This commit is contained in:
Tomas Dvorak
2025-05-26 11:39:32 +02:00
parent d3581993a7
commit 4ec4444a51
4 changed files with 1157 additions and 1160 deletions
+6 -6
View File
@@ -1,4 +1,4 @@
package main package admin
import ( import (
"crypto/rand" "crypto/rand"
@@ -53,7 +53,7 @@ func generateToken() (string, error) {
return base64.URLEncoding.EncodeToString(bytes), nil return base64.URLEncoding.EncodeToString(bytes), nil
} }
func handleLogin(w http.ResponseWriter, r *http.Request) { func HandleLogin(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json") w.Header().Set("Content-Type", "application/json")
if r.Method == "GET" { if r.Method == "GET" {
@@ -309,7 +309,7 @@ func handleLogin(w http.ResponseWriter, r *http.Request) {
}) })
} }
func handleLogout(w http.ResponseWriter, r *http.Request) { func HandleLogout(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json") w.Header().Set("Content-Type", "application/json")
token := r.Header.Get("Authorization") token := r.Header.Get("Authorization")
@@ -330,7 +330,7 @@ func handleLogout(w http.ResponseWriter, r *http.Request) {
}) })
} }
func requireAuth(next http.HandlerFunc) http.HandlerFunc { func RequireAuth(next http.HandlerFunc) http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) { return func(w http.ResponseWriter, r *http.Request) {
token := r.Header.Get("Authorization") token := r.Header.Get("Authorization")
if token == "" { if token == "" {
@@ -362,7 +362,7 @@ func requireAuth(next http.HandlerFunc) http.HandlerFunc {
} }
} }
func requireAdminAuth(next http.HandlerFunc) http.HandlerFunc { func RequireAdminAuth(next http.HandlerFunc) http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) { return func(w http.ResponseWriter, r *http.Request) {
token := r.Header.Get("Authorization") token := r.Header.Get("Authorization")
if token == "" { if token == "" {
@@ -394,7 +394,7 @@ func requireAdminAuth(next http.HandlerFunc) http.HandlerFunc {
} }
} }
func getCurrentUser(r *http.Request) *Session { func GetCurrentUser(r *http.Request) *Session {
token := r.Header.Get("Authorization") token := r.Header.Get("Authorization")
if token == "" { if token == "" {
if cookie, err := r.Cookie("authToken"); err == nil { if cookie, err := r.Cookie("authToken"); err == nil {
+7 -7
View File
@@ -1,4 +1,4 @@
package main package admin
import ( import (
"encoding/json" "encoding/json"
@@ -42,8 +42,8 @@ var gridCards = []GridCard{
}, },
} }
func handleAdmin(w http.ResponseWriter, r *http.Request) { func HandleAdmin(w http.ResponseWriter, r *http.Request) {
user := getCurrentUser(r) user := GetCurrentUser(r)
if user == nil { if user == nil {
http.Redirect(w, r, "/login", http.StatusFound) http.Redirect(w, r, "/login", http.StatusFound)
return return
@@ -607,7 +607,7 @@ func handleAdmin(w http.ResponseWriter, r *http.Request) {
t.Execute(w, data) t.Execute(w, data)
} }
func handleAdminCards(w http.ResponseWriter, r *http.Request) { func HandleAdminCards(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json") w.Header().Set("Content-Type", "application/json")
switch r.Method { switch r.Method {
@@ -644,7 +644,7 @@ func handleAdminCards(w http.ResponseWriter, r *http.Request) {
} }
} }
func handleAdminCardToggle(w http.ResponseWriter, r *http.Request) { func HandleAdminCardToggle(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json") w.Header().Set("Content-Type", "application/json")
if r.Method != "POST" { if r.Method != "POST" {
@@ -676,7 +676,7 @@ func handleAdminCardToggle(w http.ResponseWriter, r *http.Request) {
json.NewEncoder(w).Encode(map[string]string{"error": "Card not found"}) json.NewEncoder(w).Encode(map[string]string{"error": "Card not found"})
} }
func handleAdminCardDelete(w http.ResponseWriter, r *http.Request) { func HandleAdminCardDelete(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json") w.Header().Set("Content-Type", "application/json")
if r.Method != "DELETE" { if r.Method != "DELETE" {
@@ -709,7 +709,7 @@ func handleAdminCardDelete(w http.ResponseWriter, r *http.Request) {
json.NewEncoder(w).Encode(map[string]string{"error": "Card not found"}) json.NewEncoder(w).Encode(map[string]string{"error": "Card not found"})
} }
func handleGetCards(w http.ResponseWriter, r *http.Request) { func HandleGetCards(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json") w.Header().Set("Content-Type", "application/json")
// Filter only enabled cards and sort by order // Filter only enabled cards and sort by order
-4
View File
@@ -1,7 +1,5 @@
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c= github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
github.com/fsnotify/fsnotify v1.9.0 h1:2Ml+OJNzbYCTzsxtv8vKSFD9PbJjmhYF14k/jKC7S9k=
github.com/fsnotify/fsnotify v1.9.0/go.mod h1:8jBTzvmWwFyi3Pb8djgCCO5IBqzKJ/Jwo8TRcHyHii0=
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM= github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
github.com/richardlehane/mscfb v1.0.4 h1:WULscsljNPConisD5hR0+OyZjwK46Pfyr6mPu5ZawpM= github.com/richardlehane/mscfb v1.0.4 h1:WULscsljNPConisD5hR0+OyZjwK46Pfyr6mPu5ZawpM=
@@ -25,8 +23,6 @@ golang.org/x/image v0.25.0 h1:Y6uW6rH1y5y/LK1J8BPWZtr6yZ7hrsy6hFrXjgsc2fQ=
golang.org/x/image v0.25.0/go.mod h1:tCAmOEGthTtkalusGp1g3xa2gke8J6c2N565dTyl9Rs= golang.org/x/image v0.25.0/go.mod h1:tCAmOEGthTtkalusGp1g3xa2gke8J6c2N565dTyl9Rs=
golang.org/x/net v0.40.0 h1:79Xs7wF06Gbdcg4kdCCIQArK11Z1hr5POQ6+fIYHNuY= golang.org/x/net v0.40.0 h1:79Xs7wF06Gbdcg4kdCCIQArK11Z1hr5POQ6+fIYHNuY=
golang.org/x/net v0.40.0/go.mod h1:y0hY0exeL2Pku80/zKK7tpntoX23cqL3Oa6njdgRtds= golang.org/x/net v0.40.0/go.mod h1:y0hY0exeL2Pku80/zKK7tpntoX23cqL3Oa6njdgRtds=
golang.org/x/sys v0.33.0 h1:q3i8TbbEz+JRD9ywIRlyRAQbM0qF7hu24q3teo2hbuw=
golang.org/x/sys v0.33.0/go.mod h1:BJP2sWEmIv4KK5OTEluFJCKSidICx8ciO85XgH3Ak8k=
golang.org/x/text v0.25.0 h1:qVyWApTSYLk/drJRO5mDlNYskwQznZmkpV2c8q9zls4= golang.org/x/text v0.25.0 h1:qVyWApTSYLk/drJRO5mDlNYskwQznZmkpV2c8q9zls4=
golang.org/x/text v0.25.0/go.mod h1:WEdwpYrmk1qmdHvhkSTNPm3app7v4rsT8F2UD6+VHIA= golang.org/x/text v0.25.0/go.mod h1:WEdwpYrmk1qmdHvhkSTNPm3app7v4rsT8F2UD6+VHIA=
gopkg.in/alexcesaro/quotedprintable.v3 v3.0.0-20150716171945-2caba252f4dc h1:2gGKlE2+asNV9m7xrywl36YYNnBG5ZQ0r/BOOxqPpmk= gopkg.in/alexcesaro/quotedprintable.v3 v3.0.0-20150716171945-2caba252f4dc h1:2gGKlE2+asNV9m7xrywl36YYNnBG5ZQ0r/BOOxqPpmk=
+9 -8
View File
@@ -15,6 +15,7 @@ import (
"time" "time"
"gopkg.in/gomail.v2" "gopkg.in/gomail.v2"
"ppve/admin" // Import the local admin package
) )
type TripEntry struct { type TripEntry struct {
@@ -81,26 +82,26 @@ func main() {
http.Redirect(w, r, "http://webportal:8080/", http.StatusFound) http.Redirect(w, r, "http://webportal:8080/", http.StatusFound)
})) }))
// Authentication routes // Authentication routes
http.HandleFunc("/login", enableCORS(handleLogin)) http.HandleFunc("/login", enableCORS(admin.HandleLogin))
http.HandleFunc("/logout", enableCORS(handleLogout)) http.HandleFunc("/logout", enableCORS(admin.HandleLogout))
// Admin routes (protected) // Admin routes (protected)
http.HandleFunc("/admin", enableCORS(requireAdminAuth(handleAdmin))) http.HandleFunc("/admin", enableCORS(admin.RequireAdminAuth(admin.HandleAdmin)))
http.HandleFunc("/admin/cards", enableCORS(requireAdminAuth(handleAdminCards))) http.HandleFunc("/admin/cards", enableCORS(admin.RequireAdminAuth(admin.HandleAdminCards)))
http.HandleFunc("/admin/cards/", enableCORS(requireAdminAuth(func(w http.ResponseWriter, r *http.Request) { http.HandleFunc("/admin/cards/", enableCORS(admin.RequireAdminAuth(func(w http.ResponseWriter, r *http.Request) {
path := r.URL.Path path := r.URL.Path
if strings.HasSuffix(path, "/toggle") { if strings.HasSuffix(path, "/toggle") {
handleAdminCardToggle(w, r) admin.HandleAdminCardToggle(w, r)
} else if r.Method == "DELETE" { } else if r.Method == "DELETE" {
handleAdminCardDelete(w, r) admin.HandleAdminCardDelete(w, r)
} else { } else {
w.WriteHeader(http.StatusNotFound) w.WriteHeader(http.StatusNotFound)
} }
}))) })))
// Public API to get cards for homepage // Public API to get cards for homepage
http.HandleFunc("/api/cards", enableCORS(handleGetCards)) http.HandleFunc("/api/cards", enableCORS(admin.HandleGetCards))
port := os.Getenv("PORT") port := os.Getenv("PORT")
if port == "" { if port == "" {