feat(router): add whitelist mechanism for http driver and auth plugin

- implement route whitelist registration and wildcard matching in RouterExtension
- add cookie store session fallback when Redis is disabled in driver_http
- actively register public auth endpoints to whitelist in auth plugin
- update user handlers to persist session and clear cookie on logout
- document router whitelist mechanism in AGENTS.md and new-api skill
This commit is contained in:
ryan
2026-08-29 11:39:13 +08:00
parent 53ae3007d0
commit e0f2309520
17 changed files with 411 additions and 32 deletions
@@ -12,6 +12,7 @@ import (
"testing"
"time"
"github.com/gin-contrib/sessions"
"github.com/gin-gonic/gin"
"gorm.io/gorm"
)
@@ -205,3 +206,40 @@ func TestCORSAllowedOriginReadsConfigOncePerCacheWindow(t *testing.T) {
t.Errorf("expected 1 config load across 3 requests, got %d", cache.loads)
}
}
func TestBuildEngineWithCookieFallback(t *testing.T) {
gin.SetMode(gin.TestMode)
appCfg := httpAppConfig{
SessionSecret: "test-secret",
SessionCookieName: "wavelet_session",
SessionAge: 3600,
}
redisCfg := httpRedisConfig{
Enabled: false,
}
engine, err := BuildEngineWithConfig(appCfg, redisCfg)
if err != nil {
t.Fatalf("expected nil error with cookie fallback, got: %v", err)
}
engine.GET("/set-session", func(c *gin.Context) {
sess := sessions.Default(c)
sess.Set("test_user_id", uint64(12345))
_ = sess.Save()
c.String(http.StatusOK, "ok")
})
req, _ := http.NewRequest(http.MethodGet, "/set-session", nil)
w := httptest.NewRecorder()
engine.ServeHTTP(w, req)
if w.Code != http.StatusOK {
t.Fatalf("expected 200 OK, got %d", w.Code)
}
setCookie := w.Header().Get("Set-Cookie")
if setCookie == "" {
t.Fatal("expected Set-Cookie header in response, got none")
}
}