Add tenant-scoped notes REST API
internal/httpapi/notes.go exposes:
- GET /api/notes list summaries {id, title, updated_at}
- GET /api/notes/{id} full {id, title, content, updated_at}
- PUT /api/notes/{id} create/update; ?base=<unix> for
optimistic-locking conflict detection
- DELETE /api/notes/{id} remove; ?base=<unix> guards against
deleting a row modified after the
client last saw it
Backed by tenant.FS so all reads/writes go through the per-user
sandbox — path traversal is rejected at parse time (regex slug)
and again by os.Root inside the FS layer.
On-disk format is plain Markdown: first line `# Title`, rest is
content. grep / cat / vim still produce a usable view of raw
files. Title round-trips through composeNote/splitTitle.
Conflict semantics: when the client supplies ?base=<unix>, the
server compares against the file's mtime. If the file is newer,
respond 409 with the current note body so the client can present
a merge UI. Same logic on DELETE returns 409 alone.
cmd/librenotes/serve.go grows a tenantPool that memoises FS
handles per user id; defer-closes them on shutdown.
Tests cover: full CRUD round-trip, cross-tenant isolation,
unauthenticated 401s, invalid IDs (regex rejection), and the
conflict path with a real mtime advance.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -15,6 +15,7 @@ type Server struct {
|
||||
Auth auth.Handlers
|
||||
Signer *auth.Signer
|
||||
Logger *log.Logger
|
||||
Notes NotesHandler
|
||||
}
|
||||
|
||||
// Routes returns an http.Handler with all routes mounted.
|
||||
@@ -26,6 +27,9 @@ func (s *Server) Routes() http.Handler {
|
||||
|
||||
protected := http.NewServeMux()
|
||||
protected.HandleFunc("/api/whoami", s.handleWhoami)
|
||||
if s.Notes.FSFor != nil {
|
||||
s.Notes.Mount(protected)
|
||||
}
|
||||
|
||||
mw := AuthMiddleware(s.Signer, s.Logger)
|
||||
mux.Handle("/api/", mw(protected))
|
||||
|
||||
Reference in New Issue
Block a user