Build ErsatzTV Image / decisions.md append-only (pull_request) Successful in 10s
Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 10s
Build ErsatzTV Image / Formatting (changed .cs conform to .editorconfig) (pull_request) Successful in 1m12s
Build ErsatzTV Image / API docs in sync (OpenAPI + endpoint index) (pull_request) Successful in 3m4s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 8m17s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 10m36s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
Version every /api route to /api/v1 (251 controller routes + ~24 Location
headers + the scanner callback URL + the Startup request-log literal),
uniform across the machine API, auth, scanner and scripted-build surfaces.
Add ApiVersionRewriteMiddleware: a legacy unversioned /api/* request is
rewritten (NOT redirected) to /api/v1/* in-pipeline — method, body, auth
headers and query survive — carrying RFC 8594 Deprecation/Sunset headers,
so curl / the future MCP server / bookmarks keep working. An already-
versioned path passes through; a future /api/v2 is never forced to v1.
Standardize the route convention (leading-slash absolute route per method,
no class-[Route] — except the two Scanner/Scripted controllers whose ~all
actions share a parametrized {id} prefix), enforced by ApiRouteVersioningTests
(^/api/v\d+/ over the whole Controllers.Api surface; browser-nav
/auth/oidc/login is out of scope).
Regenerate v1.json (160 paths, all /api/v1)/endpoint-index/v1.d.ts; sweep 945
SPA request literals + the test mocks (regex + positional URL parsers). /api/v1
is additive-only after freeze; the legacy-rewrite shim sunsets in ~2 releases
(owner decision) with removal tracked as a Phase-3 follow-up.
Docs: decisions.md 2026-07-13, api-conventions §1/§9, rest-api/spa-conventions/
blazor-route-parity/e2e-local/domain-model.
fixes #286
refs #197
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
120 lines
4.4 KiB
TypeScript
120 lines
4.4 KiB
TypeScript
import { request } from './client';
|
|
|
|
// --- wire types -------------------------------------------------------------
|
|
// The auth surface (`/api/v1/auth/*`) is deliberately excluded from the OpenAPI document (server-side
|
|
// [IgnoreApi]), so — unlike every other domain module (spa-conventions §4) — these DTOs are NOT in the
|
|
// generated types and are hand-written here. Keep the field names camelCase to match the server records
|
|
// exactly (the JSON the auth endpoints emit). This deviation is intentional; do not try to source these
|
|
// from `./generated/v1`.
|
|
|
|
/** `GET /api/v1/auth/config` — PUBLIC; drives the boot gate. */
|
|
export interface AuthConfig {
|
|
oidcEnabled: boolean;
|
|
localLoginEnabled: boolean;
|
|
setupRequired: boolean;
|
|
}
|
|
|
|
/** `GET /api/v1/auth/session` — anonymous callers get 200 with `authenticated: false` (never 401). */
|
|
export interface AuthSession {
|
|
authenticated: boolean;
|
|
// Omitted (undefined) for anonymous callers — the server serializes `{ "authenticated": false }` and
|
|
// Newtonsoft's global NullValueHandling.Ignore drops these when null, so they are optional on the wire.
|
|
username?: string | null;
|
|
method?: string | null;
|
|
}
|
|
|
|
/**
|
|
* `GET /api/v1/auth/machine-key` — the server-generated machine API key.
|
|
* The wire field is `apiKey` (server record `MachineKeyResponse(string ApiKey)`), not `key`.
|
|
*/
|
|
export interface MachineKey {
|
|
apiKey: string;
|
|
}
|
|
|
|
const legacyApiKeyStorageKey = 'ctv-api-key';
|
|
|
|
function getStorage(): Storage | undefined {
|
|
if (typeof window === 'undefined') {
|
|
return undefined;
|
|
}
|
|
|
|
try {
|
|
return window.localStorage;
|
|
} catch {
|
|
return undefined;
|
|
}
|
|
}
|
|
|
|
// The SPA no longer stores or sends an API key — it authenticates with the session cookie (#295). This
|
|
// one-shot cleanup removes any legacy `ctv-api-key` left over from the pre-session model; AuthGate calls
|
|
// it once on reaching `ready`. (The former `get/set/clearStoredApiKey` shims were removed once the
|
|
// ApiKeyScreen stopped consuming them — this is the sole remaining reader of the legacy key.)
|
|
export function clearLegacyStoredApiKey(): void {
|
|
getStorage()?.removeItem(legacyApiKeyStorageKey);
|
|
}
|
|
|
|
// --- 401 signal -------------------------------------------------------------
|
|
// The whole `/api` surface is gated behind an authenticated session cookie (#295). Rather than teach
|
|
// every screen's error path to special-case 401, the request client emits a single app-wide signal when
|
|
// any request comes back Unauthorized; a shell-level banner subscribes and prompts the user to sign in.
|
|
// Kept here (in the auth domain module) so it never depends on a successful `/api` call.
|
|
type UnauthorizedListener = () => void;
|
|
|
|
const unauthorizedListeners = new Set<UnauthorizedListener>();
|
|
|
|
export function subscribeUnauthorized(listener: UnauthorizedListener): () => void {
|
|
unauthorizedListeners.add(listener);
|
|
return () => {
|
|
unauthorizedListeners.delete(listener);
|
|
};
|
|
}
|
|
|
|
export function notifyUnauthorized(): void {
|
|
for (const listener of unauthorizedListeners) {
|
|
listener();
|
|
}
|
|
}
|
|
|
|
// --- auth endpoints ---------------------------------------------------------
|
|
|
|
export function getAuthConfig(): Promise<AuthConfig> {
|
|
return request<AuthConfig>('/api/v1/auth/config');
|
|
}
|
|
|
|
export function getAuthSession(): Promise<AuthSession> {
|
|
return request<AuthSession>('/api/v1/auth/session');
|
|
}
|
|
|
|
export function login(username: string, password: string): Promise<AuthSession> {
|
|
// A wrong-password 401 is an expected inline answer here — it must NOT trip the global 401 banner.
|
|
return request<AuthSession>('/api/v1/auth/login', {
|
|
body: { username, password },
|
|
method: 'POST',
|
|
suppressUnauthorizedSignal: true
|
|
});
|
|
}
|
|
|
|
export function setup(username: string, password: string): Promise<AuthSession> {
|
|
return request<AuthSession>('/api/v1/auth/setup', {
|
|
body: { username, password },
|
|
method: 'POST'
|
|
});
|
|
}
|
|
|
|
export function logout(): Promise<void> {
|
|
return request<void>('/api/v1/auth/logout', { method: 'POST' });
|
|
}
|
|
|
|
export function changePassword(currentPassword: string, newPassword: string): Promise<void> {
|
|
// A wrong current-password 401 is shown inline, not via the global banner.
|
|
return request<void>('/api/v1/auth/password', {
|
|
body: { currentPassword, newPassword },
|
|
method: 'POST',
|
|
suppressUnauthorizedSignal: true
|
|
});
|
|
}
|
|
|
|
export function getMachineKey(): Promise<MachineKey> {
|
|
return request<MachineKey>('/api/v1/auth/machine-key');
|
|
}
|