handlers.go 5.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141
  1. package api
  2. import (
  3. "fmt"
  4. "io/ioutil"
  5. "log"
  6. "net/http"
  7. "path/filepath"
  8. "runtime/debug"
  9. jwtmiddleware "github.com/auth0/go-jwt-middleware"
  10. jwt "github.com/dgrijalva/jwt-go"
  11. "github.com/gorilla/mux"
  12. "github.com/gorilla/sessions"
  13. )
  14. var (
  15. signingKey = []byte("secret")
  16. store = sessions.NewCookieStore([]byte("something-very-secret"))
  17. jwtMiddleware = jwtmiddleware.New(jwtmiddleware.Options{
  18. ValidationKeyGetter: func(token *jwt.Token) (interface{}, error) {
  19. return signingKey, nil
  20. },
  21. SigningMethod: jwt.SigningMethodHS256,
  22. Extractor: fromCookie,
  23. ErrorHandler: onError,
  24. })
  25. crud []string = []string{"add", "show", "update", "delete"}
  26. )
  27. type User struct {
  28. Name string
  29. Admin bool
  30. }
  31. // Generate CRUD handlers
  32. func generateHandler(r *mux.Router, base string) {
  33. r.Handle(fmt.Sprintf("/%s", base), jwtMiddleware.Handler(recoverHandler(generalHandler(base, fmt.Sprintf("/%s", base))))).Methods("GET")
  34. r.Handle(fmt.Sprintf("/%s/{id}", base), jwtMiddleware.Handler(recoverHandler(generalHandler(base, fmt.Sprintf("/%s/{id}", base))))).Methods("GET")
  35. r.Handle(fmt.Sprintf("/%s/add/", base), jwtMiddleware.Handler(recoverHandler(generalHandler(base, fmt.Sprintf("/%s/add/", base))))).Methods("GET", "POST")
  36. r.Handle(fmt.Sprintf("/%s/{id}/update", base), jwtMiddleware.Handler(recoverHandler(generalHandler(base, fmt.Sprintf("/%s/{id}/update", base))))).Methods("GET", "POST")
  37. r.Handle(fmt.Sprintf("/%s/{id}/delete", base), jwtMiddleware.Handler(recoverHandler(generalHandler(base, fmt.Sprintf("/%s/{id}/delete", base))))).Methods("POST")
  38. }
  39. func Handlers() *mux.Router {
  40. r := mux.NewRouter()
  41. // Authentication
  42. r.Handle("/login", loginHandler())
  43. r.Handle("/logout", logoutHandler())
  44. // Dashboard
  45. r.Handle("/", jwtMiddleware.Handler(recoverHandler(dashboardHandler())))
  46. // School
  47. r.Handle("/school/{id}", jwtMiddleware.Handler(recoverHandler(schoolShowHandler())))
  48. r.Handle("/school/{id}/update", jwtMiddleware.Handler(recoverHandler(schoolUpdateHandler()))).Methods("GET", "POST")
  49. // Generate handlers
  50. for _, model := range []string{"teachers", "activities"} {
  51. generateHandler(r, model)
  52. }
  53. // // Subjects
  54. // r.Handle("/subjects", jwtMiddleware.Handler(recoverHandler(subjectsHandler())))
  55. // r.Handle("/subjects/add", jwtMiddleware.Handler(recoverHandler(subjectsAddHandler()))).Methods("GET", "POST")
  56. // r.Handle("/subjects/{id}", jwtMiddleware.Handler(recoverHandler(subjectsShowHandler()))).Methods("GET")
  57. // r.Handle("/subjects/{id}/update", jwtMiddleware.Handler(recoverHandler(subjectsUpdateHandler()))).Methods("GET", "POST")
  58. // r.Handle("/subjects/{id}/delete", jwtMiddleware.Handler(recoverHandler(subjectsDeleteHandler()))).Methods("DELETE")
  59. // r.Handle("/subjects/import", jwtMiddleware.Handler(recoverHandler(subjectsImportHandler()))).Methods("POST")
  60. // // Activities
  61. // r.Handle("/activities", jwtMiddleware.Handler(recoverHandler(activitiesHandler())))
  62. // r.Handle("/activities/add", jwtMiddleware.Handler(recoverHandler(activitiesAddHandler()))).Methods("GET", "POST")
  63. // r.Handle("/activities/{id}/update", jwtMiddleware.Handler(recoverHandler(activitiesUpdateHandler()))).Methods("GET", "POST")
  64. // r.Handle("/activities/{id}/delete", jwtMiddleware.Handler(recoverHandler(activitiesDeleteHandler()))).Methods("DELETE")
  65. // // Classes
  66. // r.Handle("/classes", jwtMiddleware.Handler(recoverHandler(classesHandler())))
  67. // r.Handle("/classes/add", jwtMiddleware.Handler(recoverHandler(classesAddHandler()))).Methods("GET", "POST")
  68. // r.Handle("/classes/{id}", jwtMiddleware.Handler(recoverHandler(classesShowHandler()))).Methods("GET")
  69. // r.Handle("/classes/{id}/update", jwtMiddleware.Handler(recoverHandler(classesUpdateHandler()))).Methods("GET", "POST")
  70. // r.Handle("/classes/{id}/delete", jwtMiddleware.Handler(recoverHandler(classesDeleteHandler()))).Methods("DELETE")
  71. // r.Handle("/classes/import", jwtMiddleware.Handler(recoverHandler(classesImportHandler()))).Methods("POST")
  72. // Static file server
  73. r.PathPrefix("/").Handler(http.FileServer(http.Dir("./dist/")))
  74. return r
  75. }
  76. func onError(w http.ResponseWriter, r *http.Request, err string) {
  77. http.Redirect(w, r, "/login", http.StatusTemporaryRedirect)
  78. }
  79. func respondWithStaticFile(w http.ResponseWriter, filename string) error {
  80. f, err := ioutil.ReadFile(filepath.Join("public/html", filename))
  81. if err != nil {
  82. return err
  83. }
  84. w.Write(f)
  85. return nil
  86. }
  87. func fromCookie(r *http.Request) (string, error) {
  88. session, err := store.Get(r, "login-session")
  89. if err != nil {
  90. return "", nil
  91. }
  92. if session.Values["token"] == nil {
  93. return "", nil
  94. }
  95. token := session.Values["token"].([]uint8)
  96. return string(token), nil
  97. }
  98. func recoverHandler(next http.Handler) http.Handler {
  99. fn := func(w http.ResponseWriter, r *http.Request) {
  100. defer func() {
  101. if err := recover(); err != nil {
  102. panicMsg := fmt.Sprintf("PANIC: %v\n\n== STACKTRACE ==\n%s", err, debug.Stack())
  103. log.Print(panicMsg)
  104. http.Error(w, panicMsg, http.StatusInternalServerError)
  105. }
  106. }()
  107. next.ServeHTTP(w, r)
  108. }
  109. return http.HandlerFunc(fn)
  110. }