feat(api): #286 — mount the whole /api surface at /api/v1
Build ErsatzTV Image / decisions.md append-only (pull_request) Successful in 10s
Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 10s
Build ErsatzTV Image / Formatting (changed .cs conform to .editorconfig) (pull_request) Successful in 1m12s
Build ErsatzTV Image / API docs in sync (OpenAPI + endpoint index) (pull_request) Successful in 3m4s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 8m17s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 10m36s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped

Version every /api route to /api/v1 (251 controller routes + ~24 Location
headers + the scanner callback URL + the Startup request-log literal),
uniform across the machine API, auth, scanner and scripted-build surfaces.

Add ApiVersionRewriteMiddleware: a legacy unversioned /api/* request is
rewritten (NOT redirected) to /api/v1/* in-pipeline — method, body, auth
headers and query survive — carrying RFC 8594 Deprecation/Sunset headers,
so curl / the future MCP server / bookmarks keep working. An already-
versioned path passes through; a future /api/v2 is never forced to v1.

Standardize the route convention (leading-slash absolute route per method,
no class-[Route] — except the two Scanner/Scripted controllers whose ~all
actions share a parametrized {id} prefix), enforced by ApiRouteVersioningTests
(^/api/v\d+/ over the whole Controllers.Api surface; browser-nav
/auth/oidc/login is out of scope).

Regenerate v1.json (160 paths, all /api/v1)/endpoint-index/v1.d.ts; sweep 945
SPA request literals + the test mocks (regex + positional URL parsers). /api/v1
is additive-only after freeze; the legacy-rewrite shim sunsets in ~2 releases
(owner decision) with removal tracked as a Phase-3 follow-up.

Docs: decisions.md 2026-07-13, api-conventions §1/§9, rest-api/spa-conventions/
blazor-route-parity/e2e-local/domain-model.

fixes #286
refs #197

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-07-13 00:30:20 +02:00
co-authored by Claude Opus 4.8
parent 51b67dea06
commit ef2bd65c27
218 changed files with 2586 additions and 2285 deletions
+11 -11
View File
@@ -1,20 +1,20 @@
import { request } from './client';
// --- wire types -------------------------------------------------------------
// The auth surface (`/api/auth/*`) is deliberately excluded from the OpenAPI document (server-side
// The auth surface (`/api/v1/auth/*`) is deliberately excluded from the OpenAPI document (server-side
// [IgnoreApi]), so — unlike every other domain module (spa-conventions §4) — these DTOs are NOT in the
// generated types and are hand-written here. Keep the field names camelCase to match the server records
// exactly (the JSON the auth endpoints emit). This deviation is intentional; do not try to source these
// from `./generated/v1`.
/** `GET /api/auth/config` — PUBLIC; drives the boot gate. */
/** `GET /api/v1/auth/config` — PUBLIC; drives the boot gate. */
export interface AuthConfig {
oidcEnabled: boolean;
localLoginEnabled: boolean;
setupRequired: boolean;
}
/** `GET /api/auth/session` — anonymous callers get 200 with `authenticated: false` (never 401). */
/** `GET /api/v1/auth/session` — anonymous callers get 200 with `authenticated: false` (never 401). */
export interface AuthSession {
authenticated: boolean;
// Omitted (undefined) for anonymous callers — the server serializes `{ "authenticated": false }` and
@@ -24,7 +24,7 @@ export interface AuthSession {
}
/**
* `GET /api/auth/machine-key` — the server-generated machine API key.
* `GET /api/v1/auth/machine-key` — the server-generated machine API key.
* The wire field is `apiKey` (server record `MachineKeyResponse(string ApiKey)`), not `key`.
*/
export interface MachineKey {
@@ -78,16 +78,16 @@ export function notifyUnauthorized(): void {
// --- auth endpoints ---------------------------------------------------------
export function getAuthConfig(): Promise<AuthConfig> {
return request<AuthConfig>('/api/auth/config');
return request<AuthConfig>('/api/v1/auth/config');
}
export function getAuthSession(): Promise<AuthSession> {
return request<AuthSession>('/api/auth/session');
return request<AuthSession>('/api/v1/auth/session');
}
export function login(username: string, password: string): Promise<AuthSession> {
// A wrong-password 401 is an expected inline answer here — it must NOT trip the global 401 banner.
return request<AuthSession>('/api/auth/login', {
return request<AuthSession>('/api/v1/auth/login', {
body: { username, password },
method: 'POST',
suppressUnauthorizedSignal: true
@@ -95,19 +95,19 @@ export function login(username: string, password: string): Promise<AuthSession>
}
export function setup(username: string, password: string): Promise<AuthSession> {
return request<AuthSession>('/api/auth/setup', {
return request<AuthSession>('/api/v1/auth/setup', {
body: { username, password },
method: 'POST'
});
}
export function logout(): Promise<void> {
return request<void>('/api/auth/logout', { method: 'POST' });
return request<void>('/api/v1/auth/logout', { method: 'POST' });
}
export function changePassword(currentPassword: string, newPassword: string): Promise<void> {
// A wrong current-password 401 is shown inline, not via the global banner.
return request<void>('/api/auth/password', {
return request<void>('/api/v1/auth/password', {
body: { currentPassword, newPassword },
method: 'POST',
suppressUnauthorizedSignal: true
@@ -115,5 +115,5 @@ export function changePassword(currentPassword: string, newPassword: string): Pr
}
export function getMachineKey(): Promise<MachineKey> {
return request<MachineKey>('/api/auth/machine-key');
return request<MachineKey>('/api/v1/auth/machine-key');
}