webhandler

package
v0.5.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 5, 2026 License: Apache-2.0 Imports: 46 Imported by: 0

Documentation

Index

Constants

View Source
const AuthCookieName = "auth"

AuthCookieName is the name of the HTTP cookie used to carry the access token for HTML routes. Exported so core/app.go can reference it when wiring the cookie-based JWT middleware onto the web route group.

Variables

This section is empty.

Functions

func CompanyMiddleware

func CompanyMiddleware(repo data.CompanyRepoer) echo.MiddlewareFunc

CompanyMiddleware resolves the /@:handle URL segment to a Company, verifies that the authenticated user has access, and injects the company (and for owners, their full company list) into the Echo context.

func RegisterWebRoutes

func RegisterWebRoutes(
	g *echo.Group,
	repos *WebRepos,
	authSvc *service.AuthService,
	a *auth.Auth,
	cfg *config.Config,
)

RegisterWebRoutes mounts all HTML routes onto the given Echo group.

func RequireAdvancedAccountingEnabledMiddleware added in v0.5.1

func RequireAdvancedAccountingEnabledMiddleware() echo.MiddlewareFunc

RequireAdvancedAccountingEnabledMiddleware renders a 403 error page if the current company has not enabled advanced accounting. Must run after CompanyMiddleware, which populates the company in context. Gates the ledger UI (chart of accounts, journal entries, trial balance, balance sheet) — the accounting engine itself posts regardless of this flag.

func RequireAssetTrackingEnabledMiddleware added in v0.5.1

func RequireAssetTrackingEnabledMiddleware() echo.MiddlewareFunc

RequireAssetTrackingEnabledMiddleware renders a 403 error page if the current company has not enabled asset tracking. Must run after CompanyMiddleware. Gates the fixed-asset UI, independent of EnableAdvancedAccounting.

func RequireAuthMiddleware

func RequireAuthMiddleware() echo.MiddlewareFunc

RequireAuthMiddleware redirects unauthenticated requests to /login.

func RequireNonInventoryRoleMiddleware added in v0.5.1

func RequireNonInventoryRoleMiddleware() echo.MiddlewareFunc

RequireNonInventoryRoleMiddleware renders a 403 error page for the inventory role. POS session/order routes are meant to stay open to cashier, manager, and owner — manager and owner already qualify via the ordinary minimum-role hierarchy (AtLeast(CashierRole)), since a manager or owner may personally staff a register. Inventory, however, ranks above cashier only for its own inventory-scoped routes and has no business running the till, so it's excluded explicitly here rather than via AtLeast, which can't express "cashier and above, except this one in-between role" with a single threshold.

func RequireRecipesEnabledMiddleware added in v0.5.1

func RequireRecipesEnabledMiddleware() echo.MiddlewareFunc

RequireRecipesEnabledMiddleware renders a 403 error page if the current company has not enabled recipes. Must run after CompanyMiddleware, which populates the company in context. Defense in depth for the Ingredients and Recipe pages: the service layer already blocks creating recipe/ingredient products and disabling the setting while any exist, so this route only becomes reachable through direct URL access in states that shouldn't normally occur.

func RequireRoleMiddleware

func RequireRoleMiddleware(minimum auth.UserRole) echo.MiddlewareFunc

RequireRoleMiddleware renders a 403 error page if the authenticated user's role is below minimum. Also redirects unauthenticated requests to /login.

Types

type AccountingHandler added in v0.5.1

type AccountingHandler struct {
	// contains filtered or unexported fields
}

func NewAccountingHandler added in v0.5.1

func NewAccountingHandler(repos *WebRepos) *AccountingHandler

type AssetHandler added in v0.5.1

type AssetHandler struct {
	// contains filtered or unexported fields
}

func NewAssetHandler added in v0.5.1

func NewAssetHandler(repos *WebRepos) *AssetHandler

type AuthHandler

type AuthHandler struct {
	// contains filtered or unexported fields
}

AuthHandler handles HTML authentication routes.

func NewAuthHandler

func NewAuthHandler(svc *service.AuthService, cfg *config.Config, clk clock.Clock) *AuthHandler

NewAuthHandler creates a new AuthHandler. The auth cookie's Expires tracks cfg.JWTExpiryHours (via clk) so it never silently diverges from the actual JWT lifetime the cookie carries.

type ChangelogHandler added in v0.1.2

type ChangelogHandler struct{}

func NewChangelogHandler added in v0.1.2

func NewChangelogHandler() *ChangelogHandler

type CustomerHandler

type CustomerHandler struct {
	// contains filtered or unexported fields
}

func NewCustomerHandler

func NewCustomerHandler(repos *WebRepos) *CustomerHandler

type DashboardHandler

type DashboardHandler struct {
	// contains filtered or unexported fields
}

func NewDashboardHandler

func NewDashboardHandler(
	reportsRepo data.ReportsQuerier,
	orderRepo data.OrderRepoer,
	branchRepo data.BranchRepoer,
	stationRepo data.POSStationRepoer,
	userRepo data.UserRepoer,
	productRepo data.ProductRepoer,
) *DashboardHandler

type DiscountHandler

type DiscountHandler struct {
	// contains filtered or unexported fields
}

func NewDiscountHandler

func NewDiscountHandler(repos *WebRepos) *DiscountHandler

type FinanceHandler

type FinanceHandler struct {
	// contains filtered or unexported fields
}

func NewFinanceHandler

func NewFinanceHandler(repos *WebRepos) *FinanceHandler

type InventoryHandler

type InventoryHandler struct {
	// contains filtered or unexported fields
}

func NewInventoryHandler

func NewInventoryHandler(repos *WebRepos) *InventoryHandler

type OrdersHandler

type OrdersHandler struct {
	// contains filtered or unexported fields
}

func NewOrdersHandler

func NewOrdersHandler(repos *WebRepos) *OrdersHandler

type POSHandler

type POSHandler struct {
	// contains filtered or unexported fields
}

func NewPOSHandler

func NewPOSHandler(repos *WebRepos) *POSHandler

type ProductHandler

type ProductHandler struct {
	// contains filtered or unexported fields
}

func NewProductHandler

func NewProductHandler(repos *WebRepos, a *auth.Auth) *ProductHandler

type ReportsHandler

type ReportsHandler struct {
	// contains filtered or unexported fields
}

func NewReportsHandler

func NewReportsHandler(repos *WebRepos) *ReportsHandler

type SetupHandler

type SetupHandler struct {
	// contains filtered or unexported fields
}

func NewSetupHandler

func NewSetupHandler(repos *WebRepos, a *auth.Auth) *SetupHandler

type SupplierHandler

type SupplierHandler struct {
	// contains filtered or unexported fields
}

func NewSupplierHandler

func NewSupplierHandler(repos *WebRepos) *SupplierHandler

type WebRepos

type WebRepos struct {
	UserRepo            data.UserRepoer
	ReportsRepo         data.ReportsQuerier
	OrderRepo           data.OrderRepoer
	SessionRepo         data.SessionRepoer
	StationRepo         data.POSStationRepoer
	ProductRepo         data.ProductRepoer
	DiscountRepo        data.DiscountRepoer
	InventoryRepo       data.InventoryRepoer
	ExpenseRepo         data.ExpenseRepoer
	CompanyRepo         data.CompanyRepoer
	BranchRepo          data.BranchRepoer
	CustomerRepo        data.CustomerRepoer
	SupplierRepo        data.SupplierRepoer
	SupplierPaymentRepo data.SupplierPaymentRepoer
	InvoiceRepo         data.InvoiceRepoer
	AccountingRepo      data.AccountingRepoer
	AssetRepo           data.AssetRepoer
	FileRepo            data.FileRepoer
	FileStorage         data.FileStorage
	FileAccessTTL       time.Duration
	IsDemo              bool
	Emitter             data.EventEmitter
	Logger              *slog.Logger
	Clock               clock.Clock
}

WebRepos holds the repo implementations for the HTML layer.

type WebUserHandler

type WebUserHandler struct {
	// contains filtered or unexported fields
}

WebUserHandler renders HTML pages for user management, scoped to the company resolved from the /@:handle URL segment (see companyFromContext).

func NewWebUserHandler

func NewWebUserHandler(svc *service.UserService) *WebUserHandler

NewWebUserHandler creates a new WebUserHandler.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL