Add tenant-scoped notes REST API
internal/httpapi/notes.go exposes:
- GET /api/notes list summaries {id, title, updated_at}
- GET /api/notes/{id} full {id, title, content, updated_at}
- PUT /api/notes/{id} create/update; ?base=<unix> for
optimistic-locking conflict detection
- DELETE /api/notes/{id} remove; ?base=<unix> guards against
deleting a row modified after the
client last saw it
Backed by tenant.FS so all reads/writes go through the per-user
sandbox — path traversal is rejected at parse time (regex slug)
and again by os.Root inside the FS layer.
On-disk format is plain Markdown: first line `# Title`, rest is
content. grep / cat / vim still produce a usable view of raw
files. Title round-trips through composeNote/splitTitle.
Conflict semantics: when the client supplies ?base=<unix>, the
server compares against the file's mtime. If the file is newer,
respond 409 with the current note body so the client can present
a merge UI. Same logic on DELETE returns 409 alone.
cmd/librenotes/serve.go grows a tenantPool that memoises FS
handles per user id; defer-closes them on shutdown.
Tests cover: full CRUD round-trip, cross-tenant isolation,
unauthenticated 401s, invalid IDs (regex rejection), and the
conflict path with a real mtime advance.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -12,11 +12,13 @@ import (
|
||||
"net/http"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"git.librete.ch/public/librenotes/internal/auth"
|
||||
"git.librete.ch/public/librenotes/internal/httpapi"
|
||||
"git.librete.ch/public/librenotes/internal/storage"
|
||||
"git.librete.ch/public/librenotes/internal/tenant"
|
||||
)
|
||||
|
||||
//go:embed all:web/public
|
||||
@@ -124,10 +126,14 @@ func runServe(args []string) error {
|
||||
defer cancel()
|
||||
go purgeLoop(ctx, tokens, logger)
|
||||
|
||||
tenants := newTenantPool(c.dataDir)
|
||||
defer tenants.Close()
|
||||
|
||||
api := &httpapi.Server{
|
||||
Auth: auth.Handlers{Service: authSvc},
|
||||
Signer: signer,
|
||||
Logger: logger,
|
||||
Notes: httpapi.NotesHandler{FSFor: tenants.FSFor},
|
||||
}
|
||||
|
||||
root := http.NewServeMux()
|
||||
@@ -165,6 +171,41 @@ func purgeLoop(ctx context.Context, tokens *auth.TokenStore, logger *log.Logger)
|
||||
}
|
||||
}
|
||||
|
||||
// tenantPool memoises tenant.FS handles per user ID. We open the
|
||||
// root once and reuse it; closing happens on shutdown.
|
||||
type tenantPool struct {
|
||||
dataDir string
|
||||
mu sync.Mutex
|
||||
by map[string]*tenant.FS
|
||||
}
|
||||
|
||||
func newTenantPool(dataDir string) *tenantPool {
|
||||
return &tenantPool{dataDir: dataDir, by: map[string]*tenant.FS{}}
|
||||
}
|
||||
|
||||
func (p *tenantPool) FSFor(userID string) (*tenant.FS, error) {
|
||||
p.mu.Lock()
|
||||
defer p.mu.Unlock()
|
||||
if fs, ok := p.by[userID]; ok {
|
||||
return fs, nil
|
||||
}
|
||||
fs, err := tenant.Open(filepath.Join(p.dataDir, userID))
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
p.by[userID] = fs
|
||||
return fs, nil
|
||||
}
|
||||
|
||||
func (p *tenantPool) Close() {
|
||||
p.mu.Lock()
|
||||
defer p.mu.Unlock()
|
||||
for _, fs := range p.by {
|
||||
_ = fs.Close()
|
||||
}
|
||||
p.by = nil
|
||||
}
|
||||
|
||||
func withSecurityHeaders(h http.Handler) http.Handler {
|
||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("X-Content-Type-Options", "nosniff")
|
||||
|
||||
Reference in New Issue
Block a user