feat(api): #286 — mount the whole /api surface at /api/v1
Build ErsatzTV Image / decisions.md append-only (pull_request) Successful in 10s
Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 10s
Build ErsatzTV Image / Formatting (changed .cs conform to .editorconfig) (pull_request) Successful in 1m12s
Build ErsatzTV Image / API docs in sync (OpenAPI + endpoint index) (pull_request) Successful in 3m4s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 8m17s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 10m36s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
Build ErsatzTV Image / decisions.md append-only (pull_request) Successful in 10s
Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 10s
Build ErsatzTV Image / Formatting (changed .cs conform to .editorconfig) (pull_request) Successful in 1m12s
Build ErsatzTV Image / API docs in sync (OpenAPI + endpoint index) (pull_request) Successful in 3m4s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 8m17s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 10m36s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
Version every /api route to /api/v1 (251 controller routes + ~24 Location
headers + the scanner callback URL + the Startup request-log literal),
uniform across the machine API, auth, scanner and scripted-build surfaces.
Add ApiVersionRewriteMiddleware: a legacy unversioned /api/* request is
rewritten (NOT redirected) to /api/v1/* in-pipeline — method, body, auth
headers and query survive — carrying RFC 8594 Deprecation/Sunset headers,
so curl / the future MCP server / bookmarks keep working. An already-
versioned path passes through; a future /api/v2 is never forced to v1.
Standardize the route convention (leading-slash absolute route per method,
no class-[Route] — except the two Scanner/Scripted controllers whose ~all
actions share a parametrized {id} prefix), enforced by ApiRouteVersioningTests
(^/api/v\d+/ over the whole Controllers.Api surface; browser-nav
/auth/oidc/login is out of scope).
Regenerate v1.json (160 paths, all /api/v1)/endpoint-index/v1.d.ts; sweep 945
SPA request literals + the test mocks (regex + positional URL parsers). /api/v1
is additive-only after freeze; the legacy-rewrite shim sunsets in ~2 releases
(owner decision) with removal tracked as a Phase-3 follow-up.
Docs: decisions.md 2026-07-13, api-conventions §1/§9, rest-api/spa-conventions/
blazor-route-parity/e2e-local/domain-model.
fixes #286
refs #197
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
+11
-11
@@ -1,20 +1,20 @@
|
||||
import { request } from './client';
|
||||
|
||||
// --- wire types -------------------------------------------------------------
|
||||
// The auth surface (`/api/auth/*`) is deliberately excluded from the OpenAPI document (server-side
|
||||
// The auth surface (`/api/v1/auth/*`) is deliberately excluded from the OpenAPI document (server-side
|
||||
// [IgnoreApi]), so — unlike every other domain module (spa-conventions §4) — these DTOs are NOT in the
|
||||
// generated types and are hand-written here. Keep the field names camelCase to match the server records
|
||||
// exactly (the JSON the auth endpoints emit). This deviation is intentional; do not try to source these
|
||||
// from `./generated/v1`.
|
||||
|
||||
/** `GET /api/auth/config` — PUBLIC; drives the boot gate. */
|
||||
/** `GET /api/v1/auth/config` — PUBLIC; drives the boot gate. */
|
||||
export interface AuthConfig {
|
||||
oidcEnabled: boolean;
|
||||
localLoginEnabled: boolean;
|
||||
setupRequired: boolean;
|
||||
}
|
||||
|
||||
/** `GET /api/auth/session` — anonymous callers get 200 with `authenticated: false` (never 401). */
|
||||
/** `GET /api/v1/auth/session` — anonymous callers get 200 with `authenticated: false` (never 401). */
|
||||
export interface AuthSession {
|
||||
authenticated: boolean;
|
||||
// Omitted (undefined) for anonymous callers — the server serializes `{ "authenticated": false }` and
|
||||
@@ -24,7 +24,7 @@ export interface AuthSession {
|
||||
}
|
||||
|
||||
/**
|
||||
* `GET /api/auth/machine-key` — the server-generated machine API key.
|
||||
* `GET /api/v1/auth/machine-key` — the server-generated machine API key.
|
||||
* The wire field is `apiKey` (server record `MachineKeyResponse(string ApiKey)`), not `key`.
|
||||
*/
|
||||
export interface MachineKey {
|
||||
@@ -78,16 +78,16 @@ export function notifyUnauthorized(): void {
|
||||
// --- auth endpoints ---------------------------------------------------------
|
||||
|
||||
export function getAuthConfig(): Promise<AuthConfig> {
|
||||
return request<AuthConfig>('/api/auth/config');
|
||||
return request<AuthConfig>('/api/v1/auth/config');
|
||||
}
|
||||
|
||||
export function getAuthSession(): Promise<AuthSession> {
|
||||
return request<AuthSession>('/api/auth/session');
|
||||
return request<AuthSession>('/api/v1/auth/session');
|
||||
}
|
||||
|
||||
export function login(username: string, password: string): Promise<AuthSession> {
|
||||
// A wrong-password 401 is an expected inline answer here — it must NOT trip the global 401 banner.
|
||||
return request<AuthSession>('/api/auth/login', {
|
||||
return request<AuthSession>('/api/v1/auth/login', {
|
||||
body: { username, password },
|
||||
method: 'POST',
|
||||
suppressUnauthorizedSignal: true
|
||||
@@ -95,19 +95,19 @@ export function login(username: string, password: string): Promise<AuthSession>
|
||||
}
|
||||
|
||||
export function setup(username: string, password: string): Promise<AuthSession> {
|
||||
return request<AuthSession>('/api/auth/setup', {
|
||||
return request<AuthSession>('/api/v1/auth/setup', {
|
||||
body: { username, password },
|
||||
method: 'POST'
|
||||
});
|
||||
}
|
||||
|
||||
export function logout(): Promise<void> {
|
||||
return request<void>('/api/auth/logout', { method: 'POST' });
|
||||
return request<void>('/api/v1/auth/logout', { method: 'POST' });
|
||||
}
|
||||
|
||||
export function changePassword(currentPassword: string, newPassword: string): Promise<void> {
|
||||
// A wrong current-password 401 is shown inline, not via the global banner.
|
||||
return request<void>('/api/auth/password', {
|
||||
return request<void>('/api/v1/auth/password', {
|
||||
body: { currentPassword, newPassword },
|
||||
method: 'POST',
|
||||
suppressUnauthorizedSignal: true
|
||||
@@ -115,5 +115,5 @@ export function changePassword(currentPassword: string, newPassword: string): Pr
|
||||
}
|
||||
|
||||
export function getMachineKey(): Promise<MachineKey> {
|
||||
return request<MachineKey>('/api/auth/machine-key');
|
||||
return request<MachineKey>('/api/v1/auth/machine-key');
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user