package routes import ( "nearle/facade" "nearle/middleware" "github.com/gofiber/fiber/v2" ) func RegisterRoutes(app *fiber.App, f *facade.Facade) { api := app.Group("/live/api") // Console sessions. // // Mounted by PATH rather than on a group object, because the `/v1/web` // routes are not one group — a dozen files each create their own // (`/v1/web/users`, `/v1/web/orders`, `/v1/web/products`, …). Registered // here, ahead of all of them, so a route added later is guarded by default // rather than by somebody remembering to. // // `/v1/pos` is deliberately NOT covered: that is the terminal surface, it // carries a different kind of token, and it has its own guard. But // `/v1/web/pos` and `/v1/web/tenants` ARE, despite their names — both are // console callers, and `createposuser` on the second mints till credentials, // which until now it did on the strength of an unauthenticated request. The // note above registerPosStaffConsoleRoutes asked for exactly this. api.Use("/v1/web", middleware.WebAuth(f.PosService())) RegisterUserRoutes(api, f) RegisterProductRoutes(api, f) RegisterOrderRoutes(api, f) RegisterDeliveriesRoutes(api, f) RegisterUtilsRoutes(api, f) RegisterTenantRoutes(api, f) RegisterPartnerRoutes(api, f) RegisterCustomerRoutes(api, f) RegisterCatalogueRoutes(api, f) RegisterPosRoutes(api, f) RegisterUploadRoutes(api, f) RegisterScanRoutes(api, f) RegisterAssistantRoutes(api, f) // What is running here. // // Registered on `api` and NOT under `/v1/web`, so it answers without a // session — which is the whole point. The question it exists for is "why // does nothing work", and a health check that needs a working credential // cannot answer that. It returns booleans and a build id, never values. api.Get("/v1/health", f.HealthController.Health) }