)
|
||||
apiV1Router.GET("/oauth/login", oauth.GetLoginURL)
|
||||
apiV1Router.GET("/oauth/:source/authorize", oauth.Authorize)
|
||||
apiV1Router.GET("/oauth/logout", oauth.Logout)
|
||||
apiV1Router.POST("/oauth/callback", oauth.Callback)
|
||||
apiV1Router.GET("/oauth/user-info", oauth.LoginRequired(), oauth.UserInfo)
|
||||
apiV1Router.GET("/user-info", oauth.LoginRequired(), oauth.UserInfo)
|
||||
apiV1Router.GET("/oauth/external-accounts", oauth.LoginRequired(), oauth.ListExternalAccounts)
|
||||
apiV1Router.POST("/oauth/external-accounts/:id/delete", oauth.LoginRequired(), oauth.DeleteExternalAccount)
|
||||
}
|
||||
|
||||
func registerUserRoutes(apiV1Router *gin.RouterGroup) {
|
||||
userRouter := apiV1Router.Group("/user")
|
||||
{
|
||||
userRouter.POST("/login", capApp.VerifyMiddleware(capApp.GetDefaultManager(), "login"), user.Login)
|
||||
userRouter.POST("/register", capApp.VerifyMiddleware(capApp.GetDefaultManager(), "register"), user.Register)
|
||||
userRouter.POST("/send-email-code", capApp.VerifyMiddleware(capApp.GetDefaultManager(), "send_email_code"), user.SendEmailCode)
|
||||
userRouter.GET("/logout", user.Logout)
|
||||
userRouter.GET("/self", oauth.LoginRequired(), oauth.UserInfo)
|
||||
userRouter.POST("/change-password", oauth.LoginRequired(), user.ChangePassword)
|
||||
userRouter.PUT("/profile", oauth.LoginRequired(), user.UpdateProfile)
|
||||
|
||||
// Access Token
|
||||
tokenRouter := userRouter.Group("/access-tokens")
|
||||
tokenRouter.Use(oauth.LoginRequired(), oauth.DisallowTokenAuth())
|
||||
{
|
||||
tokenRouter.GET("", user.ListAccessTokens)
|
||||
tokenRouter.POST("", user.CreateAccessToken)
|
||||
tokenRouter.DELETE("/:id", user.DeleteAccessToken)
|
||||
tokenRouter.POST("/:id/rotate", user.RotateAccessToken)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func registerUploadRoutes(apiV1Router *gin.RouterGroup) {
|
||||
uploadRouter := apiV1Router.Group("/upload")
|
||||
uploadRouter.Use(oauth.LoginRequired())
|
||||
{
|
||||
uploadRouter.POST("", upload.UploadFile)
|
||||
uploadRouter.GET("/my", upload.ListMyFiles)
|
||||
uploadRouter.DELETE("/:id", upload.DeleteMyFile)
|
||||
uploadRouter.PUT("/:id", upload.UpdateMyFile)
|
||||
uploadRouter.GET("/download/:id", upload.DownloadFile)
|
||||
uploadRouter.POST("/download/batch", upload.BatchDownloadFiles)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,21 @@
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
// Package v1 contains router registrations for API V1
|
||||
package v1
|
||||
|
||||
import (
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
// RegisterV1Routes registers all routes under API V1.
|
||||
func RegisterV1Routes(apiV1Router *gin.RouterGroup, apiGroup *gin.RouterGroup) {
|
||||
// 1. User & Public routes (OAuth, User, Upload, CAPTCHA, Health, Config)
|
||||
RegisterUserRoutes(apiV1Router, apiGroup)
|
||||
|
||||
// 2. Admin routes
|
||||
RegisterAdminRoutes(apiV1Router)
|
||||
|
||||
// 3. Register custom business routes
|
||||
RegisterCustomRoutes(apiV1Router)
|
||||
}
|
||||
Reference in New Issue
Block a user