package httpapi import ( "encoding/json" "log" "net/http" "git.librete.ch/public/librenotes/internal/auth" ) // Server wires routes for the multi-tenant backend. The auth endpoints // live under /auth/* and are unauthenticated. Everything under /api/* // is wrapped by AuthMiddleware and receives a Tenant on the context. type Server struct { Auth auth.Handlers Signer *auth.Signer Logger *log.Logger } // Routes returns an http.Handler with all routes mounted. func (s *Server) Routes() http.Handler { mux := http.NewServeMux() mux.HandleFunc("/auth/login", s.Auth.HandleLogin) mux.HandleFunc("/auth/verify", s.Auth.HandleVerify) protected := http.NewServeMux() protected.HandleFunc("/api/whoami", s.handleWhoami) mw := AuthMiddleware(s.Signer, s.Logger) mux.Handle("/api/", mw(protected)) return mux } // handleWhoami returns the verified tenant identity. Useful for // frontend session-bootstrapping and as the canonical example of a // tenant-scoped handler. func (s *Server) handleWhoami(w http.ResponseWriter, r *http.Request) { t, err := TenantFrom(r.Context()) if err != nil { http.Error(w, "unauthorized", http.StatusUnauthorized) return } w.Header().Set("Content-Type", "application/json") _ = json.NewEncoder(w).Encode(map[string]string{ "user_id": t.UserID, "email": t.Email, }) }