aboutsummaryrefslogtreecommitdiff
path: root/api/internal
diff options
context:
space:
mode:
Diffstat (limited to 'api/internal')
-rw-r--r--api/internal/middleware/middleware.go55
-rw-r--r--api/internal/router/router.go42
2 files changed, 97 insertions, 0 deletions
diff --git a/api/internal/middleware/middleware.go b/api/internal/middleware/middleware.go
new file mode 100644
index 0000000..819f1e5
--- /dev/null
+++ b/api/internal/middleware/middleware.go
@@ -0,0 +1,55 @@
1package middleware
2
3import (
4 "errors"
5 "github.com/gin-gonic/gin"
6 "log"
7 "net/http"
8 "strings"
9)
10
11func TokenRequired() gin.HandlerFunc {
12 return func(c *gin.Context) {
13 _, err := checkForTokenInContext(c)
14
15 if err != nil {
16 c.JSON(http.StatusUnauthorized, gin.H{"error": "Unauthorized"})
17 c.Abort()
18 return
19 }
20
21 c.Next()
22 }
23}
24
25func CORSMiddleware() gin.HandlerFunc {
26 return func(c *gin.Context) {
27 c.Writer.Header().Set("Access-Control-Allow-Origin", "*")
28 c.Writer.Header().Set("Access-Control-Allow-Credentials", "true")
29 c.Writer.Header().Set("Access-Control-Allow-Headers", "Content-Type, Content-Length, Accept-Encoding, X-CSRF-Token, Authorization, accept, origin, Cache-Control, X-Requested-With")
30 c.Writer.Header().Set("Access-Control-Allow-Methods", "POST, OPTIONS, GET, PUT")
31
32 if c.Request.Method == "OPTIONS" {
33 log.Println(c.Request.Header)
34 c.AbortWithStatus(http.StatusNoContent)
35 return
36 }
37
38 c.Next()
39 }
40}
41
42func checkForTokenInContext(c *gin.Context) (string, error) {
43 authorizationHeader := c.GetHeader("Authorization")
44 if authorizationHeader == "" {
45 return "", errors.New("authorization header is missing")
46 }
47
48 parts := strings.Split(authorizationHeader, " ")
49
50 if len(parts) != 2 || parts[0] != "Bearer" {
51 return "", errors.New("invalid Authorization header format")
52 }
53
54 return parts[1], nil
55} \ No newline at end of file
diff --git a/api/internal/router/router.go b/api/internal/router/router.go
new file mode 100644
index 0000000..adf96d0
--- /dev/null
+++ b/api/internal/router/router.go
@@ -0,0 +1,42 @@
1package router
2
3import (
4 "github.com/gin-gonic/gin"
5 "water/api/internal/controllers"
6 "water/api/internal/middleware"
7)
8
9func SetupRouter() *gin.Engine {
10 // Disable Console Color
11 // gin.DisableConsoleColor()
12 r := gin.Default()
13 r.Use(middleware.CORSMiddleware())
14 r.Use(gin.Logger())
15 r.Use(gin.Recovery())
16
17 api := r.Group("api/v1")
18
19 api.POST("/auth", controllers.AuthHandler)
20
21 user := api.Group("/user/:uuid")
22 user.Use(middleware.TokenRequired())
23 {
24 user.GET("", controllers.GetUser)
25 user.GET("preferences", controllers.GetUserPreferences)
26 user.PATCH("preferences", controllers.UpdateUserPreferences)
27 }
28
29 stats := api.Group("/stats")
30 stats.Use(middleware.TokenRequired())
31 {
32 stats.GET("/", controllers.GetAllStatistics)
33 stats.POST("/", controllers.PostNewStatistic)
34 stats.GET("weekly/", controllers.GetWeeklyStatistics)
35 stats.GET("daily/", controllers.GetDailyUserStatistics)
36 stats.GET("user/:uuid", controllers.GetUserStatistics)
37 stats.PATCH("user/:uuid", controllers.UpdateUserStatistic)
38 stats.DELETE("user/:uuid", controllers.DeleteUserStatistic)
39 }
40
41 return r
42} \ No newline at end of file