feat(router): add whitelist mechanism for http driver and auth plugin

- implement route whitelist registration and wildcard matching in RouterExtension
- add cookie store session fallback when Redis is disabled in driver_http
- actively register public auth endpoints to whitelist in auth plugin
- update user handlers to persist session and clear cookie on logout
- document router whitelist mechanism in AGENTS.md and new-api skill
This commit is contained in:
ryan
2026-08-29 11:39:13 +08:00
parent 53ae3007d0
commit e0f2309520
17 changed files with 411 additions and 32 deletions
+12
View File
@@ -93,6 +93,18 @@ func (s *scopedRouterExtension) UnregisterByID(id uint64) bool {
return s.underlying.UnregisterByID(id)
}
func (s *scopedRouterExtension) RegisterWhitelist(patterns ...string) {
s.underlying.RegisterWhitelist(patterns...)
}
func (s *scopedRouterExtension) Whitelist() []string {
return s.underlying.Whitelist()
}
func (s *scopedRouterExtension) IsWhitelisted(path string) bool {
return s.underlying.IsWhitelisted(path)
}
// scopedTaskExtension wraps a TaskExtension to automatically register
// teardown disposers on the associated Context when task handlers are declared.
type scopedTaskExtension struct {