aboutsummaryrefslogtreecommitdiff
path: root/backend/internal/api/router.go
blob: d28da71d75b9bca6230707c5b78f02f9339d8030 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
package api

import (
	"net/http"
	"strings"
)

func NewRouter(h *Handler, stream *StreamHandler, auth *AuthHandler) http.Handler {
	mux := http.NewServeMux()

	mux.HandleFunc("POST /api/auth/login", auth.Login)
	mux.HandleFunc("GET /api/auth/verify", auth.Verify)

	mux.HandleFunc("GET /api/services", h.ListServices)
	mux.HandleFunc("POST /api/services", h.CreateService)
	mux.HandleFunc("PUT /api/services/{id}", h.UpdateService)
	mux.HandleFunc("PATCH /api/services/{id}/toggle", h.ToggleService)
	mux.HandleFunc("POST /api/services/{id}/test", h.TestService)
	mux.HandleFunc("DELETE /api/services/{id}", h.DeleteService)
	mux.HandleFunc("GET /api/services/{id}/history", h.GetHistory)
	mux.HandleFunc("GET /api/services/{id}/stats", h.GetStats)
	mux.HandleFunc("GET /api/services/{id}/ssl", h.GetSSLInfo)
	mux.HandleFunc("GET /api/services/{id}/badge.svg", h.BadgeSVG)

	mux.HandleFunc("GET /api/active-maintenance", h.GetActiveMaintenance)

	mux.HandleFunc("GET /api/maintenances", h.ListMaintenances)
	mux.HandleFunc("POST /api/maintenances", h.CreateMaintenance)
	mux.HandleFunc("PUT /api/maintenances/{id}", h.UpdateMaintenance)
	mux.HandleFunc("DELETE /api/maintenances/{id}", h.DeleteMaintenance)

	mux.HandleFunc("GET /api/admin/server-stats", h.ServerStats)

	mux.Handle("GET /api/stream", stream)

	return corsMiddleware(auth.Middleware(mux))
}

func corsMiddleware(next http.Handler) http.Handler {
	return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
		origin := r.Header.Get("Origin")

		if origin != "" && isAllowedOrigin(origin) {
			w.Header().Set("Access-Control-Allow-Origin", origin)
			w.Header().Set("Vary", "Origin")
		} else {
			w.Header().Set("Access-Control-Allow-Origin", "*")
		}

		w.Header().Set("Access-Control-Allow-Methods", "GET, POST, PUT, PATCH, DELETE, OPTIONS")
		w.Header().Set("Access-Control-Allow-Headers", "Content-Type, Authorization")
		w.Header().Set("Access-Control-Max-Age", "86400")

		if r.Method == http.MethodOptions {
			w.WriteHeader(http.StatusNoContent)
			return
		}

		next.ServeHTTP(w, r)
	})
}

func isAllowedOrigin(origin string) bool {
	allowed := []string{
		"http://localhost:5173",
		"http://localhost:4173",
		"http://127.0.0.1:5173",
		"http://127.0.0.1:4173",
	}
	for _, a := range allowed {
		if strings.EqualFold(origin, a) {
			return true
		}
	}
	if strings.HasPrefix(origin, "http://localhost:") {
		return true
	}
	return false
}