feat: auth handlers and session management

This commit is contained in:
2026-08-26 23:16:08 +08:00
parent 2852097b26
commit af6aba3d37
4 changed files with 229 additions and 0 deletions
+47
View File
@@ -0,0 +1,47 @@
package server
import (
"net/http"
)
func (s *Server) requireAuth(next http.HandlerFunc) http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) {
cookie, err := r.Cookie("ydropbox_session")
if err != nil {
http.Error(w, "Unauthorized", http.StatusUnauthorized)
return
}
s.mu.Lock()
_, exists := s.sessions[cookie.Value]
s.mu.Unlock()
if !exists {
http.Error(w, "Unauthorized", http.StatusUnauthorized)
return
}
next(w, r)
}
}
func (s *Server) requireAuthPage(next http.HandlerFunc) http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) {
cookie, err := r.Cookie("ydropbox_session")
if err != nil {
http.Redirect(w, r, "/login", http.StatusFound)
return
}
s.mu.Lock()
_, exists := s.sessions[cookie.Value]
s.mu.Unlock()
if !exists {
http.Redirect(w, r, "/login", http.StatusFound)
return
}
next(w, r)
}
}