Documentation
¶
Index ¶
- Constants
- Variables
- func AdjustTimeFromSecToMilli(timeStr string, offsetMs int) string
- func AppendWebConfigCookie(setCookie func(name, value string)) error
- func CopyFile(dest string, src string)
- func DecodeBase64(s string) string
- func DeleteVal(values []string, val string) []string
- func DownloadFile(url string) (*bytes.Buffer, error)
- func EnsureFileFolderExists(path string)
- func EnsureFolderExists(path string)
- func Fetchable(raw string) error
- func FileExist(path string) bool
- func FilterField(field string) bool
- func FilterQuery(urlString string, blackList []string) string
- func GetChatFromProvider(owner, name string) string
- func GetCurrentTime() string
- func GetCurrentTimeBasedOnLastMilli(timestamp string) string
- func GetCurrentTimeEx(timestamp string) string
- func GetCurrentTimeWithMilli() string
- func GetCurrentUnixTime() int64
- func GetDescFromIP(ip string) string
- func GetDescFromUserAgent(userAgent string) string
- func GetFieldFromJsonString(jsonStr string, fieldName string) (string, error)
- func GetIPInfo(clientIP string) string
- func GetId(owner, name string) string
- func GetIdFromOwnerAndName(owner string, name string) string
- func GetLocalIPAddresses() ([]string, error)
- func GetOwnerAndNameFromIdNoCheck(id string) (string, string)
- func GetOwnerAndNameFromIdWithError(id string) (string, string, error)
- func GetPath(path string) string
- func GetRandomName() string
- func GetRandomString(length int) string
- func GetTimeAgo(d time.Duration) string
- func GetUploadXlsxPath(fileId string) string
- func Init(dataFile string) (err error)
- func InitIpDb()
- func InitMaxmindDb() error
- func InitMaxmindFiles()
- func IsAdmin(user *iam.User) bool
- func IsAnonymousUser(user *iam.User) bool
- func IsAnonymousUserByUsername(username string) bool
- func IsIPAddress(target string) bool
- func IsInternetIp(ip string) bool
- func IsLocalhostTarget(target string) bool
- func IsSuperAdmin(user *iam.User) bool
- func IsVideoNormalUser(user *iam.User) bool
- func JsonToStruct(data string, v any) error
- func MatchTargetWithMachine(target, hostname string) (bool, error)
- func ParseFloat(s string) float64
- func ParseInt(s string) int
- func ParseIntWithError(s string) (int, error)
- func ReadStringFromPath(path string) string
- func RemoveExt(filename string) string
- func ScopeOwner(callerOrg, requested string) string
- func SnakeString(s string) string
- func StopOldInstance(port int) error
- func StructToJson(v any) string
- func StructToJsonNoIndent(v any) string
- func WriteBytesToPath(b []byte, path string) error
- func WriteStringToPath(s string, path string)
- type BillingQueue
- type BillingRecord
- type LocationInfo
- type Locator
- type Paginator
- type SystemInfo
- type VersionInfo
Constants ¶
const ( UserTypeChatAdmin = "chat-admin" UserTypeVideoNormalUser = "video-normal-user" )
const AdminOrg = "admin"
AdminOrg is the reserved IAM organization whose members are Hanzo SUPER admins (platform / cross-tenant). Membership in this ONE org — not a configurable list, not a "built-in" org — is the SOLE definition of super admin across the stack. It matches IAM's conf.AdminOrg (user.IsGlobalAdmin: owner == AdminOrg) and the console super-admin gate (isSuperAdminAccount: owner == 'admin'). It is deliberately NOT a TENANT org: a hanzo-org admin (e.g. hanzo/z) is an org admin, not a super admin, and must not read/modify platform provider config (upstream API keys) or cross-tenant data.
const Null = "N/A"
Variables ¶
var (
ErrInvalidIp = errors.New("invalid IP format")
)
var (
MaxmindDownloadInProgress bool
)
var ReFieldWhiteList *regexp.Regexp
Functions ¶
func AppendWebConfigCookie ¶
func DecodeBase64 ¶
DecodeBase64 reads base64, and answers the empty string for anything that is not. Its callers decode a field out of an upstream reply and hand the result straight to JsonToStruct, which already reports what it cannot read — so a malformed reply is that call failing rather than the request dying.
func EnsureFileFolderExists ¶
func EnsureFileFolderExists(path string)
func EnsureFolderExists ¶
func EnsureFolderExists(path string)
func Fetchable ¶ added in v1.833.153
Fetchable answers whether a document address that arrived on a request may be fetched, and says why when it may not.
Two things separate such an address from one this system produced for itself. It has to name a place rather than a path: readers that take a URL treat a scheme-less string as a local file, so "/etc/passwd" and "../config" are addresses of THIS MACHINE'S disk written in the same field. And the place has to be somewhere outside — a private, loopback or link-local address is this deployment's own neighbours, which a request can name but has no business reading through us.
Storage URLs the system minted for itself do not come this way; this is for the values a person can type.
func FilterField ¶
func FilterQuery ¶
func GetChatFromProvider ¶
func GetCurrentTime ¶
func GetCurrentTime() string
func GetCurrentTimeBasedOnLastMilli ¶
GetCurrentTimeBasedOnLastMilli answers now, but never at or before timestamp, which is how a batch of records gets distinct times in the order it was given. A timestamp it cannot read is not a lower bound; the answer is now.
func GetCurrentTimeEx ¶
GetCurrentTimeEx answers now, but never at or before timestamp — it is what keeps the messages of one chat in the order they were written.
A timestamp it cannot read is simply not a lower bound, so the answer is now. Its callers pass a stored row's CreatedTime, and a row written before that field existed carries the empty string: panicking made every answer in such a chat fail on a field nobody is looking at.
func GetCurrentTimeWithMilli ¶
func GetCurrentTimeWithMilli() string
func GetCurrentUnixTime ¶
func GetCurrentUnixTime() int64
GetCurrentUnixTime returns the current Unix timestamp in seconds
func GetDescFromIP ¶
GetDescFromIP returns a string description of an IP address
func GetDescFromUserAgent ¶
GetDescFromUserAgent renders a user agent as "browser | os | device".
An agent it cannot read is not worth a panic on the request that carried it: the description is a nicety beside whatever the caller actually asked for, so an unbuildable parser yields no description and nothing else changes.
func GetFieldFromJsonString ¶
func GetIdFromOwnerAndName ¶
func GetLocalIPAddresses ¶
GetLocalIPAddresses returns all non-loopback IP addresses of the local machine Returns both IPv4 and IPv6 addresses
func GetOwnerAndNameFromIdNoCheck ¶
GetOwnerAndNameFromIdNoCheck splits an id at its FIRST slash, so a name may itself contain slashes — which is what "no check" means here and why the checked form is not a drop-in for it.
It used to index the second half unconditionally. An id carrying no slash yields one piece, so that read was out of range, and the id arrives on a query parameter: GET /v1/ai/get-file?id=x panicked, and the router turned it into a 500 with a stack trace where a malformed id deserves an answer. An id that names no name now names none, and the read below it finds nothing.
func GetRandomName ¶
func GetRandomName() string
func GetRandomString ¶
func GetTimeAgo ¶ added in v1.832.32
GetTimeAgo renders the instant d before now in the SAME format as GetCurrentTime. A stored timestamp is compared against a cutoff as a STRING — that is what the database does with these columns — so the two have to be formatted identically or the comparison means nothing.
func GetUploadXlsxPath ¶
func InitMaxmindDb ¶
func InitMaxmindDb() error
InitMaxmindDb initializes the MaxMind GeoIP2 databases
func InitMaxmindFiles ¶
func InitMaxmindFiles()
InitMaxmindFiles checks if MaxMind database files exist and downloads them if needed
func IsAdmin ¶
IsAdmin checks if the user is an ORG-level admin (or a chat-admin). This is org-scoped: it is true for the admin/owner of ANY org (e.g. a customer org owner). It must NOT be used to gate platform-wide operations — see IsSuperAdmin for that.
func IsAnonymousUser ¶ added in v1.803.1
IsAnonymousUser reports whether a resolved user is an anonymous guest — the synthesized u-<hash> record from anonymousSignin. It is the ONE canonical anonymity predicate: a guest is stamped BOTH with Type "anonymous-user" and a u-<hash> username, and either signal alone is authoritative (a session copy or a JWT claim may carry one without the other). A nil user is NOT anonymous — absence of a user is a distinct "unauthenticated" state its callers handle.
func IsIPAddress ¶
IsIPAddress checks if a string is a valid IP address (not a hostname)
func IsInternetIp ¶
func IsLocalhostTarget ¶
IsLocalhostTarget checks if a target is localhost or a loopback IP (127.0.0.1, ::1, etc.)
func IsSuperAdmin ¶ added in v1.804.0
IsSuperAdmin reports whether the user is a Hanzo SUPER admin: a member of the reserved `admin` org (AdminOrg). This is the ONE super-admin predicate — no configurable org list, no "built-in" org, no isAdmin flag: membership in the admin org alone is authoritative, matching IAM's user.IsGlobalAdmin (owner == conf.AdminOrg) and the console isSuperAdminAccount gate. It is strictly narrower than IsAdmin — a tenant-org owner (hanzo/z, maxpower/dave), even one who is isAdmin of their OWN org, is NEVER a super admin. Platform-wide AI ops (provider/upstream-key config, cross-tenant reads, topology disclosure) require this.
func IsVideoNormalUser ¶
IsVideoNormalUser checks if the user has the video-normal-user role
func JsonToStruct ¶
func MatchTargetWithMachine ¶
MatchTargetWithMachine checks if a scan target matches the current machine based on hostname or IP addresses
func ParseFloat ¶
ParseFloat reads a number, and answers 0 for anything that is not one — the same answer ParseInt gives, for the same reason.
Its call sites read the start and end of a subtitle out of a speech service's reply. A field that is not a number there is that service having a bad day, and a timing of zero is a subtitle that starts at the beginning; a panic is the whole upload failing on somebody else's JSON.
func ParseInt ¶
ParseInt reads a whole number, and answers 0 for anything that is not one.
It used to panic, and it is read from REQUEST INPUT at most of its call sites — pageSize, p, limit — so "?pageSize=abc" was a panic recovered into a 500 with a stack trace, on every paged listing in the module. A value that is not a number is not a page size.
0 is the right answer because 0 is what every caller here already handles: NewPaginator reads a size of zero or less as "use the default", and paginationOffset floors a negative offset at zero. Nothing downstream had to change to stop crashing.
func ParseIntWithError ¶
func ReadStringFromPath ¶
func ScopeOwner ¶ added in v1.833.129
ScopeOwner answers WHICH ORG a request acts on: the one it asked for when the caller is entitled to ask, and the caller's own otherwise.
The entitlement is membership of the reserved org and nothing else, which is the same predicate IsSuperAdmin reads — a tenant's own admin administers that tenant and may not name another. An owner arriving on a request is therefore a REQUEST rather than a fact, and this is where it stops being one.
It takes the two values it needs and no more. How the caller was resolved, where the requested owner arrived — a body, a query, a path — and what a refusal should look like are each the caller's own business; five groups had written this rule out five times to keep those differences local, and had already drifted on whether the reserved org is spelled by its constant. One rule, one place; the shapes around it stay where they are.
func SnakeString ¶
SnakeString transform XxYy to xx_yy
The output names a SQL column (see the ORDER BY and LIKE call sites in object/), so it is schema, not cosmetics. Two rules are load-bearing and both have a test in string_test.go:
- Every capital gets its own separator, acronyms included: "OrgID" is "org_i_d", not "org_id". That is how the live columns were named.
- A leading underscore already separates, so no second one is emitted: "_Foo" is "_foo", not "__foo".
func StopOldInstance ¶
func StructToJson ¶
func StructToJsonNoIndent ¶
func WriteBytesToPath ¶
func WriteStringToPath ¶
Types ¶
type BillingQueue ¶
type BillingQueue struct {
// contains filtered or unexported fields
}
BillingQueue is a buffered, retrying usage record delivery queue. Records are enqueued without blocking the HTTP handler. Background workers drain the queue and POST each record to Commerce with exponential backoff.
func NewBillingQueue ¶
func NewBillingQueue(endpoint, token string) *BillingQueue
NewBillingQueue creates and starts a billing queue. The endpoint and token are resolved once at startup; if the Commerce endpoint is reconfigured at runtime the process must be restarted (consistent with how other config values are used in cloud).
func (*BillingQueue) Enqueue ¶
func (q *BillingQueue) Enqueue(record *BillingRecord)
Enqueue adds a billing record to the delivery queue. If the queue is full, the record is dropped and an error is logged. This never blocks the caller.
func (*BillingQueue) Shutdown ¶
func (q *BillingQueue) Shutdown() int
Shutdown signals workers to finish and waits for the queue to drain (up to billingShutdownTimeout). Returns the number of records that were still pending when the timeout expired.
type BillingRecord ¶
type BillingRecord struct {
Body []byte // JSON payload, serialized by the caller
RequestID string // for structured logging on failure
Org string // IAM org slug — billing key + X-Org-Id namespace scope
Model string // model name for structured logging
}
BillingRecord holds a pre-serialized usage record ready for HTTP delivery. Controllers serialize once; the queue retries with the same payload bytes.
type LocationInfo ¶
func Find ¶
func Find(ipstr string) (*LocationInfo, error)
Find locationInfo by ip string It will return err when ipstr is not a valid format
func FindMaxmind ¶
func FindMaxmind(ipstr string) (*LocationInfo, error)
FindMaxmind looks up IP information using MaxMind GeoIP2
func GetInfoFromIP ¶
func GetInfoFromIP(ip string) (*LocationInfo, error)
type Locator ¶
type Locator struct {
// contains filtered or unexported fields
}
func NewLocator ¶
New locator with dataFile
func (*Locator) Find ¶
func (loc *Locator) Find(ipstr string) (info *LocationInfo, err error)
Find locationInfo by ip string It will return err when ipstr is not a valid format
func (*Locator) FindByUint ¶
func (loc *Locator) FindByUint(ip uint32) (info *LocationInfo)
Find locationInfo by uint32
type Paginator ¶ added in v1.822.0
type Paginator struct {
// contains filtered or unexported fields
}
Paginator turns the "p" page-number query parameter plus a page size and a known total count into the offset for an offset-based list query. It reads the same "p" parameter and computes the same offset as the historical list handlers.
func NewPaginator ¶ added in v1.822.0
NewPaginator builds a Paginator over the requested page, a page size and a total count. A per of zero or less defaults to 10.
The page arrives as a number rather than a request: reading "p" is the caller's job, and it was the only thing this ever wanted a request for.
type SystemInfo ¶
type SystemInfo struct {
CpuUsage []float64 `json:"cpuUsage"`
MemoryUsed uint64 `json:"memoryUsed"`
MemoryTotal uint64 `json:"memoryTotal"`
DiskUsed uint64 `json:"diskUsed"`
DiskTotal uint64 `json:"diskTotal"`
NetworkSent uint64 `json:"networkSent"`
NetworkRecv uint64 `json:"networkRecv"`
NetworkTotal uint64 `json:"networkTotal"`
}
func GetSystemInfo ¶
func GetSystemInfo() (*SystemInfo, error)
type VersionInfo ¶
type VersionInfo struct {
Version string `json:"version"`
CommitId string `json:"commitId"`
CommitOffset int `json:"commitOffset"`
}
func GetVersionInfo ¶
func GetVersionInfo() (*VersionInfo, error)
GetVersionInfo get git current commit and repo release version GetVersionInfo reports the version of the RUNNING binary.
Read ONCE. Answering it means opening the repository, resolving every tag to a revision and then walking the commit log to count the offset — measured on this repo, 410 tags and 2,759 commits, at ~1.3s. That was paid per request on /v1/ai/version, which is a second and a third of work to answer a question whose answer cannot change: the binary serving the request was built from one commit and will not be rebuilt while it runs.
It also cost a test. fiber's Test() allows one second, so the handler sat just the wrong side of the budget and passed or failed on how warm the page cache was and how many other packages were compiling at the time — TestWiredResourceRouteDispatches, reported against GET /v1/ai/version, which was the honest address of the fault all along.
func GetVersionInfoFromFile ¶
func GetVersionInfoFromFile() (*VersionInfo, error)