Files
backend_fiesta/routes/routes.go
2026-09-25 09:53:16 +05:30

52 lines
1.8 KiB
Go

package routes
import (
"nearle/facade"
"nearle/middleware"
"github.com/gofiber/fiber/v2"
)
func RegisterRoutes(app *fiber.App, f *facade.Facade) {
api := app.Group("/live/api")
// Console sessions.
//
// Mounted by PATH rather than on a group object, because the `/v1/web`
// routes are not one group — a dozen files each create their own
// (`/v1/web/users`, `/v1/web/orders`, `/v1/web/products`, …). Registered
// here, ahead of all of them, so a route added later is guarded by default
// rather than by somebody remembering to.
//
// `/v1/pos` is deliberately NOT covered: that is the terminal surface, it
// carries a different kind of token, and it has its own guard. But
// `/v1/web/pos` and `/v1/web/tenants` ARE, despite their names — both are
// console callers, and `createposuser` on the second mints till credentials,
// which until now it did on the strength of an unauthenticated request. The
// note above registerPosStaffConsoleRoutes asked for exactly this.
api.Use("/v1/web", middleware.WebAuth(f.PosService()))
RegisterUserRoutes(api, f)
RegisterProductRoutes(api, f)
RegisterOrderRoutes(api, f)
RegisterDeliveriesRoutes(api, f)
RegisterUtilsRoutes(api, f)
RegisterTenantRoutes(api, f)
RegisterPartnerRoutes(api, f)
RegisterCustomerRoutes(api, f)
RegisterCatalogueRoutes(api, f)
RegisterPosRoutes(api, f)
RegisterUploadRoutes(api, f)
RegisterScanRoutes(api, f)
RegisterAssistantRoutes(api, f)
// What is running here.
//
// Registered on `api` and NOT under `/v1/web`, so it answers without a
// session — which is the whole point. The question it exists for is "why
// does nothing work", and a health check that needs a working credential
// cannot answer that. It returns booleans and a build id, never values.
api.Get("/v1/health", f.HealthController.Health)
}