webapi

package
v1.0.0-rc.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: Apache-2.0 Imports: 19 Imported by: 0

Documentation

Overview

Package webapi is the JSON API the web UI talks to: accounts, sessions and the data of the central.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func ParseOrigins

func ParseOrigins(origins []string) ([]string, error)

ParseOrigins checks the allowed web origins: each is scheme://host[:port], with no path and no wildcard, so that what a browser may do is always named.

Types

type Config

type Config struct {
	// AllowedOrigins are the web origins that may call the API from a browser,
	// as scheme://host[:port]. Empty: no browser origin is allowed.
	AllowedOrigins []string
	// SessionTTL is how long a login lasts; zero means 12 hours.
	SessionTTL time.Duration
	// Sender delivers the test notifications of a channel; nil posts to its
	// webhook.
	Sender alert.Sender
	// HSTS tells browsers to use HTTPS only; set it when the API serves TLS.
	HSTS bool
	// Policy is where a test notification may not connect; nil means the
	// default ranges, a pointer to the zero value nowhere.
	Policy *probe.Policy
	// TrustedProxies are the reverse proxies trusted to say who the client is.
	// Without them a failed login is counted against the address of the proxy,
	// and every user would be locked out together.
	TrustedProxies auth.Proxies
}

Config is what the UI API needs besides the store.

type Server

type Server struct {
	// contains filtered or unexported fields
}

Server is the JSON API of the web UI. It authenticates with bearer tokens: there are no cookies, so there is nothing for another site to forge.

func New

func New(log *slog.Logger, st *store.Store, cfg Config) (*Server, error)

New builds the API on top of a store, or says why the settings are wrong.

func (*Server) Handler

func (s *Server) Handler() http.Handler

Handler serves the API.

func (*Server) SetupCode

func (s *Server) SetupCode() string

SetupCode is what the first administrator must give to be created from the UI. Whoever reaches a new central first could otherwise take it over, so the code is only in the log of the central, and changes at each start.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL