feat(10-01): serve the embedded admin SPA at backend.uri with cookie login
- backend.uri prefix (default /backend) mounts the admin API at {prefix}/api/v1
and the embedded SPA shell at {prefix} with an api/ JSON 404 fallback
- cookie transport: an X-Requested-With login sets the HttpOnly summer_admin
cookie and returns no token; the backend guard reads the cookie after Bearer
- CSRF wrapper refuses cookie-only POST/PUT/DELETE without X-Requested-With
- boardwalk package embeds boardwalk/dist, rewrites index.html once per prefix
and sets cache and security headers
- framework admin OpenAPI pipeline (swag, swagger2openapi, openapi-typescript)
with prefix-relative paths and typed envelopes for the tracer routes
- admin/ Vite SPA: login, plugin rail, section panel and read-only list
through the openapi-fetch client typed by the generated schema
This commit is contained in:
@@ -87,13 +87,16 @@ func NewJWTGuard(secret string, users UserProvider, bl BlacklistStore, cookieNam
|
||||
return &jwtGuard{secret: secret, users: users, bl: bl, cookieNames: cookieNames}
|
||||
}
|
||||
|
||||
// NewBackendJWTGuard is bearer-only and requires AudienceBackend.
|
||||
// write may replace the PHP-shaped 401 body; nil keeps write401.
|
||||
func NewBackendJWTGuard(secret string, users UserProvider, bl BlacklistStore, write func(http.ResponseWriter, error)) Guard {
|
||||
// NewBackendJWTGuard requires AudienceBackend. write may replace the
|
||||
// PHP-shaped 401 body; nil keeps write401. With no cookieNames it is
|
||||
// Bearer-only; otherwise each cookie is tried, in order, after the
|
||||
// Authorization header, so a Bearer token still wins when both are sent.
|
||||
func NewBackendJWTGuard(secret string, users UserProvider, bl BlacklistStore, write func(http.ResponseWriter, error), cookieNames ...string) Guard {
|
||||
return &jwtGuard{
|
||||
secret: secret,
|
||||
users: users,
|
||||
bl: bl,
|
||||
cookieNames: cookieNames,
|
||||
audience: AudienceBackend,
|
||||
requireAudience: true,
|
||||
writeFn: write,
|
||||
|
||||
Reference in New Issue
Block a user