aravind changes
This commit is contained in:
@@ -1,17 +1,24 @@
|
||||
// Package httpserver holds the HTTP surface.
|
||||
//
|
||||
// It serves /health, the sign-in endpoints, the entity endpoints described in
|
||||
// docs/api-contract.md, and the current-user endpoints.
|
||||
// docs/api-contract.md, the current-user endpoints, the agent and skill
|
||||
// definition endpoints, and the Owliver panel's suggestion endpoint.
|
||||
//
|
||||
// Phase 3C replaced the development identity with real authentication. Every
|
||||
// request outside the small public allowlist in auth.go must carry a session
|
||||
// cookie; the middleware resolves it to a user row and puts that user, and
|
||||
// their organization, on the request context. Nothing downstream changed —
|
||||
// every service and repository already took the organization as a parameter,
|
||||
// which is what devOrgMiddleware existed to make true.
|
||||
// Authentication replaced the development identity: every request outside the
|
||||
// small public allowlist in auth.go must carry a session cookie; the middleware
|
||||
// resolves it to a user row and puts that user, and their organization, on the
|
||||
// request context. Nothing downstream changed — every service and repository
|
||||
// already took the organization as a parameter, which is what devOrgMiddleware
|
||||
// existed to make true.
|
||||
//
|
||||
// Authorization is NOT here. A signed-in user reaches every endpoint they could
|
||||
// reach before; deciding which roles may do what is Phase 3D.
|
||||
// Authorization is here, in Server.authorize: it reads the role off the
|
||||
// authenticated identity, consults the deny-by-default policy table in
|
||||
// internal/domain/policy.go, and answers 403 before any query runs. Row
|
||||
// visibility — organization scope, and ownership for talent callers — is a SQL
|
||||
// predicate in internal/repo instead, so an invisible row answers 404 rather
|
||||
// than 403. The definition endpoints are the exception: they are not
|
||||
// domain.Resource values, so their role checks are written inline in
|
||||
// internal/service/definitions.go rather than in the policy table.
|
||||
package httpserver
|
||||
|
||||
import (
|
||||
@@ -38,6 +45,7 @@ type Server struct {
|
||||
api *service.Registry
|
||||
definitions *service.DefinitionsService
|
||||
workflows *service.WorkflowService
|
||||
suggestions *service.SuggestionsService
|
||||
log *slog.Logger
|
||||
http *http.Server
|
||||
started time.Time
|
||||
@@ -126,6 +134,7 @@ func New(cfg *config.Config, database *db.DB, log *slog.Logger, opts ...Option)
|
||||
api: service.NewRegistry(database.Pool),
|
||||
definitions: service.NewDefinitions(database.Pool),
|
||||
workflows: service.NewWorkflows(database.Pool).WithClock(o.now),
|
||||
suggestions: service.NewSuggestions(),
|
||||
started: o.now(),
|
||||
sessions: sessions,
|
||||
users: users,
|
||||
@@ -138,7 +147,7 @@ func New(cfg *config.Config, database *db.DB, log *slog.Logger, opts ...Option)
|
||||
mux := http.NewServeMux()
|
||||
mux.HandleFunc("GET /health", s.handleHealth)
|
||||
s.endpoints = s.routeAuth(mux) + s.routeResources(mux) + s.routeMe(mux) +
|
||||
s.routeDefinitions(mux) + s.routeWorkflows(mux)
|
||||
s.routeDefinitions(mux) + s.routeWorkflows(mux) + s.routeOwliver(mux)
|
||||
|
||||
handler := jsonErrors(mux)
|
||||
// Authentication sits where devOrgMiddleware used to, so every route below
|
||||
|
||||
Reference in New Issue
Block a user