mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-10 17:26:38 +08:00
feat(router): add whitelist mechanism for http driver and auth plugin
- implement route whitelist registration and wildcard matching in RouterExtension - add cookie store session fallback when Redis is disabled in driver_http - actively register public auth endpoints to whitelist in auth plugin - update user handlers to persist session and clear cookie on logout - document router whitelist mechanism in AGENTS.md and new-api skill
This commit is contained in:
@@ -5,6 +5,7 @@
|
||||
package driver_http
|
||||
|
||||
import (
|
||||
"Wavelet/core/extpoints"
|
||||
"Wavelet/pkg/logger"
|
||||
"Wavelet/pkg/response"
|
||||
"context"
|
||||
@@ -24,8 +25,31 @@ import (
|
||||
var (
|
||||
apiPrefixMu sync.RWMutex
|
||||
apiPrefix = "/api/v1"
|
||||
|
||||
whitelistMu sync.RWMutex
|
||||
whitelistPatterns []string
|
||||
)
|
||||
|
||||
// SetWhitelist configures global whitelist patterns for HTTP routes.
|
||||
func SetWhitelist(patterns []string) {
|
||||
whitelistMu.Lock()
|
||||
defer whitelistMu.Unlock()
|
||||
whitelistPatterns = make([]string, len(patterns))
|
||||
copy(whitelistPatterns, patterns)
|
||||
}
|
||||
|
||||
// IsPathWhitelisted checks if the given path matches any registered whitelist pattern.
|
||||
func IsPathWhitelisted(path string) bool {
|
||||
whitelistMu.RLock()
|
||||
defer whitelistMu.RUnlock()
|
||||
for _, pattern := range whitelistPatterns {
|
||||
if extpoints.MatchPathPattern(pattern, path) {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func setAPIPrefix(prefix string) {
|
||||
if prefix == "" {
|
||||
return
|
||||
|
||||
Reference in New Issue
Block a user