Documentation
¶
Overview ¶
Package middleware holds the Fiber middleware that wraps the HTTP layer: authentication, a uniform response envelope, and the standard cross-cutting stack every request passes through.
Authentication ¶
AuthMiddleware guards the admin routes. RequireAuth reads the JWT from the admin_token cookie, validates it, and confirms its claims name the configured admin — a missing, invalid, or wrong-admin token is rejected and the cookie cleared. When a valid token is inside its refresh window the middleware mints a fresh one and resets the cookie, giving the admin a sliding session. The cookie is HTTP-only, Secure, and SameSite=Strict. Validated claims are stashed in the request context under AdminClaimsKey; downstream handlers read them with GetAdminClaims.
Response envelope ¶
FormatResponse gives every endpoint the same JSON shape — status, code, data, and message. Handlers don't write the body themselves: they put their result in the data local or, on failure, return a Fiber error and set the error local. The middleware reads whichever is present, derives the HTTP status and a human-readable message, and marks the envelope success or error.
Cross-cutting stack ¶
FiberMiddleware registers the rest in one call: security headers (helmet), panic recovery, CORS with credentials, a request rate limiter, and a favicon handler, behind RequestID, Tracing and AccessLog. RequestID attaches a request ID to the user context so every *Context log call below it carries the ID; Tracing starts the request's server span; AccessLog writes one structured line per request, carrying both. It also mounts the /health and /ready endpoints backed by the health checker.
Index ¶
- Constants
- func AccessLog(logger *slog.Logger, skip ...string) fiber.Handler
- func ClientIP(c *fiber.Ctx) string
- func FiberMiddleware(a *fiber.App, healthChecker *health.Checker, logger *slog.Logger)
- func FormatResponse() fiber.Handler
- func GetAdminClaims(c *fiber.Ctx) *auth.Claims
- func NoteError(c *fiber.Ctx, err error)
- func RequestID() fiber.Handler
- func Tracing(skip ...string) fiber.Handler
- type AuthMiddleware
- type Response
Constants ¶
const AdminClaimsKey = "admin_claims"
const RequestIDHeader = "X-Request-ID"
RequestIDHeader carries the request ID in and out.
Variables ¶
This section is empty.
Functions ¶
func AccessLog ¶ added in v1.7.0
AccessLog logs one line per request after the handler chain and the app's error handler have run, with the error recorded by NoteError or, failing that, the one the chain returned. The noted error wins because handlers usually replace the cause with a generic HTTP error. A request with an error and a non-5xx status logs at warn. A path equal to an entry in skip is not logged; an entry ending in "/" skips every path under it.
func ClientIP ¶ added in v1.7.0
ClientIP returns the TCP peer address, or the rightmost X-Forwarded-For hop when the peer is a configured trusted proxy. Unparseable hops fall back to the peer.
func FiberMiddleware ¶
FiberMiddleware provide Fiber's built-in middlewares. See: https://docs.gofiber.io/api/middleware
func FormatResponse ¶
FormatResponse middleware formats the response to a standard format.
func GetAdminClaims ¶
GetAdminClaims retrieves admin claims from the Fiber context
func NoteError ¶ added in v1.7.0
NoteError records an error the handler dealt with itself — rendered into a page or turned into a response — so AccessLog reports it on the request's line instead of the handler logging it separately.
func RequestID ¶ added in v1.7.0
RequestID adopts a well-formed inbound X-Request-ID or generates one, echoes it on the response and attaches it to the request's user context.
func Tracing ¶ added in v1.7.0
Tracing starts a root server span per request, named by method and route, and records the HTTP server metrics (duration, sizes, in-flight requests) labelled by method, route and status. Every caller is external — partners, the USSD gateway, browsers — so inbound trace headers are ignored and none are written back. Paths are skipped as in AccessLog.
Types ¶
type AuthMiddleware ¶
type AuthMiddleware struct {
// contains filtered or unexported fields
}
AuthMiddleware handles JWT authentication for protected routes
func NewAuthMiddleware ¶
func NewAuthMiddleware(jwtService *auth.JWTService, config *config.StellarConfig) *AuthMiddleware
NewAuthMiddleware creates a new auth middleware instance
func (*AuthMiddleware) RequireAuth ¶
func (m *AuthMiddleware) RequireAuth() fiber.Handler
RequireAuth is a middleware that validates JWT tokens from cookies
type Response ¶
type Response struct {
// Status is "success" or "error", derived from Code.
Status string `json:"status" example:"success"`
// Code is the HTTP status code of the response.
Code int `json:"code" example:"200"`
// Data is the handler's payload on success, or {"error": ...} on failure.
Data any `json:"data"`
// Message is a human-readable summary of the status code.
Message string `json:"message" example:"Request processed successfully"`
}
Response represents the response format