- H now holds only small port interfaces (UserStore/LibraryStore/BookStore/ ProgressStore/BookmarkStore/RateLimiter/Scanner/Media/UploadSessions); NewRouter is the composition root distributing *store.Store and *redispkg.R - ports.Media gains EnsurePage; ChaptersOf returns ports.Chapter (media's local duplicate dropped); *media.M now provably satisfies ports.Media; ports.UploadSessions gains LibraryID for root validation before Complete - content.go: duplicated page-index cache + cover self-heal + page extract logic removed in favor of media service — same redis keys, same contract; path traversal check stays in handler (403 semantics preserved) - getLibrary/getLibRow merged into getLib(c, id); idParam helper dedupes :id parsing; isUnique replaced by ports.IsUniqueViolation (Task 28 partial) - main.go assembles media + upload and passes upload.U as scanner Sweeper Full gate green: gofmt, vet, go test -p 1 (real PG+Redis, 0 skip)
85 lines
2.0 KiB
Go
85 lines
2.0 KiB
Go
package handlers
|
|
|
|
import (
|
|
"errors"
|
|
"net/http"
|
|
"time"
|
|
|
|
"github.com/gin-gonic/gin"
|
|
"github.com/jackc/pgx/v5"
|
|
|
|
"booklib/internal/auth"
|
|
"booklib/internal/ports"
|
|
"booklib/internal/store"
|
|
)
|
|
|
|
func (h *H) ListUsers(c *gin.Context) {
|
|
users, e := h.users.ListUsers(c)
|
|
if e != nil {
|
|
dbErr(c, e)
|
|
return
|
|
}
|
|
out := make([]gin.H, 0, len(users))
|
|
for _, u := range users {
|
|
out = append(out, gin.H{"id": u.ID, "username": u.Username, "role": u.Role,
|
|
"created_at": u.CreatedAt.Format(time.RFC3339)})
|
|
}
|
|
c.JSON(http.StatusOK, out)
|
|
}
|
|
|
|
func (h *H) CreateUser(c *gin.Context) {
|
|
var req struct{ Username, Password, Role string }
|
|
if c.ShouldBindJSON(&req) != nil {
|
|
err(c, http.StatusBadRequest, "bad_request", "json body required")
|
|
return
|
|
}
|
|
if req.Role != "admin" && req.Role != "member" {
|
|
err(c, http.StatusBadRequest, "bad_request", "role must be admin|member")
|
|
return
|
|
}
|
|
if len(req.Password) < 8 {
|
|
err(c, http.StatusBadRequest, "bad_request", "password too short (min 8)")
|
|
return
|
|
}
|
|
hp, e := auth.HashPassword(req.Password)
|
|
if e != nil {
|
|
err(c, http.StatusInternalServerError, "internal", "hash")
|
|
return
|
|
}
|
|
id, e := h.users.CreateUser(c, req.Username, hp, req.Role)
|
|
if e != nil {
|
|
if ports.IsUniqueViolation(e) {
|
|
err(c, http.StatusConflict, "exists", "username taken")
|
|
return
|
|
}
|
|
dbErr(c, e)
|
|
return
|
|
}
|
|
c.JSON(http.StatusCreated, gin.H{"id": id, "username": req.Username, "role": req.Role})
|
|
}
|
|
|
|
func (h *H) DeleteUser(c *gin.Context) {
|
|
id, ok := idParam(c)
|
|
if !ok {
|
|
return
|
|
}
|
|
if id == uid(c) {
|
|
err(c, http.StatusBadRequest, "bad_request", "cannot delete yourself")
|
|
return
|
|
}
|
|
// B5: transactional last-admin check eliminates TOCTOU race.
|
|
if e := h.users.DeleteUser(c, id); e != nil {
|
|
if errors.Is(e, pgx.ErrNoRows) {
|
|
err(c, http.StatusNotFound, "not_found", "no such user")
|
|
return
|
|
}
|
|
if errors.Is(e, store.ErrLastAdmin) {
|
|
err(c, http.StatusBadRequest, "bad_request", "cannot delete the last admin")
|
|
return
|
|
}
|
|
dbErr(c, e)
|
|
return
|
|
}
|
|
c.Status(http.StatusNoContent)
|
|
}
|