first
This commit is contained in:
@@ -0,0 +1,130 @@
|
||||
package auth
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"net/http"
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
"github.com/google/uuid"
|
||||
|
||||
"backend/internal/modules/users"
|
||||
"backend/internal/platform/middleware"
|
||||
"backend/internal/platform/security"
|
||||
)
|
||||
|
||||
const (
|
||||
adminRefreshCookieName = "admin_refresh_token"
|
||||
adminRefreshCookiePath = "/api/auth/admin"
|
||||
)
|
||||
|
||||
// AdminHandler exposes the admin-space auth endpoints. It is kept entirely
|
||||
// separate from CustomerHandler: different cookie name, different cookie
|
||||
// path, different JWT audience, so an admin session can never be replayed
|
||||
// against a future customer-facing endpoint.
|
||||
type AdminHandler struct {
|
||||
service *Service
|
||||
cookieSecure bool
|
||||
}
|
||||
|
||||
func NewAdminHandler(service *Service, cookieSecure bool) *AdminHandler {
|
||||
return &AdminHandler{service: service, cookieSecure: cookieSecure}
|
||||
}
|
||||
|
||||
type loginRequest struct {
|
||||
Email string `json:"email" binding:"required,email"`
|
||||
Password string `json:"password" binding:"required"`
|
||||
}
|
||||
|
||||
type authUserResponse struct {
|
||||
ID uuid.UUID `json:"id"`
|
||||
Email string `json:"email"`
|
||||
Role string `json:"role"`
|
||||
}
|
||||
|
||||
type accessTokenResponse struct {
|
||||
AccessToken string `json:"access_token"`
|
||||
User *authUserResponse `json:"user,omitempty"`
|
||||
}
|
||||
|
||||
func (h *AdminHandler) Login(c *gin.Context) {
|
||||
var req loginRequest
|
||||
if err := c.ShouldBindJSON(&req); err != nil {
|
||||
c.JSON(http.StatusBadRequest, gin.H{"error": "validation error", "details": err.Error()})
|
||||
return
|
||||
}
|
||||
|
||||
pair, user, err := h.service.Login(c.Request.Context(), security.AudienceAdmin, users.RoleAdmin, req.Email, req.Password)
|
||||
if err != nil {
|
||||
h.respondLoginError(c, err)
|
||||
return
|
||||
}
|
||||
|
||||
h.setRefreshCookie(c, pair.RefreshToken)
|
||||
c.JSON(http.StatusOK, accessTokenResponse{
|
||||
AccessToken: pair.AccessToken,
|
||||
User: &authUserResponse{ID: user.ID, Email: user.Email, Role: user.Role},
|
||||
})
|
||||
}
|
||||
|
||||
func (h *AdminHandler) Refresh(c *gin.Context) {
|
||||
token, err := c.Cookie(adminRefreshCookieName)
|
||||
if err != nil || token == "" {
|
||||
c.JSON(http.StatusUnauthorized, gin.H{"error": "missing refresh token"})
|
||||
return
|
||||
}
|
||||
|
||||
pair, err := h.service.Refresh(c.Request.Context(), security.AudienceAdmin, token)
|
||||
if err != nil {
|
||||
h.clearRefreshCookie(c)
|
||||
c.JSON(http.StatusUnauthorized, gin.H{"error": "invalid or expired refresh token"})
|
||||
return
|
||||
}
|
||||
|
||||
h.setRefreshCookie(c, pair.RefreshToken)
|
||||
c.JSON(http.StatusOK, accessTokenResponse{AccessToken: pair.AccessToken})
|
||||
}
|
||||
|
||||
func (h *AdminHandler) Logout(c *gin.Context) {
|
||||
if token, err := c.Cookie(adminRefreshCookieName); err == nil && token != "" {
|
||||
_ = h.service.Logout(c.Request.Context(), security.AudienceAdmin, token)
|
||||
}
|
||||
h.clearRefreshCookie(c)
|
||||
c.JSON(http.StatusOK, gin.H{"message": "logged out"})
|
||||
}
|
||||
|
||||
func (h *AdminHandler) Me(c *gin.Context) {
|
||||
userID, ok := middleware.GetUserID(c)
|
||||
if !ok {
|
||||
c.JSON(http.StatusUnauthorized, gin.H{"error": "unauthorized"})
|
||||
return
|
||||
}
|
||||
user, err := h.service.Me(c.Request.Context(), userID)
|
||||
if err != nil {
|
||||
if errors.Is(err, users.ErrNotFound) {
|
||||
c.JSON(http.StatusNotFound, gin.H{"error": "user not found"})
|
||||
return
|
||||
}
|
||||
c.JSON(http.StatusInternalServerError, gin.H{"error": "failed to load user"})
|
||||
return
|
||||
}
|
||||
c.JSON(http.StatusOK, authUserResponse{ID: user.ID, Email: user.Email, Role: user.Role})
|
||||
}
|
||||
|
||||
func (h *AdminHandler) respondLoginError(c *gin.Context, err error) {
|
||||
switch {
|
||||
case errors.Is(err, ErrInvalidCredentials), errors.Is(err, ErrAccountDisabled):
|
||||
c.JSON(http.StatusUnauthorized, gin.H{"error": "invalid credentials"})
|
||||
default:
|
||||
c.JSON(http.StatusInternalServerError, gin.H{"error": "login failed"})
|
||||
}
|
||||
}
|
||||
|
||||
func (h *AdminHandler) setRefreshCookie(c *gin.Context, token string) {
|
||||
c.SetSameSite(http.SameSiteStrictMode)
|
||||
c.SetCookie(adminRefreshCookieName, token, int(h.service.RefreshTTL().Seconds()), adminRefreshCookiePath, "", h.cookieSecure, true)
|
||||
}
|
||||
|
||||
func (h *AdminHandler) clearRefreshCookie(c *gin.Context) {
|
||||
c.SetSameSite(http.SameSiteStrictMode)
|
||||
c.SetCookie(adminRefreshCookieName, "", -1, adminRefreshCookiePath, "", h.cookieSecure, true)
|
||||
}
|
||||
Reference in New Issue
Block a user