Files
librenotes/internal/httpapi/router.go
T
libretechandClaude Opus 4.7 635a03098b Add Dockerfile, Compose stacks, and /healthz endpoint
Dockerfile is multi-stage:
- build: golang:1.25-bookworm, CGO_ENABLED=0 (modernc.org/sqlite
  is pure-Go) + -trimpath + -ldflags "-s -w" so the resulting
  binary is small and reproducible-ish.
- runtime: gcr.io/distroless/static:nonroot, ~2 MB. Runs as uid
  65532. /data and /var/lib/librenotes are declared volumes so
  per-tenant notes and the SQLite database survive container
  restarts.

healthcheck subcommand: distroless static has no shell or
wget/curl, so /healthz is reachable but no client to call it. A
new "librenotes healthcheck" subcommand uses net/http to GET
$LIBRENOTES_HEALTHCHECK_URL (default 127.0.0.1:8080/healthz) and
exits non-zero on failure. Both compose files invoke it from the
HEALTHCHECK directive.

httpapi adds a tiny GET /healthz that returns {"status":"ok"}
(no DB ping yet — added when readiness probes need it).

docker-compose.yml: dev stack on :8080 with named volumes and a
LogMailer; everything via env vars, JWT secret defaulted to a
dev value.
docker-compose.prod.yml: layered overrides — pulls a registry
image, expects LIBRENOTES_* env, sets memory limits and JSON-
file log rotation.

Closes #25.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-28 22:47:42 +02:00

59 lines
1.6 KiB
Go

package httpapi
import (
"encoding/json"
"log"
"net/http"
"git.librete.ch/public/librenotes/internal/auth"
)
// Server wires routes for the multi-tenant backend. The auth endpoints
// live under /auth/* and are unauthenticated. Everything under /api/*
// is wrapped by AuthMiddleware and receives a Tenant on the context.
type Server struct {
Auth auth.Handlers
Signer *auth.Signer
Logger *log.Logger
Notes NotesHandler
}
// Routes returns an http.Handler with all routes mounted.
func (s *Server) Routes() http.Handler {
mux := http.NewServeMux()
mux.HandleFunc("/healthz", func(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
_, _ = w.Write([]byte(`{"status":"ok"}`))
})
mux.HandleFunc("/auth/login", s.Auth.HandleLogin)
mux.HandleFunc("/auth/verify", s.Auth.HandleVerify)
protected := http.NewServeMux()
protected.HandleFunc("/api/whoami", s.handleWhoami)
if s.Notes.FSFor != nil {
s.Notes.Mount(protected)
}
mw := AuthMiddleware(s.Signer, s.Logger)
mux.Handle("/api/", mw(protected))
return mux
}
// handleWhoami returns the verified tenant identity. Useful for
// frontend session-bootstrapping and as the canonical example of a
// tenant-scoped handler.
func (s *Server) handleWhoami(w http.ResponseWriter, r *http.Request) {
t, err := TenantFrom(r.Context())
if err != nil {
http.Error(w, "unauthorized", http.StatusUnauthorized)
return
}
w.Header().Set("Content-Type", "application/json")
_ = json.NewEncoder(w).Encode(map[string]string{
"user_id": t.UserID,
"email": t.Email,
})
}