v1

package
v0.31.0-rc.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 15, 2026 License: MIT Imports: 78 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// DefaultUploadSizeLimitBytes applies when no upload size limit is configured.
	DefaultUploadSizeLimitBytes = 32 << 20
	MebiByte                    = 1024 * 1024
)
View Source
const (
	// DefaultPageSize is the default page size for requests.
	DefaultPageSize = 50
	// MaxPageSize is the maximum page size for requests.
	MaxPageSize = 1000
)
View Source
const (
	InstanceSettingNamePrefix  = "instance/settings/"
	UserNamePrefix             = "users/"
	MemoNamePrefix             = "memos/"
	MemoShareNamePrefix        = "shares/"
	AttachmentNamePrefix       = "attachments/"
	ReactionNamePrefix         = "reactions/"
	InboxNamePrefix            = "inboxes/"
	IdentityProviderNamePrefix = "identity-providers/"
	WebhookNamePrefix          = "webhooks/"
	SpaceNamePrefix            = "spaces/"
	SpaceMemberNamePrefix      = "members/"
	SpaceInvitationNamePrefix  = "invitations/"
)
View Source
const MaxAPIRequestBytes = 256 << 20

MaxAPIRequestBytes caps the size of a request body accepted by the API. The in-process MCP endpoint forwards every tool call through these same routes, so it derives its own limit from this constant to keep the two gates in lockstep.

Variables

View Source
var AuthBootstrapMethods = map[string]struct{}{

	"/memos.api.v1.AuthService/SignIn":       {},
	"/memos.api.v1.AuthService/RefreshToken": {},

	"/memos.api.v1.InstanceService/GetInstanceProfile":       {},
	"/memos.api.v1.InstanceService/GetInstanceSetting":       {},
	"/memos.api.v1.InstanceService/BatchGetInstanceSettings": {},

	"/memos.api.v1.IdentityProviderService/ListIdentityProviders": {},

	"/memos.api.v1.UserService/CreateUser": {},

	"/memos.api.v1.MemoService/GetSharedMemo": {},
}

AuthBootstrapMethods is the subset of PublicMethods that stays reachable by anonymous callers even when the instance access mode is PRIVATE.

It is the minimum required to render the sign-in page, authenticate, and follow share links, and register when instance settings permit it. Every entry here MUST also exist in PublicMethods.

View Source
var ErrUnauthenticated = errors.New("authentication required")

ErrUnauthenticated is returned by the Authorizer when a request must be rejected for lack of valid credentials. Each transport maps it to its own status code (Connect: CodeUnauthenticated, gRPC-Gateway: HTTP 401).

View Source
var PublicMethods = map[string]struct{}{

	"/memos.api.v1.AuthService/SignIn":       {},
	"/memos.api.v1.AuthService/RefreshToken": {},

	"/memos.api.v1.InstanceService/GetInstanceProfile":       {},
	"/memos.api.v1.InstanceService/GetInstanceSetting":       {},
	"/memos.api.v1.InstanceService/BatchGetInstanceSettings": {},

	"/memos.api.v1.UserService/CreateUser":       {},
	"/memos.api.v1.UserService/GetUser":          {},
	"/memos.api.v1.UserService/BatchGetUsers":    {},
	"/memos.api.v1.UserService/GetUserAvatar":    {},
	"/memos.api.v1.UserService/GetUserStats":     {},
	"/memos.api.v1.UserService/ListAllUserStats": {},

	"/memos.api.v1.IdentityProviderService/ListIdentityProviders": {},

	"/memos.api.v1.MemoService/GetMemo":              {},
	"/memos.api.v1.MemoService/ListMemos":            {},
	"/memos.api.v1.MemoService/ListMemoComments":     {},
	"/memos.api.v1.MemoService/ListMemoAttachments":  {},
	"/memos.api.v1.MemoService/ListMemoReactions":    {},
	"/memos.api.v1.MemoService/ListMemoRelations":    {},
	"/memos.api.v1.MemoService/GetLinkMetadata":      {},
	"/memos.api.v1.MemoService/BatchGetLinkMetadata": {},

	"/memos.api.v1.AttachmentService/GetAttachment": {},

	"/memos.api.v1.MemoService/GetSharedMemo": {},
}

PublicMethods defines API endpoints that don't require authentication. All other endpoints require a valid session or access token.

This is the SINGLE SOURCE OF TRUTH for public endpoints. Both Connect interceptor and gRPC-Gateway interceptor use this map.

Format: Full gRPC procedure path as returned by req.Spec().Procedure (Connect) or info.FullMethod (gRPC interceptor).

Functions

func BuildUserName

func BuildUserName(username string) string

BuildUserName returns the canonical public resource name for a user.

func ExtractAttachmentUIDFromName

func ExtractAttachmentUIDFromName(name string) (string, error)

ExtractAttachmentUIDFromName returns the attachment UID from a resource name.

func ExtractIdentityProviderUIDFromName

func ExtractIdentityProviderUIDFromName(name string) (string, error)

func ExtractInboxIDFromName

func ExtractInboxIDFromName(name string) (int32, error)

ExtractInboxIDFromName returns the inbox ID from a resource name.

func ExtractInstanceSettingKeyFromName

func ExtractInstanceSettingKeyFromName(name string) (string, error)

func ExtractMemoReactionIDFromName

func ExtractMemoReactionIDFromName(name string) (string, int32, error)

ExtractMemoReactionIDFromName returns the memo UID and reaction ID from a resource name. e.g., "memos/abc/reactions/123" -> ("abc", 123).

func ExtractMemoUIDFromName

func ExtractMemoUIDFromName(name string) (string, error)

ExtractMemoUIDFromName returns the memo UID from a resource name. e.g., "memos/uuid" -> "uuid".

func ExtractSpaceInvitationTokensFromName

func ExtractSpaceInvitationTokensFromName(name string) (string, string, error)

ExtractSpaceInvitationTokensFromName returns the Space UID and invitee username from a SpaceInvitation resource name.

func ExtractSpaceMemberTokensFromName

func ExtractSpaceMemberTokensFromName(name string) (string, string, error)

ExtractSpaceMemberTokensFromName returns the Space UID and username from a SpaceMember resource name.

func ExtractSpaceUIDFromName

func ExtractSpaceUIDFromName(name string) (string, error)

ExtractSpaceUIDFromName returns the UID from a Space resource name.

func ExtractUserIDFromName

func ExtractUserIDFromName(name string) (int32, error)

ExtractUserIDFromName returns the uid from a resource name.

func GetNameParentTokens

func GetNameParentTokens(name string, tokenPrefixes ...string) ([]string, error)

GetNameParentTokens returns the tokens from a resource name.

func IsAuthBootstrapMethod

func IsAuthBootstrapMethod(procedure string) bool

IsAuthBootstrapMethod reports whether an anonymous request to procedure is one of the fixed endpoints allowed while the instance is private.

func IsPublicMethod

func IsPublicMethod(procedure string) bool

IsPublicMethod checks if a procedure path is public (no authentication required). Returns true for public methods, false for protected methods.

func RegisterSSERoutes

func RegisterSSERoutes(router sseRouteRegistrar, hub *SSEHub, storeInstance *store.Store, secret string)

RegisterSSERoutes registers the SSE endpoint on the given Echo router.

func ResolveUserByName

func ResolveUserByName(ctx context.Context, stores *store.Store, name string) (*store.User, error)

ResolveUserByName resolves a username-based user resource name to a store user.

func SetResponseHeader

func SetResponseHeader(ctx context.Context, key, value string) error

SetResponseHeader sets a header in the response.

This function works for both gRPC and Connect protocols:

  • For gRPC: Uses grpc.SetHeader to set headers in gRPC metadata
  • For Connect: Stores in HeaderCarrier for Connect wrapper to apply later

The protocol is automatically detected based on whether a HeaderCarrier exists in the context (injected by Connect wrappers).

func ValidateAndGenerateSpaceUID

func ValidateAndGenerateSpaceUID(provided string) (string, error)

ValidateAndGenerateSpaceUID validates a user-provided Space UID or generates a UUID v4. Custom UIDs use the same format as other public-resource UIDs.

func ValidateAndGenerateUID

func ValidateAndGenerateUID(provided string) (string, error)

ValidateAndGenerateUID validates a user-provided UID or generates a new one. If provided is empty, a new shortuuid is generated. If provided is non-empty, it is validated against identifier.UIDMatcher.

func WithHeaderCarrier

func WithHeaderCarrier(ctx context.Context) context.Context

WithHeaderCarrier adds a header carrier to the context.

Types

type APIV1Service

type APIV1Service struct {
	v1pb.UnimplementedInstanceServiceServer
	v1pb.UnimplementedAuthServiceServer
	v1pb.UnimplementedUserServiceServer
	v1pb.UnimplementedMemoServiceServer
	v1pb.UnimplementedSpaceServiceServer
	v1pb.UnimplementedAttachmentServiceServer
	v1pb.UnimplementedAIServiceServer
	v1pb.UnimplementedIdentityProviderServiceServer

	Secret                  string
	Profile                 *profile.Profile
	Store                   *store.Store
	MarkdownService         markdown.Service
	SSEHub                  *SSEHub
	NotificationEmailSender notification.EmailSender

	// RateLimiter bounds request rates; nil disables every limit.
	RateLimiter ratelimit.Limiter
	// Challenge verifies proof-of-humanity tokens on signup and password
	// sign-in; nil means no challenge is configured.
	Challenge ratelimit.Challenge
	// SignupPolicy decides whether a self-service registration may proceed;
	// nil allows every registration.
	SignupPolicy ratelimit.SignupPolicy
	// contains filtered or unexported fields
}

func NewAPIV1Service

func NewAPIV1Service(secret string, profile *profile.Profile, store *store.Store) *APIV1Service

NewAPIV1Service creates an API v1 service with its shared dependencies.

func (*APIV1Service) AcceptSpaceInvitation

func (s *APIV1Service) AcceptSpaceInvitation(ctx context.Context, request *v1pb.AcceptSpaceInvitationRequest) (*v1pb.SpaceMember, error)

AcceptSpaceInvitation activates the invited user's membership with the role selected by the administrator who created the invitation.

func (*APIV1Service) BatchDeleteAttachments

func (s *APIV1Service) BatchDeleteAttachments(ctx context.Context, request *v1pb.BatchDeleteAttachmentsRequest) (*emptypb.Empty, error)

func (*APIV1Service) BatchGetInstanceSettings

BatchGetInstanceSettings returns multiple instance settings in request order.

func (*APIV1Service) BatchGetLinkMetadata

BatchGetLinkMetadata gets metadata for links.

func (*APIV1Service) BatchGetUsers

func (*APIV1Service) CloseAttachmentUploads

func (s *APIV1Service) CloseAttachmentUploads()

CloseAttachmentUploads stops expiration work and removes pending upload files. Call it after draining HTTP requests during server shutdown.

func (*APIV1Service) CreateAttachment

func (s *APIV1Service) CreateAttachment(ctx context.Context, request *v1pb.CreateAttachmentRequest) (*v1pb.Attachment, error)

func (*APIV1Service) CreateIdentityProvider

func (s *APIV1Service) CreateIdentityProvider(ctx context.Context, request *v1pb.CreateIdentityProviderRequest) (*v1pb.IdentityProvider, error)

func (*APIV1Service) CreateLinkedIdentity

func (s *APIV1Service) CreateLinkedIdentity(ctx context.Context, request *v1pb.CreateLinkedIdentityRequest) (*v1pb.LinkedIdentity, error)

func (*APIV1Service) CreateMemo

func (s *APIV1Service) CreateMemo(ctx context.Context, request *v1pb.CreateMemoRequest) (*v1pb.Memo, error)

func (*APIV1Service) CreateMemoComment

func (s *APIV1Service) CreateMemoComment(ctx context.Context, request *v1pb.CreateMemoCommentRequest) (*v1pb.Memo, error)

CreateMemoComment creates a comment on an existing memo.

func (*APIV1Service) CreateMemoShare

func (s *APIV1Service) CreateMemoShare(ctx context.Context, request *v1pb.CreateMemoShareRequest) (*v1pb.MemoShare, error)

CreateMemoShare creates an opaque share link for a memo. Only the memo's creator may call this.

func (*APIV1Service) CreateMemoView

func (s *APIV1Service) CreateMemoView(ctx context.Context, request *v1pb.CreateMemoViewRequest) (*v1pb.MemoView, error)

CreateMemoView creates a saved memo view for a user.

func (*APIV1Service) CreatePersonalAccessToken

CreatePersonalAccessToken creates a new Personal Access Token (PAT) for a user.

Use cases: - User manually creates token in settings for mobile app - User creates token for CLI tool - User creates token for third-party integration

Token properties: - Random string with memos_pat_ prefix - SHA-256 hash stored in database - Optional expiration time (can be never-expiring) - User-provided description for identification

Security considerations: - Full token is only shown ONCE (in this response) - User should copy and store it securely - Token can be revoked by deleting it from settings

Authentication: Required (session cookie or access token) Authorization: User can only create tokens for themselves.

func (*APIV1Service) CreateSpace

func (s *APIV1Service) CreateSpace(ctx context.Context, request *v1pb.CreateSpaceRequest) (*v1pb.Space, error)

CreateSpace creates a space with the caller as its first administrator.

func (*APIV1Service) CreateSpaceInvitation

func (s *APIV1Service) CreateSpaceInvitation(ctx context.Context, request *v1pb.CreateSpaceInvitationRequest) (*v1pb.SpaceInvitation, error)

CreateSpaceInvitation creates a pending invitation without granting any Space access to the invitee.

func (*APIV1Service) CreateUser

func (s *APIV1Service) CreateUser(ctx context.Context, request *v1pb.CreateUserRequest) (*v1pb.User, error)

func (*APIV1Service) CreateUserWebhook

func (s *APIV1Service) CreateUserWebhook(ctx context.Context, request *v1pb.CreateUserWebhookRequest) (*v1pb.UserWebhook, error)

func (*APIV1Service) DeclineSpaceInvitation

func (s *APIV1Service) DeclineSpaceInvitation(ctx context.Context, request *v1pb.DeclineSpaceInvitationRequest) (*emptypb.Empty, error)

DeclineSpaceInvitation deletes the authenticated invitee's pending invitation without ever creating a membership.

func (*APIV1Service) DeleteAttachment

func (s *APIV1Service) DeleteAttachment(ctx context.Context, request *v1pb.DeleteAttachmentRequest) (*emptypb.Empty, error)

func (*APIV1Service) DeleteIdentityProvider

func (s *APIV1Service) DeleteIdentityProvider(ctx context.Context, request *v1pb.DeleteIdentityProviderRequest) (*emptypb.Empty, error)

func (*APIV1Service) DeleteLinkedIdentity

func (s *APIV1Service) DeleteLinkedIdentity(ctx context.Context, request *v1pb.DeleteLinkedIdentityRequest) (*emptypb.Empty, error)

func (*APIV1Service) DeleteMemo

func (s *APIV1Service) DeleteMemo(ctx context.Context, request *v1pb.DeleteMemoRequest) (*emptypb.Empty, error)

func (*APIV1Service) DeleteMemoReaction

func (s *APIV1Service) DeleteMemoReaction(ctx context.Context, request *v1pb.DeleteMemoReactionRequest) (*emptypb.Empty, error)

func (*APIV1Service) DeleteMemoShare

func (s *APIV1Service) DeleteMemoShare(ctx context.Context, request *v1pb.DeleteMemoShareRequest) (*emptypb.Empty, error)

DeleteMemoShare revokes a share link. Only the memo's creator may call this.

func (*APIV1Service) DeleteMemoView

func (s *APIV1Service) DeleteMemoView(ctx context.Context, request *v1pb.DeleteMemoViewRequest) (*emptypb.Empty, error)

DeleteMemoView deletes a saved memo view by resource name.

func (*APIV1Service) DeletePersonalAccessToken

func (s *APIV1Service) DeletePersonalAccessToken(ctx context.Context, request *v1pb.DeletePersonalAccessTokenRequest) (*emptypb.Empty, error)

DeletePersonalAccessToken revokes a Personal Access Token.

This endpoint: 1. Removes the token from the user's access tokens list 2. Immediately invalidates the token (subsequent API calls with it will fail)

Use cases: - User revokes a compromised token - User removes token for unused app/device - User cleans up old tokens

Authentication: Required (session cookie or access token) Authorization: User can only delete their own tokens.

func (*APIV1Service) DeleteSpace

func (s *APIV1Service) DeleteSpace(ctx context.Context, request *v1pb.DeleteSpaceRequest) (*emptypb.Empty, error)

DeleteSpace permanently deletes the Space and every memo directly placed in it. The result deliberately exposes no memo inventory to the administrator.

func (*APIV1Service) DeleteSpaceInvitation

func (s *APIV1Service) DeleteSpaceInvitation(ctx context.Context, request *v1pb.DeleteSpaceInvitationRequest) (*emptypb.Empty, error)

DeleteSpaceInvitation revokes a pending invitation. Only an active Space administrator can revoke it.

func (*APIV1Service) DeleteSpaceMember

func (s *APIV1Service) DeleteSpaceMember(ctx context.Context, request *v1pb.DeleteSpaceMemberRequest) (*emptypb.Empty, error)

DeleteSpaceMember removes a membership or lets a member leave a space.

func (*APIV1Service) DeleteUser

func (s *APIV1Service) DeleteUser(ctx context.Context, request *v1pb.DeleteUserRequest) (*emptypb.Empty, error)

func (*APIV1Service) DeleteUserNotification

func (s *APIV1Service) DeleteUserNotification(ctx context.Context, request *v1pb.DeleteUserNotificationRequest) (*emptypb.Empty, error)

DeleteUserNotification permanently deletes a notification. Only the notification owner can delete their notifications.

func (*APIV1Service) DeleteUserWebhook

func (s *APIV1Service) DeleteUserWebhook(ctx context.Context, request *v1pb.DeleteUserWebhookRequest) (*emptypb.Empty, error)

func (*APIV1Service) DispatchMemoCommentCreatedWebhook

func (s *APIV1Service) DispatchMemoCommentCreatedWebhook(
	ctx context.Context,
	comment, relatedMemo *store.Memo,
	relatedMemoCreatorID int32,
) error

DispatchMemoCommentCreatedWebhook dispatches webhook to the related memo owner when a comment is created.

func (*APIV1Service) DispatchMemoCreatedWebhook

func (s *APIV1Service) DispatchMemoCreatedWebhook(ctx context.Context, memo *v1pb.Memo) error

DispatchMemoCreatedWebhook dispatches a webhook when a memo is created.

func (*APIV1Service) DispatchMemoDeletedWebhook

func (s *APIV1Service) DispatchMemoDeletedWebhook(ctx context.Context, memo *v1pb.Memo) error

DispatchMemoDeletedWebhook dispatches webhook when memo is deleted.

func (*APIV1Service) DispatchMemoUpdatedWebhook

func (s *APIV1Service) DispatchMemoUpdatedWebhook(ctx context.Context, memo *v1pb.Memo) error

DispatchMemoUpdatedWebhook dispatches webhook when memo is updated.

func (*APIV1Service) GetAttachment

func (s *APIV1Service) GetAttachment(ctx context.Context, request *v1pb.GetAttachmentRequest) (*v1pb.Attachment, error)

func (*APIV1Service) GetAttachmentBlob

func (s *APIV1Service) GetAttachmentBlob(ctx context.Context, attachment *store.Attachment) ([]byte, error)

GetAttachmentBlob reads an attachment from its configured storage.

func (*APIV1Service) GetCurrentUser

GetCurrentUser returns the authenticated user's information. Validates the access token and returns user details.

Authentication: Required (access token). Returns: User information.

func (*APIV1Service) GetIdentityProvider

func (s *APIV1Service) GetIdentityProvider(ctx context.Context, request *v1pb.GetIdentityProviderRequest) (*v1pb.IdentityProvider, error)

func (*APIV1Service) GetInstanceAdmin

func (s *APIV1Service) GetInstanceAdmin(ctx context.Context) (*v1pb.User, error)

func (*APIV1Service) GetInstanceProfile

GetInstanceProfile returns the instance profile.

func (*APIV1Service) GetInstanceSetting

func (s *APIV1Service) GetInstanceSetting(ctx context.Context, request *v1pb.GetInstanceSettingRequest) (*v1pb.InstanceSetting, error)

func (*APIV1Service) GetInstanceStats

GetInstanceStats returns resource usage statistics. Admin only.

func (*APIV1Service) GetLinkMetadata

func (s *APIV1Service) GetLinkMetadata(ctx context.Context, request *v1pb.GetLinkMetadataRequest) (*v1pb.LinkMetadata, error)

GetLinkMetadata gets metadata for a link.

func (*APIV1Service) GetLinkedIdentity

func (s *APIV1Service) GetLinkedIdentity(ctx context.Context, request *v1pb.GetLinkedIdentityRequest) (*v1pb.LinkedIdentity, error)

func (*APIV1Service) GetMemo

func (s *APIV1Service) GetMemo(ctx context.Context, request *v1pb.GetMemoRequest) (*v1pb.Memo, error)

func (*APIV1Service) GetMemoView

func (s *APIV1Service) GetMemoView(ctx context.Context, request *v1pb.GetMemoViewRequest) (*v1pb.MemoView, error)

GetMemoView returns a saved memo view by resource name.

func (*APIV1Service) GetSharedMemo

func (s *APIV1Service) GetSharedMemo(ctx context.Context, request *v1pb.GetSharedMemoRequest) (*v1pb.Memo, error)

GetSharedMemo resolves a share token to its memo. No authentication required. Returns NOT_FOUND for invalid or expired tokens (no information leakage).

func (*APIV1Service) GetSpace

func (s *APIV1Service) GetSpace(ctx context.Context, request *v1pb.GetSpaceRequest) (*v1pb.Space, error)

GetSpace gets a space visible to the caller through membership.

func (*APIV1Service) GetSpaceInvitation

func (s *APIV1Service) GetSpaceInvitation(ctx context.Context, request *v1pb.GetSpaceInvitationRequest) (*v1pb.SpaceInvitation, error)

GetSpaceInvitation gets a pending invitation for its invitee or a Space administrator.

func (*APIV1Service) GetSpaceMember

func (s *APIV1Service) GetSpaceMember(ctx context.Context, request *v1pb.GetSpaceMemberRequest) (*v1pb.SpaceMember, error)

GetSpaceMember gets one membership visible to another member of the space.

func (*APIV1Service) GetUser

func (s *APIV1Service) GetUser(ctx context.Context, request *v1pb.GetUserRequest) (*v1pb.User, error)

func (*APIV1Service) GetUserSetting

func (s *APIV1Service) GetUserSetting(ctx context.Context, request *v1pb.GetUserSettingRequest) (*v1pb.UserSetting, error)

func (*APIV1Service) GetUserStats

func (s *APIV1Service) GetUserStats(ctx context.Context, request *v1pb.GetUserStatsRequest) (*v1pb.UserStats, error)

func (*APIV1Service) GetUserWebhookSigningSecret

GetUserWebhookSigningSecret reveals the signing secret for a single webhook. This is the only endpoint that returns the secret value; it is gated to the webhook owner and the secret is never included in list/create/update responses.

func (*APIV1Service) ListAllUserStats

func (*APIV1Service) ListAttachments

func (*APIV1Service) ListLinkedIdentities

func (*APIV1Service) ListMemoAttachments

func (*APIV1Service) ListMemoComments

func (*APIV1Service) ListMemoReactions

func (*APIV1Service) ListMemoRelations

func (*APIV1Service) ListMemoShares

ListMemoShares lists all share links for a memo. Only the memo's creator may call this.

func (*APIV1Service) ListMemoViews

ListMemoViews lists the saved memo views owned by a user.

func (*APIV1Service) ListMemos

func (s *APIV1Service) ListMemos(ctx context.Context, request *v1pb.ListMemosRequest) (*v1pb.ListMemosResponse, error)

func (*APIV1Service) ListPersonalAccessTokens

func (*APIV1Service) ListSpaceInvitations

ListSpaceInvitations lists pending invitations after requiring an active Space administrator.

func (*APIV1Service) ListSpaceMembers

ListSpaceMembers lists memberships after authorizing the caller's own membership before applying pagination.

func (*APIV1Service) ListSpaces

ListSpaces lists only spaces with a membership for the caller.

func (*APIV1Service) ListUserNotifications

func (*APIV1Service) ListUserSettings

func (*APIV1Service) ListUserSpaceInvitations

ListUserSpaceInvitations lists the authenticated user's received pending invitations. A user cannot enumerate another user's invitations.

func (*APIV1Service) ListUserWebhooks

func (*APIV1Service) ListUsers

func (s *APIV1Service) ListUsers(ctx context.Context, request *v1pb.ListUsersRequest) (*v1pb.ListUsersResponse, error)

func (*APIV1Service) RefreshToken

RefreshToken exchanges a valid refresh token for a new access token.

This endpoint implements refresh token rotation with sliding window sessions: 1. Extracts the refresh token from the HttpOnly cookie (memos_refresh) 2. Validates the refresh token against the database (checking expiry and revocation) 3. Rotates the refresh token: generates a new one with fresh 30-day expiry 4. Generates a new short-lived access token (15 minutes) 5. Sets the new refresh token as HttpOnly cookie 6. Returns the new access token and its expiry time

Token rotation provides: - Sliding window sessions: active users stay logged in indefinitely - Better security: stolen refresh tokens become invalid after legitimate refresh

Authentication: Requires valid refresh token in cookie (public endpoint) Returns: New access token and expiry timestamp.

func (*APIV1Service) RegisterGateway

func (s *APIV1Service) RegisterGateway(ctx context.Context, echoServer *echo.Echo) error

RegisterGateway registers the gRPC-Gateway and Connect handlers with the given Echo instance.

func (*APIV1Service) SetMemoAttachments

func (s *APIV1Service) SetMemoAttachments(ctx context.Context, request *v1pb.SetMemoAttachmentsRequest) (*emptypb.Empty, error)

func (*APIV1Service) SetMemoRelations

func (s *APIV1Service) SetMemoRelations(ctx context.Context, request *v1pb.SetMemoRelationsRequest) (*emptypb.Empty, error)

func (*APIV1Service) SignIn

func (s *APIV1Service) SignIn(ctx context.Context, request *v1pb.SignInRequest) (*v1pb.SignInResponse, error)

SignIn authenticates a user with credentials and returns tokens. On success, returns an access token and sets a refresh token cookie.

Supports two authentication methods: 1. Password-based authentication (username + password). 2. SSO authentication (OAuth2 authorization code).

Authentication: Not required (public endpoint). Returns: User info, access token, and token expiry.

func (*APIV1Service) SignOut

SignOut terminates the user's authentication. Revokes the refresh token and clears the authentication cookie.

Authentication: Required (access token). Returns: Empty response on success.

func (*APIV1Service) TestInstanceEmailSetting

func (s *APIV1Service) TestInstanceEmailSetting(ctx context.Context, request *v1pb.TestInstanceEmailSettingRequest) (*emptypb.Empty, error)

func (*APIV1Service) Transcribe

Transcribe transcribes an audio file using an instance AI provider.

func (*APIV1Service) UpdateAttachment

func (s *APIV1Service) UpdateAttachment(ctx context.Context, request *v1pb.UpdateAttachmentRequest) (*v1pb.Attachment, error)

func (*APIV1Service) UpdateIdentityProvider

func (s *APIV1Service) UpdateIdentityProvider(ctx context.Context, request *v1pb.UpdateIdentityProviderRequest) (*v1pb.IdentityProvider, error)

func (*APIV1Service) UpdateInstanceSetting

func (s *APIV1Service) UpdateInstanceSetting(ctx context.Context, request *v1pb.UpdateInstanceSettingRequest) (*v1pb.InstanceSetting, error)

func (*APIV1Service) UpdateMemo

func (s *APIV1Service) UpdateMemo(ctx context.Context, request *v1pb.UpdateMemoRequest) (*v1pb.Memo, error)

UpdateMemo updates an existing memo.

func (*APIV1Service) UpdateMemoView

func (s *APIV1Service) UpdateMemoView(ctx context.Context, request *v1pb.UpdateMemoViewRequest) (*v1pb.MemoView, error)

UpdateMemoView updates the selected fields of a saved memo view.

func (*APIV1Service) UpdateSpace

func (s *APIV1Service) UpdateSpace(ctx context.Context, request *v1pb.UpdateSpaceRequest) (*v1pb.Space, error)

UpdateSpace updates Space metadata.

func (*APIV1Service) UpdateSpaceMember

func (s *APIV1Service) UpdateSpaceMember(ctx context.Context, request *v1pb.UpdateSpaceMemberRequest) (*v1pb.SpaceMember, error)

UpdateSpaceMember changes a member's role in a Space.

func (*APIV1Service) UpdateUser

func (s *APIV1Service) UpdateUser(ctx context.Context, request *v1pb.UpdateUserRequest) (*v1pb.User, error)

func (*APIV1Service) UpdateUserNotification

func (s *APIV1Service) UpdateUserNotification(ctx context.Context, request *v1pb.UpdateUserNotificationRequest) (*v1pb.UserNotification, error)

UpdateUserNotification updates a notification's status (e.g., marking as read/archived). Only the notification owner can update their notifications.

func (*APIV1Service) UpdateUserSetting

func (s *APIV1Service) UpdateUserSetting(ctx context.Context, request *v1pb.UpdateUserSettingRequest) (*v1pb.UserSetting, error)

func (*APIV1Service) UpdateUserWebhook

func (s *APIV1Service) UpdateUserWebhook(ctx context.Context, request *v1pb.UpdateUserWebhookRequest) (*v1pb.UserWebhook, error)

func (*APIV1Service) UploadAttachment

UploadAttachment accepts bounded unary chunks. A call carrying a spec opens a new upload; a call carrying an upload ID continues one. Either kind may write data and finalize.

func (*APIV1Service) UpsertMemoReaction

func (s *APIV1Service) UpsertMemoReaction(ctx context.Context, request *v1pb.UpsertMemoReactionRequest) (*v1pb.Reaction, error)

type AuthInterceptor

type AuthInterceptor struct {
	// contains filtered or unexported fields
}

AuthInterceptor enforces authentication and anonymous-access policy for Connect handlers by delegating to the shared Authorizer. Role-based authorization (admin checks) remains in the service layer.

func NewAuthInterceptor

func NewAuthInterceptor(authorizer *Authorizer) *AuthInterceptor

NewAuthInterceptor creates a new auth interceptor backed by the shared Authorizer.

func (*AuthInterceptor) WrapStreamingClient

func (*AuthInterceptor) WrapStreamingHandler

func (*AuthInterceptor) WrapUnary

func (in *AuthInterceptor) WrapUnary(next connect.UnaryFunc) connect.UnaryFunc

type Authorizer

type Authorizer struct {
	// contains filtered or unexported fields
}

Authorizer is the single source of truth for method-level access control.

It authenticates a request from its Authorization header and decides whether the (possibly anonymous) caller may reach a given RPC procedure. The Connect interceptor and the gRPC-Gateway middleware share one Authorizer so both transports enforce identical rules.

Role-based authorization (admin checks) stays in the service layer; this type governs only authentication and anonymous access.

func NewAuthorizer

func NewAuthorizer(store *store.Store, secret string) *Authorizer

NewAuthorizer creates an Authorizer backed by the given store and token secret.

func (*Authorizer) Authenticate

func (a *Authorizer) Authenticate(ctx context.Context, authHeader string) *auth.AuthResult

Authenticate resolves the caller from the Authorization header, returning nil for an anonymous request. It never enforces policy — pair it with CheckAccess.

func (*Authorizer) CheckAccess

func (a *Authorizer) CheckAccess(ctx context.Context, procedure string, result *auth.AuthResult) error

CheckAccess enforces method-level access policy for procedure given the authentication result (nil = anonymous). It returns nil when the request is permitted and ErrUnauthenticated otherwise.

Policy:

  • Authenticated caller (access token or PAT): always permitted here.
  • Anonymous + protected method: denied.
  • Anonymous + auth-bootstrap method: permitted on every instance.
  • Anonymous + other public method: permitted only when the stored access mode is PUBLIC.

func (*Authorizer) Throttle

func (a *Authorizer) Throttle(ctx context.Context, _ string, result *auth.AuthResult) error

Throttle enforces the catch-all budget for a request that CheckAccess has already permitted: the authenticated budget keyed by user, or the anonymous budget keyed by client address. Every request costs one unit; batch handlers add their item count afterwards. It returns a RESOURCE_EXHAUSTED status when the budget is spent.

func (*Authorizer) WithRateLimiter

func (a *Authorizer) WithRateLimiter(limiter ratelimit.Limiter) *Authorizer

WithRateLimiter enables the catch-all request budgets. A nil limiter leaves every request unbounded.

type ConnectServiceHandler

type ConnectServiceHandler struct {
	*APIV1Service
}

ConnectServiceHandler wraps APIV1Service to implement Connect handler interfaces. It adapts the existing gRPC service implementations to work with Connect's request/response wrapper types.

This wrapper pattern allows us to: - Reuse existing gRPC service implementations - Support both native gRPC and Connect protocols - Maintain a single source of truth for business logic.

func NewConnectServiceHandler

func NewConnectServiceHandler(svc *APIV1Service) *ConnectServiceHandler

NewConnectServiceHandler creates a new Connect service handler.

func (*ConnectServiceHandler) AcceptSpaceInvitation

func (*ConnectServiceHandler) BatchDeleteAttachments

func (*ConnectServiceHandler) CreateAttachment

func (*ConnectServiceHandler) CreateMemo

func (*ConnectServiceHandler) CreateMemoComment

func (*ConnectServiceHandler) CreateMemoShare

func (*ConnectServiceHandler) CreateMemoView

CreateMemoView creates a saved memo view for a user.

func (*ConnectServiceHandler) CreateSpace

func (*ConnectServiceHandler) CreateUser

func (*ConnectServiceHandler) CreateUserWebhook

func (*ConnectServiceHandler) DeclineSpaceInvitation

func (*ConnectServiceHandler) DeleteAttachment

func (*ConnectServiceHandler) DeleteIdentityProvider

func (*ConnectServiceHandler) DeleteLinkedIdentity

func (*ConnectServiceHandler) DeleteMemo

func (*ConnectServiceHandler) DeleteMemoReaction

func (*ConnectServiceHandler) DeleteMemoShare

func (*ConnectServiceHandler) DeleteMemoView

DeleteMemoView deletes a saved memo view by resource name.

func (*ConnectServiceHandler) DeletePersonalAccessToken

func (*ConnectServiceHandler) DeleteSpace

func (*ConnectServiceHandler) DeleteSpaceInvitation

func (*ConnectServiceHandler) DeleteSpaceMember

func (*ConnectServiceHandler) DeleteUser

func (*ConnectServiceHandler) DeleteUserNotification

func (*ConnectServiceHandler) DeleteUserWebhook

func (*ConnectServiceHandler) GetAttachment

func (*ConnectServiceHandler) GetInstanceStats

func (*ConnectServiceHandler) GetLinkMetadata

func (*ConnectServiceHandler) GetLinkedIdentity

func (*ConnectServiceHandler) GetMemo

func (*ConnectServiceHandler) GetMemoView

GetMemoView returns a saved memo view by resource name.

func (*ConnectServiceHandler) GetSharedMemo

func (*ConnectServiceHandler) GetSpace

func (*ConnectServiceHandler) GetSpaceMember

func (*ConnectServiceHandler) GetUser

func (*ConnectServiceHandler) GetUserSetting

func (*ConnectServiceHandler) GetUserStats

func (*ConnectServiceHandler) ListMemoViews

ListMemoViews lists the saved memo views owned by a user.

func (*ConnectServiceHandler) ListMemos

func (*ConnectServiceHandler) ListSpaces

func (*ConnectServiceHandler) ListUsers

func (*ConnectServiceHandler) RegisterConnectHandlers

func (s *ConnectServiceHandler) RegisterConnectHandlers(mux *http.ServeMux, opts ...connect.HandlerOption)

RegisterConnectHandlers registers all Connect service handlers on the given mux.

func (*ConnectServiceHandler) SetMemoAttachments

func (*ConnectServiceHandler) SetMemoRelations

func (*ConnectServiceHandler) SignIn

func (*ConnectServiceHandler) SignOut

func (*ConnectServiceHandler) TestInstanceEmailSetting

func (*ConnectServiceHandler) Transcribe

func (*ConnectServiceHandler) UpdateAttachment

func (*ConnectServiceHandler) UpdateMemo

func (*ConnectServiceHandler) UpdateMemoView

UpdateMemoView updates the selected fields of a saved memo view.

func (*ConnectServiceHandler) UpdateSpace

func (*ConnectServiceHandler) UpdateSpaceMember

func (*ConnectServiceHandler) UpdateUser

func (*ConnectServiceHandler) UpdateUserSetting

func (*ConnectServiceHandler) UpdateUserWebhook

func (*ConnectServiceHandler) UpsertMemoReaction

type HeaderCarrier

type HeaderCarrier struct {
	// contains filtered or unexported fields
}

HeaderCarrier stores headers that need to be set in the response.

Problem: The codebase supports two protocols simultaneously:

  • Native gRPC: Uses grpc.SetHeader() to set response headers
  • Connect-RPC: Uses connect.Response.Header().Set() to set response headers

Solution: HeaderCarrier provides a protocol-agnostic way to set headers.

  • Service methods call SetResponseHeader() regardless of protocol
  • For gRPC requests: SetResponseHeader uses grpc.SetHeader directly
  • For Connect requests: SetResponseHeader stores headers in HeaderCarrier
  • Connect wrappers extract headers from HeaderCarrier and apply to response

This allows service methods to work with both protocols without knowing which one is being used.

func GetHeaderCarrier

func GetHeaderCarrier(ctx context.Context) *HeaderCarrier

GetHeaderCarrier retrieves the header carrier from the context. Returns nil if no carrier is present.

func (*HeaderCarrier) All

func (h *HeaderCarrier) All() map[string]string

All returns all headers.

func (*HeaderCarrier) Get

func (h *HeaderCarrier) Get(key string) string

Get retrieves a header from the carrier.

func (*HeaderCarrier) Set

func (h *HeaderCarrier) Set(key, value string)

Set adds a header to the carrier.

type LoggingInterceptor

type LoggingInterceptor struct {
	// contains filtered or unexported fields
}

LoggingInterceptor logs Connect RPC requests with appropriate log levels.

Log levels: - INFO: Successful requests and expected client errors (not found, permission denied, etc.) - ERROR: Server errors (internal, unavailable, etc.)

func NewLoggingInterceptor

func NewLoggingInterceptor(logStacktrace bool) *LoggingInterceptor

NewLoggingInterceptor creates a new logging interceptor.

func (*LoggingInterceptor) WrapStreamingClient

func (*LoggingInterceptor) WrapStreamingHandler

func (*LoggingInterceptor) WrapUnary

type MetadataInterceptor

type MetadataInterceptor struct{}

MetadataInterceptor converts Connect HTTP headers to gRPC metadata.

This ensures service methods can use metadata.FromIncomingContext() to access headers like User-Agent, X-Forwarded-For, etc., regardless of whether the request came via Connect RPC or gRPC-Gateway.

func NewMetadataInterceptor

func NewMetadataInterceptor() *MetadataInterceptor

NewMetadataInterceptor creates a new metadata interceptor.

func (*MetadataInterceptor) WrapStreamingClient

func (*MetadataInterceptor) WrapStreamingHandler

func (*MetadataInterceptor) WrapUnary

type RecoveryInterceptor

type RecoveryInterceptor struct {
	// contains filtered or unexported fields
}

RecoveryInterceptor recovers from panics in Connect handlers and returns an internal error.

func NewRecoveryInterceptor

func NewRecoveryInterceptor(logStacktrace bool) *RecoveryInterceptor

NewRecoveryInterceptor creates a new recovery interceptor.

func (*RecoveryInterceptor) WrapStreamingClient

func (*RecoveryInterceptor) WrapStreamingHandler

func (*RecoveryInterceptor) WrapUnary

type SSEClient

type SSEClient struct {
	// contains filtered or unexported fields
}

SSEClient represents a single SSE connection.

type SSEHub

type SSEHub struct {
	// contains filtered or unexported fields
}

SSEHub manages SSE client connections and broadcasts events. It is safe for concurrent use.

func NewSSEHub

func NewSSEHub() *SSEHub

NewSSEHub creates a new SSE hub.

func (*SSEHub) Close

func (h *SSEHub) Close()

Close disconnects all subscribed SSE clients.

func (*SSEHub) Subscribe

func (h *SSEHub) Subscribe() *SSEClient

Subscribe registers a new client and returns it. The caller must call Unsubscribe when done.

func (*SSEHub) Unsubscribe

func (h *SSEHub) Unsubscribe(c *SSEClient)

Unsubscribe removes a client and closes its channels.

Directories

Path Synopsis

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL