Files
ersatztv/ErsatzTV/Filters/LocalhostOnlyAttribute.cs
T
timothyandClaude Opus 4.8 ef2bd65c27
Build ErsatzTV Image / decisions.md append-only (pull_request) Successful in 10s
Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 10s
Build ErsatzTV Image / Formatting (changed .cs conform to .editorconfig) (pull_request) Successful in 1m12s
Build ErsatzTV Image / API docs in sync (OpenAPI + endpoint index) (pull_request) Successful in 3m4s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 8m17s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 10m36s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
feat(api): #286 — mount the whole /api surface at /api/v1
Version every /api route to /api/v1 (251 controller routes + ~24 Location
headers + the scanner callback URL + the Startup request-log literal),
uniform across the machine API, auth, scanner and scripted-build surfaces.

Add ApiVersionRewriteMiddleware: a legacy unversioned /api/* request is
rewritten (NOT redirected) to /api/v1/* in-pipeline — method, body, auth
headers and query survive — carrying RFC 8594 Deprecation/Sunset headers,
so curl / the future MCP server / bookmarks keep working. An already-
versioned path passes through; a future /api/v2 is never forced to v1.

Standardize the route convention (leading-slash absolute route per method,
no class-[Route] — except the two Scanner/Scripted controllers whose ~all
actions share a parametrized {id} prefix), enforced by ApiRouteVersioningTests
(^/api/v\d+/ over the whole Controllers.Api surface; browser-nav
/auth/oidc/login is out of scope).

Regenerate v1.json (160 paths, all /api/v1)/endpoint-index/v1.d.ts; sweep 945
SPA request literals + the test mocks (regex + positional URL parsers). /api/v1
is additive-only after freeze; the legacy-rewrite shim sunsets in ~2 releases
(owner decision) with removal tracked as a Phase-3 follow-up.

Docs: decisions.md 2026-07-13, api-conventions §1/§9, rest-api/spa-conventions/
blazor-route-parity/e2e-local/domain-model.

fixes #286
refs #197

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-13 00:30:20 +02:00

39 lines
1.5 KiB
C#

using System.Net;
using Microsoft.AspNetCore.Http;
using Microsoft.AspNetCore.Mvc;
using Microsoft.AspNetCore.Mvc.Filters;
namespace ErsatzTV.Filters;
/// <summary>
/// Restricts an endpoint to loopback callers (127.0.0.0/8, ::1). Used for the in-process scanner
/// callback surface (<c>/api/v1/scan/*</c>), which is always reached over
/// <c>http://localhost:{UiPort}</c> from the co-located scanner child process. Replaces relying
/// on a guessable scan-id GUID as the sole gate (issue #285). This is only spoof-resistant when
/// <c>ForwardedHeaders</c> trust is restricted (KnownProxies/KnownNetworks configured), since the
/// forwarded-headers middleware rewrites <see cref="ConnectionInfo.RemoteIpAddress" />.
/// </summary>
[AttributeUsage(AttributeTargets.Class | AttributeTargets.Method)]
public sealed class LocalhostOnlyAttribute : ActionFilterAttribute
{
public override void OnActionExecuting(ActionExecutingContext context)
{
IPAddress remoteIp = context.HttpContext.Connection.RemoteIpAddress;
if (remoteIp is null || !IsLoopback(remoteIp))
{
context.Result = new StatusCodeResult(StatusCodes.Status403Forbidden);
}
}
private static bool IsLoopback(IPAddress address)
{
if (IPAddress.IsLoopback(address))
{
return true;
}
// A loopback IPv4 address can arrive mapped into IPv6 (::ffff:127.0.0.1).
return address.IsIPv4MappedToIPv6 && IPAddress.IsLoopback(address.MapToIPv4());
}
}