This commit is contained in:
Tomas Dvorak
2025-05-26 11:39:32 +02:00
parent d3581993a7
commit 4ec4444a51
4 changed files with 1157 additions and 1160 deletions
+6 -6
View File
@@ -1,4 +1,4 @@
package main
package admin
import (
"crypto/rand"
@@ -53,7 +53,7 @@ func generateToken() (string, error) {
return base64.URLEncoding.EncodeToString(bytes), nil
}
func handleLogin(w http.ResponseWriter, r *http.Request) {
func HandleLogin(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
if r.Method == "GET" {
@@ -309,7 +309,7 @@ func handleLogin(w http.ResponseWriter, r *http.Request) {
})
}
func handleLogout(w http.ResponseWriter, r *http.Request) {
func HandleLogout(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
token := r.Header.Get("Authorization")
@@ -330,7 +330,7 @@ func handleLogout(w http.ResponseWriter, r *http.Request) {
})
}
func requireAuth(next http.HandlerFunc) http.HandlerFunc {
func RequireAuth(next http.HandlerFunc) http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) {
token := r.Header.Get("Authorization")
if token == "" {
@@ -362,7 +362,7 @@ func requireAuth(next http.HandlerFunc) http.HandlerFunc {
}
}
func requireAdminAuth(next http.HandlerFunc) http.HandlerFunc {
func RequireAdminAuth(next http.HandlerFunc) http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) {
token := r.Header.Get("Authorization")
if token == "" {
@@ -394,7 +394,7 @@ func requireAdminAuth(next http.HandlerFunc) http.HandlerFunc {
}
}
func getCurrentUser(r *http.Request) *Session {
func GetCurrentUser(r *http.Request) *Session {
token := r.Header.Get("Authorization")
if token == "" {
if cookie, err := r.Cookie("authToken"); err == nil {
+7 -7
View File
@@ -1,4 +1,4 @@
package main
package admin
import (
"encoding/json"
@@ -42,8 +42,8 @@ var gridCards = []GridCard{
},
}
func handleAdmin(w http.ResponseWriter, r *http.Request) {
user := getCurrentUser(r)
func HandleAdmin(w http.ResponseWriter, r *http.Request) {
user := GetCurrentUser(r)
if user == nil {
http.Redirect(w, r, "/login", http.StatusFound)
return
@@ -607,7 +607,7 @@ func handleAdmin(w http.ResponseWriter, r *http.Request) {
t.Execute(w, data)
}
func handleAdminCards(w http.ResponseWriter, r *http.Request) {
func HandleAdminCards(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
switch r.Method {
@@ -644,7 +644,7 @@ func handleAdminCards(w http.ResponseWriter, r *http.Request) {
}
}
func handleAdminCardToggle(w http.ResponseWriter, r *http.Request) {
func HandleAdminCardToggle(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
if r.Method != "POST" {
@@ -676,7 +676,7 @@ func handleAdminCardToggle(w http.ResponseWriter, r *http.Request) {
json.NewEncoder(w).Encode(map[string]string{"error": "Card not found"})
}
func handleAdminCardDelete(w http.ResponseWriter, r *http.Request) {
func HandleAdminCardDelete(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
if r.Method != "DELETE" {
@@ -709,7 +709,7 @@ func handleAdminCardDelete(w http.ResponseWriter, r *http.Request) {
json.NewEncoder(w).Encode(map[string]string{"error": "Card not found"})
}
func handleGetCards(w http.ResponseWriter, r *http.Request) {
func HandleGetCards(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
// Filter only enabled cards and sort by order
-4
View File
@@ -1,7 +1,5 @@
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
github.com/fsnotify/fsnotify v1.9.0 h1:2Ml+OJNzbYCTzsxtv8vKSFD9PbJjmhYF14k/jKC7S9k=
github.com/fsnotify/fsnotify v1.9.0/go.mod h1:8jBTzvmWwFyi3Pb8djgCCO5IBqzKJ/Jwo8TRcHyHii0=
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
github.com/richardlehane/mscfb v1.0.4 h1:WULscsljNPConisD5hR0+OyZjwK46Pfyr6mPu5ZawpM=
@@ -25,8 +23,6 @@ golang.org/x/image v0.25.0 h1:Y6uW6rH1y5y/LK1J8BPWZtr6yZ7hrsy6hFrXjgsc2fQ=
golang.org/x/image v0.25.0/go.mod h1:tCAmOEGthTtkalusGp1g3xa2gke8J6c2N565dTyl9Rs=
golang.org/x/net v0.40.0 h1:79Xs7wF06Gbdcg4kdCCIQArK11Z1hr5POQ6+fIYHNuY=
golang.org/x/net v0.40.0/go.mod h1:y0hY0exeL2Pku80/zKK7tpntoX23cqL3Oa6njdgRtds=
golang.org/x/sys v0.33.0 h1:q3i8TbbEz+JRD9ywIRlyRAQbM0qF7hu24q3teo2hbuw=
golang.org/x/sys v0.33.0/go.mod h1:BJP2sWEmIv4KK5OTEluFJCKSidICx8ciO85XgH3Ak8k=
golang.org/x/text v0.25.0 h1:qVyWApTSYLk/drJRO5mDlNYskwQznZmkpV2c8q9zls4=
golang.org/x/text v0.25.0/go.mod h1:WEdwpYrmk1qmdHvhkSTNPm3app7v4rsT8F2UD6+VHIA=
gopkg.in/alexcesaro/quotedprintable.v3 v3.0.0-20150716171945-2caba252f4dc h1:2gGKlE2+asNV9m7xrywl36YYNnBG5ZQ0r/BOOxqPpmk=
+9 -8
View File
@@ -15,6 +15,7 @@ import (
"time"
"gopkg.in/gomail.v2"
"ppve/admin" // Import the local admin package
)
type TripEntry struct {
@@ -81,26 +82,26 @@ func main() {
http.Redirect(w, r, "http://webportal:8080/", http.StatusFound)
}))
// Authentication routes
http.HandleFunc("/login", enableCORS(handleLogin))
http.HandleFunc("/logout", enableCORS(handleLogout))
http.HandleFunc("/login", enableCORS(admin.HandleLogin))
http.HandleFunc("/logout", enableCORS(admin.HandleLogout))
// Admin routes (protected)
http.HandleFunc("/admin", enableCORS(requireAdminAuth(handleAdmin)))
http.HandleFunc("/admin/cards", enableCORS(requireAdminAuth(handleAdminCards)))
http.HandleFunc("/admin", enableCORS(admin.RequireAdminAuth(admin.HandleAdmin)))
http.HandleFunc("/admin/cards", enableCORS(admin.RequireAdminAuth(admin.HandleAdminCards)))
http.HandleFunc("/admin/cards/", enableCORS(requireAdminAuth(func(w http.ResponseWriter, r *http.Request) {
http.HandleFunc("/admin/cards/", enableCORS(admin.RequireAdminAuth(func(w http.ResponseWriter, r *http.Request) {
path := r.URL.Path
if strings.HasSuffix(path, "/toggle") {
handleAdminCardToggle(w, r)
admin.HandleAdminCardToggle(w, r)
} else if r.Method == "DELETE" {
handleAdminCardDelete(w, r)
admin.HandleAdminCardDelete(w, r)
} else {
w.WriteHeader(http.StatusNotFound)
}
})))
// Public API to get cards for homepage
http.HandleFunc("/api/cards", enableCORS(handleGetCards))
http.HandleFunc("/api/cards", enableCORS(admin.HandleGetCards))
port := os.Getenv("PORT")
if port == "" {