api

package
v0.0.0-...-c8ae2dd Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: AGPL-3.0 Imports: 52 Imported by: 0

Documentation

Overview

Package api is the HTTP API of the app listener (ADR-0008): the strict server generated from api/openapi.yaml, mounted under /api/v1, behind the middleware of the contract — request metrics, authentication by a bearer token or the session cookie, the CSRF check of the session, request validation and the Permission of each operation's x-permission — with every error answered as an RFC 9457 problem. Handlers are thin: they call the domain packages. An operation that no story has implemented yet answers 501.

Index

Constants

View Source
const BasePath = "/api/v1"

BasePath is where the API is mounted on the app listener.

View Source
const MaxBodyBytes = 1 << 20

MaxBodyBytes bounds the body of an API request on the app listener; a larger one is 413 payload-too-large.

Variables

This section is empty.

Functions

func LoadSpec

func LoadSpec() (*openapi3.T, error)

LoadSpec parses the embedded specification with the app listener's base path as its only server, which is how the router and the request validation match request paths.

Types

type AlertGroups

type AlertGroups interface {
	List(ctx context.Context, r groups.ListRequest) (groups.ListPage, error)
	Counts(ctx context.Context, f groups.Filter) (groups.Counts, error)
	Get(ctx context.Context, publicID string) (groups.View, error)
	Alerts(ctx context.Context, publicID string, f groups.AlertFilter) (groups.AlertPage, error)
	Timeline(ctx context.Context, publicID string, f groups.TimelineFilter) (groups.TimelinePage, error)
	Notes(ctx context.Context, publicID string, after *groups.NotePosition, limit int) (groups.NotePage, error)
	Related(ctx context.Context, publicID string, after *groups.ListPosition, limit int) (groups.RelatedPage, error)
	Statistics(ctx context.Context, r groups.StatisticsRequest) (groups.Statistics, error)
	OpenCounts(ctx context.Context, integrations []string) (map[string]int64, error)
	MoveOpenAlertGroups(ctx context.Context, r groups.Requester, routeID string) (int, error)
}

AlertGroups is what the API needs of internal/groups: the list with its counts, one Alert Group, its Alerts, its Timeline, its Notes and its related Alert Groups, the statistics, the open count of Integrations, and the move of a Route's open Alert Groups to the Default route.

type Alerts

type Alerts interface {
	List(ctx context.Context, f ingest.AlertFilter) (ingest.AlertPage, error)
	Routes(ctx context.Context, integration string) ([]ingest.AlertmanagerRoute, error)
}

Alerts is what the API needs of the Alerts view of internal/ingest and of the learned Alertmanager routes.

type AuditLog

type AuditLog interface {
	List(ctx context.Context, f audit.Filter) (audit.Page, error)
}

AuditLog is what the API needs of the Audit log reader in internal/audit.

type Commands

type Commands interface {
	Acknowledge(ctx context.Context, c groups.Caller, publicID string) (groups.Result, error)
	Unacknowledge(ctx context.Context, c groups.Caller, publicID string) (groups.Result, error)
	Resolve(ctx context.Context, c groups.Caller, publicID string, note *string) (groups.Result, error)
	Unresolve(ctx context.Context, c groups.Caller, publicID string) (groups.Result, error)
	Snooze(ctx context.Context, c groups.Caller, publicID string, end groups.SnoozeEnd) (groups.Result, error)
	Unsnooze(ctx context.Context, c groups.Caller, publicID string) (groups.Result, error)
	AddNote(ctx context.Context, c groups.Caller, publicID, body string) (groups.NoteView, error)
	Bulk(ctx context.Context, c groups.Caller, r groups.BulkRequest) ([]groups.BulkItem, error)
}

Commands is what the API needs of the command layer of internal/groups (ADR-0016): the Commands of C-10, Add Note included, and bulk commands, each checked by the dispatcher, Permission included.

type Config

type Config struct {
	Sessions     Sessions
	Users        Users
	Admin        UserAdmin
	AuditLog     AuditLog
	TOTP         TOTP
	Organization Organization
	Notices      Notices
	Live         Live
	OIDC         OIDC
	Tokens       Tokens
	Integrations Integrations
	Snapshots    StoredSnapshots
	Alerts       Alerts
	Routes       Routes
	AlertGroups  AlertGroups
	Commands     Commands
	Directory    UserDirectory
	Connections  Connections
	Destinations Destinations
	Webhooks     Webhooks
	Deliveries   Deliveries
	Templates    Templates
	Links        Links
	// TrustedProxies are MUSTER_TRUSTED_PROXIES, for the client address.
	TrustedProxies []netip.Prefix
	Log            *logging.Logger
	// Real is the real clock, for the request durations.
	Real clock.Clock
}

Config is what the API serves with.

type Connections

type Connections interface {
	List(ctx context.Context, f connections.ListFilter) (connections.Page, error)
	Get(ctx context.Context, publicID string) (connections.Connection, error)
	Create(ctx context.Context, r connections.Requester, in connections.Input) (connections.Connection, error)
	Update(ctx context.Context, r connections.Requester, publicID string, version *int64, in connections.Input) (
		connections.Connection, error)
	Delete(ctx context.Context, r connections.Requester, publicID string, version *int64) error
	Check(ctx context.Context, publicID string, baseURL *string) (connections.CheckResult, error)
	Channels(ctx context.Context, publicID, teamID, q string) ([]connections.Channel, error)
	CallbackURL(publicID string) string
}

Connections is what the API needs of internal/connections: Mattermost and Telegram Connections, their checks and the channels of a Mattermost one.

type Deliveries

type Deliveries interface {
	States(ctx context.Context, publicID string) ([]delivery.State, error)
}

Deliveries is what the API needs of internal/delivery: the delivery state of an Alert Group per Destination.

type Destinations

type Destinations interface {
	List(ctx context.Context, f destinations.ListFilter) (destinations.Page, error)
	Get(ctx context.Context, publicID string) (destinations.Destination, error)
	RouteRefs(ctx context.Context, routeIDs []int64) (map[int64][]destinations.Ref, error)
	Create(ctx context.Context, r destinations.Requester, in destinations.Input) (destinations.Destination, error)
	Update(ctx context.Context, r destinations.Requester, publicID string, version *int64, in destinations.Input) (
		destinations.Destination, error)
	Check(ctx context.Context, publicID string) (destinations.CheckResult, error)
	Delete(ctx context.Context, r destinations.Requester, publicID string, version *int64) error
}

Destinations is what the API needs of internal/destinations: reading Destinations of every type with their health and Routes, the Destinations of Routes, saving a Destination, its Destination check, and deleting a Destination.

type Integrations

type Integrations interface {
	List(ctx context.Context, f integrations.ListFilter) (integrations.Page, error)
	Get(ctx context.Context, publicID string) (integrations.Integration, error)
	Create(ctx context.Context, r integrations.Requester, in integrations.Input) (integrations.Integration, error)
	Update(ctx context.Context, r integrations.Requester, publicID string, version *int64, in integrations.Input) (
		integrations.Integration, error)
	Delete(ctx context.Context, r integrations.Requester, publicID string, version *int64) error
	ListTokens(ctx context.Context, publicID string) ([]integrations.Token, error)
	CreateToken(ctx context.Context, r integrations.Requester, publicID, name string) (integrations.CreatedToken, error)
	RevokeToken(ctx context.Context, r integrations.Requester, publicID, tokenID string) error
	IngestURL() string
	HeartbeatURL() string
}

Integrations is what the API needs of internal/integrations: Integrations and their tokens.

type Links interface {
	ListTables(ctx context.Context, f links.ListFilter) (links.TablePage, error)
	GetTable(ctx context.Context, publicID string) (links.Table, error)
	CreateTable(ctx context.Context, r links.Requester, in links.TableInput) (links.Table, error)
	UpdateTable(ctx context.Context, r links.Requester, publicID string, version *int64, in links.TableInput) (
		links.Table, error)
	DeleteTable(ctx context.Context, r links.Requester, publicID string, version *int64) error
	ListRules(ctx context.Context, f links.ListFilter) (links.RulePage, error)
	GetRule(ctx context.Context, publicID string) (links.Rule, error)
	CreateRule(ctx context.Context, r links.Requester, in links.RuleInput) (links.Rule, error)
	UpdateRule(ctx context.Context, r links.Requester, publicID string, version *int64, in links.RuleInput) (
		links.Rule, error)
	DeleteRule(ctx context.Context, r links.Requester, publicID string, version *int64) error
}

Links is what the API needs of internal/links: Lookup tables and Link rules.

type Live

type Live interface {
	Subscribe(s live.Subscriber) (*live.Subscription, error)
	Unsubscribe(sub *live.Subscription)
	Stream(ctx context.Context, w io.Writer, flush func() error, sub *live.Subscription) error
}

Live is what the API needs of the live-updates Hub in internal/live.

type Notices

type Notices interface {
	Visible(ctx context.Context, admin bool) ([]organization.Notice, error)
}

Notices is what the API needs of the Organization-wide notices in internal/live.

type OIDC

type OIDC interface {
	Get(ctx context.Context) (oidc.Settings, error)
	Update(ctx context.Context, r oidc.Requester, version *int64, in oidc.Input) (oidc.Settings, error)
	Check(ctx context.Context) (oidc.CheckResult, error)
	SignInOptions(ctx context.Context) (bool, string, error)
	StartSignIn(ctx context.Context, returnTo string) (oidc.Start, error)
	CompleteSignIn(ctx context.Context, cb oidc.Callback) oidc.Outcome
	StartLink(ctx context.Context, sess auth.Session) (oidc.LinkStart, error)
	CompleteLink(ctx context.Context, sess auth.Session, cb oidc.Callback) oidc.Outcome
}

OIDC is what the API needs of internal/oidc.

type Organization

type Organization interface {
	Get(ctx context.Context) (organization.Organization, error)
	Update(ctx context.Context, actor audit.Actor, t audit.Transport, addr netip.Addr, version *int64,
		in organization.Input) (organization.Organization, error)
}

Organization is what the API needs of the organization resource in internal/organization.

type Problem

type Problem struct {
	Status     int
	Type       string
	Code       string
	Detail     string
	Errors     []gen.ProblemError
	RetryAfter int
	// OpenAlertGroupCount is set on route-has-open-alert-groups.
	OpenAlertGroupCount int64
	// RelatedAlertGroup is set on a refusal that names another Alert Group.
	RelatedAlertGroup *gen.AlertGroupRef
	// LinkRules is set on the in_use refusal of a Lookup table: the Link rules that read it.
	LinkRules []gen.EntityRef
}

Problem is an RFC 9457 problem as an error: handlers and middleware return it, and writeProblem answers it.

func (*Problem) Error

func (p *Problem) Error() string

type Routes

type Routes interface {
	List(ctx context.Context) (routing.List, error)
	Get(ctx context.Context, publicID string) (routing.Route, error)
	Create(ctx context.Context, r routing.Requester, in routing.Input) (routing.Route, error)
	Update(ctx context.Context, r routing.Requester, publicID string, version *int64, in routing.Input) (
		routing.Route, error)
	Delete(ctx context.Context, r routing.Requester, publicID string, version *int64) error
	Reorder(ctx context.Context, r routing.Requester, version *int64, ids []string) (routing.List, error)
	Preview(ctx context.Context, req routing.PreviewRequest) (routing.Preview, error)
	Suggestions(ctx context.Context, userID *int64) ([]routing.Suggestion, error)
	AcceptSuggestion(ctx context.Context, r routing.Requester, id string, destinationIDs []string) (routing.Route,
		error)
	DismissSuggestion(ctx context.Context, userID int64, id string) error
}

Routes is what the API needs of internal/routing: Routes and their order, the Group key preview and the Route suggestions.

type Server

type Server struct {
	gen.StrictServerInterface // nil: the operations no story has implemented answer 501 before reaching it
	// contains filtered or unexported fields
}

Server is the API handler.

func New

func New(cfg Config) (*Server, error)

New returns the API handler; it serves every path under BasePath.

func (*Server) AcceptRouteSuggestion

AcceptRouteSuggestion is acceptRouteSuggestion: the suggested Route at the top of the list.

func (*Server) AcknowledgeAlertGroup

AcknowledgeAlertGroup is acknowledgeAlertGroup.

func (*Server) BeginTotpEnrolment

BeginTotpEnrolment is beginTotpEnrolment: a new pending seed, returned once with its otpauth URI (C-03.FR-10).

func (*Server) ChangePassword

ChangePassword is changePassword: it needs the current password and ends the user's other sessions.

func (*Server) CheckConnection

CheckConnection is checkConnection (C-13.FR-2, C-14.FR-11) on the interactive path: the steps with their latency and path — the token of a Mattermost Connection; the dry probe, getMe and getWebhookInfo of a Telegram one, only the dry probe with an unsaved base_url — the bot's name once the token works, a Telegram bot's webhook and pending updates, and the warnings that do not fail the check.

func (*Server) CheckDestination

CheckDestination is checkDestination (C-13.FR-10, C-14.FR-14) on the interactive path: each check with its result, and the health after it; a passing check ends a Broken state.

func (*Server) CheckOidcSettings

CheckOidcSettings is checkOidcSettings: discovery with the saved settings (C-03.FR-8).

CompleteOidcLink is completeOidcLink: the identity provider's redirect back to a link, accepted only in the web session that started it; every outcome is a redirect to the profile, with ?error=<code> after a failure.

func (*Server) CompleteOidcSignIn

CompleteOidcSignIn is completeOidcSignIn: every outcome is a redirect to the SPA — the page of return_to or / with the session cookie, or the sign-in page with the error (C-03.FR-25). The binding cookie is removed either way.

func (*Server) CompletePasswordSetup

CompletePasswordSetup is completePasswordSetup, public: it sets the password from the token of a setup link (C-03.FR-26).

func (*Server) ConfirmTotpEnrolment

ConfirmTotpEnrolment is confirmTotpEnrolment: the first code completes the enrolment and returns the recovery codes, shown once; a session that had to enrol becomes active.

func (*Server) ConvertUserToLocal

ConvertUserToLocal is convertUserToLocal: an Admin converts an account that signs in through OIDC back to local; the identity goes, the sessions end and the answer carries a password setup link (C-03.FR-29).

func (*Server) CreateAlertGroupNote

CreateAlertGroupNote is createAlertGroupNote: the Command Add Note, whose Permission the dispatcher checks.

func (*Server) CreateConnection

CreateConnection is createConnection (C-13.FR-1, C-14.FR-1): a Mattermost or Telegram Connection; the bot token is write-only.

func (*Server) CreateDestination

CreateDestination is createDestination (C-13.FR-2, FR-3, C-14.FR-2): a Mattermost or Telegram Destination, saved once its Destination check passed on the interactive path, or an outgoing webhook.

func (*Server) CreateIntegration

CreateIntegration is createIntegration.

func (*Server) CreateIntegrationToken

CreateIntegrationToken is createIntegrationToken: the value and the Alertmanager snippet, and the Heartbeat snippet while the Integration's Heartbeat is on, shown this once.

func (*Server) CreateLinkRule

CreateLinkRule is createLinkRule: the URL template is dry-run first.

func (*Server) CreateLookupTable

CreateLookupTable is createLookupTable.

CreatePasswordSetupLink is createPasswordSetupLink: a new single-use link that supersedes the user's older ones.

func (*Server) CreatePersonalAccessToken

CreatePersonalAccessToken is createPersonalAccessToken: a token narrowed to Permissions the caller holds now, its value shown this once (C-04.FR-3, FR-7). The middleware lets only the web session through.

func (*Server) CreateRoute

CreateRoute is createRoute: the Route goes before the Default route.

func (*Server) CreateServiceAccount

CreateServiceAccount is createServiceAccount: an active Service account with a Role and no tokens yet.

func (*Server) CreateServiceAccountToken

CreateServiceAccountToken is createServiceAccountToken: a token whose value is shown this once. The middleware lets only the web session through (C-04.FR-7).

func (*Server) CreateSession

CreateSession is createSession: local sign-in (C-03.FR-3, FR-24), with the second factor when the request carries it; a user with TOTP who gives no code gets a session in the state totp_required.

func (*Server) CreateUser

CreateUser is createUser: a local user and the single-use link that sets its first password (C-03.FR-3).

func (*Server) DeleteConnection

DeleteConnection is deleteConnection (C-13.FR-6), with an optional If-Match: refused with in_use while a Destination that is not deleted uses the Connection.

func (*Server) DeleteCurrentSession

DeleteCurrentSession is deleteCurrentSession: sign out.

func (*Server) DeleteDestination

DeleteDestination is deleteDestination (C-11.FR-14), with an optional If-Match: the Destination leaves every Route and every list, its open Root messages get their final edit and its secrets are wiped once they are done.

func (*Server) DeleteDestinationSecret

DeleteDestinationSecret is deleteDestinationSecret (C-15.FR-10).

func (*Server) DeleteIntegration

DeleteIntegration is deleteIntegration: the Integration leaves every list and its tokens stop working at once.

func (*Server) DeleteLinkRule

DeleteLinkRule is deleteLinkRule: the built-in rule answers 409 builtin_immutable.

func (*Server) DeleteLookupTable

DeleteLookupTable is deleteLookupTable: refused with 409 in_use while a Link rule reads the table.

func (*Server) DeleteMySessions

DeleteMySessions is deleteMySessions: sign out everywhere, the current session included.

func (*Server) DeleteRoute

DeleteRoute is deleteRoute: the Route leaves the evaluation order at once; the Default route cannot be deleted.

func (*Server) DeleteServiceAccount

DeleteServiceAccount is deleteServiceAccount: the account goes and its tokens are revoked.

func (*Server) DeleteUser

DeleteUser is deleteUser: pseudonymization (C-03.FR-13), with an optional If-Match.

func (*Server) DisableServiceAccount

DisableServiceAccount is disableServiceAccount: its tokens stop working until it is enabled.

func (*Server) DisableUser

DisableUser is disableUser: the user's sessions end and sign-in is refused until enableUser.

func (*Server) DismissRouteSuggestion

DismissRouteSuggestion is dismissRouteSuggestion: remembered for the calling User, so a Service account is refused.

func (*Server) EnableServiceAccount

EnableServiceAccount is enableServiceAccount: its tokens work again.

func (*Server) EnableUser

EnableUser is enableUser.

func (*Server) GenerateSigningSecret

GenerateSigningSecret is generateSigningSecret (C-15.FR-5): the new Signing secret, shown once; the previous one still signs until it is retired.

func (*Server) GetAlertGroup

GetAlertGroup is getAlertGroup: the Alert Group with its resolution, Owner, Snooze, labels, notices and the Commands the caller may run.

func (*Server) GetAlertGroupCounts

GetAlertGroupCounts is getAlertGroupCounts: the Alert Groups of the list's filters per status tab.

func (*Server) GetAlertGroupStatistics

GetAlertGroupStatistics is getAlertGroupStatistics: per Route or per Integration, totals and days.

func (*Server) GetAlertGroupTimeline

GetAlertGroupTimeline is getAlertGroupTimeline: the entries with the Notes and delivery events merged by time, newest first by default, filtered by kind.

func (*Server) GetConnection

GetConnection is getConnection; a deleted Connection reads as 404.

func (*Server) GetCurrentSession

GetCurrentSession is getCurrentSession: the session in any state, with its CSRF token.

func (*Server) GetDestination

GetDestination is getDestination; a deleted Destination reads as 404.

func (*Server) GetIntegration

GetIntegration is getIntegration.

func (*Server) GetLinkRule

GetLinkRule is getLinkRule.

func (*Server) GetLookupTable

GetLookupTable is getLookupTable.

func (*Server) GetMe

GetMe is getMe: the caller and the effective Permissions (C-03.FR-12).

func (*Server) GetMyTotp

GetMyTotp is getMyTotp: whether the caller has TOTP, waits for a first code, and how many recovery codes remain.

func (*Server) GetOidcSettings

GetOidcSettings is getOidcSettings: the client secret and the proxy password only as their status (C-03.FR-21).

func (*Server) GetOpenApiSpec

GetOpenApiSpec is getOpenApiSpec: the embedded specification, byte for byte (C-03.FR-23).

func (*Server) GetOrganization

GetOrganization is getOrganization: the organization resource for every signed-in identity, its Secrets shown only as set or not (C-03.FR-20, FR-21).

func (*Server) GetRoute

GetRoute is getRoute.

func (*Server) GetServiceAccount

GetServiceAccount is getServiceAccount.

func (*Server) GetSignInOptions

GetSignInOptions is getSignInOptions: public, and says only whether the OIDC button shows and its provider name (C-03.FR-24).

func (*Server) GetSigningSecret

GetSigningSecret is getSigningSecret (C-15.FR-5): the status of the Signing secrets, never a value.

func (*Server) GetStoredSnapshot

GetStoredSnapshot is getStoredSnapshot: the body exactly as received, as text when it is valid UTF-8 and in base64 otherwise.

func (*Server) GetUser

GetUser is getUser, deleted users included.

func (*Server) ListAlertGroupAlerts

ListAlertGroupAlerts is listAlertGroupAlerts: firing Alerts first, then resolved ones with their reason.

func (*Server) ListAlertGroupDeliveries

ListAlertGroupDeliveries is listAlertGroupDeliveries: the delivery state of the Alert Group in each Destination.

func (*Server) ListAlertGroupNotes

ListAlertGroupNotes is listAlertGroupNotes: the Notes in the order they were added, also once the details of the Alert Group were removed.

func (*Server) ListAlertGroups

ListAlertGroups is listAlertGroups: a page of the Alert Group list with its filters, range, search and order.

func (*Server) ListAlertmanagerRoutes

ListAlertmanagerRoutes is listAlertmanagerRoutes: the Alertmanager routes Muster learned for the Integration, with the learned repeat interval, the time to resolve by absence and, above processing.long_repeat_warning, the warning and a recommended route snippet.

func (*Server) ListAuditLog

ListAuditLog is listAuditLog: entries newest first, by cursor, filtered by time range, actor, action and resource (C-03.FR-15). Without from and to there is no time limit.

func (*Server) ListConnectionChannels

ListConnectionChannels is listConnectionChannels: the channels the bot of a Mattermost Connection belongs to, on the interactive path.

func (*Server) ListConnections

ListConnections is listConnections: the Connections that are not deleted, in the order they were created.

func (*Server) ListDestinationSecrets

ListDestinationSecrets is listDestinationSecrets (C-15.FR-10): the names of the Secrets with their status, never a value, and the ETag of the Secrets.

func (*Server) ListDestinations

ListDestinations is listDestinations: Destinations of every type with their health and Routes, filtered by type, health and Route, in pages.

func (*Server) ListIntegrationAlerts

ListIntegrationAlerts is listIntegrationAlerts: the Alerts view of an Integration, filtered by state, Matchers and text, sorted by the last time seen (newest first by default) or startsAt.

func (*Server) ListIntegrationTokens

ListIntegrationTokens is listIntegrationTokens: the tokens that are not revoked, never their values.

func (*Server) ListIntegrations

ListIntegrations is listIntegrations: the Integrations that are not deleted, in the order they were created.

func (*Server) ListLinkRules

ListLinkRules is listLinkRules: the Link rules in the order they were created, the built-in "Explore" first.

func (*Server) ListLookupTables

ListLookupTables is listLookupTables: the Lookup tables with their rows, in the order they were created.

func (*Server) ListMySessions

ListMySessions is listMySessions: the user's sessions, the current one marked.

func (*Server) ListPersonalAccessTokens

ListPersonalAccessTokens is listPersonalAccessTokens: the caller's tokens that are not revoked, without values.

func (*Server) ListRelatedAlertGroups

ListRelatedAlertGroups is listRelatedAlertGroups: the other Alert Groups of the same Route and Group key values, newest first.

func (*Server) ListRoles

ListRoles is listRoles: the three Roles with their Permissions (C-03.FR-2).

func (*Server) ListRouteProfiles

ListRouteProfiles is listRouteProfiles: On-call and Informational, from the built-in defaults.

func (*Server) ListRouteSuggestions

ListRouteSuggestions is listRouteSuggestions: the suggestions that apply and that the calling User has not dismissed; a Service account has no dismissals.

func (*Server) ListRoutes

ListRoutes is listRoutes: every Route in evaluation order, the Default route last, with the list ETag.

func (*Server) ListServiceAccountTokens

ListServiceAccountTokens is listServiceAccountTokens: the tokens that are not revoked, without values.

func (*Server) ListServiceAccounts

ListServiceAccounts is listServiceAccounts: the Service accounts that are not deleted, in the order they were created.

func (*Server) ListStoredSnapshots

ListStoredSnapshots is listStoredSnapshots: the Stored Snapshots of an Integration, a deleted one included, newest first, never older than retention.stored_snapshots.

func (*Server) ListSystemNotices

ListSystemNotices is listSystemNotices: the active Organization-wide notices (C-03.FR-18, C-02.FR-24) — "recovering after downtime" for every signed-in identity, "no replica is leading" only for one that holds system-status:read.

func (*Server) ListUserDirectory

ListUserDirectory is listUserDirectory: every user, deleted ones as deactivated, with only their name and login, for everyone who reads Alert Groups.

func (*Server) ListUsers

ListUsers is listUsers: users in the order of their name, with the filters q, role, status and source.

func (*Server) MoveOpenAlertGroups

MoveOpenAlertGroups is moveOpenAlertGroups: the open Alert Groups of the Route move to the Default route, after which the Route can be deleted.

func (*Server) PreviewGroupKey

PreviewGroupKey is previewGroupKey: how the Stored Snapshots of the period group with the current and the proposed Group key.

func (*Server) PreviewTemplate

PreviewTemplate is previewTemplate: a template rendered in the sandbox against its sample. A template that fails answers 200 with valid false and its errors, never a Problem.

func (*Server) RegenerateTotpRecoveryCodes

RegenerateTotpRecoveryCodes is regenerateTotpRecoveryCodes: a current code replaces the unused recovery codes.

func (*Server) RemoveTotp

RemoveTotp is removeTotp: the current password, a current code or a recovery code removes the caller's TOTP (C-03.FR-27); a wrong proof is 401 and changes nothing, and a user without TOTP gets 404.

func (*Server) ReorderRoutes

ReorderRoutes is reorderRoutes: If-Match carries the list ETag of listRoutes.

func (*Server) ResetUserTotp

ResetUserTotp is resetUserTotp: an Admin removes a user's TOTP and recovery codes, which ends the user's sessions and is recorded in the Audit log (C-03.FR-11).

func (*Server) ResolveAlertGroup

ResolveAlertGroup is resolveAlertGroup, with an optional Note that the command layer records after the resolve.

func (*Server) RetirePreviousSigningSecret

RetirePreviousSigningSecret is retirePreviousSigningSecret (C-15.FR-5): the previous Signing secret signs no more.

func (*Server) RevokeIntegrationToken

RevokeIntegrationToken is revokeIntegrationToken: the token answers 401 from the next request.

func (*Server) RevokePersonalAccessToken

RevokePersonalAccessToken is revokePersonalAccessToken: the caller's token stops working at once.

func (*Server) RevokeServiceAccountToken

RevokeServiceAccountToken is revokeServiceAccountToken: the token stops working at once.

func (*Server) RunBulkCommand

RunBulkCommand is runBulkCommand: one outcome per Alert Group, in the order of the request.

func (*Server) ServeHTTP

func (s *Server) ServeHTTP(w http.ResponseWriter, r *http.Request)

ServeHTTP is the middleware chain of the API, in the order of the contract: security headers, request metrics, authentication, the CSRF check, request validation, the Permission of the operation, then the handler.

func (*Server) SetDestinationSecret

SetDestinationSecret is setDestinationSecret (C-15.FR-10): the value is write-only; the answer is its status.

func (*Server) SnoozeAlertGroup

SnoozeAlertGroup is snoozeAlertGroup: the request names until or no_end, which the command layer checks.

StartOidcLink is startOidcLink: the authorization URL of a link of the caller's account to an identity at the identity provider, bound to this web session (C-03.FR-29).

func (*Server) StartOidcSignIn

StartOidcSignIn is startOidcSignIn: the redirect to the identity provider with PKCE S256, state and nonce (C-03.FR-25), and the cookie that binds the callback to this browser. return_to is kept only when it is a relative path. A failed discovery sends the browser to the sign-in page with idp_error.

func (*Server) StreamLiveUpdates

StreamLiveUpdates is streamLiveUpdates: the server-sent events stream of change hints (C-09.FR-25, ADR-0009). It lasts until the client goes, the session ends or the server shuts down; the reconnect of an ended session gets 401.

func (*Server) SubmitSessionTotp

SubmitSessionTotp is submitSessionTotp: a TOTP code or a recovery code completes a session in the state totp_required (C-03.FR-24, AC-13).

func (*Server) UnacknowledgeAlertGroup

UnacknowledgeAlertGroup is unacknowledgeAlertGroup.

func (*Server) UnresolveAlertGroup

UnresolveAlertGroup is unresolveAlertGroup.

func (*Server) UnsnoozeAlertGroup

UnsnoozeAlertGroup is unsnoozeAlertGroup.

func (*Server) UpdateConnection

UpdateConnection is updateConnection, with If-Match; an omitted bot token keeps the stored one.

func (*Server) UpdateDestination

UpdateDestination is updateDestination, with If-Match: saving a Mattermost or Telegram Destination runs its Destination check as createDestination does.

func (*Server) UpdateIntegration

UpdateIntegration is updateIntegration, with If-Match.

func (*Server) UpdateLinkRule

UpdateLinkRule is updateLinkRule, with If-Match: the built-in rule keeps its name and scope.

func (*Server) UpdateLookupTable

UpdateLookupTable is updateLookupTable, with If-Match: the rows replace the stored ones as a whole.

func (*Server) UpdateMe

UpdateMe is updateMe: the name, the time zone and the language. An omitted time zone or language keeps its value and null clears it, so that it follows the browser.

func (*Server) UpdateOidcSettings

UpdateOidcSettings is updateOidcSettings, with If-Match: omitted optional fields keep their value, and the Secrets follow the rule of every Secret field.

func (*Server) UpdateOrganization

UpdateOrganization is updateOrganization with If-Match: in this release it changes the TOTP policy, and a changed value of any other field is 422 with unsupported at that field (C-03.FR-20).

func (*Server) UpdateRoute

UpdateRoute is updateRoute, with If-Match; it applies to the next Alerts routed.

func (*Server) UpdateServiceAccount

UpdateServiceAccount is updateServiceAccount: the name and the Role, with If-Match.

func (*Server) UpdateUser

UpdateUser is updateUser: name, email and Role, with If-Match. An omitted email keeps its value and null clears it; a Role change ends the user's sessions.

type Sessions

type Sessions interface {
	SignIn(ctx context.Context, req auth.SignInRequest) (auth.Session, error)
	Authenticate(ctx context.Context, cookie string) (auth.Session, error)
	Permissions(sess auth.Session) []auth.Permission
	CSRFToken(sess auth.Session) (string, error)
	CheckCSRF(sess auth.Session, header string) bool
	SignOut(ctx context.Context, sess auth.Session, addr netip.Addr) error
	SignOutEverywhere(ctx context.Context, sess auth.Session, addr netip.Addr) error
	ListSessions(ctx context.Context, sess auth.Session) ([]auth.SessionInfo, error)
	SubmitSecondFactor(ctx context.Context, sess auth.Session, p auth.Proof, addr netip.Addr) (auth.Session, error)
	ChangePassword(ctx context.Context, sess auth.Session, c auth.PasswordChange) error
	Roles() auth.Roles
}

Sessions is what the API needs of internal/auth.

type StoredSnapshots

type StoredSnapshots interface {
	List(ctx context.Context, f ingest.ListFilter) (ingest.Page, error)
	Get(ctx context.Context, publicID string) (ingest.Snapshot, error)
}

StoredSnapshots is what the API needs of the Stored Snapshot reads of internal/ingest.

type TOTP

type TOTP interface {
	Status(ctx context.Context, userID int64) (totp.Status, error)
	Begin(ctx context.Context, sess auth.Session) (totp.Enrolment, error)
	Confirm(ctx context.Context, sess auth.Session, code string, addr netip.Addr) ([]string, error)
	RegenerateRecoveryCodes(ctx context.Context, sess auth.Session, code string, addr netip.Addr) ([]string, error)
	Remove(ctx context.Context, sess auth.Session, p totp.Removal, addr netip.Addr) error
	Reset(ctx context.Context, actor audit.Actor, t audit.Transport, addr netip.Addr, publicID string) error
}

TOTP is what the API needs of internal/totp.

type Templates

type Templates interface {
	Preview(ctx context.Context, req messages.PreviewRequest) (messages.PreviewResult, error)
}

Templates previews templates (C-12.FR-5); *messages.Renderer implements it.

type Tokens

type Tokens interface {
	Authenticate(ctx context.Context, value string, addr netip.Addr) (*auth.Identity, error)
	ListPersonal(ctx context.Context, ownerID int64) ([]tokens.Token, error)
	CreatePersonal(ctx context.Context, r tokens.Requester, owner tokens.Owner, held []auth.Permission,
		n tokens.NewPersonal) (tokens.Created, error)
	RevokePersonal(ctx context.Context, r tokens.Requester, owner tokens.Owner, publicID string) error
	ListServiceAccounts(ctx context.Context, f tokens.ListFilter) (tokens.Page, error)
	GetServiceAccount(ctx context.Context, publicID string) (tokens.ServiceAccount, error)
	CreateServiceAccount(ctx context.Context, r tokens.Requester, in tokens.ServiceAccountInput) (tokens.ServiceAccount,
		error)
	UpdateServiceAccount(ctx context.Context, r tokens.Requester, publicID string, version *int64,
		in tokens.ServiceAccountInput) (tokens.ServiceAccount, error)
	DisableServiceAccount(ctx context.Context, r tokens.Requester, publicID string) (tokens.ServiceAccount, error)
	EnableServiceAccount(ctx context.Context, r tokens.Requester, publicID string) (tokens.ServiceAccount, error)
	DeleteServiceAccount(ctx context.Context, r tokens.Requester, publicID string, version *int64) error
	ListServiceAccountTokens(ctx context.Context, publicID string) ([]tokens.Token, error)
	CreateServiceAccountToken(ctx context.Context, r tokens.Requester, publicID string, n tokens.NewToken) (
		tokens.Created, error)
	RevokeServiceAccountToken(ctx context.Context, r tokens.Requester, publicID, tokenID string) error
}

Tokens is what the API needs of internal/tokens: bearer authentication, Personal access tokens and Service accounts.

type UserAdmin

type UserAdmin interface {
	List(ctx context.Context, f users.ListFilter) (users.Page, error)
	Get(ctx context.Context, id string) (users.User, error)
	Create(ctx context.Context, r users.Requester, n users.NewUser) (users.User, users.SetupLink, error)
	Update(ctx context.Context, r users.Requester, id string, version *int64, c users.Changes) (users.User, error)
	Disable(ctx context.Context, r users.Requester, id string) (users.User, error)
	Enable(ctx context.Context, r users.Requester, id string) (users.User, error)
	Delete(ctx context.Context, r users.Requester, id string, version *int64) error
	CreateSetupLink(ctx context.Context, r users.Requester, id string) (users.SetupLink, error)
	ConvertToLocal(ctx context.Context, r users.Requester, id string) (users.User, users.SetupLink, error)
	CompleteSetup(ctx context.Context, token, password string, addr netip.Addr) error
}

UserAdmin is what the API needs of the administration of users in internal/users.

type UserDirectory

type UserDirectory interface {
	List(ctx context.Context, q string, after *users.Cursor, limit int) (users.DirectoryPage, error)
}

UserDirectory is what the API needs of the user directory in internal/users.

type Users

type Users interface {
	Get(ctx context.Context, id int64) (users.User, error)
	UpdateProfile(ctx context.Context, id int64, actor audit.Actor, p users.Profile, addr netip.Addr) (users.User, error)
}

Users is what the API needs of internal/users.

type Webhooks

type Webhooks interface {
	ListSecrets(ctx context.Context, publicID string) (webhooks.Secrets, error)
	SetSecret(ctx context.Context, r webhooks.Requester, publicID string, version *int64, name string,
		value logging.Secret) (webhooks.Secret, int64, error)
	DeleteSecret(ctx context.Context, r webhooks.Requester, publicID string, version *int64, name string) error
	SigningStatus(ctx context.Context, publicID string) (webhooks.SigningStatus, error)
	GenerateSigningSecret(ctx context.Context, r webhooks.Requester, publicID string) (logging.Secret,
		webhooks.SigningStatus, error)
	RetirePreviousSigningSecret(ctx context.Context, r webhooks.Requester, publicID string) error
}

Webhooks is what the API needs of internal/webhooks: the Secrets and the Signing secrets of outgoing webhook Destinations.

Directories

Path Synopsis
Package gen provides primitives to interact with the openapi HTTP API.
Package gen provides primitives to interact with the openapi HTTP API.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL