feat(router): add whitelist mechanism for http driver and auth plugin

- implement route whitelist registration and wildcard matching in RouterExtension
- add cookie store session fallback when Redis is disabled in driver_http
- actively register public auth endpoints to whitelist in auth plugin
- update user handlers to persist session and clear cookie on logout
- document router whitelist mechanism in AGENTS.md and new-api skill
This commit is contained in:
ryan
2026-08-29 11:39:13 +08:00
parent 53ae3007d0
commit e0f2309520
17 changed files with 411 additions and 32 deletions
@@ -5,6 +5,7 @@
package driver_http
import (
"Wavelet/core/extpoints"
"Wavelet/pkg/logger"
"Wavelet/pkg/response"
"context"
@@ -24,8 +25,31 @@ import (
var (
apiPrefixMu sync.RWMutex
apiPrefix = "/api/v1"
whitelistMu sync.RWMutex
whitelistPatterns []string
)
// SetWhitelist configures global whitelist patterns for HTTP routes.
func SetWhitelist(patterns []string) {
whitelistMu.Lock()
defer whitelistMu.Unlock()
whitelistPatterns = make([]string, len(patterns))
copy(whitelistPatterns, patterns)
}
// IsPathWhitelisted checks if the given path matches any registered whitelist pattern.
func IsPathWhitelisted(path string) bool {
whitelistMu.RLock()
defer whitelistMu.RUnlock()
for _, pattern := range whitelistPatterns {
if extpoints.MatchPathPattern(pattern, path) {
return true
}
}
return false
}
func setAPIPrefix(prefix string) {
if prefix == "" {
return