Documentation
¶
Index ¶
- func HandleAPIPrincipalHTTP(w http.ResponseWriter, r *http.Request)
- func HandleExportCSV(deps *Deps) forge.Handler
- func HandleExportJSON(deps *Deps) forge.Handler
- func HandleExportPrometheus(deps *Deps) forge.Handler
- func NewPrincipalHandler(opts PrincipalOptions) http.HandlerFunc
- type Deps
- type PrincipalOptions
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func HandleAPIPrincipalHTTP ¶ added in v1.6.4
func HandleAPIPrincipalHTTP(w http.ResponseWriter, r *http.Request)
HandleAPIPrincipalHTTP is the auth-enabled default for callers that don't configure the handler explicitly. Kept for backwards compatibility with tests and any direct route registrations.
func HandleExportCSV ¶
HandleExportCSV exports dashboard service data as CSV.
func HandleExportJSON ¶
HandleExportJSON exports dashboard data as JSON.
func HandleExportPrometheus ¶
HandleExportPrometheus exports metrics in Prometheus text format.
func NewPrincipalHandler ¶ added in v1.6.4
func NewPrincipalHandler(opts PrincipalOptions) http.HandlerFunc
NewPrincipalHandler returns the GET /api/dashboard/v1/principal handler configured for a given dashboard. It replaced an earlier static handler so a client can distinguish "auth disabled" from "auth required, not signed in".
Types ¶
type Deps ¶
type Deps struct {
Collector *collector.DataCollector
}
Deps holds the data sources the export handlers read from.
type PrincipalOptions ¶ added in v1.6.4
PrincipalOptions configures the principal endpoint. AuthEnabled toggles between two response shapes:
- false: always 200 with `{authenticated:false}` (auth disabled, the shell skips the login gate and renders the layout for an anonymous user).
- true: 200 with the populated principal when a user is in context, or 401 with `{code:"UNAUTHENTICATED",loginPath:...}` when not — the shell interprets that as "render the LoginScreen".
LoginPath is the absolute URL a client should send users to for sign-in (e.g. /<basePath>/login). Only included in the 401 envelope; ignored when auth is disabled.
RequiredRoles, if non-empty, restricts dashboard access to users carrying at least one of the listed roles. Authenticated users without any matching role get a 403 with `{code:"PERMISSION_DENIED"}`, which a client is meant to render as an "access denied" panel. Added so authsome can wire role-gated dashboards via config. The 403 is served; no client renders it yet.