Document every exported symbol and how callers use the library.
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
+14
-11
@@ -2,6 +2,7 @@ package gonexapp
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
"slices"
|
||||
"strings"
|
||||
"sync"
|
||||
"time"
|
||||
@@ -39,7 +40,13 @@ const (
|
||||
CheckUnavailable
|
||||
)
|
||||
|
||||
// Wrap returns a handler that applies the Access Gate before next.
|
||||
// Wrap returns a handler that runs Check before next.
|
||||
// CheckAllowed calls next.
|
||||
// CheckUnauthorized writes 401. CheckUnavailable writes 503.
|
||||
// CheckDenied writes English HTML with status 200 and frame-ancestors 'self'
|
||||
// when the request accepts text/html, and 403 otherwise.
|
||||
// An empty Groups list allows every request. Paths /heartbeat, /enabled,
|
||||
// /init, and /js/ are skipped, plus ExtraSkipPaths.
|
||||
func (g AccessGate) Wrap(next http.Handler) http.Handler {
|
||||
gate := g.normalized()
|
||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
@@ -93,13 +100,11 @@ func (g *AccessGate) memberOfRequired(userID string) (bool, error) {
|
||||
return false, err
|
||||
}
|
||||
for _, need := range g.Groups {
|
||||
for _, have := range groups {
|
||||
if have == need {
|
||||
if g.CacheTTL > 0 {
|
||||
g.storeAllowed(key)
|
||||
}
|
||||
return true, nil
|
||||
if slices.Contains(groups, need) {
|
||||
if g.CacheTTL > 0 {
|
||||
g.storeAllowed(key)
|
||||
}
|
||||
return true, nil
|
||||
}
|
||||
}
|
||||
return false, nil
|
||||
@@ -166,10 +171,8 @@ func (g *AccessGate) shouldSkip(path string) bool {
|
||||
if isTopMenuScriptPath(path) {
|
||||
return true
|
||||
}
|
||||
for _, p := range defaultSkipPaths {
|
||||
if path == p {
|
||||
return true
|
||||
}
|
||||
if slices.Contains(defaultSkipPaths, path) {
|
||||
return true
|
||||
}
|
||||
for _, p := range g.ExtraSkipPaths {
|
||||
if path == normalizeGatePath(p) {
|
||||
|
||||
Reference in New Issue
Block a user