Files
usernode/internal/router/router.go
T
cao.wangrenbo a5f501dba4 feat(M2): SSH 密钥管理 — 公钥上传/重命名/吊销、authorized_keys 原子同步与吊销即时失效
- KeyService:crypto/ssh 解析校验(单行/类型/长度/去重指纹,拒 ssh-dss 与 RSA<2048),
  Create/Rename/Revoke/List,变更后以 DB 状态全量重写 authorized_keys(同步失败回滚)
- system 层:SyncAuthorizedKeys 完善 —— sudo 模式经白名单命令(mkdir/chown/chmod/install)
  落位并修正属主(sshd StrictModes),direct 模式 root 时同样修正属主;dry-run 计划日志
- API:GET/POST /me/keys、PATCH/DELETE /me/keys/:id(user 会话)、GET /users/:id/keys(admin),
  密钥操作带审计;deploy/sudoers.example 补充密钥同步白名单
- 版本 0.3.0-m2;测试:service 单元(校验/生命周期/回滚/权限)、system 直写落盘、
  API 全流程集成;容器 E2E 32 项 PASS(真实 useradd/authorized_keys/吊销即时失效/禁用清空/删除回收)
2026-08-29 23:55:39 +08:00

106 lines
3.3 KiB
Go
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
// Package router 负责路由注册与中间件装配。
package router
import (
"log/slog"
"net/http"
"time"
"github.com/gin-gonic/gin"
"ws_usernode/internal/api"
"ws_usernode/internal/auth"
"ws_usernode/internal/config"
"ws_usernode/internal/webui"
)
// New 构建根 routerAPI v1 + 前端静态资源(go:embed)。
// production 模式启用 gin.ReleaseMode;否则启用调试模式与开发日志。
func New(cfg *config.Config, h *api.Handler, sessions auth.SessionStore, log *slog.Logger) *gin.Engine {
if cfg.App.Env == "production" {
gin.SetMode(gin.ReleaseMode)
}
r := gin.New()
r.Use(gin.Recovery(), requestLogger(log))
// 健康检查(不进 /api/v1 前缀,便于负载均衡/探针)
r.GET("/healthz", h.Health.Healthz)
// RESTful API v1
v1 := r.Group("/api/v1")
{
authGrp := v1.Group("/auth")
{
authGrp.GET("/captcha", h.Auth.Captcha)
authGrp.POST("/otp/send", h.Auth.OTPSend)
authGrp.POST("/otp/login", h.Auth.OTPLogin)
authGrp.POST("/admin/login", h.Auth.AdminLogin)
authGrp.POST("/admin/forgot", h.Auth.AdminForgot)
authGrp.POST("/admin/reset", h.Auth.AdminReset)
// 需要会话(管理员或外部用户)
authed := authGrp.Group("", sessionMiddleware(sessions))
authed.POST("/logout", h.Auth.Logout)
authed.GET("/me", h.Auth.Me)
}
// 用户管理(admin
users := v1.Group("/users", sessionMiddleware(sessions), requireUserType(auth.SessionUserAdmin))
{
users.GET("", h.User.List)
users.POST("", h.User.Create)
users.GET("/:id", h.User.Get)
users.PATCH("/:id", h.User.Update)
users.POST("/:id/disable", h.User.Disable)
users.POST("/:id/enable", h.User.Enable)
users.POST("/:id/extend", h.User.Extend)
users.DELETE("/:id", h.User.Delete)
users.GET("/:id/keys", h.Key.ListForUser)
}
// 我的密钥(外部用户,自助管理;仅用户上传,管理员不代签)
me := v1.Group("/me", sessionMiddleware(sessions), requireUserType(auth.SessionUserUser))
{
me.GET("/keys", h.Key.ListMine)
me.POST("/keys", h.Key.Create)
me.PATCH("/keys/:id", h.Key.Rename)
me.DELETE("/keys/:id", h.Key.Revoke)
}
// 后续里程碑
v1.POST("/approvals", notImplemented("提交申请(M3"))
v1.GET("/approvals", notImplemented("申请列表(M3"))
v1.POST("/approvals/:id/review", notImplemented("审批(M3"))
v1.GET("/audit", notImplemented("审计查询(M4"))
v1.GET("/audit/export", notImplemented("审计导出(M4"))
v1.GET("/settings", notImplemented("设置(M4"))
v1.PUT("/settings", notImplemented("设置(M4"))
}
// 前端静态资源(go:embeddev 阶段由 Vite dev server 代理,见 Makefile dev
r.NoRoute(gin.WrapH(webui.NewHandler()))
return r
}
// notImplemented 返回 501 占位 handler,标注里程碑。
func notImplemented(what string) gin.HandlerFunc {
return func(c *gin.Context) {
c.JSON(http.StatusNotImplemented, gin.H{"error": "接口 " + what + " 尚未实现"})
}
}
// requestLogger 以 slog 输出结构化请求日志。
func requestLogger(log *slog.Logger) gin.HandlerFunc {
return func(c *gin.Context) {
start := time.Now()
c.Next()
log.Info("http",
"method", c.Request.Method,
"path", c.Request.URL.Path,
"status", c.Writer.Status(),
"ip", c.ClientIP(),
"latency_ms", time.Since(start).Milliseconds(),
)
}
}