bbe0757ab6
Implement complete refresh token flow for improved security: - Short-lived access tokens (configurable, default 1h) - Long-lived refresh tokens (configurable, default 7d) - Automatic token rotation on refresh - Token revocation for proper logout Domain layer: - Add RefreshToken entity with validation and revocation - Add RefreshTokenRepository interface Application layer: - Add RefreshTokenHandler for token refresh operations - Add RevokeTokenHandler for single token revocation - Add RevokeAllTokensHandler for user-wide revocation Infrastructure layer: - Implement SQLite RefreshTokenRepository - Add refresh_tokens table migration with indexes - Add parseDuration helper for flexible time configuration HTTP layer: - Add POST /api/v1/auth/refresh endpoint - Add POST /api/v1/auth/logout endpoint - Update login/register to return refresh tokens - Improve Swagger documentation with clear descriptions Configuration: - Update .env.example with secure token expiry defaults - Add support for minute/hour/day duration formats Tests: - Fix test suite to work with new signatures - All existing tests passing
67 lines
2.0 KiB
Go
67 lines
2.0 KiB
Go
package http
|
|
|
|
import (
|
|
"net/http"
|
|
"time"
|
|
|
|
"apocapoc-api/internal/infrastructure/auth"
|
|
|
|
"github.com/go-chi/chi/v5"
|
|
"github.com/go-chi/chi/v5/middleware"
|
|
"github.com/go-chi/cors"
|
|
"github.com/go-chi/httprate"
|
|
httpSwagger "github.com/swaggo/http-swagger"
|
|
|
|
_ "apocapoc-api/docs"
|
|
)
|
|
|
|
func NewRouter(corsOrigins string, habitHandlers *HabitHandlers, authHandlers *AuthHandlers, statsHandlers *StatsHandlers, healthHandlers *HealthHandlers, jwtService *auth.JWTService) *chi.Mux {
|
|
r := chi.NewRouter()
|
|
|
|
r.Use(middleware.Logger)
|
|
r.Use(middleware.Recoverer)
|
|
r.Use(cors.Handler(cors.Options{
|
|
AllowedOrigins: []string{corsOrigins},
|
|
AllowedMethods: []string{"GET", "POST", "PUT", "DELETE", "OPTIONS"},
|
|
AllowedHeaders: []string{"Accept", "Authorization", "Content-Type"},
|
|
AllowCredentials: true,
|
|
}))
|
|
|
|
r.Get("/api/v1/docs", func(w http.ResponseWriter, r *http.Request) {
|
|
http.Redirect(w, r, "/api/v1/docs/index.html", http.StatusMovedPermanently)
|
|
})
|
|
r.Get("/api/v1/docs/*", httpSwagger.Handler(
|
|
httpSwagger.URL("/api/v1/docs/doc.json"),
|
|
))
|
|
|
|
r.Get("/api/v1/health", healthHandlers.Health)
|
|
|
|
r.Route("/api/v1/auth", func(r chi.Router) {
|
|
r.Use(httprate.LimitByIP(10, 1*time.Minute))
|
|
r.Post("/register", authHandlers.Register)
|
|
r.Post("/login", authHandlers.Login)
|
|
r.Post("/refresh", authHandlers.Refresh)
|
|
r.Post("/logout", authHandlers.Logout)
|
|
})
|
|
|
|
r.Route("/api/v1/habits", func(r chi.Router) {
|
|
r.Use(AuthMiddleware(jwtService))
|
|
r.Post("/", habitHandlers.CreateHabit)
|
|
r.Get("/", habitHandlers.GetUserHabits)
|
|
r.Get("/today", habitHandlers.GetTodaysHabits)
|
|
r.Get("/{id}", habitHandlers.GetHabitByID)
|
|
r.Put("/{id}", habitHandlers.UpdateHabit)
|
|
r.Delete("/{id}", habitHandlers.ArchiveHabit)
|
|
r.Get("/{id}/entries", habitHandlers.GetHabitEntries)
|
|
r.Post("/{id}/mark", habitHandlers.MarkHabit)
|
|
r.Delete("/{id}/entries/{date}", habitHandlers.UnmarkHabit)
|
|
})
|
|
|
|
r.Route("/api/v1/stats", func(r chi.Router) {
|
|
r.Use(AuthMiddleware(jwtService))
|
|
r.Get("/habits/{id}", statsHandlers.GetHabitStats)
|
|
})
|
|
|
|
return r
|
|
}
|