Switch from net/http to gin-gonic web framework

- Added gin-gonic v1.10.0 dependency
- Refactored router.go: clean route groups with middleware chains
- Refactored all handlers to use gin.Context instead of http.ResponseWriter/*http.Request
- Simplified response helpers (JSON, Error, Success, Created, NoContent)
- Clean auth middleware using Gin's c.Set() for context
- Cleaner route definitions with path parameters (e.g., /domains/:name/users/:id)
- Admin routes moved to /api/admin group with RequireAdmin middleware
This commit is contained in:
Christoph Haas 2026-03-22 23:28:28 +01:00
parent 68285d861a
commit 2834657125
13 changed files with 474 additions and 812 deletions

View file

@ -1,10 +1,10 @@
package handlers
import (
"encoding/json"
"net/http"
"strings"
"strconv"
"github.com/gin-gonic/gin"
"github.com/imc-vibe/backend/internal/db"
)
@ -17,7 +17,7 @@ func NewDomainHandler(database *db.DB) *DomainHandler {
}
type CreateDomainRequest struct {
Name string `json:"name"`
Name string `json:"name" binding:"required"`
}
type DomainPermissions struct {
@ -27,22 +27,17 @@ type DomainPermissions struct {
CanManage bool `json:"canManage"`
}
func (h *DomainHandler) List(w http.ResponseWriter, r *http.Request) {
if r.Method != http.MethodGet {
Error(w, http.StatusMethodNotAllowed, "method not allowed")
return
}
authCtx := GetAuthContext(r)
func (h *DomainHandler) List(c *gin.Context) {
authCtx := GetAuthContext(c)
if authCtx == nil {
Error(w, http.StatusUnauthorized, "authentication required")
Error(c, http.StatusUnauthorized, "authentication required")
return
}
isAdmin := authCtx.IsAdmin()
domains, err := h.db.GetUserAccessibleDomains(authCtx.UserID, isAdmin)
if err != nil {
Error(w, http.StatusInternalServerError, "database error")
Error(c, http.StatusInternalServerError, "database error")
return
}
@ -59,144 +54,119 @@ func (h *DomainHandler) List(w http.ResponseWriter, r *http.Request) {
}
}
Success(w, domainStats)
Success(c, domainStats)
}
func (h *DomainHandler) Get(w http.ResponseWriter, r *http.Request) {
if r.Method != http.MethodGet {
Error(w, http.StatusMethodNotAllowed, "method not allowed")
return
}
domainName := extractDomainName(r.URL.Path)
func (h *DomainHandler) Get(c *gin.Context) {
domainName := c.Param("name")
if domainName == "" {
Error(w, http.StatusBadRequest, "domain name required")
Error(c, http.StatusBadRequest, "domain name required")
return
}
domain, err := h.db.GetDomainByName(domainName)
if err != nil {
Error(w, http.StatusNotFound, "domain not found")
Error(c, http.StatusNotFound, "domain not found")
return
}
authCtx := GetAuthContext(r)
authCtx := GetAuthContext(c)
if authCtx == nil {
Error(w, http.StatusUnauthorized, "authentication required")
Error(c, http.StatusUnauthorized, "authentication required")
return
}
canAccess, _ := h.db.CanAccessDomain(authCtx.UserID, domainName, authCtx.IsAdmin())
if !canAccess {
Error(w, http.StatusForbidden, "access denied")
Error(c, http.StatusForbidden, "access denied")
return
}
Success(w, domain)
Success(c, domain)
}
func (h *DomainHandler) Create(w http.ResponseWriter, r *http.Request) {
if r.Method != http.MethodPost {
Error(w, http.StatusMethodNotAllowed, "method not allowed")
return
}
authCtx := GetAuthContext(r)
func (h *DomainHandler) Create(c *gin.Context) {
authCtx := GetAuthContext(c)
if authCtx == nil || !authCtx.IsAdmin() {
Error(w, http.StatusForbidden, "admin access required")
Error(c, http.StatusForbidden, "admin access required")
return
}
var req CreateDomainRequest
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
Error(w, http.StatusBadRequest, "invalid request body")
return
}
if req.Name == "" {
Error(w, http.StatusBadRequest, "domain name required")
if err := c.ShouldBindJSON(&req); err != nil {
Error(c, http.StatusBadRequest, "invalid request body")
return
}
existing, err := h.db.GetDomainByName(req.Name)
if err == nil && existing != nil {
Error(w, http.StatusConflict, "domain already exists")
Error(c, http.StatusConflict, "domain already exists")
return
}
domain, err := h.db.CreateDomain(req.Name)
if err != nil {
Error(w, http.StatusInternalServerError, "failed to create domain")
Error(c, http.StatusInternalServerError, "failed to create domain")
return
}
Created(w, domain)
Created(c, domain)
}
func (h *DomainHandler) Delete(w http.ResponseWriter, r *http.Request) {
if r.Method != http.MethodDelete {
Error(w, http.StatusMethodNotAllowed, "method not allowed")
return
}
authCtx := GetAuthContext(r)
func (h *DomainHandler) Delete(c *gin.Context) {
authCtx := GetAuthContext(c)
if authCtx == nil || !authCtx.IsAdmin() {
Error(w, http.StatusForbidden, "admin access required")
Error(c, http.StatusForbidden, "admin access required")
return
}
domainName := extractDomainName(r.URL.Path)
domainName := c.Param("name")
if domainName == "" {
Error(w, http.StatusBadRequest, "domain name required")
Error(c, http.StatusBadRequest, "domain name required")
return
}
domain, err := h.db.GetDomainByName(domainName)
if err != nil {
Error(w, http.StatusNotFound, "domain not found")
Error(c, http.StatusNotFound, "domain not found")
return
}
if err := h.db.DeleteDomain(domain.ID); err != nil {
Error(w, http.StatusInternalServerError, "failed to delete domain")
Error(c, http.StatusInternalServerError, "failed to delete domain")
return
}
NoContent(w)
NoContent(c)
}
func (h *DomainHandler) GetPermissions(w http.ResponseWriter, r *http.Request) {
if r.Method != http.MethodGet {
Error(w, http.StatusMethodNotAllowed, "method not allowed")
return
}
authCtx := GetAuthContext(r)
func (h *DomainHandler) GetPermissions(c *gin.Context) {
authCtx := GetAuthContext(c)
if authCtx == nil {
Error(w, http.StatusUnauthorized, "authentication required")
Error(c, http.StatusUnauthorized, "authentication required")
return
}
if !authCtx.IsAdmin() {
Error(w, http.StatusForbidden, "admin access required")
Error(c, http.StatusForbidden, "admin access required")
return
}
domainName := extractDomainName(r.URL.Path)
domainName := c.Param("name")
if domainName == "" {
Error(w, http.StatusBadRequest, "domain name required")
Error(c, http.StatusBadRequest, "domain name required")
return
}
domain, err := h.db.GetDomainByName(domainName)
if err != nil {
Error(w, http.StatusNotFound, "domain not found")
Error(c, http.StatusNotFound, "domain not found")
return
}
users, err := h.db.GetUsersForDomain(domain.ID)
if err != nil {
Error(w, http.StatusInternalServerError, "database error")
Error(c, http.StatusInternalServerError, "database error")
return
}
@ -210,107 +180,74 @@ func (h *DomainHandler) GetPermissions(w http.ResponseWriter, r *http.Request) {
}
}
Success(w, permissions)
Success(c, permissions)
}
func (h *DomainHandler) AddPermission(w http.ResponseWriter, r *http.Request) {
if r.Method != http.MethodPost {
Error(w, http.StatusMethodNotAllowed, "method not allowed")
return
}
authCtx := GetAuthContext(r)
func (h *DomainHandler) AddPermission(c *gin.Context) {
authCtx := GetAuthContext(c)
if authCtx == nil || !authCtx.IsAdmin() {
Error(w, http.StatusForbidden, "admin access required")
Error(c, http.StatusForbidden, "admin access required")
return
}
domainName := extractDomainName(r.URL.Path)
domainName := c.Param("name")
if domainName == "" {
Error(w, http.StatusBadRequest, "domain name required")
Error(c, http.StatusBadRequest, "domain name required")
return
}
domain, err := h.db.GetDomainByName(domainName)
if err != nil {
Error(w, http.StatusNotFound, "domain not found")
Error(c, http.StatusNotFound, "domain not found")
return
}
var req struct {
UserID uint `json:"userId"`
UserID uint `json:"userId" binding:"required"`
}
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
Error(w, http.StatusBadRequest, "invalid request")
if err := c.ShouldBindJSON(&req); err != nil {
Error(c, http.StatusBadRequest, "invalid request")
return
}
if err := h.db.AddUserToDomain(req.UserID, domain.ID); err != nil {
Error(w, http.StatusInternalServerError, "failed to add user to domain")
Error(c, http.StatusInternalServerError, "failed to add user to domain")
return
}
Success(w, map[string]string{"message": "user added to domain"})
Success(c, map[string]string{"message": "user added to domain"})
}
func (h *DomainHandler) RemovePermission(w http.ResponseWriter, r *http.Request) {
if r.Method != http.MethodDelete {
Error(w, http.StatusMethodNotAllowed, "method not allowed")
return
}
authCtx := GetAuthContext(r)
func (h *DomainHandler) RemovePermission(c *gin.Context) {
authCtx := GetAuthContext(c)
if authCtx == nil || !authCtx.IsAdmin() {
Error(w, http.StatusForbidden, "admin access required")
Error(c, http.StatusForbidden, "admin access required")
return
}
domainName := extractDomainName(r.URL.Path)
domainName := c.Param("name")
if domainName == "" {
Error(w, http.StatusBadRequest, "domain name required")
Error(c, http.StatusBadRequest, "domain name required")
return
}
domain, err := h.db.GetDomainByName(domainName)
if err != nil {
Error(w, http.StatusNotFound, "domain not found")
Error(c, http.StatusNotFound, "domain not found")
return
}
userID := extractIDFromPath(r.URL.Path)
if err := h.db.RemoveUserFromDomain(userID, domain.ID); err != nil {
Error(w, http.StatusInternalServerError, "failed to remove user from domain")
userIDStr := c.Param("userId")
userID, err := strconv.ParseUint(userIDStr, 10, 64)
if err != nil {
Error(c, http.StatusBadRequest, "invalid user id")
return
}
NoContent(w)
}
func extractDomainName(path string) string {
parts := strings.Split(strings.TrimPrefix(path, "/api/"), "/")
if len(parts) >= 2 && parts[1] != "" {
return parts[1]
if err := h.db.RemoveUserFromDomain(uint(userID), domain.ID); err != nil {
Error(c, http.StatusInternalServerError, "failed to remove user from domain")
return
}
return ""
}
func extractIDFromPath(path string) uint {
parts := strings.Split(path, "/")
for i := len(parts) - 1; i >= 0; i-- {
if idStr := parts[i]; idStr != "" {
var id uint
for _, c := range idStr {
if c >= '0' && c <= '9' {
id = id*10 + uint(c-'0')
} else {
break
}
}
if id > 0 {
return id
}
}
}
return 0
NoContent(c)
}