middleware

package
v1.7.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: AGPL-3.0 Imports: 21 Imported by: 0

Documentation

Overview

Package middleware holds the Fiber middleware that wraps the HTTP layer: authentication, a uniform response envelope, and the standard cross-cutting stack every request passes through.

Authentication

AuthMiddleware guards the admin routes. RequireAuth reads the JWT from the admin_token cookie, validates it, and confirms its claims name the configured admin — a missing, invalid, or wrong-admin token is rejected and the cookie cleared. When a valid token is inside its refresh window the middleware mints a fresh one and resets the cookie, giving the admin a sliding session. The cookie is HTTP-only, Secure, and SameSite=Strict. Validated claims are stashed in the request context under AdminClaimsKey; downstream handlers read them with GetAdminClaims.

Response envelope

FormatResponse gives every endpoint the same JSON shape — status, code, data, and message. Handlers don't write the body themselves: they put their result in the data local or, on failure, return a Fiber error and set the error local. The middleware reads whichever is present, derives the HTTP status and a human-readable message, and marks the envelope success or error.

Cross-cutting stack

FiberMiddleware registers the rest in one call: security headers (helmet), panic recovery, CORS with credentials, a request rate limiter, and a favicon handler, behind RequestID, Tracing and AccessLog. RequestID attaches a request ID to the user context so every *Context log call below it carries the ID; Tracing starts the request's server span; AccessLog writes one structured line per request, carrying both. It also mounts the /health and /ready endpoints backed by the health checker.

Index

Constants

View Source
const AdminClaimsKey = "admin_claims"
View Source
const RequestIDHeader = "X-Request-ID"

RequestIDHeader carries the request ID in and out.

Variables

This section is empty.

Functions

func AccessLog added in v1.7.0

func AccessLog(logger *slog.Logger, skip ...string) fiber.Handler

AccessLog logs one line per request after the handler chain and the app's error handler have run, with the error recorded by NoteError or, failing that, the one the chain returned. The noted error wins because handlers usually replace the cause with a generic HTTP error. A request with an error and a non-5xx status logs at warn. A path equal to an entry in skip is not logged; an entry ending in "/" skips every path under it.

func ClientIP added in v1.7.0

func ClientIP(c *fiber.Ctx) string

ClientIP returns the TCP peer address, or the rightmost X-Forwarded-For hop when the peer is a configured trusted proxy. Unparseable hops fall back to the peer.

func FiberMiddleware

func FiberMiddleware(a *fiber.App, healthChecker *health.Checker, logger *slog.Logger)

FiberMiddleware provide Fiber's built-in middlewares. See: https://docs.gofiber.io/api/middleware

func FormatResponse

func FormatResponse() fiber.Handler

FormatResponse middleware formats the response to a standard format.

func GetAdminClaims

func GetAdminClaims(c *fiber.Ctx) *auth.Claims

GetAdminClaims retrieves admin claims from the Fiber context

func NoteError added in v1.7.0

func NoteError(c *fiber.Ctx, err error)

NoteError records an error the handler dealt with itself — rendered into a page or turned into a response — so AccessLog reports it on the request's line instead of the handler logging it separately.

func RequestID added in v1.7.0

func RequestID() fiber.Handler

RequestID adopts a well-formed inbound X-Request-ID or generates one, echoes it on the response and attaches it to the request's user context.

func Tracing added in v1.7.0

func Tracing(skip ...string) fiber.Handler

Tracing starts a root server span per request, named by method and route, and records the HTTP server metrics (duration, sizes, in-flight requests) labelled by method, route and status. Every caller is external — partners, the USSD gateway, browsers — so inbound trace headers are ignored and none are written back. Paths are skipped as in AccessLog.

Types

type AuthMiddleware

type AuthMiddleware struct {
	// contains filtered or unexported fields
}

AuthMiddleware handles JWT authentication for protected routes

func NewAuthMiddleware

func NewAuthMiddleware(jwtService *auth.JWTService, config *config.StellarConfig) *AuthMiddleware

NewAuthMiddleware creates a new auth middleware instance

func (*AuthMiddleware) RequireAuth

func (m *AuthMiddleware) RequireAuth() fiber.Handler

RequireAuth is a middleware that validates JWT tokens from cookies

type Response

type Response struct {
	// Status is "success" or "error", derived from Code.
	Status string `json:"status" example:"success"`
	// Code is the HTTP status code of the response.
	Code int `json:"code" example:"200"`
	// Data is the handler's payload on success, or {"error": ...} on failure.
	Data any `json:"data"`
	// Message is a human-readable summary of the status code.
	Message string `json:"message" example:"Request processed successfully"`
}

Response represents the response format

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL