Files
ersatztv/web/src/api/auth.ts
T
timothyandClaude Opus 4.8 ef2bd65c27
Build ErsatzTV Image / decisions.md append-only (pull_request) Successful in 10s
Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 10s
Build ErsatzTV Image / Formatting (changed .cs conform to .editorconfig) (pull_request) Successful in 1m12s
Build ErsatzTV Image / API docs in sync (OpenAPI + endpoint index) (pull_request) Successful in 3m4s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 8m17s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 10m36s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
feat(api): #286 — mount the whole /api surface at /api/v1
Version every /api route to /api/v1 (251 controller routes + ~24 Location
headers + the scanner callback URL + the Startup request-log literal),
uniform across the machine API, auth, scanner and scripted-build surfaces.

Add ApiVersionRewriteMiddleware: a legacy unversioned /api/* request is
rewritten (NOT redirected) to /api/v1/* in-pipeline — method, body, auth
headers and query survive — carrying RFC 8594 Deprecation/Sunset headers,
so curl / the future MCP server / bookmarks keep working. An already-
versioned path passes through; a future /api/v2 is never forced to v1.

Standardize the route convention (leading-slash absolute route per method,
no class-[Route] — except the two Scanner/Scripted controllers whose ~all
actions share a parametrized {id} prefix), enforced by ApiRouteVersioningTests
(^/api/v\d+/ over the whole Controllers.Api surface; browser-nav
/auth/oidc/login is out of scope).

Regenerate v1.json (160 paths, all /api/v1)/endpoint-index/v1.d.ts; sweep 945
SPA request literals + the test mocks (regex + positional URL parsers). /api/v1
is additive-only after freeze; the legacy-rewrite shim sunsets in ~2 releases
(owner decision) with removal tracked as a Phase-3 follow-up.

Docs: decisions.md 2026-07-13, api-conventions §1/§9, rest-api/spa-conventions/
blazor-route-parity/e2e-local/domain-model.

fixes #286
refs #197

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-13 00:30:20 +02:00

120 lines
4.4 KiB
TypeScript

import { request } from './client';
// --- wire types -------------------------------------------------------------
// The auth surface (`/api/v1/auth/*`) is deliberately excluded from the OpenAPI document (server-side
// [IgnoreApi]), so — unlike every other domain module (spa-conventions §4) — these DTOs are NOT in the
// generated types and are hand-written here. Keep the field names camelCase to match the server records
// exactly (the JSON the auth endpoints emit). This deviation is intentional; do not try to source these
// from `./generated/v1`.
/** `GET /api/v1/auth/config` — PUBLIC; drives the boot gate. */
export interface AuthConfig {
oidcEnabled: boolean;
localLoginEnabled: boolean;
setupRequired: boolean;
}
/** `GET /api/v1/auth/session` — anonymous callers get 200 with `authenticated: false` (never 401). */
export interface AuthSession {
authenticated: boolean;
// Omitted (undefined) for anonymous callers — the server serializes `{ "authenticated": false }` and
// Newtonsoft's global NullValueHandling.Ignore drops these when null, so they are optional on the wire.
username?: string | null;
method?: string | null;
}
/**
* `GET /api/v1/auth/machine-key` — the server-generated machine API key.
* The wire field is `apiKey` (server record `MachineKeyResponse(string ApiKey)`), not `key`.
*/
export interface MachineKey {
apiKey: string;
}
const legacyApiKeyStorageKey = 'ctv-api-key';
function getStorage(): Storage | undefined {
if (typeof window === 'undefined') {
return undefined;
}
try {
return window.localStorage;
} catch {
return undefined;
}
}
// The SPA no longer stores or sends an API key — it authenticates with the session cookie (#295). This
// one-shot cleanup removes any legacy `ctv-api-key` left over from the pre-session model; AuthGate calls
// it once on reaching `ready`. (The former `get/set/clearStoredApiKey` shims were removed once the
// ApiKeyScreen stopped consuming them — this is the sole remaining reader of the legacy key.)
export function clearLegacyStoredApiKey(): void {
getStorage()?.removeItem(legacyApiKeyStorageKey);
}
// --- 401 signal -------------------------------------------------------------
// The whole `/api` surface is gated behind an authenticated session cookie (#295). Rather than teach
// every screen's error path to special-case 401, the request client emits a single app-wide signal when
// any request comes back Unauthorized; a shell-level banner subscribes and prompts the user to sign in.
// Kept here (in the auth domain module) so it never depends on a successful `/api` call.
type UnauthorizedListener = () => void;
const unauthorizedListeners = new Set<UnauthorizedListener>();
export function subscribeUnauthorized(listener: UnauthorizedListener): () => void {
unauthorizedListeners.add(listener);
return () => {
unauthorizedListeners.delete(listener);
};
}
export function notifyUnauthorized(): void {
for (const listener of unauthorizedListeners) {
listener();
}
}
// --- auth endpoints ---------------------------------------------------------
export function getAuthConfig(): Promise<AuthConfig> {
return request<AuthConfig>('/api/v1/auth/config');
}
export function getAuthSession(): Promise<AuthSession> {
return request<AuthSession>('/api/v1/auth/session');
}
export function login(username: string, password: string): Promise<AuthSession> {
// A wrong-password 401 is an expected inline answer here — it must NOT trip the global 401 banner.
return request<AuthSession>('/api/v1/auth/login', {
body: { username, password },
method: 'POST',
suppressUnauthorizedSignal: true
});
}
export function setup(username: string, password: string): Promise<AuthSession> {
return request<AuthSession>('/api/v1/auth/setup', {
body: { username, password },
method: 'POST'
});
}
export function logout(): Promise<void> {
return request<void>('/api/v1/auth/logout', { method: 'POST' });
}
export function changePassword(currentPassword: string, newPassword: string): Promise<void> {
// A wrong current-password 401 is shown inline, not via the global banner.
return request<void>('/api/v1/auth/password', {
body: { currentPassword, newPassword },
method: 'POST',
suppressUnauthorizedSignal: true
});
}
export function getMachineKey(): Promise<MachineKey> {
return request<MachineKey>('/api/v1/auth/machine-key');
}