router.go 24 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166
  1. package router
  2. import (
  3. "net/http"
  4. "os"
  5. "github.com/go-chi/chi"
  6. "github.com/porter-dev/porter/internal/auth/token"
  7. "github.com/porter-dev/porter/server/api"
  8. "github.com/porter-dev/porter/server/requestlog"
  9. mw "github.com/porter-dev/porter/server/router/middleware"
  10. )
  11. // New creates a new Chi router instance and registers all routes supported by the
  12. // API
  13. func New(a *api.App) *chi.Mux {
  14. l := a.Logger
  15. r := chi.NewRouter()
  16. auth := mw.NewAuth(a.Store, a.ServerConf.CookieName, &token.TokenGeneratorConf{
  17. TokenSecret: a.ServerConf.TokenGeneratorSecret,
  18. }, a.Repo)
  19. r.Route("/api", func(r chi.Router) {
  20. r.Use(mw.ContentTypeJSON)
  21. // health checks
  22. r.Method("GET", "/livez", http.HandlerFunc(a.HandleLive))
  23. r.Method("GET", "/readyz", http.HandlerFunc(a.HandleReady))
  24. // /api/users routes
  25. r.Method(
  26. "GET",
  27. "/users/{user_id}",
  28. auth.DoesUserIDMatch(
  29. requestlog.NewHandler(a.HandleReadUser, l),
  30. mw.URLParam,
  31. ),
  32. )
  33. r.Method(
  34. "GET",
  35. "/users/{user_id}/projects",
  36. auth.DoesUserIDMatch(
  37. requestlog.NewHandler(a.HandleListUserProjects, l),
  38. mw.URLParam,
  39. ),
  40. )
  41. r.Method(
  42. "POST",
  43. "/users",
  44. requestlog.NewHandler(a.HandleCreateUser, l),
  45. )
  46. r.Method(
  47. "DELETE",
  48. "/users/{user_id}",
  49. auth.DoesUserIDMatch(
  50. requestlog.NewHandler(a.HandleDeleteUser, l),
  51. mw.URLParam,
  52. ),
  53. )
  54. r.Method(
  55. "GET",
  56. "/cli/login",
  57. auth.BasicAuthenticateWithRedirect(
  58. requestlog.NewHandler(a.HandleCLILoginUser, l),
  59. ),
  60. )
  61. r.Method(
  62. "GET",
  63. "/cli/login/exchange",
  64. requestlog.NewHandler(a.HandleCLILoginExchangeToken, l),
  65. )
  66. r.Method(
  67. "POST",
  68. "/login",
  69. requestlog.NewHandler(a.HandleLoginUser, l),
  70. )
  71. r.Method(
  72. "GET",
  73. "/auth/check",
  74. auth.BasicAuthenticate(
  75. requestlog.NewHandler(a.HandleAuthCheck, l),
  76. ),
  77. )
  78. r.Method(
  79. "POST",
  80. "/logout",
  81. auth.BasicAuthenticate(
  82. requestlog.NewHandler(a.HandleLogoutUser, l),
  83. ),
  84. )
  85. // /api/integrations routes
  86. r.Method(
  87. "GET",
  88. "/integrations/cluster",
  89. auth.BasicAuthenticate(
  90. requestlog.NewHandler(a.HandleListClusterIntegrations, l),
  91. ),
  92. )
  93. r.Method(
  94. "GET",
  95. "/integrations/registry",
  96. auth.BasicAuthenticate(
  97. requestlog.NewHandler(a.HandleListRegistryIntegrations, l),
  98. ),
  99. )
  100. r.Method(
  101. "GET",
  102. "/integrations/helm",
  103. auth.BasicAuthenticate(
  104. requestlog.NewHandler(a.HandleListHelmRepoIntegrations, l),
  105. ),
  106. )
  107. r.Method(
  108. "GET",
  109. "/integrations/repo",
  110. auth.BasicAuthenticate(
  111. requestlog.NewHandler(a.HandleListRepoIntegrations, l),
  112. ),
  113. )
  114. // /api/templates routes
  115. r.Method(
  116. "GET",
  117. "/templates",
  118. auth.BasicAuthenticate(
  119. requestlog.NewHandler(a.HandleListTemplates, l),
  120. ),
  121. )
  122. r.Method(
  123. "GET",
  124. "/templates/{name}/{version}",
  125. auth.BasicAuthenticate(
  126. requestlog.NewHandler(a.HandleReadTemplate, l),
  127. ),
  128. )
  129. // /api/oauth routes
  130. r.Method(
  131. "GET",
  132. "/oauth/projects/{project_id}/github",
  133. auth.DoesUserHaveProjectAccess(
  134. requestlog.NewHandler(a.HandleGithubOAuthStartProject, l),
  135. mw.URLParam,
  136. mw.WriteAccess,
  137. ),
  138. )
  139. r.Method(
  140. "GET",
  141. "/oauth/login/github",
  142. requestlog.NewHandler(a.HandleGithubOAuthStartUser, l),
  143. )
  144. r.Method(
  145. "GET",
  146. "/oauth/github/callback",
  147. requestlog.NewHandler(a.HandleGithubOAuthCallback, l),
  148. )
  149. r.Method(
  150. "GET",
  151. "/oauth/projects/{project_id}/digitalocean",
  152. auth.DoesUserHaveProjectAccess(
  153. requestlog.NewHandler(a.HandleDOOAuthStartProject, l),
  154. mw.URLParam,
  155. mw.WriteAccess,
  156. ),
  157. )
  158. r.Method(
  159. "GET",
  160. "/oauth/digitalocean/callback",
  161. requestlog.NewHandler(a.HandleDOOAuthCallback, l),
  162. )
  163. // /api/projects routes
  164. r.Method(
  165. "GET",
  166. "/projects/{project_id}",
  167. auth.DoesUserHaveProjectAccess(
  168. requestlog.NewHandler(a.HandleReadProject, l),
  169. mw.URLParam,
  170. mw.ReadAccess,
  171. ),
  172. )
  173. r.Method(
  174. "POST",
  175. "/projects",
  176. auth.BasicAuthenticate(
  177. requestlog.NewHandler(a.HandleCreateProject, l),
  178. ),
  179. )
  180. r.Method(
  181. "DELETE",
  182. "/projects/{project_id}",
  183. auth.DoesUserHaveProjectAccess(
  184. requestlog.NewHandler(a.HandleDeleteProject, l),
  185. mw.URLParam,
  186. mw.WriteAccess,
  187. ),
  188. )
  189. // /api/projects/{project_id}/ci routes
  190. r.Method(
  191. "POST",
  192. "/projects/{project_id}/ci/actions",
  193. auth.DoesUserHaveProjectAccess(
  194. auth.DoesUserHaveClusterAccess(
  195. requestlog.NewHandler(a.HandleCreateGitAction, l),
  196. mw.URLParam,
  197. mw.QueryParam,
  198. ),
  199. mw.URLParam,
  200. mw.ReadAccess,
  201. ),
  202. )
  203. // /api/projects/{project_id}/invites routes
  204. r.Method(
  205. "POST",
  206. "/projects/{project_id}/invites",
  207. auth.DoesUserHaveProjectAccess(
  208. requestlog.NewHandler(a.HandleCreateInvite, l),
  209. mw.URLParam,
  210. mw.WriteAccess,
  211. ),
  212. )
  213. r.Method(
  214. "GET",
  215. "/projects/{project_id}/invites",
  216. auth.DoesUserHaveProjectAccess(
  217. requestlog.NewHandler(a.HandleListProjectInvites, l),
  218. mw.URLParam,
  219. mw.ReadAccess,
  220. ),
  221. )
  222. r.Method(
  223. "GET",
  224. "/projects/{project_id}/invites/{token}",
  225. auth.BasicAuthenticateWithRedirect(
  226. requestlog.NewHandler(a.HandleAcceptInvite, l),
  227. ),
  228. )
  229. r.Method(
  230. "DELETE",
  231. "/projects/{project_id}/invites/{invite_id}",
  232. auth.DoesUserHaveProjectAccess(
  233. auth.DoesUserHaveInviteAccess(
  234. requestlog.NewHandler(a.HandleDeleteProjectInvite, l),
  235. mw.URLParam,
  236. mw.URLParam,
  237. ),
  238. mw.URLParam,
  239. mw.WriteAccess,
  240. ),
  241. )
  242. // /api/projects/{project_id}/infra routes
  243. r.Method(
  244. "GET",
  245. "/projects/{project_id}/infra",
  246. auth.DoesUserHaveProjectAccess(
  247. requestlog.NewHandler(a.HandleListProjectInfra, l),
  248. mw.URLParam,
  249. mw.ReadAccess,
  250. ),
  251. )
  252. // /api/projects/{project_id}/provision routes
  253. r.Method(
  254. "POST",
  255. "/projects/{project_id}/provision/test",
  256. auth.DoesUserHaveProjectAccess(
  257. requestlog.NewHandler(a.HandleProvisionTestInfra, l),
  258. mw.URLParam,
  259. mw.ReadAccess,
  260. ),
  261. )
  262. r.Method(
  263. "POST",
  264. "/projects/{project_id}/provision/ecr",
  265. auth.DoesUserHaveProjectAccess(
  266. auth.DoesUserHaveAWSIntegrationAccess(
  267. requestlog.NewHandler(a.HandleProvisionAWSECRInfra, l),
  268. mw.URLParam,
  269. mw.BodyParam,
  270. false,
  271. ),
  272. mw.URLParam,
  273. mw.ReadAccess,
  274. ),
  275. )
  276. r.Method(
  277. "POST",
  278. "/projects/{project_id}/provision/eks",
  279. auth.DoesUserHaveProjectAccess(
  280. auth.DoesUserHaveAWSIntegrationAccess(
  281. requestlog.NewHandler(a.HandleProvisionAWSEKSInfra, l),
  282. mw.URLParam,
  283. mw.BodyParam,
  284. false,
  285. ),
  286. mw.URLParam,
  287. mw.ReadAccess,
  288. ),
  289. )
  290. r.Method(
  291. "POST",
  292. "/projects/{project_id}/provision/gcr",
  293. auth.DoesUserHaveProjectAccess(
  294. auth.DoesUserHaveGCPIntegrationAccess(
  295. requestlog.NewHandler(a.HandleProvisionGCPGCRInfra, l),
  296. mw.URLParam,
  297. mw.BodyParam,
  298. false,
  299. ),
  300. mw.URLParam,
  301. mw.ReadAccess,
  302. ),
  303. )
  304. r.Method(
  305. "POST",
  306. "/projects/{project_id}/provision/gke",
  307. auth.DoesUserHaveProjectAccess(
  308. auth.DoesUserHaveGCPIntegrationAccess(
  309. requestlog.NewHandler(a.HandleProvisionGCPGKEInfra, l),
  310. mw.URLParam,
  311. mw.BodyParam,
  312. false,
  313. ),
  314. mw.URLParam,
  315. mw.ReadAccess,
  316. ),
  317. )
  318. r.Method(
  319. "POST",
  320. "/projects/{project_id}/provision/docr",
  321. auth.DoesUserHaveProjectAccess(
  322. auth.DoesUserHaveDOIntegrationAccess(
  323. requestlog.NewHandler(a.HandleProvisionDODOCRInfra, l),
  324. mw.URLParam,
  325. mw.BodyParam,
  326. false,
  327. ),
  328. mw.URLParam,
  329. mw.ReadAccess,
  330. ),
  331. )
  332. r.Method(
  333. "POST",
  334. "/projects/{project_id}/provision/doks",
  335. auth.DoesUserHaveProjectAccess(
  336. auth.DoesUserHaveDOIntegrationAccess(
  337. requestlog.NewHandler(a.HandleProvisionDODOKSInfra, l),
  338. mw.URLParam,
  339. mw.BodyParam,
  340. false,
  341. ),
  342. mw.URLParam,
  343. mw.ReadAccess,
  344. ),
  345. )
  346. r.Method(
  347. "GET",
  348. "/projects/{project_id}/provision/{kind}/{infra_id}/logs",
  349. auth.DoesUserHaveProjectAccess(
  350. auth.DoesUserHaveInfraAccess(
  351. requestlog.NewHandler(a.HandleGetProvisioningLogs, l),
  352. mw.URLParam,
  353. mw.URLParam,
  354. ),
  355. mw.URLParam,
  356. mw.ReadAccess,
  357. ),
  358. )
  359. r.Method(
  360. "POST",
  361. "/projects/{project_id}/provision/{kind}/{infra_id}/logs",
  362. auth.DoesUserHaveProjectAccess(
  363. auth.DoesUserHaveInfraAccess(
  364. requestlog.NewHandler(a.HandleGetProvisioningLogs, l),
  365. mw.URLParam,
  366. mw.URLParam,
  367. ),
  368. mw.URLParam,
  369. mw.ReadAccess,
  370. ),
  371. )
  372. r.Method(
  373. "POST",
  374. "/projects/{project_id}/infra/{infra_id}/ecr/destroy",
  375. auth.DoesUserHaveProjectAccess(
  376. auth.DoesUserHaveInfraAccess(
  377. requestlog.NewHandler(a.HandleDestroyAWSECRInfra, l),
  378. mw.URLParam,
  379. mw.URLParam,
  380. ),
  381. mw.URLParam,
  382. mw.ReadAccess,
  383. ),
  384. )
  385. r.Method(
  386. "POST",
  387. "/projects/{project_id}/infra/{infra_id}/test/destroy",
  388. auth.DoesUserHaveProjectAccess(
  389. auth.DoesUserHaveInfraAccess(
  390. requestlog.NewHandler(a.HandleDestroyTestInfra, l),
  391. mw.URLParam,
  392. mw.URLParam,
  393. ),
  394. mw.URLParam,
  395. mw.ReadAccess,
  396. ),
  397. )
  398. r.Method(
  399. "POST",
  400. "/projects/{project_id}/infra/{infra_id}/eks/destroy",
  401. auth.DoesUserHaveProjectAccess(
  402. auth.DoesUserHaveInfraAccess(
  403. requestlog.NewHandler(a.HandleDestroyAWSEKSInfra, l),
  404. mw.URLParam,
  405. mw.URLParam,
  406. ),
  407. mw.URLParam,
  408. mw.ReadAccess,
  409. ),
  410. )
  411. r.Method(
  412. "POST",
  413. "/projects/{project_id}/infra/{infra_id}/gke/destroy",
  414. auth.DoesUserHaveProjectAccess(
  415. auth.DoesUserHaveInfraAccess(
  416. requestlog.NewHandler(a.HandleDestroyGCPGKEInfra, l),
  417. mw.URLParam,
  418. mw.URLParam,
  419. ),
  420. mw.URLParam,
  421. mw.ReadAccess,
  422. ),
  423. )
  424. r.Method(
  425. "POST",
  426. "/projects/{project_id}/infra/{infra_id}/docr/destroy",
  427. auth.DoesUserHaveProjectAccess(
  428. auth.DoesUserHaveInfraAccess(
  429. requestlog.NewHandler(a.HandleDestroyDODOCRInfra, l),
  430. mw.URLParam,
  431. mw.URLParam,
  432. ),
  433. mw.URLParam,
  434. mw.ReadAccess,
  435. ),
  436. )
  437. r.Method(
  438. "POST",
  439. "/projects/{project_id}/infra/{infra_id}/doks/destroy",
  440. auth.DoesUserHaveProjectAccess(
  441. auth.DoesUserHaveInfraAccess(
  442. requestlog.NewHandler(a.HandleDestroyDODOKSInfra, l),
  443. mw.URLParam,
  444. mw.URLParam,
  445. ),
  446. mw.URLParam,
  447. mw.ReadAccess,
  448. ),
  449. )
  450. // /api/projects/{project_id}/clusters routes
  451. r.Method(
  452. "GET",
  453. "/projects/{project_id}/clusters",
  454. auth.DoesUserHaveProjectAccess(
  455. requestlog.NewHandler(a.HandleListProjectClusters, l),
  456. mw.URLParam,
  457. mw.ReadAccess,
  458. ),
  459. )
  460. r.Method(
  461. "POST",
  462. "/projects/{project_id}/clusters",
  463. auth.DoesUserHaveProjectAccess(
  464. auth.DoesUserHaveAWSIntegrationAccess(
  465. auth.DoesUserHaveGCPIntegrationAccess(
  466. requestlog.NewHandler(a.HandleCreateProjectCluster, l),
  467. mw.URLParam,
  468. mw.BodyParam,
  469. true,
  470. ),
  471. mw.URLParam,
  472. mw.BodyParam,
  473. true,
  474. ),
  475. mw.URLParam,
  476. mw.WriteAccess,
  477. ),
  478. )
  479. r.Method(
  480. "GET",
  481. "/projects/{project_id}/clusters/{cluster_id}",
  482. auth.DoesUserHaveProjectAccess(
  483. auth.DoesUserHaveClusterAccess(
  484. requestlog.NewHandler(a.HandleReadProjectCluster, l),
  485. mw.URLParam,
  486. mw.URLParam,
  487. ),
  488. mw.URLParam,
  489. mw.ReadAccess,
  490. ),
  491. )
  492. r.Method(
  493. "POST",
  494. "/projects/{project_id}/clusters/{cluster_id}",
  495. auth.DoesUserHaveProjectAccess(
  496. auth.DoesUserHaveClusterAccess(
  497. requestlog.NewHandler(a.HandleUpdateProjectCluster, l),
  498. mw.URLParam,
  499. mw.URLParam,
  500. ),
  501. mw.URLParam,
  502. mw.WriteAccess,
  503. ),
  504. )
  505. r.Method(
  506. "DELETE",
  507. "/projects/{project_id}/clusters/{cluster_id}",
  508. auth.DoesUserHaveProjectAccess(
  509. auth.DoesUserHaveClusterAccess(
  510. requestlog.NewHandler(a.HandleDeleteProjectCluster, l),
  511. mw.URLParam,
  512. mw.URLParam,
  513. ),
  514. mw.URLParam,
  515. mw.WriteAccess,
  516. ),
  517. )
  518. // /api/projects/{project_id}/clusters/candidates routes
  519. r.Method(
  520. "POST",
  521. "/projects/{project_id}/clusters/candidates",
  522. auth.DoesUserHaveProjectAccess(
  523. requestlog.NewHandler(a.HandleCreateProjectClusterCandidates, l),
  524. mw.URLParam,
  525. mw.WriteAccess,
  526. ),
  527. )
  528. r.Method(
  529. "GET",
  530. "/projects/{project_id}/clusters/candidates",
  531. auth.DoesUserHaveProjectAccess(
  532. requestlog.NewHandler(a.HandleListProjectClusterCandidates, l),
  533. mw.URLParam,
  534. mw.WriteAccess,
  535. ),
  536. )
  537. r.Method(
  538. "POST",
  539. "/projects/{project_id}/clusters/candidates/{candidate_id}/resolve",
  540. auth.DoesUserHaveProjectAccess(
  541. requestlog.NewHandler(a.HandleResolveClusterCandidate, l),
  542. mw.URLParam,
  543. mw.WriteAccess,
  544. ),
  545. )
  546. // /api/projects/{project_id}/integrations routes
  547. r.Method(
  548. "POST",
  549. "/projects/{project_id}/integrations/gcp",
  550. auth.DoesUserHaveProjectAccess(
  551. requestlog.NewHandler(a.HandleCreateGCPIntegration, l),
  552. mw.URLParam,
  553. mw.WriteAccess,
  554. ),
  555. )
  556. r.Method(
  557. "POST",
  558. "/projects/{project_id}/integrations/aws",
  559. auth.DoesUserHaveProjectAccess(
  560. requestlog.NewHandler(a.HandleCreateAWSIntegration, l),
  561. mw.URLParam,
  562. mw.WriteAccess,
  563. ),
  564. )
  565. r.Method(
  566. "POST",
  567. "/projects/{project_id}/integrations/basic",
  568. auth.DoesUserHaveProjectAccess(
  569. requestlog.NewHandler(a.HandleCreateBasicAuthIntegration, l),
  570. mw.URLParam,
  571. mw.WriteAccess,
  572. ),
  573. )
  574. r.Method(
  575. "GET",
  576. "/projects/{project_id}/integrations/oauth",
  577. auth.DoesUserHaveProjectAccess(
  578. requestlog.NewHandler(a.HandleListProjectOAuthIntegrations, l),
  579. mw.URLParam,
  580. mw.WriteAccess,
  581. ),
  582. )
  583. // /api/projects/{project_id}/helmrepos routes
  584. r.Method(
  585. "POST",
  586. "/projects/{project_id}/helmrepos",
  587. auth.DoesUserHaveProjectAccess(
  588. auth.DoesUserHaveAWSIntegrationAccess(
  589. auth.DoesUserHaveGCPIntegrationAccess(
  590. requestlog.NewHandler(a.HandleCreateHelmRepo, l),
  591. mw.URLParam,
  592. mw.BodyParam,
  593. true,
  594. ),
  595. mw.URLParam,
  596. mw.BodyParam,
  597. true,
  598. ),
  599. mw.URLParam,
  600. mw.WriteAccess,
  601. ),
  602. )
  603. r.Method(
  604. "GET",
  605. "/projects/{project_id}/helmrepos",
  606. auth.DoesUserHaveProjectAccess(
  607. requestlog.NewHandler(a.HandleListProjectHelmRepos, l),
  608. mw.URLParam,
  609. mw.WriteAccess,
  610. ),
  611. )
  612. r.Method(
  613. "GET",
  614. "/projects/{project_id}/helmrepos/{helm_id}/charts",
  615. auth.DoesUserHaveProjectAccess(
  616. requestlog.NewHandler(a.HandleListHelmRepoCharts, l),
  617. mw.URLParam,
  618. mw.WriteAccess,
  619. ),
  620. )
  621. // /api/projects/{project_id}/registries routes
  622. r.Method(
  623. "POST",
  624. "/projects/{project_id}/registries",
  625. auth.DoesUserHaveProjectAccess(
  626. auth.DoesUserHaveAWSIntegrationAccess(
  627. auth.DoesUserHaveGCPIntegrationAccess(
  628. auth.DoesUserHaveDOIntegrationAccess(
  629. requestlog.NewHandler(a.HandleCreateRegistry, l),
  630. mw.URLParam,
  631. mw.BodyParam,
  632. true,
  633. ),
  634. mw.URLParam,
  635. mw.BodyParam,
  636. true,
  637. ),
  638. mw.URLParam,
  639. mw.BodyParam,
  640. true,
  641. ),
  642. mw.URLParam,
  643. mw.WriteAccess,
  644. ),
  645. )
  646. r.Method(
  647. "GET",
  648. "/projects/{project_id}/registries",
  649. auth.DoesUserHaveProjectAccess(
  650. requestlog.NewHandler(a.HandleListProjectRegistries, l),
  651. mw.URLParam,
  652. mw.WriteAccess,
  653. ),
  654. )
  655. r.Method(
  656. "POST",
  657. "/projects/{project_id}/registries/{registry_id}",
  658. auth.DoesUserHaveProjectAccess(
  659. auth.DoesUserHaveRegistryAccess(
  660. requestlog.NewHandler(a.HandleUpdateProjectRegistry, l),
  661. mw.URLParam,
  662. mw.URLParam,
  663. ),
  664. mw.URLParam,
  665. mw.WriteAccess,
  666. ),
  667. )
  668. r.Method(
  669. "GET",
  670. "/projects/{project_id}/registries/ecr/{region}/token",
  671. auth.DoesUserHaveProjectAccess(
  672. requestlog.NewHandler(a.HandleGetProjectRegistryECRToken, l),
  673. mw.URLParam,
  674. mw.WriteAccess,
  675. ),
  676. )
  677. r.Method(
  678. "GET",
  679. "/projects/{project_id}/registries/gcr/token",
  680. auth.DoesUserHaveProjectAccess(
  681. requestlog.NewHandler(a.HandleGetProjectRegistryGCRToken, l),
  682. mw.URLParam,
  683. mw.WriteAccess,
  684. ),
  685. )
  686. r.Method(
  687. "GET",
  688. "/projects/{project_id}/registries/dockerhub/token",
  689. auth.DoesUserHaveProjectAccess(
  690. requestlog.NewHandler(a.HandleGetProjectRegistryDockerhubToken, l),
  691. mw.URLParam,
  692. mw.WriteAccess,
  693. ),
  694. )
  695. r.Method(
  696. "GET",
  697. "/projects/{project_id}/registries/docr/token",
  698. auth.DoesUserHaveProjectAccess(
  699. requestlog.NewHandler(a.HandleGetProjectRegistryDOCRToken, l),
  700. mw.URLParam,
  701. mw.WriteAccess,
  702. ),
  703. )
  704. r.Method(
  705. "DELETE",
  706. "/projects/{project_id}/registries/{registry_id}",
  707. auth.DoesUserHaveProjectAccess(
  708. auth.DoesUserHaveRegistryAccess(
  709. requestlog.NewHandler(a.HandleDeleteProjectRegistry, l),
  710. mw.URLParam,
  711. mw.URLParam,
  712. ),
  713. mw.URLParam,
  714. mw.WriteAccess,
  715. ),
  716. )
  717. // /api/projects/{project_id}/registries/{registry_id}/repositories routes
  718. r.Method(
  719. "GET",
  720. "/projects/{project_id}/registries/{registry_id}/repositories",
  721. auth.DoesUserHaveProjectAccess(
  722. auth.DoesUserHaveRegistryAccess(
  723. requestlog.NewHandler(a.HandleListRepositories, l),
  724. mw.URLParam,
  725. mw.URLParam,
  726. ),
  727. mw.URLParam,
  728. mw.WriteAccess,
  729. ),
  730. )
  731. r.Method(
  732. "GET",
  733. // * is the repo name, which can itself be nested
  734. // for example, for GCR this is project-id/repo
  735. // need to use wildcard, see https://github.com/go-chi/chi/issues/243
  736. "/projects/{project_id}/registries/{registry_id}/repositories/*",
  737. auth.DoesUserHaveProjectAccess(
  738. auth.DoesUserHaveRegistryAccess(
  739. requestlog.NewHandler(a.HandleListImages, l),
  740. mw.URLParam,
  741. mw.URLParam,
  742. ),
  743. mw.URLParam,
  744. mw.WriteAccess,
  745. ),
  746. )
  747. // /api/projects/{project_id}/releases routes
  748. r.Method(
  749. "GET",
  750. "/projects/{project_id}/releases",
  751. auth.DoesUserHaveProjectAccess(
  752. auth.DoesUserHaveClusterAccess(
  753. requestlog.NewHandler(a.HandleListReleases, l),
  754. mw.URLParam,
  755. mw.QueryParam,
  756. ),
  757. mw.URLParam,
  758. mw.ReadAccess,
  759. ),
  760. )
  761. r.Method(
  762. "GET",
  763. "/projects/{project_id}/releases/{name}/{revision}/components",
  764. auth.DoesUserHaveProjectAccess(
  765. auth.DoesUserHaveClusterAccess(
  766. requestlog.NewHandler(a.HandleGetReleaseComponents, l),
  767. mw.URLParam,
  768. mw.QueryParam,
  769. ),
  770. mw.URLParam,
  771. mw.ReadAccess,
  772. ),
  773. )
  774. r.Method(
  775. "GET",
  776. "/projects/{project_id}/releases/{name}/{revision}/controllers",
  777. auth.DoesUserHaveProjectAccess(
  778. auth.DoesUserHaveClusterAccess(
  779. requestlog.NewHandler(a.HandleGetReleaseControllers, l),
  780. mw.URLParam,
  781. mw.QueryParam,
  782. ),
  783. mw.URLParam,
  784. mw.ReadAccess,
  785. ),
  786. )
  787. r.Method(
  788. "GET",
  789. "/projects/{project_id}/releases/{name}/history",
  790. auth.DoesUserHaveProjectAccess(
  791. auth.DoesUserHaveClusterAccess(
  792. requestlog.NewHandler(a.HandleListReleaseHistory, l),
  793. mw.URLParam,
  794. mw.QueryParam,
  795. ),
  796. mw.URLParam,
  797. mw.ReadAccess,
  798. ),
  799. )
  800. r.Method(
  801. "GET",
  802. "/projects/{project_id}/releases/{name}/webhook_token",
  803. auth.DoesUserHaveProjectAccess(
  804. auth.DoesUserHaveClusterAccess(
  805. requestlog.NewHandler(a.HandleGetReleaseToken, l),
  806. mw.URLParam,
  807. mw.QueryParam,
  808. ),
  809. mw.URLParam,
  810. mw.ReadAccess,
  811. ),
  812. )
  813. r.Method(
  814. "POST",
  815. "/projects/{project_id}/releases/{name}/upgrade",
  816. auth.DoesUserHaveProjectAccess(
  817. auth.DoesUserHaveClusterAccess(
  818. requestlog.NewHandler(a.HandleUpgradeRelease, l),
  819. mw.URLParam,
  820. mw.QueryParam,
  821. ),
  822. mw.URLParam,
  823. mw.ReadAccess,
  824. ),
  825. )
  826. r.Method(
  827. "GET",
  828. "/projects/{project_id}/releases/{name}/{revision}",
  829. auth.DoesUserHaveProjectAccess(
  830. auth.DoesUserHaveClusterAccess(
  831. requestlog.NewHandler(a.HandleGetRelease, l),
  832. mw.URLParam,
  833. mw.QueryParam,
  834. ),
  835. mw.URLParam,
  836. mw.ReadAccess,
  837. ),
  838. )
  839. r.Method(
  840. "POST",
  841. "/projects/{project_id}/releases/{name}/rollback",
  842. auth.DoesUserHaveProjectAccess(
  843. auth.DoesUserHaveClusterAccess(
  844. requestlog.NewHandler(a.HandleRollbackRelease, l),
  845. mw.URLParam,
  846. mw.QueryParam,
  847. ),
  848. mw.URLParam,
  849. mw.ReadAccess,
  850. ),
  851. )
  852. r.Method(
  853. "POST",
  854. "/webhooks/deploy/{token}",
  855. requestlog.NewHandler(a.HandleReleaseDeployWebhook, l),
  856. )
  857. // /api/projects/{project_id}/gitrepos routes
  858. r.Method(
  859. "GET",
  860. "/projects/{project_id}/gitrepos",
  861. auth.DoesUserHaveProjectAccess(
  862. requestlog.NewHandler(a.HandleListProjectGitRepos, l),
  863. mw.URLParam,
  864. mw.ReadAccess,
  865. ),
  866. )
  867. r.Method(
  868. "DELETE",
  869. "/projects/{project_id}/gitrepos/{git_repo_id}",
  870. auth.DoesUserHaveProjectAccess(
  871. auth.DoesUserHaveGitRepoAccess(
  872. requestlog.NewHandler(a.HandleDeleteProjectGitRepo, l),
  873. mw.URLParam,
  874. mw.URLParam,
  875. ),
  876. mw.URLParam,
  877. mw.WriteAccess,
  878. ),
  879. )
  880. r.Method(
  881. "GET",
  882. "/projects/{project_id}/gitrepos/{git_repo_id}/repos",
  883. auth.DoesUserHaveProjectAccess(
  884. auth.DoesUserHaveGitRepoAccess(
  885. requestlog.NewHandler(a.HandleListRepos, l),
  886. mw.URLParam,
  887. mw.URLParam,
  888. ),
  889. mw.URLParam,
  890. mw.ReadAccess,
  891. ),
  892. )
  893. r.Method(
  894. "GET",
  895. "/projects/{project_id}/gitrepos/{git_repo_id}/repos/{kind}/{owner}/{name}/branches",
  896. auth.DoesUserHaveProjectAccess(
  897. auth.DoesUserHaveGitRepoAccess(
  898. requestlog.NewHandler(a.HandleGetBranches, l),
  899. mw.URLParam,
  900. mw.URLParam,
  901. ),
  902. mw.URLParam,
  903. mw.ReadAccess,
  904. ),
  905. )
  906. r.Method(
  907. "GET",
  908. "/projects/{project_id}/gitrepos/{git_repo_id}/repos/{kind}/{owner}/{name}/{branch}/contents",
  909. auth.DoesUserHaveProjectAccess(
  910. auth.DoesUserHaveGitRepoAccess(
  911. requestlog.NewHandler(a.HandleGetBranchContents, l),
  912. mw.URLParam,
  913. mw.URLParam,
  914. ),
  915. mw.URLParam,
  916. mw.ReadAccess,
  917. ),
  918. )
  919. // /api/projects/{project_id}/deploy routes
  920. r.Method(
  921. "POST",
  922. "/projects/{project_id}/deploy/{name}/{version}",
  923. auth.DoesUserHaveProjectAccess(
  924. auth.DoesUserHaveClusterAccess(
  925. requestlog.NewHandler(a.HandleDeployTemplate, l),
  926. mw.URLParam,
  927. mw.QueryParam,
  928. ),
  929. mw.URLParam,
  930. mw.ReadAccess,
  931. ),
  932. )
  933. // /api/projects/{project_id}/deploy routes
  934. r.Method(
  935. "POST",
  936. "/projects/{project_id}/delete/{name}",
  937. auth.DoesUserHaveProjectAccess(
  938. auth.DoesUserHaveClusterAccess(
  939. requestlog.NewHandler(a.HandleUninstallTemplate, l),
  940. mw.URLParam,
  941. mw.QueryParam,
  942. ),
  943. mw.URLParam,
  944. mw.ReadAccess,
  945. ),
  946. )
  947. // /api/projects/{project_id}/k8s routes
  948. r.Method(
  949. "GET",
  950. "/projects/{project_id}/k8s/namespaces",
  951. auth.DoesUserHaveProjectAccess(
  952. auth.DoesUserHaveClusterAccess(
  953. requestlog.NewHandler(a.HandleListNamespaces, l),
  954. mw.URLParam,
  955. mw.QueryParam,
  956. ),
  957. mw.URLParam,
  958. mw.ReadAccess,
  959. ),
  960. )
  961. r.Method(
  962. "GET",
  963. "/projects/{project_id}/k8s/prometheus/detect",
  964. auth.DoesUserHaveProjectAccess(
  965. auth.DoesUserHaveClusterAccess(
  966. requestlog.NewHandler(a.HandleDetectPrometheusInstalled, l),
  967. mw.URLParam,
  968. mw.QueryParam,
  969. ),
  970. mw.URLParam,
  971. mw.ReadAccess,
  972. ),
  973. )
  974. r.Method(
  975. "GET",
  976. "/projects/{project_id}/k8s/metrics",
  977. auth.DoesUserHaveProjectAccess(
  978. auth.DoesUserHaveClusterAccess(
  979. requestlog.NewHandler(a.HandleGetPodMetrics, l),
  980. mw.URLParam,
  981. mw.QueryParam,
  982. ),
  983. mw.URLParam,
  984. mw.ReadAccess,
  985. ),
  986. )
  987. r.Method(
  988. "GET",
  989. "/projects/{project_id}/k8s/{namespace}/pod/{name}/logs",
  990. auth.DoesUserHaveProjectAccess(
  991. auth.DoesUserHaveClusterAccess(
  992. requestlog.NewHandler(a.HandleGetPodLogs, l),
  993. mw.URLParam,
  994. mw.QueryParam,
  995. ),
  996. mw.URLParam,
  997. mw.ReadAccess,
  998. ),
  999. )
  1000. r.Method(
  1001. "GET",
  1002. "/projects/{project_id}/k8s/{namespace}/ingress/{name}",
  1003. auth.DoesUserHaveProjectAccess(
  1004. auth.DoesUserHaveClusterAccess(
  1005. requestlog.NewHandler(a.HandleGetIngress, l),
  1006. mw.URLParam,
  1007. mw.QueryParam,
  1008. ),
  1009. mw.URLParam,
  1010. mw.ReadAccess,
  1011. ),
  1012. )
  1013. r.Method(
  1014. "GET",
  1015. "/projects/{project_id}/k8s/{kind}/status",
  1016. auth.DoesUserHaveProjectAccess(
  1017. auth.DoesUserHaveClusterAccess(
  1018. requestlog.NewHandler(a.HandleStreamControllerStatus, l),
  1019. mw.URLParam,
  1020. mw.QueryParam,
  1021. ),
  1022. mw.URLParam,
  1023. mw.ReadAccess,
  1024. ),
  1025. )
  1026. r.Method(
  1027. "GET",
  1028. "/projects/{project_id}/k8s/pods",
  1029. auth.DoesUserHaveProjectAccess(
  1030. auth.DoesUserHaveClusterAccess(
  1031. requestlog.NewHandler(a.HandleListPods, l),
  1032. mw.URLParam,
  1033. mw.QueryParam,
  1034. ),
  1035. mw.URLParam,
  1036. mw.ReadAccess,
  1037. ),
  1038. )
  1039. // /api/projects/{project_id}/subdomain routes
  1040. r.Method(
  1041. "POST",
  1042. "/projects/{project_id}/k8s/subdomain",
  1043. auth.DoesUserHaveProjectAccess(
  1044. auth.DoesUserHaveClusterAccess(
  1045. requestlog.NewHandler(a.HandleCreateDNSRecord, l),
  1046. mw.URLParam,
  1047. mw.QueryParam,
  1048. ),
  1049. mw.URLParam,
  1050. mw.ReadAccess,
  1051. ),
  1052. )
  1053. })
  1054. staticFilePath := a.ServerConf.StaticFilePath
  1055. fs := http.FileServer(http.Dir(staticFilePath))
  1056. r.Get("/*", func(w http.ResponseWriter, r *http.Request) {
  1057. if _, err := os.Stat(staticFilePath + r.RequestURI); os.IsNotExist(err) {
  1058. http.StripPrefix(r.URL.Path, fs).ServeHTTP(w, r)
  1059. } else {
  1060. fs.ServeHTTP(w, r)
  1061. }
  1062. })
  1063. return r
  1064. }