| 12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227322832293230323132323233323432353236323732383239324032413242324332443245324632473248324932503251325232533254325532563257325832593260326132623263326432653266326732683269327032713272327332743275327632773278327932803281328232833284328532863287328832893290329132923293329432953296329732983299330033013302330333043305330633073308330933103311331233133314331533163317331833193320332133223323332433253326332733283329333033313332333333343335333633373338333933403341334233433344334533463347334833493350335133523353335433553356335733583359336033613362336333643365336633673368336933703371337233733374337533763377337833793380338133823383338433853386338733883389339033913392339333943395339633973398339934003401340234033404340534063407340834093410341134123413341434153416341734183419342034213422342334243425342634273428342934303431343234333434343534363437343834393440344134423443344434453446344734483449345034513452345334543455345634573458345934603461346234633464346534663467346834693470347134723473347434753476347734783479348034813482348334843485348634873488348934903491349234933494349534963497349834993500350135023503350435053506350735083509351035113512351335143515351635173518351935203521352235233524352535263527352835293530353135323533353435353536353735383539354035413542354335443545354635473548354935503551355235533554355535563557355835593560356135623563356435653566356735683569357035713572357335743575357635773578357935803581358235833584358535863587358835893590359135923593359435953596359735983599360036013602360336043605360636073608360936103611361236133614361536163617361836193620362136223623362436253626362736283629363036313632363336343635363636373638363936403641364236433644364536463647364836493650365136523653365436553656365736583659366036613662366336643665366636673668366936703671367236733674367536763677367836793680368136823683368436853686368736883689369036913692369336943695369636973698369937003701370237033704370537063707370837093710371137123713371437153716371737183719372037213722372337243725372637273728372937303731373237333734373537363737373837393740374137423743374437453746374737483749375037513752375337543755375637573758375937603761376237633764376537663767376837693770377137723773377437753776377737783779378037813782378337843785378637873788378937903791379237933794379537963797379837993800380138023803380438053806380738083809381038113812381338143815381638173818381938203821382238233824382538263827382838293830383138323833383438353836383738383839384038413842384338443845384638473848384938503851385238533854385538563857385838593860386138623863386438653866386738683869387038713872387338743875387638773878387938803881388238833884388538863887388838893890389138923893389438953896389738983899390039013902390339043905390639073908390939103911391239133914391539163917391839193920392139223923392439253926392739283929393039313932393339343935393639373938393939403941394239433944394539463947394839493950395139523953395439553956395739583959396039613962396339643965396639673968396939703971397239733974397539763977397839793980398139823983398439853986398739883989399039913992399339943995399639973998399940004001400240034004400540064007400840094010401140124013401440154016401740184019402040214022402340244025402640274028402940304031403240334034403540364037403840394040404140424043404440454046404740484049405040514052405340544055405640574058405940604061406240634064406540664067406840694070407140724073407440754076407740784079408040814082408340844085408640874088408940904091409240934094409540964097409840994100410141024103410441054106410741084109411041114112411341144115411641174118411941204121412241234124412541264127412841294130413141324133413441354136413741384139414041414142414341444145414641474148414941504151415241534154415541564157415841594160416141624163416441654166416741684169417041714172417341744175417641774178417941804181418241834184418541864187418841894190419141924193419441954196419741984199420042014202420342044205420642074208420942104211421242134214421542164217421842194220422142224223422442254226422742284229423042314232423342344235423642374238423942404241424242434244424542464247424842494250425142524253425442554256425742584259426042614262426342644265426642674268426942704271427242734274427542764277427842794280428142824283428442854286428742884289429042914292429342944295429642974298429943004301430243034304430543064307430843094310431143124313431443154316431743184319432043214322432343244325432643274328432943304331433243334334433543364337433843394340434143424343434443454346434743484349435043514352435343544355435643574358435943604361436243634364436543664367436843694370437143724373437443754376437743784379438043814382438343844385438643874388438943904391439243934394439543964397439843994400440144024403440444054406440744084409441044114412441344144415441644174418441944204421442244234424442544264427442844294430443144324433443444354436443744384439444044414442444344444445444644474448444944504451445244534454445544564457445844594460446144624463446444654466446744684469447044714472447344744475447644774478447944804481448244834484448544864487448844894490449144924493449444954496449744984499450045014502450345044505450645074508450945104511451245134514451545164517451845194520452145224523452445254526452745284529453045314532453345344535453645374538453945404541454245434544454545464547454845494550455145524553455445554556455745584559456045614562456345644565456645674568456945704571457245734574457545764577457845794580458145824583458445854586458745884589459045914592459345944595459645974598459946004601460246034604460546064607460846094610461146124613461446154616461746184619462046214622462346244625462646274628462946304631463246334634463546364637463846394640464146424643464446454646464746484649465046514652465346544655465646574658465946604661466246634664466546664667466846694670467146724673467446754676467746784679468046814682468346844685468646874688468946904691469246934694469546964697469846994700470147024703470447054706470747084709471047114712471347144715471647174718471947204721472247234724472547264727472847294730473147324733473447354736473747384739474047414742474347444745474647474748474947504751475247534754475547564757475847594760476147624763476447654766476747684769477047714772477347744775477647774778477947804781478247834784478547864787478847894790479147924793479447954796479747984799480048014802480348044805480648074808480948104811481248134814481548164817481848194820482148224823482448254826482748284829483048314832483348344835483648374838483948404841484248434844484548464847484848494850485148524853485448554856485748584859486048614862486348644865486648674868486948704871487248734874487548764877487848794880488148824883488448854886488748884889489048914892489348944895489648974898489949004901490249034904490549064907490849094910491149124913491449154916491749184919492049214922492349244925492649274928492949304931493249334934493549364937493849394940494149424943494449454946494749484949495049514952495349544955495649574958495949604961496249634964496549664967496849694970497149724973497449754976497749784979498049814982498349844985498649874988498949904991499249934994499549964997499849995000500150025003500450055006500750085009501050115012501350145015501650175018501950205021502250235024502550265027502850295030503150325033503450355036503750385039504050415042504350445045504650475048504950505051505250535054505550565057505850595060506150625063506450655066506750685069507050715072507350745075507650775078507950805081508250835084508550865087508850895090509150925093509450955096509750985099510051015102510351045105510651075108510951105111511251135114511551165117511851195120512151225123512451255126512751285129513051315132513351345135513651375138513951405141514251435144514551465147514851495150515151525153515451555156515751585159516051615162516351645165516651675168516951705171517251735174517551765177517851795180518151825183518451855186518751885189519051915192519351945195519651975198519952005201520252035204520552065207520852095210521152125213521452155216521752185219522052215222522352245225522652275228522952305231523252335234523552365237523852395240524152425243524452455246524752485249525052515252525352545255525652575258525952605261526252635264526552665267526852695270527152725273527452755276527752785279528052815282528352845285528652875288528952905291529252935294529552965297529852995300530153025303530453055306530753085309531053115312531353145315531653175318531953205321532253235324532553265327532853295330533153325333533453355336533753385339534053415342534353445345534653475348534953505351535253535354535553565357535853595360536153625363536453655366536753685369537053715372537353745375537653775378537953805381538253835384538553865387538853895390539153925393539453955396539753985399540054015402540354045405540654075408540954105411541254135414541554165417541854195420542154225423542454255426542754285429543054315432543354345435543654375438543954405441544254435444544554465447544854495450545154525453545454555456545754585459546054615462546354645465546654675468546954705471547254735474547554765477547854795480548154825483548454855486548754885489549054915492549354945495549654975498549955005501550255035504550555065507550855095510551155125513551455155516551755185519552055215522552355245525552655275528552955305531553255335534553555365537553855395540554155425543 |
- #include "smartbotic/webserver/http_server.hpp"
- #include "smartbotic/webserver/permissions.hpp"
- #include <nlohmann/json.hpp>
- #include <spdlog/spdlog.h>
- #include <algorithm>
- #include <chrono>
- #include <cstring>
- #include <filesystem>
- #include <fstream>
- #include <random>
- #include <sstream>
- namespace smartbotic::webserver {
- // ============================================================================
- // WebSocketServer Implementation
- // ============================================================================
- // Static instance pointer for callback access
- WebSocketServer* WebSocketServer::instance_ = nullptr;
- namespace {
- auto GenerateSessionId() -> std::string {
- static std::random_device rd;
- static std::mt19937 gen(rd());
- static std::uniform_int_distribution<> dis(0, 15);
- static const char* hex = "0123456789abcdef";
- std::string uuid;
- uuid.reserve(36);
- for (int i = 0; i < 36; ++i) {
- if (i == 8 || i == 13 || i == 18 || i == 23) {
- uuid += '-';
- } else {
- uuid += hex[dis(gen)];
- }
- }
- return uuid;
- }
- } // namespace
- // LWS protocol definition - first protocol handles HTTP and is the default for WS
- static lws_protocols protocols[] = {
- {
- "http", // Default protocol name for HTTP/WS upgrade
- WebSocketServer::WsCallback,
- 0, // per_session_data_size - we manage our own
- 65536, // rx buffer size
- 0, // id
- nullptr, // user
- 65536 // tx_packet_size
- },
- LWS_PROTOCOL_LIST_TERM
- };
- WebSocketServer::WebSocketServer(uint16_t port, const std::string& path)
- : port_(port), path_(path) {
- instance_ = this;
- }
- WebSocketServer::~WebSocketServer() {
- Stop();
- instance_ = nullptr;
- }
- void WebSocketServer::Start() {
- if (running_.load()) {
- spdlog::warn("WebSocket server already running");
- return;
- }
- spdlog::info("Starting WebSocket server on port {}", port_);
- lws_context_creation_info info{};
- std::memset(&info, 0, sizeof(info));
- info.port = port_;
- info.protocols = protocols;
- info.gid = -1;
- info.uid = -1;
- info.options = LWS_SERVER_OPTION_DO_SSL_GLOBAL_INIT;
- info.vhost_name = "smartbotic-ws";
- // Suppress verbose lws logging
- lws_set_log_level(LLL_ERR | LLL_WARN, nullptr);
- context_ = lws_create_context(&info);
- if (context_ == nullptr) {
- spdlog::error("Failed to create libwebsocket context");
- return;
- }
- running_.store(true);
- eventLoopThread_ = std::thread(&WebSocketServer::RunEventLoop, this);
- spdlog::info("WebSocket server started on port {}", port_);
- }
- void WebSocketServer::Stop() {
- if (!running_.load()) {
- return;
- }
- spdlog::info("Stopping WebSocket server...");
- running_.store(false);
- // Cancel the event loop to wake up lws_service() immediately
- // This is async-signal-safe and can be called from signal handlers
- if (context_ != nullptr) {
- lws_cancel_service(context_);
- }
- if (eventLoopThread_.joinable()) {
- eventLoopThread_.join();
- }
- if (context_ != nullptr) {
- lws_context_destroy(context_);
- context_ = nullptr;
- }
- {
- std::lock_guard<std::mutex> lock(connectionsMutex_);
- connections_.clear();
- }
- spdlog::info("WebSocket server stopped");
- }
- void WebSocketServer::RunEventLoop() {
- while (running_.load()) {
- lws_service(context_, 50); // 50ms timeout
- }
- }
- void WebSocketServer::Broadcast(const std::string& message) {
- std::lock_guard<std::mutex> lock(connectionsMutex_);
- for (auto& [wsi, conn] : connections_) {
- QueueMessage(conn.get(), message);
- }
- }
- void WebSocketServer::SendToSession(const std::string& sessionId, const std::string& message) {
- std::lock_guard<std::mutex> lock(connectionsMutex_);
- for (auto& [wsi, conn] : connections_) {
- if (conn->sessionId == sessionId) {
- QueueMessage(conn.get(), message);
- break;
- }
- }
- }
- void WebSocketServer::SendToSubscribers(const std::string& subscription_key, const std::string& message) {
- std::lock_guard<std::mutex> lock(connectionsMutex_);
- for (auto& [wsi, conn] : connections_) {
- // Check if this connection is subscribed and authenticated
- if (!conn->authenticated) {
- continue;
- }
- const auto& subs = conn->subscriptions;
- if (std::find(subs.begin(), subs.end(), subscription_key) != subs.end()) {
- QueueMessage(conn.get(), message);
- }
- }
- }
- auto WebSocketServer::ConnectionCount() const -> size_t {
- std::lock_guard<std::mutex> lock(connectionsMutex_);
- return connections_.size();
- }
- void WebSocketServer::SetMessageHandler(WebSocketMessageHandler handler) {
- messageHandler_ = std::move(handler);
- }
- void WebSocketServer::HandleConnect(lws* wsi) {
- auto conn = std::make_unique<WsConnection>();
- conn->wsi = wsi;
- conn->sessionId = GenerateSessionId();
- spdlog::info("WebSocket client connected (session: {})", conn->sessionId);
- std::lock_guard<std::mutex> lock(connectionsMutex_);
- connections_[wsi] = std::move(conn);
- }
- void WebSocketServer::HandleDisconnect(lws* wsi) {
- std::lock_guard<std::mutex> lock(connectionsMutex_);
- auto it = connections_.find(wsi);
- if (it != connections_.end()) {
- spdlog::info("WebSocket client disconnected (session: {})", it->second->sessionId);
- connections_.erase(it);
- }
- }
- void WebSocketServer::HandleMessage(lws* wsi, const std::string& message) {
- WsConnection* conn = nullptr;
- {
- std::lock_guard<std::mutex> lock(connectionsMutex_);
- auto it = connections_.find(wsi);
- if (it != connections_.end()) {
- conn = it->second.get();
- }
- }
- // Call handler outside the lock to avoid deadlock with SendToSession
- if (conn && messageHandler_) {
- messageHandler_(conn, message);
- }
- }
- void WebSocketServer::QueueMessage(WsConnection* conn, const std::string& message) {
- std::lock_guard<std::mutex> lock(conn->sendMutex);
- // Prepend LWS_PRE bytes for libwebsockets
- conn->sendBuffer.resize(LWS_PRE + message.size());
- std::memcpy(conn->sendBuffer.data() + LWS_PRE, message.data(), message.size());
- lws_callback_on_writable(conn->wsi);
- }
- auto WebSocketServer::WsCallback(lws* wsi, lws_callback_reasons reason,
- void* user, void* in, size_t len) -> int {
- if (instance_ == nullptr) {
- return 0;
- }
- switch (reason) {
- case LWS_CALLBACK_PROTOCOL_INIT:
- spdlog::debug("WebSocket protocol initialized");
- break;
- case LWS_CALLBACK_ESTABLISHED:
- spdlog::debug("WebSocket connection established");
- instance_->HandleConnect(wsi);
- break;
- case LWS_CALLBACK_CLOSED:
- spdlog::debug("WebSocket connection closed");
- instance_->HandleDisconnect(wsi);
- break;
- case LWS_CALLBACK_RECEIVE: {
- std::string message(static_cast<char*>(in), len);
- spdlog::debug("WebSocket received {} bytes", len);
- instance_->HandleMessage(wsi, message);
- break;
- }
- case LWS_CALLBACK_SERVER_WRITEABLE: {
- std::lock_guard<std::mutex> lock(instance_->connectionsMutex_);
- auto it = instance_->connections_.find(wsi);
- if (it != instance_->connections_.end()) {
- auto& conn = it->second;
- std::lock_guard<std::mutex> sendLock(conn->sendMutex);
- if (conn->sendBuffer.size() > LWS_PRE) {
- size_t msgLen = conn->sendBuffer.size() - LWS_PRE;
- lws_write(wsi, conn->sendBuffer.data() + LWS_PRE, msgLen, LWS_WRITE_TEXT);
- conn->sendBuffer.clear();
- }
- }
- break;
- }
- case LWS_CALLBACK_HTTP:
- // Return non-zero to close the connection for non-WebSocket HTTP requests
- return -1;
- case LWS_CALLBACK_FILTER_PROTOCOL_CONNECTION:
- // Allow the connection
- return 0;
- default:
- break;
- }
- return 0;
- }
- // ============================================================================
- // HttpServer Implementation
- // ============================================================================
- HttpServer::HttpServer(HttpServerConfig config)
- : config_(std::move(config)),
- httpServer_(std::make_unique<httplib::Server>()),
- dbClient_(std::make_unique<DatabaseClient>(config_)),
- authService_(std::make_unique<AuthService>(config_.jwt)) {}
- HttpServer::~HttpServer() {
- if (running_.load()) {
- Stop();
- }
- }
- auto HttpServer::Start(bool require_database) -> bool {
- if (running_.load()) {
- spdlog::warn("Server already running");
- return true;
- }
- spdlog::info("Starting HTTP server on {}", config_.GetListenAddress());
- // Connect to database first (fail-fast if required)
- if (require_database) {
- spdlog::info("Connecting to database at {} (fail-fast mode enabled)", config_.database_address);
- if (!ConnectToDatabase()) {
- spdlog::error("Failed to connect to database - server startup aborted");
- return false;
- }
- } else {
- // Try to connect but don't fail if unavailable
- spdlog::info("Connecting to database at {} (optional mode)", config_.database_address);
- if (!ConnectToDatabase()) {
- spdlog::warn("Database connection failed - server will start without database connectivity");
- }
- }
- // Initialize services (only if database is connected)
- if (IsDatabaseConnected()) {
- if (!InitializeServices()) {
- spdlog::error("Failed to initialize services - server startup aborted");
- return false;
- }
- }
- // Setup routes
- SetupRoutes();
- // Start WebSocket server on separate port
- wsServer_ = std::make_unique<WebSocketServer>(config_.ws_port, config_.ws_path);
- // Setup WebSocket message handler using WsHandler if available
- if (wsHandler_) {
- wsServer_->SetMessageHandler([this](WsConnection* conn, const std::string& message) {
- wsHandler_->HandleMessage(conn, message,
- [this](WsConnection* c, const std::string& response) {
- wsServer_->SendToSession(c->sessionId, response);
- });
- });
- spdlog::info("WebSocket message handler configured with WsHandler");
- } else if (wsMessageHandler_) {
- wsServer_->SetMessageHandler(wsMessageHandler_);
- }
- wsServer_->Start();
- // Start HTTP server in a separate thread
- running_.store(true);
- httpThread_ = std::thread(&HttpServer::RunHttpServer, this);
- spdlog::info("HTTP server started successfully on {}", config_.GetListenAddress());
- spdlog::info("WebSocket server: ws://{}:{}{}", config_.address, config_.ws_port, config_.ws_path);
- spdlog::info("Static files: {}", config_.webui_path);
- spdlog::info("Database: {} ({})", config_.database_address,
- IsDatabaseConnected() ? "connected" : "not connected");
- return true;
- }
- void HttpServer::Stop() {
- if (!running_.load()) {
- return;
- }
- spdlog::info("Stopping HTTP server...");
- running_.store(false);
- // Stop WebSocket server first (this uses lws_cancel_service which is async-signal-safe)
- if (wsServer_) {
- wsServer_->Stop();
- }
- // Stop HTTP server - this makes listen() return
- if (httpServer_) {
- httpServer_->stop();
- }
- // Disconnect from database
- if (dbClient_) {
- dbClient_->Disconnect();
- }
- // NOTE: Don't join httpThread_ here - let Wait() handle it
- // This avoids race condition when Stop() is called from signal handler
- // while main thread is blocked in Wait()
- spdlog::info("HTTP server stop requested");
- }
- void HttpServer::Wait() {
- if (httpThread_.joinable()) {
- httpThread_.join();
- }
- spdlog::info("HTTP server stopped");
- }
- void HttpServer::BroadcastWebSocket(const std::string& message) {
- if (wsServer_) {
- wsServer_->Broadcast(message);
- }
- }
- void HttpServer::BroadcastDocumentEvent(const std::string& workspace_id,
- const std::string& collection,
- DocumentAction action,
- const std::string& document_id,
- const nlohmann::json& data) {
- if (!wsServer_ || !wsHandler_) {
- return;
- }
- std::string subscription_key = WsHandler::BuildSubscriptionKey(workspace_id, collection);
- // Build the event JSON
- nlohmann::json event = {
- {"type", "document"},
- {"action", DocumentActionToString(action)},
- {"workspace_id", workspace_id},
- {"collection", collection},
- {"document_id", document_id}
- };
- // Include data for create/update, exclude for delete
- if (action != DocumentAction::Delete && !data.is_null()) {
- event["data"] = data;
- }
- std::string event_str = event.dump();
- spdlog::debug("Broadcasting document event: {} {} in {} (key={})",
- DocumentActionToString(action), document_id, collection, subscription_key);
- wsServer_->SendToSubscribers(subscription_key, event_str);
- }
- void HttpServer::SetWebSocketMessageHandler(WebSocketMessageHandler handler) {
- wsMessageHandler_ = std::move(handler);
- if (wsServer_) {
- wsServer_->SetMessageHandler(wsMessageHandler_);
- }
- }
- auto HttpServer::GetWebSocketClientCount() const -> size_t {
- return wsServer_ ? wsServer_->ConnectionCount() : 0;
- }
- auto HttpServer::IsDatabaseConnected() const -> bool {
- return dbClient_ && dbClient_->IsConnected();
- }
- auto HttpServer::ConnectToDatabase() -> bool {
- if (!dbClient_) {
- dbClient_ = std::make_unique<DatabaseClient>(config_);
- }
- // Try to connect
- if (!dbClient_->Connect()) {
- return false;
- }
- // Perform a health check to verify the connection is working
- auto health = dbClient_->HealthCheck();
- if (!health.healthy) {
- spdlog::error("Database health check failed: {}", health.message);
- return false;
- }
- spdlog::info("Database health check passed (latency: {}ms)", health.latency.count());
- return true;
- }
- auto HttpServer::InitializeServices() -> bool {
- // Initialize UserService
- userService_ = std::make_unique<UserService>(*dbClient_);
- if (!userService_->Initialize()) {
- spdlog::error("Failed to initialize UserService");
- return false;
- }
- spdlog::info("UserService initialized successfully");
- // Initialize WorkspaceService
- workspaceService_ = std::make_unique<WorkspaceService>(*dbClient_);
- if (!workspaceService_->Initialize()) {
- spdlog::error("Failed to initialize WorkspaceService");
- return false;
- }
- spdlog::info("WorkspaceService initialized successfully");
- // Initialize GroupService
- groupService_ = std::make_unique<GroupService>(*dbClient_);
- if (!groupService_->Initialize()) {
- spdlog::error("Failed to initialize GroupService");
- return false;
- }
- spdlog::info("GroupService initialized successfully");
- // Initialize MembershipService
- membershipService_ = std::make_unique<MembershipService>(*dbClient_);
- if (!membershipService_->Initialize()) {
- spdlog::error("Failed to initialize MembershipService");
- return false;
- }
- spdlog::info("MembershipService initialized successfully");
- // Initialize ApiKeyService
- apiKeyService_ = std::make_unique<ApiKeyService>(*dbClient_);
- if (!apiKeyService_->Initialize()) {
- spdlog::error("Failed to initialize ApiKeyService");
- return false;
- }
- spdlog::info("ApiKeyService initialized successfully");
- // Initialize CollectionService
- collectionService_ = std::make_unique<CollectionService>(*dbClient_);
- spdlog::info("CollectionService initialized successfully");
- // Initialize DocumentService
- documentService_ = std::make_unique<DocumentService>(*dbClient_);
- spdlog::info("DocumentService initialized successfully");
- // Initialize ViewService
- viewService_ = std::make_unique<ViewService>(*dbClient_);
- if (!viewService_->Initialize()) {
- spdlog::error("Failed to initialize ViewService");
- return false;
- }
- spdlog::info("ViewService initialized successfully");
- // Initialize PageService
- pageService_ = std::make_unique<PageService>(*dbClient_);
- if (!pageService_->Initialize()) {
- spdlog::error("Failed to initialize PageService");
- return false;
- }
- spdlog::info("PageService initialized successfully");
- // Initialize AuthorizationService
- authorizationService_ = std::make_unique<AuthorizationService>(*groupService_, *collectionService_);
- if (!authorizationService_->Initialize()) {
- spdlog::error("Failed to initialize AuthorizationService");
- return false;
- }
- spdlog::info("AuthorizationService initialized successfully");
- // Initialize WsHandler for WebSocket real-time updates
- wsHandler_ = std::make_unique<WsHandler>(*authService_);
- spdlog::info("WsHandler initialized successfully");
- // Note: WebSocket message handler is set up in Start() after wsServer_ is created
- return true;
- }
- void HttpServer::SetupRoutes() {
- // Pre-routing handler for CORS
- httpServer_->set_pre_routing_handler([this](const httplib::Request& req, httplib::Response& res) {
- // Apply CORS headers if enabled
- if (config_.cors.enabled) {
- // Combine allowed origins
- std::string origins;
- for (size_t i = 0; i < config_.cors.allowed_origins.size(); ++i) {
- if (i > 0) origins += ", ";
- origins += config_.cors.allowed_origins[i];
- }
- res.set_header("Access-Control-Allow-Origin", origins);
- // Combine allowed methods
- std::string methods;
- for (size_t i = 0; i < config_.cors.allowed_methods.size(); ++i) {
- if (i > 0) methods += ", ";
- methods += config_.cors.allowed_methods[i];
- }
- res.set_header("Access-Control-Allow-Methods", methods);
- // Combine allowed headers
- std::string headers;
- for (size_t i = 0; i < config_.cors.allowed_headers.size(); ++i) {
- if (i > 0) headers += ", ";
- headers += config_.cors.allowed_headers[i];
- }
- res.set_header("Access-Control-Allow-Headers", headers);
- if (config_.cors.allow_credentials) {
- res.set_header("Access-Control-Allow-Credentials", "true");
- }
- res.set_header("Access-Control-Max-Age", std::to_string(config_.cors.max_age));
- }
- res.set_header("Server", "SmartBotic-Server/0.1.0");
- // Handle CORS preflight
- if (req.method == "OPTIONS") {
- res.status = 204;
- return httplib::Server::HandlerResponse::Handled;
- }
- return httplib::Server::HandlerResponse::Unhandled;
- });
- // Health check endpoint
- httpServer_->Get("/api/health", [this](const httplib::Request& req, httplib::Response& res) {
- HandleHealth(req, res);
- });
- // Version endpoint
- httpServer_->Get("/api/version", [this](const httplib::Request& req, httplib::Response& res) {
- HandleVersion(req, res);
- });
- // Bootstrap endpoint - creates first admin user if no users exist
- httpServer_->Post("/api/bootstrap", [this](const httplib::Request& req, httplib::Response& res) {
- HandleBootstrap(req, res);
- });
- // Setup authentication routes
- SetupAuthRoutes();
- // Setup user management routes
- SetupUserRoutes();
- // Setup API key routes (under /api/users/:id/api-keys)
- SetupApiKeyRoutes();
- // Setup membership routes (before workspace routes since they're more specific)
- SetupMembershipRoutes();
- // Setup document routes (most specific - before collections)
- SetupDocumentRoutes();
- // Setup view routes (schema definitions)
- SetupViewRoutes();
- // Setup page routes (page builder)
- SetupPageRoutes();
- // Setup collection routes (before workspace routes since they're more specific)
- SetupCollectionRoutes();
- // Setup group management routes (before workspace routes since they're more specific)
- SetupGroupRoutes();
- // Setup workspace management routes
- SetupWorkspaceRoutes();
- // Mount static file directory for WebUI
- if (std::filesystem::exists(config_.webui_path)) {
- httpServer_->set_mount_point("/", config_.webui_path);
- spdlog::info("Mounted static files from: {}", config_.webui_path);
- } else {
- spdlog::warn("WebUI path does not exist: {}", config_.webui_path);
- }
- // Custom error handler for 404 (only if response body is empty)
- httpServer_->set_error_handler([](const httplib::Request& /*req*/, httplib::Response& res) {
- // Only set default error message if body hasn't been set by a handler
- if (res.body.empty()) {
- res.set_content(R"({"error":"Not found"})", "application/json");
- }
- });
- // Logger for requests
- httpServer_->set_logger([](const httplib::Request& req, const httplib::Response& res) {
- auto status = res.status;
- if (status >= 500) {
- spdlog::error("{} {} {}", req.method, req.path, status);
- } else if (status >= 400) {
- spdlog::warn("{} {} {}", req.method, req.path, status);
- } else {
- spdlog::info("{} {} {}", req.method, req.path, status);
- }
- });
- }
- void HttpServer::RunHttpServer() {
- if (!httpServer_->listen(config_.address, config_.port)) {
- spdlog::error("Failed to start HTTP server on {}", config_.GetListenAddress());
- running_.store(false);
- }
- }
- void HttpServer::HandleHealth(const httplib::Request& req, httplib::Response& res) {
- res.set_content(R"({"status":"healthy","service":"smartbotic-server"})", "application/json");
- }
- void HttpServer::HandleVersion(const httplib::Request& req, httplib::Response& res) {
- res.set_content(R"({"version":"0.1.0","name":"SmartBotic Web Server"})", "application/json");
- }
- void HttpServer::HandleBootstrap(const httplib::Request& req, httplib::Response& res) {
- // Bootstrap endpoint - creates first admin user if no users exist
- if (!userService_) {
- res.status = 500;
- res.set_content(R"({"error":"User service not available"})", "application/json");
- return;
- }
- // Check if any users exist
- auto users = userService_->ListUsers();
- if (!users.users.empty()) {
- res.status = 400;
- res.set_content(R"({"error":"System already bootstrapped - users exist"})", "application/json");
- return;
- }
- // Parse request body
- nlohmann::json body;
- try {
- body = nlohmann::json::parse(req.body);
- } catch (...) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- return;
- }
- // Validate required fields
- if (!body.contains("email") || !body.contains("password")) {
- res.status = 400;
- res.set_content(R"({"error":"Email and password are required"})", "application/json");
- return;
- }
- CreateUserRequest user_request;
- user_request.email = body["email"].get<std::string>();
- user_request.password = body["password"].get<std::string>();
- user_request.name = body.value("name", "Admin");
- // Create the admin user
- auto result = userService_->CreateUser(user_request);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response;
- error_response["error"] = result.error;
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Get the superadmin group to assign to the first user
- std::string superadmin_group_id;
- if (groupService_) {
- auto sa_group = groupService_->GetSuperadminGroup();
- if (sa_group.success && sa_group.group) {
- superadmin_group_id = sa_group.group->id;
- spdlog::info("Found superadmin group: {}", superadmin_group_id);
- } else {
- spdlog::warn("Superadmin group not found - first user will not have admin privileges");
- }
- }
- // Create a default workspace
- if (workspaceService_) {
- CreateWorkspaceRequest ws_request;
- ws_request.name = "Default Workspace";
- ws_request.settings["default"] = true;
- auto ws_result = workspaceService_->CreateWorkspace(ws_request);
- // Add user to workspace with superadmin group
- if (ws_result.success && ws_result.workspace && membershipService_) {
- AddMemberRequest member_request;
- member_request.workspace_id = ws_result.workspace->id;
- member_request.user_id = result.user->id;
- // Assign the superadmin group to the first user
- if (!superadmin_group_id.empty()) {
- member_request.group_ids = {superadmin_group_id};
- spdlog::info("Assigning superadmin group to bootstrap user");
- } else {
- member_request.group_ids = {};
- }
- [[maybe_unused]] auto member_result = membershipService_->AddMember(member_request);
- }
- }
- // Return success with user info
- nlohmann::json response;
- response["success"] = true;
- response["message"] = "System bootstrapped successfully";
- response["user"]["id"] = result.user->id;
- response["user"]["email"] = result.user->email;
- response["user"]["name"] = result.user->name;
- spdlog::info("System bootstrapped with admin user: {}", user_request.email);
- res.set_content(response.dump(), "application/json");
- }
- auto HttpServer::GetMimeType(const std::string& path) -> std::string {
- auto ext_pos = path.rfind('.');
- if (ext_pos == std::string::npos) {
- return "application/octet-stream";
- }
- std::string ext = path.substr(ext_pos);
- static const std::unordered_map<std::string, std::string> mime_types = {
- {".html", "text/html"},
- {".htm", "text/html"},
- {".css", "text/css"},
- {".js", "application/javascript"},
- {".json", "application/json"},
- {".png", "image/png"},
- {".jpg", "image/jpeg"},
- {".jpeg", "image/jpeg"},
- {".gif", "image/gif"},
- {".svg", "image/svg+xml"},
- {".ico", "image/x-icon"},
- {".woff", "font/woff"},
- {".woff2", "font/woff2"},
- {".ttf", "font/ttf"},
- {".eot", "application/vnd.ms-fontobject"},
- {".txt", "text/plain"},
- {".xml", "application/xml"},
- {".pdf", "application/pdf"},
- };
- auto it = mime_types.find(ext);
- if (it != mime_types.end()) {
- return it->second;
- }
- return "application/octet-stream";
- }
- // ============================================================================
- // Authentication Routes Implementation
- // ============================================================================
- void HttpServer::SetupAuthRoutes() {
- // POST /api/auth/login - Authenticate user and return JWT
- httpServer_->Post("/api/auth/login", [this](const httplib::Request& req, httplib::Response& res) {
- HandleAuthLogin(req, res);
- });
- // POST /api/auth/refresh - Refresh access token
- httpServer_->Post("/api/auth/refresh", [this](const httplib::Request& req, httplib::Response& res) {
- HandleAuthRefresh(req, res);
- });
- // POST /api/auth/logout - Invalidate refresh token
- httpServer_->Post("/api/auth/logout", [this](const httplib::Request& req, httplib::Response& res) {
- HandleAuthLogout(req, res);
- });
- // GET /api/auth/me - Get current authenticated user info
- httpServer_->Get("/api/auth/me", [this](const httplib::Request& req, httplib::Response& res) {
- HandleAuthMe(req, res);
- });
- spdlog::info("Authentication routes registered: /api/auth/login, /api/auth/refresh, /api/auth/logout, /api/auth/me");
- }
- void HttpServer::HandleAuthLogin(const httplib::Request& req, httplib::Response& res) {
- try {
- // Parse request body
- auto body = nlohmann::json::parse(req.body);
- if (!body.contains("email") || !body.contains("password")) {
- res.status = 400;
- res.set_content(R"({"error":"Missing email or password"})", "application/json");
- return;
- }
- std::string email = body["email"].get<std::string>();
- std::string password = body["password"].get<std::string>();
- if (config_.jwt.secret.empty()) {
- res.status = 500;
- res.set_content(R"({"error":"JWT secret not configured"})", "application/json");
- return;
- }
- if (!userService_) {
- res.status = 500;
- res.set_content(R"({"error":"User service not available"})", "application/json");
- return;
- }
- // Verify user credentials
- auto user_result = userService_->VerifyCredentials(email, password);
- if (!user_result.success || !user_result.user) {
- res.status = 401;
- res.set_content(R"({"error":"Invalid email or password"})", "application/json");
- return;
- }
- const auto& user = *user_result.user;
- // Get user's workspace memberships
- std::vector<std::string> workspace_ids;
- if (membershipService_) {
- auto memberships = membershipService_->ListUserMemberships(user.id);
- for (const auto& m : memberships.members) {
- workspace_ids.push_back(m.workspace_id);
- }
- }
- // Collect user's groups from memberships
- // Note: Superadmin status is determined by group membership, not by special logic
- // The first user gets superadmin group assigned during bootstrap
- std::vector<std::string> groups;
- if (membershipService_) {
- auto memberships = membershipService_->ListUserMemberships(user.id);
- for (const auto& m : memberships.members) {
- for (const auto& gid : m.group_ids) {
- if (std::find(groups.begin(), groups.end(), gid) == groups.end()) {
- groups.push_back(gid);
- }
- }
- }
- }
- auto tokens = authService_->GenerateTokens(user.id, email, workspace_ids, groups);
- nlohmann::json response = {
- {"access_token", tokens.access_token},
- {"refresh_token", tokens.refresh_token},
- {"token_type", "Bearer"},
- {"expires_in", tokens.access_expires_in}
- };
- spdlog::info("User logged in: {}", email);
- res.set_content(response.dump(), "application/json");
- } catch (const nlohmann::json::parse_error& e) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Login error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleAuthRefresh(const httplib::Request& req, httplib::Response& res) {
- try {
- // Parse request body
- auto body = nlohmann::json::parse(req.body);
- if (!body.contains("refresh_token")) {
- res.status = 400;
- res.set_content(R"({"error":"Missing refresh_token"})", "application/json");
- return;
- }
- std::string refresh_token = body["refresh_token"].get<std::string>();
- auto new_tokens = authService_->RefreshAccessToken(refresh_token);
- if (!new_tokens) {
- res.status = 401;
- res.set_content(R"({"error":"Invalid or expired refresh token"})", "application/json");
- return;
- }
- nlohmann::json response = {
- {"access_token", new_tokens->access_token},
- {"refresh_token", new_tokens->refresh_token},
- {"token_type", "Bearer"},
- {"expires_in", new_tokens->access_expires_in}
- };
- spdlog::debug("Token refreshed successfully");
- res.set_content(response.dump(), "application/json");
- } catch (const nlohmann::json::parse_error& e) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Token refresh error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleAuthLogout(const httplib::Request& req, httplib::Response& res) {
- try {
- // Parse request body
- auto body = nlohmann::json::parse(req.body);
- if (!body.contains("refresh_token")) {
- res.status = 400;
- res.set_content(R"({"error":"Missing refresh_token"})", "application/json");
- return;
- }
- std::string refresh_token = body["refresh_token"].get<std::string>();
- if (authService_->InvalidateRefreshToken(refresh_token)) {
- spdlog::debug("User logged out successfully");
- res.set_content(R"({"message":"Logged out successfully"})", "application/json");
- } else {
- res.status = 400;
- res.set_content(R"({"error":"Invalid refresh token"})", "application/json");
- }
- } catch (const nlohmann::json::parse_error& e) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Logout error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleAuthMe(const httplib::Request& req, httplib::Response& res) {
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Build response with user info from token
- nlohmann::json response = {
- {"id", auth_user->user_id},
- {"email", auth_user->email},
- {"groups", auth_user->groups},
- {"workspace_ids", auth_user->workspace_ids}
- };
- // Try to get additional user info from database
- if (userService_) {
- auto user_result = userService_->GetUser(auth_user->user_id);
- if (user_result.success && user_result.user) {
- response["name"] = user_result.user->name;
- response["created_at"] = user_result.user->created_at;
- }
- }
- // Check if user is superadmin based on groups
- response["is_superadmin"] = IsSuperadmin(*auth_user);
- res.set_content(response.dump(), "application/json");
- }
- auto HttpServer::AuthenticateRequest(const httplib::Request& req) -> std::optional<AuthUser> {
- std::string auth_token;
- // First check X-API-Key header (direct API key)
- auto api_key_header = req.get_header_value("X-API-Key");
- if (!api_key_header.empty()) {
- auth_token = api_key_header;
- } else {
- // Check Authorization header
- auto auth_header = req.get_header_value("Authorization");
- if (auth_header.empty()) {
- return std::nullopt;
- }
- auto token = AuthService::ExtractBearerToken(auth_header);
- if (!token) {
- return std::nullopt;
- }
- auth_token = *token;
- }
- // Check if this is an API key (starts with "sk_")
- if (auth_token.starts_with("sk_")) {
- if (!apiKeyService_) {
- spdlog::warn("API key authentication attempted but service not available");
- return std::nullopt;
- }
- auto validation = apiKeyService_->ValidateApiKey(auth_token);
- if (!validation.valid || !validation.api_key) {
- spdlog::debug("API key validation failed: {}", validation.error);
- return std::nullopt;
- }
- // Check if key is expired
- if (validation.api_key->IsExpired()) {
- spdlog::debug("API key expired");
- return std::nullopt;
- }
- // Update last used timestamp (fire and forget)
- apiKeyService_->UpdateLastUsed(validation.api_key->id);
- // Build AuthUser from API key
- AuthUser auth_user;
- auth_user.user_id = validation.api_key->user_id;
- // Use API key permissions as groups
- auth_user.groups = validation.api_key->permissions;
- // Try to fetch additional user info
- if (userService_) {
- auto user_result = userService_->GetUser(validation.api_key->user_id);
- if (user_result.success && user_result.user) {
- auth_user.email = user_result.user->email;
- // Fetch workspace memberships for the user
- if (membershipService_) {
- auto memberships = membershipService_->ListUserMemberships(user_result.user->id);
- for (const auto& m : memberships.members) {
- auth_user.workspace_ids.push_back(m.workspace_id);
- }
- }
- } else {
- spdlog::debug("API key owner user not found in database: {}", validation.api_key->user_id);
- }
- }
- return auth_user;
- }
- // Otherwise, treat as JWT token
- auto validation = authService_->ValidateAccessToken(auth_token);
- if (!validation.valid) {
- spdlog::debug("Token validation failed: {}", validation.error);
- return std::nullopt;
- }
- // Verify the user still exists in the database
- // This handles cases where the database was reset or user was deleted
- if (userService_ && validation.user) {
- auto user_result = userService_->GetUser(validation.user->user_id);
- if (!user_result.success || !user_result.user) {
- spdlog::debug("Token user no longer exists in database: {}", validation.user->user_id);
- return std::nullopt;
- }
- }
- return validation.user;
- }
- // ============================================================================
- // User Management Routes Implementation
- // ============================================================================
- void HttpServer::SetupUserRoutes() {
- // POST /api/users - Create a new user (superadmin only)
- httpServer_->Post("/api/users", [this](const httplib::Request& req, httplib::Response& res) {
- HandleCreateUser(req, res);
- });
- // GET /api/users - List all users (superadmin only)
- httpServer_->Get("/api/users", [this](const httplib::Request& req, httplib::Response& res) {
- HandleListUsers(req, res);
- });
- // GET /api/users/:id - Get a specific user
- httpServer_->Get(R"(/api/users/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleGetUser(req, res);
- });
- // PATCH /api/users/:id - Update a user
- httpServer_->Patch(R"(/api/users/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleUpdateUser(req, res);
- });
- // DELETE /api/users/:id - Soft delete a user (superadmin only)
- httpServer_->Delete(R"(/api/users/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleDeleteUser(req, res);
- });
- spdlog::info("User management routes registered: /api/users");
- }
- auto HttpServer::IsSuperadmin(const AuthUser& user) -> bool {
- // Delegate to authorization service for proper permission checking
- // This maintains backward compatibility while using the new RBAC system
- if (authorizationService_) {
- return authorizationService_->IsSuperadmin(user);
- }
- // Fallback to old behavior if authorization service not available
- return std::find(user.groups.begin(), user.groups.end(), "superadmin") != user.groups.end();
- }
- auto HttpServer::ResolveUserName(const std::string& user_id) -> std::string {
- if (user_id.empty() || !userService_) {
- return "";
- }
- auto result = userService_->GetUser(user_id, true);
- if (result.success && result.user) {
- return result.user->name;
- }
- return "";
- }
- void HttpServer::HandleCreateUser(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Check permission to create users
- if (!authorizationService_ || !authorizationService_->HasPermission(*auth_user, smartbotic::permissions::kUsersCreate)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - requires system:users:create permission"})", "application/json");
- return;
- }
- // Check if UserService is available
- if (!userService_) {
- res.status = 503;
- res.set_content(R"({"error":"User service not available"})", "application/json");
- return;
- }
- try {
- auto body = nlohmann::json::parse(req.body);
- CreateUserRequest create_req;
- create_req.actor_id = auth_user->user_id;
- if (body.contains("email")) {
- create_req.email = body["email"].get<std::string>();
- }
- if (body.contains("password")) {
- create_req.password = body["password"].get<std::string>();
- }
- if (body.contains("name")) {
- create_req.name = body["name"].get<std::string>();
- }
- auto result = userService_->CreateUser(create_req);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return created user (without password_hash)
- nlohmann::json user_json = {
- {"id", result.user->id},
- {"email", result.user->email},
- {"name", result.user->name},
- {"created_at", result.user->created_at},
- {"updated_at", result.user->updated_at}
- };
- res.status = 201;
- res.set_content(user_json.dump(), "application/json");
- } catch (const nlohmann::json::parse_error& e) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Create user error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleListUsers(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Requires system:users:read permission
- if (!authorizationService_->HasPermission(*auth_user, permissions::kUsersRead)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - requires system:users:read permission"})", "application/json");
- return;
- }
- // Check if UserService is available
- if (!userService_) {
- res.status = 503;
- res.set_content(R"({"error":"User service not available"})", "application/json");
- return;
- }
- try {
- // Parse query parameters
- int limit = 100;
- int offset = 0;
- bool include_deleted = false;
- if (req.has_param("limit")) {
- limit = std::stoi(req.get_param_value("limit"));
- if (limit < 1 || limit > 1000) {
- limit = 100;
- }
- }
- if (req.has_param("offset")) {
- offset = std::stoi(req.get_param_value("offset"));
- if (offset < 0) {
- offset = 0;
- }
- }
- if (req.has_param("include_deleted")) {
- include_deleted = req.get_param_value("include_deleted") == "true";
- }
- auto result = userService_->ListUsers(limit, offset, include_deleted);
- if (!result.success) {
- res.status = 500;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Build response
- nlohmann::json users_array = nlohmann::json::array();
- for (const auto& user : result.users) {
- nlohmann::json user_obj = {
- {"id", user.id},
- {"email", user.email},
- {"name", user.name},
- {"created_at", user.created_at},
- {"updated_at", user.updated_at},
- {"deleted_at", user.deleted_at},
- {"created_by", user.created_by},
- {"updated_by", user.updated_by},
- {"created_by_name", ResolveUserName(user.created_by)},
- {"updated_by_name", ResolveUserName(user.updated_by)}
- };
- users_array.push_back(user_obj);
- }
- nlohmann::json response = {
- {"users", users_array},
- {"total_count", result.total_count},
- {"limit", limit},
- {"offset", offset}
- };
- res.set_content(response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("List users error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleGetUser(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Check if UserService is available
- if (!userService_) {
- res.status = 503;
- res.set_content(R"({"error":"User service not available"})", "application/json");
- return;
- }
- try {
- // Extract user ID from path
- std::string user_id = req.matches[1].str();
- // Users can only get their own info, or require system:users:read permission
- bool is_own = (auth_user->user_id == user_id);
- if (!is_own && !authorizationService_->HasPermission(*auth_user, permissions::kUsersRead)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - can only access your own user data or requires system:users:read permission"})", "application/json");
- return;
- }
- auto result = userService_->GetUser(user_id);
- if (!result.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return user (without password_hash)
- nlohmann::json user_json = {
- {"id", result.user->id},
- {"email", result.user->email},
- {"name", result.user->name},
- {"created_at", result.user->created_at},
- {"updated_at", result.user->updated_at}
- };
- res.set_content(user_json.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Get user error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleUpdateUser(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Check if UserService is available
- if (!userService_) {
- res.status = 503;
- res.set_content(R"({"error":"User service not available"})", "application/json");
- return;
- }
- try {
- // Extract user ID from path
- std::string user_id = req.matches[1].str();
- // Users can only update their own info, or require system:users:update permission
- bool is_own = (auth_user->user_id == user_id);
- if (!is_own && !authorizationService_->HasPermission(*auth_user, permissions::kUsersUpdate)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - can only update your own user data or requires system:users:update permission"})", "application/json");
- return;
- }
- auto body = nlohmann::json::parse(req.body);
- UpdateUserRequest update_req;
- update_req.actor_id = auth_user->user_id;
- if (body.contains("email")) {
- update_req.email = body["email"].get<std::string>();
- }
- if (body.contains("password")) {
- update_req.password = body["password"].get<std::string>();
- }
- if (body.contains("name")) {
- update_req.name = body["name"].get<std::string>();
- }
- auto result = userService_->UpdateUser(user_id, update_req);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return updated user (without password_hash)
- nlohmann::json user_json = {
- {"id", result.user->id},
- {"email", result.user->email},
- {"name", result.user->name},
- {"created_at", result.user->created_at},
- {"updated_at", result.user->updated_at}
- };
- res.set_content(user_json.dump(), "application/json");
- } catch (const nlohmann::json::parse_error& e) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Update user error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleDeleteUser(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Requires system:users:delete permission
- if (!authorizationService_->HasPermission(*auth_user, permissions::kUsersDelete)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - requires system:users:delete permission"})", "application/json");
- return;
- }
- // Check if UserService is available
- if (!userService_) {
- res.status = 503;
- res.set_content(R"({"error":"User service not available"})", "application/json");
- return;
- }
- try {
- // Extract user ID from path
- std::string user_id = req.matches[1].str();
- auto result = userService_->DeleteUser(user_id);
- if (!result.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- res.set_content(R"({"message":"User deleted successfully"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Delete user error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- // ============================================================================
- // Workspace Management Routes Implementation
- // ============================================================================
- void HttpServer::SetupWorkspaceRoutes() {
- // POST /api/workspaces - Create a new workspace (superadmin only)
- httpServer_->Post("/api/workspaces", [this](const httplib::Request& req, httplib::Response& res) {
- HandleCreateWorkspace(req, res);
- });
- // GET /api/workspaces - List workspaces (filtered by user membership for non-superadmin)
- httpServer_->Get("/api/workspaces", [this](const httplib::Request& req, httplib::Response& res) {
- HandleListWorkspaces(req, res);
- });
- // GET /api/workspaces/:id - Get a specific workspace
- httpServer_->Get(R"(/api/workspaces/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleGetWorkspace(req, res);
- });
- // PATCH /api/workspaces/:id - Update a workspace
- httpServer_->Patch(R"(/api/workspaces/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleUpdateWorkspace(req, res);
- });
- // DELETE /api/workspaces/:id - Soft delete a workspace (superadmin only)
- httpServer_->Delete(R"(/api/workspaces/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleDeleteWorkspace(req, res);
- });
- spdlog::info("Workspace management routes registered: /api/workspaces");
- }
- void HttpServer::HandleCreateWorkspace(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Requires system:workspaces:create permission
- if (!authorizationService_->HasPermission(*auth_user, permissions::kWorkspacesCreate)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - requires system:workspaces:create permission"})", "application/json");
- return;
- }
- // Check if WorkspaceService is available
- if (!workspaceService_) {
- res.status = 503;
- res.set_content(R"({"error":"Workspace service not available"})", "application/json");
- return;
- }
- try {
- auto body = nlohmann::json::parse(req.body);
- CreateWorkspaceRequest create_req;
- create_req.actor_id = auth_user->user_id;
- if (body.contains("name")) {
- create_req.name = body["name"].get<std::string>();
- }
- if (body.contains("settings")) {
- create_req.settings = body["settings"];
- }
- auto result = workspaceService_->CreateWorkspace(create_req);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return created workspace
- nlohmann::json workspace_json = {
- {"id", result.workspace->id},
- {"name", result.workspace->name},
- {"settings", result.workspace->settings},
- {"created_at", result.workspace->created_at},
- {"updated_at", result.workspace->updated_at}
- };
- res.status = 201;
- res.set_content(workspace_json.dump(), "application/json");
- } catch (const nlohmann::json::parse_error& e) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Create workspace error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleListWorkspaces(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Check if WorkspaceService is available
- if (!workspaceService_) {
- res.status = 503;
- res.set_content(R"({"error":"Workspace service not available"})", "application/json");
- return;
- }
- try {
- WorkspaceListResult result;
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kWorkspacesRead);
- // Users with system:workspaces:read can see all workspaces, others only see their memberships
- if (has_system_access) {
- // Parse query parameters
- int limit = 100;
- int offset = 0;
- bool include_deleted = false;
- if (req.has_param("limit")) {
- limit = std::stoi(req.get_param_value("limit"));
- if (limit < 1 || limit > 1000) {
- limit = 100;
- }
- }
- if (req.has_param("offset")) {
- offset = std::stoi(req.get_param_value("offset"));
- if (offset < 0) {
- offset = 0;
- }
- }
- if (req.has_param("include_deleted")) {
- include_deleted = req.get_param_value("include_deleted") == "true";
- }
- result = workspaceService_->ListWorkspaces(limit, offset, include_deleted);
- } else {
- // Non-privileged user: filter by user's workspace memberships
- result = workspaceService_->ListWorkspacesByIds(auth_user->workspace_ids, false);
- }
- if (!result.success) {
- res.status = 500;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Build response
- nlohmann::json workspaces_array = nlohmann::json::array();
- for (const auto& workspace : result.workspaces) {
- nlohmann::json ws_json = {
- {"id", workspace.id},
- {"name", workspace.name},
- {"settings", workspace.settings},
- {"created_at", workspace.created_at},
- {"updated_at", workspace.updated_at},
- {"created_by", workspace.created_by},
- {"updated_by", workspace.updated_by},
- {"created_by_name", ResolveUserName(workspace.created_by)},
- {"updated_by_name", ResolveUserName(workspace.updated_by)}
- };
- if (has_system_access) {
- ws_json["deleted_at"] = workspace.deleted_at;
- }
- workspaces_array.push_back(ws_json);
- }
- nlohmann::json response = {
- {"workspaces", workspaces_array},
- {"total_count", result.total_count}
- };
- res.set_content(response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("List workspaces error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleGetWorkspace(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Check if WorkspaceService is available
- if (!workspaceService_) {
- res.status = 503;
- res.set_content(R"({"error":"Workspace service not available"})", "application/json");
- return;
- }
- try {
- // Extract workspace ID from path
- std::string workspace_id = req.matches[1].str();
- // Check access: must be member OR have system:workspaces:read permission
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kWorkspacesRead);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - not a member of this workspace"})", "application/json");
- return;
- }
- auto result = workspaceService_->GetWorkspace(workspace_id);
- if (!result.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return workspace
- nlohmann::json workspace_json = {
- {"id", result.workspace->id},
- {"name", result.workspace->name},
- {"settings", result.workspace->settings},
- {"created_at", result.workspace->created_at},
- {"updated_at", result.workspace->updated_at}
- };
- res.set_content(workspace_json.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Get workspace error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleUpdateWorkspace(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID from path (needed for IsWorkspaceAdmin check)
- std::string workspace_id = req.matches[1].str();
- // Requires system:workspaces:update permission OR workspace admin
- bool can_update = authorizationService_->HasPermission(*auth_user, permissions::kWorkspacesUpdate) ||
- authorizationService_->IsWorkspaceAdmin(*auth_user, workspace_id);
- if (!can_update) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - requires system:workspaces:update permission or workspace admin"})", "application/json");
- return;
- }
- // Check if WorkspaceService is available
- if (!workspaceService_) {
- res.status = 503;
- res.set_content(R"({"error":"Workspace service not available"})", "application/json");
- return;
- }
- try {
- auto body = nlohmann::json::parse(req.body);
- UpdateWorkspaceRequest update_req;
- update_req.actor_id = auth_user->user_id;
- if (body.contains("name")) {
- update_req.name = body["name"].get<std::string>();
- }
- if (body.contains("settings")) {
- update_req.settings = body["settings"];
- }
- auto result = workspaceService_->UpdateWorkspace(workspace_id, update_req);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return updated workspace
- nlohmann::json workspace_json = {
- {"id", result.workspace->id},
- {"name", result.workspace->name},
- {"settings", result.workspace->settings},
- {"created_at", result.workspace->created_at},
- {"updated_at", result.workspace->updated_at}
- };
- res.set_content(workspace_json.dump(), "application/json");
- } catch (const nlohmann::json::parse_error& e) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Update workspace error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleDeleteWorkspace(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Requires system:workspaces:delete permission
- if (!authorizationService_->HasPermission(*auth_user, permissions::kWorkspacesDelete)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - requires system:workspaces:delete permission"})", "application/json");
- return;
- }
- // Check if WorkspaceService is available
- if (!workspaceService_) {
- res.status = 503;
- res.set_content(R"({"error":"Workspace service not available"})", "application/json");
- return;
- }
- try {
- // Extract workspace ID from path
- std::string workspace_id = req.matches[1].str();
- auto result = workspaceService_->DeleteWorkspace(workspace_id);
- if (!result.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- res.set_content(R"({"message":"Workspace deleted successfully"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Delete workspace error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- // ============================================================================
- // Group Management Routes Implementation
- // ============================================================================
- void HttpServer::SetupGroupRoutes() {
- // POST /api/workspaces/:wid/groups - Create a new group in workspace
- httpServer_->Post(R"(/api/workspaces/([a-zA-Z0-9\-]+)/groups)", [this](const httplib::Request& req, httplib::Response& res) {
- HandleCreateGroup(req, res);
- });
- // GET /api/workspaces/:wid/groups - List groups in workspace
- httpServer_->Get(R"(/api/workspaces/([a-zA-Z0-9\-]+)/groups)", [this](const httplib::Request& req, httplib::Response& res) {
- HandleListGroups(req, res);
- });
- // GET /api/workspaces/:wid/groups/:id - Get a specific group
- httpServer_->Get(R"(/api/workspaces/([a-zA-Z0-9\-]+)/groups/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleGetGroup(req, res);
- });
- // PATCH /api/workspaces/:wid/groups/:id - Update a group
- httpServer_->Patch(R"(/api/workspaces/([a-zA-Z0-9\-]+)/groups/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleUpdateGroup(req, res);
- });
- // DELETE /api/workspaces/:wid/groups/:id - Delete a group
- httpServer_->Delete(R"(/api/workspaces/([a-zA-Z0-9\-]+)/groups/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleDeleteGroup(req, res);
- });
- spdlog::info("Group management routes registered: /api/workspaces/:wid/groups");
- }
- void HttpServer::HandleCreateGroup(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID from path
- std::string workspace_id = req.matches[1].str();
- // Requires system:groups:create permission OR workspace group management permission
- bool can_create = authorizationService_->HasPermission(*auth_user, permissions::kGroupsCreate) ||
- authorizationService_->CanManageWorkspaceGroups(*auth_user, workspace_id);
- if (!can_create) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - requires system:groups:create permission or workspace group management"})", "application/json");
- return;
- }
- // Check if GroupService is available
- if (!groupService_) {
- res.status = 503;
- res.set_content(R"({"error":"Group service not available"})", "application/json");
- return;
- }
- try {
- auto body = nlohmann::json::parse(req.body);
- CreateGroupRequest create_req;
- create_req.workspace_id = workspace_id;
- create_req.actor_id = auth_user->user_id;
- if (body.contains("name")) {
- create_req.name = body["name"].get<std::string>();
- }
- if (body.contains("permissions") && body["permissions"].is_array()) {
- for (const auto& perm : body["permissions"]) {
- if (perm.is_string()) {
- create_req.permissions.push_back(perm.get<std::string>());
- }
- }
- }
- auto result = groupService_->CreateGroup(create_req);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return created group
- nlohmann::json group_json = {
- {"id", result.group->id},
- {"workspace_id", result.group->workspace_id},
- {"name", result.group->name},
- {"permissions", result.group->permissions},
- {"created_at", result.group->created_at},
- {"updated_at", result.group->updated_at}
- };
- res.status = 201;
- res.set_content(group_json.dump(), "application/json");
- } catch (const nlohmann::json::parse_error& e) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Create group error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleListGroups(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID from path
- std::string workspace_id = req.matches[1].str();
- // Check access: must be member OR have system:groups:read permission
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kGroupsRead);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - not a member of this workspace"})", "application/json");
- return;
- }
- // Check if GroupService is available
- if (!groupService_) {
- res.status = 503;
- res.set_content(R"({"error":"Group service not available"})", "application/json");
- return;
- }
- try {
- // Parse query parameters
- int limit = 100;
- int offset = 0;
- bool include_deleted = false;
- if (req.has_param("limit")) {
- limit = std::stoi(req.get_param_value("limit"));
- if (limit < 1 || limit > 1000) {
- limit = 100;
- }
- }
- if (req.has_param("offset")) {
- offset = std::stoi(req.get_param_value("offset"));
- if (offset < 0) {
- offset = 0;
- }
- }
- if (has_system_access && req.has_param("include_deleted")) {
- include_deleted = req.get_param_value("include_deleted") == "true";
- }
- bool include_system = has_system_access &&
- req.has_param("include_system") &&
- req.get_param_value("include_system") == "true";
- auto result = groupService_->ListGroups(workspace_id, limit, offset, include_deleted);
- if (!result.success) {
- res.status = 500;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Build response
- nlohmann::json groups_array = nlohmann::json::array();
- // Add global system groups first if requested
- if (include_system) {
- auto global_result = groupService_->ListSystemGroups();
- if (global_result.success) {
- for (const auto& group : global_result.groups) {
- nlohmann::json grp_json = {
- {"id", group.id},
- {"workspace_id", group.workspace_id},
- {"name", group.name},
- {"permissions", group.permissions},
- {"is_system", group.is_system},
- {"parent_group_id", group.parent_group_id},
- {"created_at", group.created_at},
- {"updated_at", group.updated_at},
- {"deleted_at", group.deleted_at},
- {"created_by", group.created_by},
- {"updated_by", group.updated_by},
- {"created_by_name", ResolveUserName(group.created_by)},
- {"updated_by_name", ResolveUserName(group.updated_by)}
- };
- groups_array.push_back(grp_json);
- }
- }
- }
- for (const auto& group : result.groups) {
- nlohmann::json grp_json = {
- {"id", group.id},
- {"workspace_id", group.workspace_id},
- {"name", group.name},
- {"permissions", group.permissions},
- {"is_system", group.is_system},
- {"parent_group_id", group.parent_group_id},
- {"created_at", group.created_at},
- {"updated_at", group.updated_at},
- {"created_by", group.created_by},
- {"updated_by", group.updated_by},
- {"created_by_name", ResolveUserName(group.created_by)},
- {"updated_by_name", ResolveUserName(group.updated_by)}
- };
- if (has_system_access) {
- grp_json["deleted_at"] = group.deleted_at;
- }
- groups_array.push_back(grp_json);
- }
- nlohmann::json response = {
- {"groups", groups_array},
- {"total_count", result.total_count}
- };
- res.set_content(response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("List groups error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleGetGroup(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and group ID from path
- std::string workspace_id = req.matches[1].str();
- std::string group_id = req.matches[2].str();
- // Check access: must be member OR have system:groups:read permission
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kGroupsRead);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - not a member of this workspace"})", "application/json");
- return;
- }
- // Check if GroupService is available
- if (!groupService_) {
- res.status = 503;
- res.set_content(R"({"error":"Group service not available"})", "application/json");
- return;
- }
- try {
- auto result = groupService_->GetGroup(group_id);
- if (!result.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Verify group belongs to the workspace
- if (result.group->workspace_id != workspace_id) {
- res.status = 404;
- res.set_content(R"({"error":"Group not found in this workspace"})", "application/json");
- return;
- }
- // Return group
- nlohmann::json group_json = {
- {"id", result.group->id},
- {"workspace_id", result.group->workspace_id},
- {"name", result.group->name},
- {"permissions", result.group->permissions},
- {"created_at", result.group->created_at},
- {"updated_at", result.group->updated_at}
- };
- res.set_content(group_json.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Get group error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleUpdateGroup(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and group ID from path
- std::string workspace_id = req.matches[1].str();
- std::string group_id = req.matches[2].str();
- // Requires system:groups:update permission OR workspace group management permission
- bool can_update = authorizationService_->HasPermission(*auth_user, permissions::kGroupsUpdate) ||
- authorizationService_->CanManageWorkspaceGroups(*auth_user, workspace_id);
- if (!can_update) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - requires system:groups:update permission or workspace group management"})", "application/json");
- return;
- }
- // Check if GroupService is available
- if (!groupService_) {
- res.status = 503;
- res.set_content(R"({"error":"Group service not available"})", "application/json");
- return;
- }
- try {
- // First verify group belongs to the workspace
- auto existing = groupService_->GetGroup(group_id);
- if (!existing.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", existing.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- if (existing.group->workspace_id != workspace_id) {
- res.status = 404;
- res.set_content(R"({"error":"Group not found in this workspace"})", "application/json");
- return;
- }
- auto body = nlohmann::json::parse(req.body);
- UpdateGroupRequest update_req;
- update_req.actor_id = auth_user->user_id;
- if (body.contains("name")) {
- update_req.name = body["name"].get<std::string>();
- }
- if (body.contains("permissions") && body["permissions"].is_array()) {
- std::vector<std::string> perms;
- for (const auto& perm : body["permissions"]) {
- if (perm.is_string()) {
- perms.push_back(perm.get<std::string>());
- }
- }
- update_req.permissions = perms;
- }
- auto result = groupService_->UpdateGroup(group_id, update_req);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return updated group
- nlohmann::json group_json = {
- {"id", result.group->id},
- {"workspace_id", result.group->workspace_id},
- {"name", result.group->name},
- {"permissions", result.group->permissions},
- {"created_at", result.group->created_at},
- {"updated_at", result.group->updated_at}
- };
- res.set_content(group_json.dump(), "application/json");
- } catch (const nlohmann::json::parse_error& e) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Update group error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleDeleteGroup(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and group ID from path
- std::string workspace_id = req.matches[1].str();
- std::string group_id = req.matches[2].str();
- // Requires system:groups:delete permission OR workspace group management permission
- bool can_delete = authorizationService_->HasPermission(*auth_user, permissions::kGroupsDelete) ||
- authorizationService_->CanManageWorkspaceGroups(*auth_user, workspace_id);
- if (!can_delete) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - requires system:groups:delete permission or workspace group management"})", "application/json");
- return;
- }
- // Check if GroupService is available
- if (!groupService_) {
- res.status = 503;
- res.set_content(R"({"error":"Group service not available"})", "application/json");
- return;
- }
- try {
- // First verify group belongs to the workspace
- auto existing = groupService_->GetGroup(group_id);
- if (!existing.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", existing.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- if (existing.group->workspace_id != workspace_id) {
- res.status = 404;
- res.set_content(R"({"error":"Group not found in this workspace"})", "application/json");
- return;
- }
- auto result = groupService_->DeleteGroup(group_id);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- res.set_content(R"({"message":"Group deleted successfully"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Delete group error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- // ============================================================================
- // Membership Routes
- // ============================================================================
- void HttpServer::SetupMembershipRoutes() {
- // POST /api/workspaces/:wid/members - Add a user to workspace
- httpServer_->Post(R"(/api/workspaces/([a-zA-Z0-9\-]+)/members)", [this](const httplib::Request& req, httplib::Response& res) {
- HandleAddMember(req, res);
- });
- // GET /api/workspaces/:wid/members - List members in workspace
- httpServer_->Get(R"(/api/workspaces/([a-zA-Z0-9\-]+)/members)", [this](const httplib::Request& req, httplib::Response& res) {
- HandleListMembers(req, res);
- });
- // GET /api/workspaces/:wid/members/:userId - Get a specific member
- httpServer_->Get(R"(/api/workspaces/([a-zA-Z0-9\-]+)/members/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleGetMember(req, res);
- });
- // PUT /api/workspaces/:wid/members/:userId - Update user's groups in workspace
- httpServer_->Put(R"(/api/workspaces/([a-zA-Z0-9\-]+)/members/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleUpdateMember(req, res);
- });
- // DELETE /api/workspaces/:wid/members/:userId - Remove user from workspace
- httpServer_->Delete(R"(/api/workspaces/([a-zA-Z0-9\-]+)/members/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleRemoveMember(req, res);
- });
- spdlog::info("Membership routes registered: /api/workspaces/:wid/members");
- }
- void HttpServer::HandleAddMember(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID from path
- std::string workspace_id = req.matches[1].str();
- // Requires system:memberships:create permission OR workspace member management permission
- bool can_add = authorizationService_->HasPermission(*auth_user, permissions::kMembershipsCreate) ||
- authorizationService_->CanManageWorkspaceMembers(*auth_user, workspace_id);
- if (!can_add) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - requires system:memberships:create permission or workspace member management"})", "application/json");
- return;
- }
- // Check if MembershipService is available
- if (!membershipService_) {
- res.status = 503;
- res.set_content(R"({"error":"Membership service not available"})", "application/json");
- return;
- }
- try {
- // Parse request body
- auto json = nlohmann::json::parse(req.body);
- AddMemberRequest add_req;
- add_req.workspace_id = workspace_id;
- if (json.contains("user_id") && json["user_id"].is_string()) {
- add_req.user_id = json["user_id"].get<std::string>();
- } else {
- res.status = 400;
- res.set_content(R"({"error":"user_id is required"})", "application/json");
- return;
- }
- if (json.contains("group_ids") && json["group_ids"].is_array()) {
- for (const auto& item : json["group_ids"]) {
- if (item.is_string()) {
- add_req.group_ids.push_back(item.get<std::string>());
- }
- }
- }
- auto result = membershipService_->AddMember(add_req);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return created membership
- nlohmann::json member_json = {
- {"id", result.member->id},
- {"workspace_id", result.member->workspace_id},
- {"user_id", result.member->user_id},
- {"group_ids", result.member->group_ids},
- {"created_at", result.member->created_at},
- {"updated_at", result.member->updated_at}
- };
- res.status = 201;
- res.set_content(member_json.dump(), "application/json");
- } catch (const nlohmann::json::exception& e) {
- res.status = 400;
- nlohmann::json error_response = {{"error", "Invalid JSON: " + std::string(e.what())}};
- res.set_content(error_response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Add member error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleListMembers(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID from path
- std::string workspace_id = req.matches[1].str();
- // Check access: must be member OR have system:memberships:read permission
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kMembershipsRead);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - not a member of this workspace"})", "application/json");
- return;
- }
- // Check if MembershipService is available
- if (!membershipService_) {
- res.status = 503;
- res.set_content(R"({"error":"Membership service not available"})", "application/json");
- return;
- }
- try {
- // Get query parameters
- int limit = 100;
- int offset = 0;
- bool include_deleted = false;
- if (req.has_param("limit")) {
- limit = std::stoi(req.get_param_value("limit"));
- if (limit < 1 || limit > 1000) {
- limit = 100;
- }
- }
- if (req.has_param("offset")) {
- offset = std::stoi(req.get_param_value("offset"));
- if (offset < 0) {
- offset = 0;
- }
- }
- if (has_system_access && req.has_param("include_deleted")) {
- include_deleted = req.get_param_value("include_deleted") == "true";
- }
- auto result = membershipService_->ListMembers(workspace_id, limit, offset, include_deleted);
- if (!result.success) {
- res.status = 500;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Build response with user details
- nlohmann::json members_array = nlohmann::json::array();
- for (const auto& member : result.members) {
- nlohmann::json member_json = {
- {"id", member.id},
- {"workspace_id", member.workspace_id},
- {"user_id", member.user_id},
- {"group_ids", member.group_ids},
- {"created_at", member.created_at},
- {"updated_at", member.updated_at}
- };
- if (has_system_access) {
- member_json["deleted_at"] = member.deleted_at;
- }
- // Fetch user details if UserService is available
- if (userService_) {
- auto user_result = userService_->GetUser(member.user_id);
- if (user_result.success && user_result.user) {
- member_json["user"] = {
- {"id", user_result.user->id},
- {"email", user_result.user->email},
- {"name", user_result.user->name},
- {"created_at", user_result.user->created_at}
- };
- }
- }
- members_array.push_back(member_json);
- }
- nlohmann::json response = {
- {"members", members_array},
- {"total_count", result.total_count}
- };
- res.set_content(response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("List members error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleGetMember(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and user ID from path
- std::string workspace_id = req.matches[1].str();
- std::string user_id = req.matches[2].str();
- // Check access: must be member OR have system:memberships:read permission
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kMembershipsRead);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - not a member of this workspace"})", "application/json");
- return;
- }
- // Check if MembershipService is available
- if (!membershipService_) {
- res.status = 503;
- res.set_content(R"({"error":"Membership service not available"})", "application/json");
- return;
- }
- try {
- auto result = membershipService_->GetMembershipByUser(workspace_id, user_id);
- if (!result.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return membership
- nlohmann::json member_json = {
- {"id", result.member->id},
- {"workspace_id", result.member->workspace_id},
- {"user_id", result.member->user_id},
- {"group_ids", result.member->group_ids},
- {"created_at", result.member->created_at},
- {"updated_at", result.member->updated_at}
- };
- res.set_content(member_json.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Get member error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleUpdateMember(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and user ID from path
- std::string workspace_id = req.matches[1].str();
- std::string user_id = req.matches[2].str();
- // Requires system:memberships:update permission OR workspace member management permission
- bool can_update = authorizationService_->HasPermission(*auth_user, permissions::kMembershipsUpdate) ||
- authorizationService_->CanManageWorkspaceMembers(*auth_user, workspace_id);
- if (!can_update) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - requires system:memberships:update permission or workspace member management"})", "application/json");
- return;
- }
- // Check if MembershipService is available
- if (!membershipService_) {
- res.status = 503;
- res.set_content(R"({"error":"Membership service not available"})", "application/json");
- return;
- }
- try {
- // Parse request body
- auto json = nlohmann::json::parse(req.body);
- UpdateMemberRequest update_req;
- if (json.contains("group_ids") && json["group_ids"].is_array()) {
- std::vector<std::string> group_ids;
- for (const auto& item : json["group_ids"]) {
- if (item.is_string()) {
- group_ids.push_back(item.get<std::string>());
- }
- }
- update_req.group_ids = group_ids;
- }
- auto result = membershipService_->UpdateMembership(workspace_id, user_id, update_req);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return updated membership
- nlohmann::json member_json = {
- {"id", result.member->id},
- {"workspace_id", result.member->workspace_id},
- {"user_id", result.member->user_id},
- {"group_ids", result.member->group_ids},
- {"created_at", result.member->created_at},
- {"updated_at", result.member->updated_at}
- };
- res.set_content(member_json.dump(), "application/json");
- } catch (const nlohmann::json::exception& e) {
- res.status = 400;
- nlohmann::json error_response = {{"error", "Invalid JSON: " + std::string(e.what())}};
- res.set_content(error_response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Update member error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleRemoveMember(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and user ID from path
- std::string workspace_id = req.matches[1].str();
- std::string user_id = req.matches[2].str();
- // Requires system:memberships:delete permission OR workspace member management permission
- bool can_remove = authorizationService_->HasPermission(*auth_user, permissions::kMembershipsDelete) ||
- authorizationService_->CanManageWorkspaceMembers(*auth_user, workspace_id);
- if (!can_remove) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - requires system:memberships:delete permission or workspace member management"})", "application/json");
- return;
- }
- // Check if MembershipService is available
- if (!membershipService_) {
- res.status = 503;
- res.set_content(R"({"error":"Membership service not available"})", "application/json");
- return;
- }
- try {
- auto result = membershipService_->RemoveMember(workspace_id, user_id);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- res.set_content(R"({"message":"Member removed successfully"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Remove member error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- // ============================================================================
- // API Key Routes
- // ============================================================================
- void HttpServer::SetupApiKeyRoutes() {
- // POST /api/users/:id/api-keys - Create an API key for a user
- httpServer_->Post(R"(/api/users/([a-zA-Z0-9\-]+)/api-keys)", [this](const httplib::Request& req, httplib::Response& res) {
- HandleCreateApiKey(req, res);
- });
- // GET /api/users/:id/api-keys - List user's API keys
- httpServer_->Get(R"(/api/users/([a-zA-Z0-9\-]+)/api-keys)", [this](const httplib::Request& req, httplib::Response& res) {
- HandleListApiKeys(req, res);
- });
- // DELETE /api/users/:id/api-keys/:keyId - Revoke an API key
- httpServer_->Delete(R"(/api/users/([a-zA-Z0-9\-]+)/api-keys/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleRevokeApiKey(req, res);
- });
- spdlog::info("API key routes registered: /api/users/:id/api-keys");
- }
- void HttpServer::HandleCreateApiKey(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract user ID from path
- std::string target_user_id = req.matches[1].str();
- // Check permissions: own OR system:api_keys:create permission
- bool is_own = (auth_user->user_id == target_user_id);
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kApiKeysCreate);
- if (!is_own && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - can only create API keys for yourself or requires system:api_keys:create permission"})", "application/json");
- return;
- }
- // Check if ApiKeyService is available
- if (!apiKeyService_) {
- res.status = 503;
- res.set_content(R"({"error":"API key service not available"})", "application/json");
- return;
- }
- try {
- // Parse request body
- auto json = nlohmann::json::parse(req.body);
- CreateApiKeyRequest create_req;
- create_req.user_id = target_user_id;
- if (json.contains("name") && json["name"].is_string()) {
- create_req.name = json["name"].get<std::string>();
- } else {
- res.status = 400;
- res.set_content(R"({"error":"name is required"})", "application/json");
- return;
- }
- if (json.contains("permissions") && json["permissions"].is_array()) {
- for (const auto& item : json["permissions"]) {
- if (item.is_string()) {
- std::string perm = item.get<std::string>();
- // Users can only grant permissions they have (unless they have system access)
- if (!has_system_access) {
- // For now, allow all permissions - proper permission checking
- // would require looking up user's actual permissions
- }
- create_req.permissions.push_back(perm);
- }
- }
- }
- if (json.contains("expires_at") && json["expires_at"].is_string()) {
- create_req.expires_at = json["expires_at"].get<std::string>();
- }
- auto result = apiKeyService_->CreateApiKey(create_req);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return created key info INCLUDING the raw key (only time it's returned!)
- nlohmann::json key_json = {
- {"id", result.api_key->id},
- {"user_id", result.api_key->user_id},
- {"name", result.api_key->name},
- {"key_prefix", result.api_key->key_prefix},
- {"key", result.raw_key}, // THE RAW KEY - only returned once!
- {"permissions", result.api_key->permissions},
- {"created_at", result.api_key->created_at},
- {"expires_at", result.api_key->expires_at}
- };
- res.status = 201;
- res.set_content(key_json.dump(), "application/json");
- } catch (const nlohmann::json::exception& e) {
- res.status = 400;
- nlohmann::json error_response = {{"error", "Invalid JSON: " + std::string(e.what())}};
- res.set_content(error_response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Create API key error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleListApiKeys(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract user ID from path
- std::string target_user_id = req.matches[1].str();
- // Check permissions: own OR system:api_keys:read permission
- bool is_own = (auth_user->user_id == target_user_id);
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kApiKeysRead);
- if (!is_own && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - can only list your own API keys or requires system:api_keys:read permission"})", "application/json");
- return;
- }
- // Check if ApiKeyService is available
- if (!apiKeyService_) {
- res.status = 503;
- res.set_content(R"({"error":"API key service not available"})", "application/json");
- return;
- }
- try {
- // Check for include_revoked parameter (requires system access)
- bool include_revoked = false;
- if (has_system_access && req.has_param("include_revoked")) {
- include_revoked = req.get_param_value("include_revoked") == "true";
- }
- auto result = apiKeyService_->ListApiKeys(target_user_id, include_revoked);
- if (!result.success) {
- res.status = 500;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Build response (note: raw keys and hashes are NOT included)
- nlohmann::json keys_array = nlohmann::json::array();
- for (const auto& key : result.api_keys) {
- nlohmann::json key_json = {
- {"id", key.id},
- {"user_id", key.user_id},
- {"name", key.name},
- {"key_prefix", key.key_prefix}, // Only prefix, not full key
- {"permissions", key.permissions},
- {"created_at", key.created_at},
- {"updated_at", key.updated_at},
- {"last_used_at", key.last_used_at},
- {"expires_at", key.expires_at}
- };
- if (has_system_access) {
- key_json["deleted_at"] = key.deleted_at;
- }
- keys_array.push_back(key_json);
- }
- nlohmann::json response = {
- {"api_keys", keys_array},
- {"total_count", result.total_count}
- };
- res.set_content(response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("List API keys error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleRevokeApiKey(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract user ID and key ID from path
- std::string target_user_id = req.matches[1].str();
- std::string key_id = req.matches[2].str();
- // Check permissions: own OR system:api_keys:delete permission
- bool is_own = (auth_user->user_id == target_user_id);
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kApiKeysDelete);
- if (!is_own && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - can only revoke your own API keys or requires system:api_keys:delete permission"})", "application/json");
- return;
- }
- // Check if ApiKeyService is available
- if (!apiKeyService_) {
- res.status = 503;
- res.set_content(R"({"error":"API key service not available"})", "application/json");
- return;
- }
- try {
- auto result = apiKeyService_->RevokeApiKey(key_id, target_user_id);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- res.set_content(R"({"message":"API key revoked successfully"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Revoke API key error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- // ============================================================================
- // Collection Routes
- // ============================================================================
- void HttpServer::SetupCollectionRoutes() {
- // POST /api/workspaces/:wid/collections - Create a collection
- httpServer_->Post(R"(/api/workspaces/([a-zA-Z0-9\-]+)/collections)", [this](const httplib::Request& req, httplib::Response& res) {
- HandleCreateCollection(req, res);
- });
- // GET /api/workspaces/:wid/collections - List collections
- httpServer_->Get(R"(/api/workspaces/([a-zA-Z0-9\-]+)/collections)", [this](const httplib::Request& req, httplib::Response& res) {
- HandleListCollections(req, res);
- });
- // GET /api/workspaces/:wid/collections/:name - Get a collection
- httpServer_->Get(R"(/api/workspaces/([a-zA-Z0-9\-]+)/collections/([a-zA-Z_][a-zA-Z0-9_]*))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleGetCollection(req, res);
- });
- // PUT /api/workspaces/:wid/collections/:name - Update a collection
- httpServer_->Put(R"(/api/workspaces/([a-zA-Z0-9\-]+)/collections/([a-zA-Z_][a-zA-Z0-9_]*))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleUpdateCollection(req, res);
- });
- // DELETE /api/workspaces/:wid/collections/:name - Drop a collection
- httpServer_->Delete(R"(/api/workspaces/([a-zA-Z0-9\-]+)/collections/([a-zA-Z_][a-zA-Z0-9_]*))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleDropCollection(req, res);
- });
- spdlog::info("Collection routes registered: /api/workspaces/:wid/collections");
- }
- void HttpServer::HandleCreateCollection(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID from path
- std::string workspace_id = req.matches[1].str();
- // Verify workspace exists and user has access
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Requires system:collections:create permission OR workspace membership with manage_collections
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kCollectionsCreate);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no access to this workspace"})", "application/json");
- return;
- }
- // Check if CollectionService is available
- if (!collectionService_) {
- res.status = 503;
- res.set_content(R"({"error":"Collection service not available"})", "application/json");
- return;
- }
- try {
- // Parse request body
- auto json = nlohmann::json::parse(req.body);
- CreateCollectionRequest create_req;
- create_req.workspace_id = workspace_id;
- if (json.contains("name") && json["name"].is_string()) {
- create_req.name = json["name"].get<std::string>();
- } else {
- res.status = 400;
- res.set_content(R"({"error":"name is required"})", "application/json");
- return;
- }
- // Parse settings
- if (json.contains("schema") && json["schema"].is_string()) {
- create_req.settings.schema = json["schema"].get<std::string>();
- }
- if (json.contains("encrypted_fields") && json["encrypted_fields"].is_array()) {
- for (const auto& item : json["encrypted_fields"]) {
- if (item.is_string()) {
- create_req.settings.encrypted_fields.push_back(item.get<std::string>());
- }
- }
- }
- if (json.contains("ttl_seconds") && json["ttl_seconds"].is_number_integer()) {
- create_req.settings.ttl_seconds = json["ttl_seconds"].get<int64_t>();
- }
- auto result = collectionService_->CreateCollection(create_req);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return created collection info
- nlohmann::json coll_json = {
- {"name", result.collection->name},
- {"workspace_id", result.collection->workspace_id},
- {"document_count", result.collection->document_count},
- {"size_bytes", result.collection->size_bytes},
- {"created_at", result.collection->created_at},
- {"settings", {
- {"schema", result.collection->settings.schema},
- {"encrypted_fields", result.collection->settings.encrypted_fields},
- {"ttl_seconds", result.collection->settings.ttl_seconds}
- }}
- };
- res.status = 201;
- res.set_content(coll_json.dump(), "application/json");
- } catch (const nlohmann::json::exception& e) {
- spdlog::warn("Create collection JSON parse error: {}", e.what());
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON in request body"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Create collection error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleListCollections(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID from path
- std::string workspace_id = req.matches[1].str();
- // Verify workspace exists and user has access
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Check access: must be member OR have system:collections:read permission
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kCollectionsRead);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no access to this workspace"})", "application/json");
- return;
- }
- // Check if CollectionService is available
- if (!collectionService_) {
- res.status = 503;
- res.set_content(R"({"error":"Collection service not available"})", "application/json");
- return;
- }
- try {
- // Check if user with system access wants to include system collections
- bool include_system = has_system_access &&
- req.has_param("include_system") &&
- req.get_param_value("include_system") == "true";
- auto result = collectionService_->ListCollections(workspace_id);
- if (!result.success) {
- res.status = 500;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- nlohmann::json collections_array = nlohmann::json::array();
- for (const auto& coll : result.collections) {
- // Check if collection name starts with underscore (system collection)
- bool is_system = !coll.name.empty() && coll.name[0] == '_';
- nlohmann::json coll_json = {
- {"name", coll.name},
- {"workspace_id", coll.workspace_id},
- {"document_count", coll.document_count},
- {"size_bytes", coll.size_bytes},
- {"created_at", coll.created_at},
- {"updated_at", coll.updated_at},
- {"is_system", is_system},
- {"created_by", coll.created_by},
- {"updated_by", coll.updated_by},
- {"created_by_name", ResolveUserName(coll.created_by)},
- {"updated_by_name", ResolveUserName(coll.updated_by)},
- {"settings", {
- {"schema", coll.settings.schema},
- {"encrypted_fields", coll.settings.encrypted_fields},
- {"ttl_seconds", coll.settings.ttl_seconds}
- }}
- };
- collections_array.push_back(coll_json);
- }
- // If superadmin requested system collections, add global system collections
- if (include_system) {
- auto system_result = collectionService_->ListSystemCollections();
- if (system_result.success) {
- for (const auto& coll : system_result.collections) {
- nlohmann::json coll_json = {
- {"name", coll.name},
- {"workspace_id", ""},
- {"document_count", coll.document_count},
- {"size_bytes", coll.size_bytes},
- {"created_at", coll.created_at},
- {"updated_at", coll.updated_at},
- {"is_system", true},
- {"created_by", coll.created_by},
- {"updated_by", coll.updated_by},
- {"created_by_name", ResolveUserName(coll.created_by)},
- {"updated_by_name", ResolveUserName(coll.updated_by)},
- {"settings", nlohmann::json::object()}
- };
- collections_array.push_back(coll_json);
- }
- }
- }
- nlohmann::json response = {
- {"collections", collections_array},
- {"total_count", static_cast<int64_t>(collections_array.size())}
- };
- res.set_content(response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("List collections error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleGetCollection(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and collection name from path
- std::string workspace_id = req.matches[1].str();
- std::string collection_name = req.matches[2].str();
- // Verify workspace exists and user has access
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Check access: must be member OR have system:collections:read permission
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kCollectionsRead);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no access to this workspace"})", "application/json");
- return;
- }
- // Check if CollectionService is available
- if (!collectionService_) {
- res.status = 503;
- res.set_content(R"({"error":"Collection service not available"})", "application/json");
- return;
- }
- try {
- auto result = collectionService_->GetCollection(workspace_id, collection_name);
- if (!result.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- nlohmann::json coll_json = {
- {"name", result.collection->name},
- {"workspace_id", result.collection->workspace_id},
- {"document_count", result.collection->document_count},
- {"size_bytes", result.collection->size_bytes},
- {"created_at", result.collection->created_at},
- {"updated_at", result.collection->updated_at},
- {"settings", {
- {"schema", result.collection->settings.schema},
- {"encrypted_fields", result.collection->settings.encrypted_fields},
- {"ttl_seconds", result.collection->settings.ttl_seconds}
- }}
- };
- res.set_content(coll_json.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Get collection error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleUpdateCollection(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and collection name from path
- std::string workspace_id = req.matches[1].str();
- std::string collection_name = req.matches[2].str();
- // Verify workspace exists and user has access
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Requires system:collections:update permission OR workspace membership
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kCollectionsUpdate);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no access to this workspace"})", "application/json");
- return;
- }
- // Check if CollectionService is available
- if (!collectionService_) {
- res.status = 503;
- res.set_content(R"({"error":"Collection service not available"})", "application/json");
- return;
- }
- try {
- // Parse request body
- auto json = nlohmann::json::parse(req.body);
- // Get existing settings first
- auto get_result = collectionService_->GetCollection(workspace_id, collection_name);
- if (!get_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Collection not found"})", "application/json");
- return;
- }
- CollectionSettings settings = get_result.collection->settings;
- // Update only provided fields
- if (json.contains("schema") && json["schema"].is_string()) {
- settings.schema = json["schema"].get<std::string>();
- }
- if (json.contains("encrypted_fields") && json["encrypted_fields"].is_array()) {
- settings.encrypted_fields.clear();
- for (const auto& item : json["encrypted_fields"]) {
- if (item.is_string()) {
- settings.encrypted_fields.push_back(item.get<std::string>());
- }
- }
- }
- if (json.contains("ttl_seconds") && json["ttl_seconds"].is_number_integer()) {
- settings.ttl_seconds = json["ttl_seconds"].get<int64_t>();
- }
- auto result = collectionService_->UpdateCollection(workspace_id, collection_name, settings);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- nlohmann::json coll_json = {
- {"name", result.collection->name},
- {"workspace_id", result.collection->workspace_id},
- {"document_count", result.collection->document_count},
- {"size_bytes", result.collection->size_bytes},
- {"created_at", result.collection->created_at},
- {"updated_at", result.collection->updated_at},
- {"settings", {
- {"schema", result.collection->settings.schema},
- {"encrypted_fields", result.collection->settings.encrypted_fields},
- {"ttl_seconds", result.collection->settings.ttl_seconds}
- }}
- };
- res.set_content(coll_json.dump(), "application/json");
- } catch (const nlohmann::json::exception& e) {
- spdlog::warn("Update collection JSON parse error: {}", e.what());
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON in request body"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Update collection error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- // ============================================================================
- // Document Routes
- // ============================================================================
- void HttpServer::SetupDocumentRoutes() {
- // POST /api/workspaces/:wid/collections/:name/documents - Create a document
- httpServer_->Post(R"(/api/workspaces/([a-zA-Z0-9\-]+)/collections/([a-zA-Z_][a-zA-Z0-9_]*)/documents)", [this](const httplib::Request& req, httplib::Response& res) {
- HandleCreateDocument(req, res);
- });
- // GET /api/workspaces/:wid/collections/:name/documents - List documents
- httpServer_->Get(R"(/api/workspaces/([a-zA-Z0-9\-]+)/collections/([a-zA-Z_][a-zA-Z0-9_]*)/documents)", [this](const httplib::Request& req, httplib::Response& res) {
- HandleListDocuments(req, res);
- });
- // GET /api/workspaces/:wid/collections/:name/documents/:id - Get a document
- httpServer_->Get(R"(/api/workspaces/([a-zA-Z0-9\-]+)/collections/([a-zA-Z_][a-zA-Z0-9_]*)/documents/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleGetDocument(req, res);
- });
- // PUT /api/workspaces/:wid/collections/:name/documents/:id - Update a document
- httpServer_->Put(R"(/api/workspaces/([a-zA-Z0-9\-]+)/collections/([a-zA-Z_][a-zA-Z0-9_]*)/documents/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleUpdateDocument(req, res);
- });
- // PATCH /api/workspaces/:wid/collections/:name/documents/:id - Update a document (partial)
- httpServer_->Patch(R"(/api/workspaces/([a-zA-Z0-9\-]+)/collections/([a-zA-Z_][a-zA-Z0-9_]*)/documents/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleUpdateDocument(req, res);
- });
- // DELETE /api/workspaces/:wid/collections/:name/documents/:id - Delete a document
- httpServer_->Delete(R"(/api/workspaces/([a-zA-Z0-9\-]+)/collections/([a-zA-Z_][a-zA-Z0-9_]*)/documents/([a-zA-Z0-9\-]+))", [this](const httplib::Request& req, httplib::Response& res) {
- HandleDeleteDocument(req, res);
- });
- spdlog::info("Document routes registered: /api/workspaces/:wid/collections/:name/documents");
- }
- void HttpServer::HandleCreateDocument(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and collection name from path
- std::string workspace_id = req.matches[1].str();
- std::string collection_name = req.matches[2].str();
- // Verify workspace exists and user has access
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Check document create permission using AuthorizationService
- if (!authorizationService_->CanCreateDocument(*auth_user, workspace_id, collection_name)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no permission to create documents in this collection"})", "application/json");
- return;
- }
- // Check if DocumentService is available
- if (!documentService_) {
- res.status = 503;
- res.set_content(R"({"error":"Document service not available"})", "application/json");
- return;
- }
- try {
- // Parse request body
- auto json = nlohmann::json::parse(req.body);
- CreateDocumentRequest create_req;
- create_req.workspace_id = workspace_id;
- create_req.collection = collection_name;
- create_req.user_id = auth_user->user_id; // Set user for _created_by tracking
- if (json.contains("id") && json["id"].is_string()) {
- create_req.id = json["id"].get<std::string>();
- }
- if (json.contains("data") && json["data"].is_object()) {
- create_req.data = json["data"];
- } else {
- // Treat entire body as data if no "data" field
- create_req.data = json;
- create_req.data.erase("id"); // Remove id from data
- }
- auto result = documentService_->CreateDocument(create_req);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Return created document info
- nlohmann::json doc_json = {
- {"id", result.document->id},
- {"collection", result.document->collection},
- {"workspace_id", result.document->workspace_id},
- {"data", result.document->data},
- {"created_at", result.document->created_at},
- {"updated_at", result.document->updated_at},
- {"version", result.document->version}
- };
- // Broadcast document create event to WebSocket subscribers
- BroadcastDocumentEvent(workspace_id, collection_name, DocumentAction::Create,
- result.document->id, result.document->data);
- res.status = 201;
- res.set_content(doc_json.dump(), "application/json");
- } catch (const nlohmann::json::exception& e) {
- spdlog::warn("Create document JSON parse error: {}", e.what());
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON in request body"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Create document error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleListDocuments(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and collection name from path
- std::string workspace_id = req.matches[1].str();
- std::string collection_name = req.matches[2].str();
- // Verify workspace exists and user has access
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Check collection read permission using AuthorizationService
- if (!authorizationService_->CanReadCollection(*auth_user, workspace_id, collection_name)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no permission to read documents in this collection"})", "application/json");
- return;
- }
- // Check if DocumentService is available
- if (!documentService_) {
- res.status = 503;
- res.set_content(R"({"error":"Document service not available"})", "application/json");
- return;
- }
- try {
- DocumentQuery query;
- query.workspace_id = workspace_id;
- query.collection = collection_name;
- // Parse query parameters
- if (req.has_param("limit")) {
- query.limit = std::stoi(req.get_param_value("limit"));
- if (query.limit < 1) query.limit = 1;
- if (query.limit > 1000) query.limit = 1000;
- }
- if (req.has_param("offset")) {
- query.offset = std::stoi(req.get_param_value("offset"));
- if (query.offset < 0) query.offset = 0;
- }
- if (req.has_param("sort")) {
- query.sort_field = req.get_param_value("sort");
- }
- if (req.has_param("order")) {
- query.sort_ascending = (req.get_param_value("order") != "desc");
- }
- if (req.has_param("filter")) {
- try {
- query.filter = nlohmann::json::parse(req.get_param_value("filter"));
- } catch (...) {
- // Invalid filter JSON - ignore
- }
- }
- auto result = documentService_->ListDocuments(query);
- if (!result.success) {
- res.status = 500;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- nlohmann::json docs_array = nlohmann::json::array();
- for (const auto& doc : result.documents) {
- // Resolve user names for _created_by and _updated_by
- nlohmann::json enriched_data = doc.data;
- if (doc.data.contains("_created_by") && doc.data["_created_by"].is_string()) {
- std::string created_by_name = ResolveUserName(doc.data["_created_by"].get<std::string>());
- if (!created_by_name.empty()) {
- enriched_data["_created_by_name"] = created_by_name;
- }
- }
- if (doc.data.contains("_updated_by") && doc.data["_updated_by"].is_string()) {
- std::string updated_by_name = ResolveUserName(doc.data["_updated_by"].get<std::string>());
- if (!updated_by_name.empty()) {
- enriched_data["_updated_by_name"] = updated_by_name;
- }
- }
- nlohmann::json doc_json = {
- {"id", doc.id},
- {"collection", doc.collection},
- {"workspace_id", doc.workspace_id},
- {"data", enriched_data},
- {"created_at", doc.created_at},
- {"updated_at", doc.updated_at},
- {"version", doc.version}
- };
- docs_array.push_back(doc_json);
- }
- nlohmann::json response = {
- {"documents", docs_array},
- {"total_count", result.total_count}
- };
- res.set_content(response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("List documents error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleGetDocument(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID, collection name, and document ID from path
- std::string workspace_id = req.matches[1].str();
- std::string collection_name = req.matches[2].str();
- std::string document_id = req.matches[3].str();
- // Verify workspace exists and user has access
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Check if DocumentService is available
- if (!documentService_) {
- res.status = 503;
- res.set_content(R"({"error":"Document service not available"})", "application/json");
- return;
- }
- try {
- auto result = documentService_->GetDocument(workspace_id, collection_name, document_id);
- if (!result.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Check document read permission with ownership
- std::string doc_owner = result.document->data.value("_created_by", "");
- if (!authorizationService_->CanReadDocument(*auth_user, workspace_id, collection_name, doc_owner)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no permission to read this document"})", "application/json");
- return;
- }
- nlohmann::json doc_json = {
- {"id", result.document->id},
- {"collection", result.document->collection},
- {"workspace_id", result.document->workspace_id},
- {"data", result.document->data},
- {"created_at", result.document->created_at},
- {"updated_at", result.document->updated_at},
- {"version", result.document->version}
- };
- res.set_content(doc_json.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Get document error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleUpdateDocument(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID, collection name, and document ID from path
- std::string workspace_id = req.matches[1].str();
- std::string collection_name = req.matches[2].str();
- std::string document_id = req.matches[3].str();
- // Verify workspace exists and user has access
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Check if DocumentService is available
- if (!documentService_) {
- res.status = 503;
- res.set_content(R"({"error":"Document service not available"})", "application/json");
- return;
- }
- try {
- // First get the document to check ownership
- auto existing = documentService_->GetDocument(workspace_id, collection_name, document_id);
- if (!existing.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", existing.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Check document write permission with ownership
- std::string doc_owner = existing.document->data.value("_created_by", "");
- if (!authorizationService_->CanWriteDocument(*auth_user, workspace_id, collection_name, doc_owner)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no permission to update this document"})", "application/json");
- return;
- }
- // Parse request body
- auto json = nlohmann::json::parse(req.body);
- UpdateDocumentRequest update_req;
- update_req.workspace_id = workspace_id;
- update_req.collection = collection_name;
- update_req.id = document_id;
- update_req.user_id = auth_user->user_id; // Set user for _updated_by tracking
- if (json.contains("data") && json["data"].is_object()) {
- update_req.data = json["data"];
- } else {
- // Treat entire body as data if no "data" field
- update_req.data = json;
- }
- if (json.contains("merge") && json["merge"].is_boolean()) {
- update_req.merge = json["merge"].get<bool>();
- }
- if (json.contains("expected_version") && json["expected_version"].is_number_integer()) {
- update_req.expected_version = json["expected_version"].get<int64_t>();
- }
- auto result = documentService_->UpdateDocument(update_req);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- nlohmann::json doc_json = {
- {"id", result.document->id},
- {"collection", result.document->collection},
- {"workspace_id", result.document->workspace_id},
- {"data", result.document->data},
- {"created_at", result.document->created_at},
- {"updated_at", result.document->updated_at},
- {"version", result.document->version}
- };
- // Broadcast document update event to WebSocket subscribers
- BroadcastDocumentEvent(workspace_id, collection_name, DocumentAction::Update,
- result.document->id, result.document->data);
- res.set_content(doc_json.dump(), "application/json");
- } catch (const nlohmann::json::exception& e) {
- spdlog::warn("Update document JSON parse error: {}", e.what());
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON in request body"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Update document error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleDeleteDocument(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID, collection name, and document ID from path
- std::string workspace_id = req.matches[1].str();
- std::string collection_name = req.matches[2].str();
- std::string document_id = req.matches[3].str();
- // Verify workspace exists and user has access
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Check if DocumentService is available
- if (!documentService_) {
- res.status = 503;
- res.set_content(R"({"error":"Document service not available"})", "application/json");
- return;
- }
- try {
- // First get the document to check ownership
- auto existing = documentService_->GetDocument(workspace_id, collection_name, document_id);
- if (!existing.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", existing.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Check document delete permission with ownership
- std::string doc_owner = existing.document->data.value("_created_by", "");
- if (!authorizationService_->CanDeleteDocument(*auth_user, workspace_id, collection_name, doc_owner)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no permission to delete this document"})", "application/json");
- return;
- }
- auto result = documentService_->DeleteDocument(workspace_id, collection_name, document_id);
- if (!result.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Broadcast document delete event to WebSocket subscribers
- BroadcastDocumentEvent(workspace_id, collection_name, DocumentAction::Delete,
- document_id, nlohmann::json::object());
- res.set_content(R"({"message":"Document deleted successfully"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Delete document error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleDropCollection(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and collection name from path
- std::string workspace_id = req.matches[1].str();
- std::string collection_name = req.matches[2].str();
- // Verify workspace exists and user has access
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Requires system:collections:delete permission OR workspace membership
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kCollectionsDelete);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no access to this workspace"})", "application/json");
- return;
- }
- // Check if CollectionService is available
- if (!collectionService_) {
- res.status = 503;
- res.set_content(R"({"error":"Collection service not available"})", "application/json");
- return;
- }
- try {
- // Check for force parameter
- bool force = false;
- if (req.has_param("force")) {
- force = req.get_param_value("force") == "true";
- }
- auto result = collectionService_->DropCollection(workspace_id, collection_name, force);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- res.set_content(R"({"message":"Collection dropped successfully"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Drop collection error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- // ============================================================================
- // View Routes
- // ============================================================================
- void HttpServer::SetupViewRoutes() {
- // POST /api/workspaces/:workspace_id/views - Create a new view
- httpServer_->Post(R"(/api/workspaces/([^/]+)/views)",
- [this](const httplib::Request& req, httplib::Response& res) {
- HandleCreateView(req, res);
- });
- // GET /api/workspaces/:workspace_id/views - List all views
- httpServer_->Get(R"(/api/workspaces/([^/]+)/views)",
- [this](const httplib::Request& req, httplib::Response& res) {
- HandleListViews(req, res);
- });
- // GET /api/workspaces/:workspace_id/views/:view_id - Get a specific view
- httpServer_->Get(R"(/api/workspaces/([^/]+)/views/([^/]+))",
- [this](const httplib::Request& req, httplib::Response& res) {
- HandleGetView(req, res);
- });
- // PATCH /api/workspaces/:workspace_id/views/:view_id - Update a view
- httpServer_->Patch(R"(/api/workspaces/([^/]+)/views/([^/]+))",
- [this](const httplib::Request& req, httplib::Response& res) {
- HandleUpdateView(req, res);
- });
- // DELETE /api/workspaces/:workspace_id/views/:view_id - Delete a view
- httpServer_->Delete(R"(/api/workspaces/([^/]+)/views/([^/]+))",
- [this](const httplib::Request& req, httplib::Response& res) {
- HandleDeleteView(req, res);
- });
- spdlog::info("View routes configured");
- }
- void HttpServer::HandleCreateView(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID from path
- std::string workspace_id = req.matches[1].str();
- // Verify workspace exists
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Requires system:views:create permission OR workspace membership
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kViewsCreate);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no access to this workspace"})", "application/json");
- return;
- }
- // Check if ViewService is available
- if (!viewService_) {
- res.status = 503;
- res.set_content(R"({"error":"View service not available"})", "application/json");
- return;
- }
- // Parse request body
- nlohmann::json body;
- try {
- body = nlohmann::json::parse(req.body);
- } catch (const nlohmann::json::parse_error& /*e*/) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- return;
- }
- // Validate required fields
- if (!body.contains("name") || !body["name"].is_string()) {
- res.status = 400;
- res.set_content(R"({"error":"name is required"})", "application/json");
- return;
- }
- if (!body.contains("collection_name") || !body["collection_name"].is_string()) {
- res.status = 400;
- res.set_content(R"({"error":"collection_name is required"})", "application/json");
- return;
- }
- try {
- CreateViewRequest request;
- request.workspace_id = workspace_id;
- request.name = body["name"].get<std::string>();
- request.collection_name = body["collection_name"].get<std::string>();
- // Parse schema if provided
- if (body.contains("schema") && body["schema"].is_object()) {
- const auto& schema_json = body["schema"];
- if (schema_json.contains("title")) {
- request.schema.title = schema_json.value("title", "");
- }
- if (schema_json.contains("description")) {
- request.schema.description = schema_json.value("description", "");
- }
- if (schema_json.contains("layout")) {
- request.schema.layout = schema_json["layout"];
- }
- if (schema_json.contains("fields") && schema_json["fields"].is_array()) {
- for (const auto& field_json : schema_json["fields"]) {
- SchemaField field;
- field.name = field_json.value("name", "");
- field.type = StringToFieldType(field_json.value("type", "text"));
- field.label = field_json.value("label", "");
- field.description = field_json.value("description", "");
- field.required = field_json.value("required", false);
- field.display_order = field_json.value("display_order", 0);
- field.widget = field_json.value("widget", "");
- field.group = field_json.value("group", "");
- field.default_value = field_json.value("default_value", nlohmann::json());
- field.options = field_json.value("options", nlohmann::json());
- field.reference_collection = field_json.value("reference_collection", "");
- field.computed_expression = field_json.value("computed_expression", "");
- request.schema.fields.push_back(field);
- }
- }
- }
- // Parse settings if provided
- if (body.contains("settings") && body["settings"].is_object()) {
- const auto& settings_json = body["settings"];
- request.settings.is_default = settings_json.value("is_default", false);
- request.settings.show_in_sidebar = settings_json.value("show_in_sidebar", true);
- request.settings.show_create_button = settings_json.value("show_create_button", true);
- request.settings.icon = settings_json.value("icon", "");
- request.settings.filters = settings_json.value("filters", nlohmann::json::object());
- request.settings.sort = settings_json.value("sort", nlohmann::json::object());
- request.settings.quick_create_mode = settings_json.value("quick_create_mode", "modal");
- request.settings.quick_edit_mode = settings_json.value("quick_edit_mode", "modal");
- request.settings.show_edit_button = settings_json.value("show_edit_button", true);
- if (settings_json.contains("quick_create_fields") && settings_json["quick_create_fields"].is_array()) {
- for (const auto& field : settings_json["quick_create_fields"]) {
- if (field.is_string()) {
- request.settings.quick_create_fields.push_back(field.get<std::string>());
- }
- }
- }
- if (settings_json.contains("quick_edit_fields") && settings_json["quick_edit_fields"].is_array()) {
- for (const auto& field : settings_json["quick_edit_fields"]) {
- if (field.is_string()) {
- request.settings.quick_edit_fields.push_back(field.get<std::string>());
- }
- }
- }
- }
- auto result = viewService_->CreateView(request);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Build response with view info
- nlohmann::json view_json = {
- {"id", result.view->id},
- {"workspace_id", result.view->workspace_id},
- {"name", result.view->name},
- {"collection_name", result.view->collection_name},
- {"created_at", result.view->created_at},
- {"updated_at", result.view->updated_at}
- };
- // Add schema
- nlohmann::json schema_json = {
- {"title", result.view->schema.title},
- {"description", result.view->schema.description},
- {"layout", result.view->schema.layout}
- };
- nlohmann::json fields_json = nlohmann::json::array();
- for (const auto& field : result.view->schema.fields) {
- nlohmann::json field_json = {
- {"name", field.name},
- {"type", FieldTypeToString(field.type)},
- {"label", field.label},
- {"description", field.description},
- {"required", field.required},
- {"display_order", field.display_order},
- {"widget", field.widget},
- {"group", field.group}
- };
- if (!field.default_value.is_null()) {
- field_json["default_value"] = field.default_value;
- }
- if (!field.options.is_null()) {
- field_json["options"] = field.options;
- }
- if (!field.reference_collection.empty()) {
- field_json["reference_collection"] = field.reference_collection;
- }
- if (!field.computed_expression.empty()) {
- field_json["computed_expression"] = field.computed_expression;
- }
- fields_json.push_back(field_json);
- }
- schema_json["fields"] = fields_json;
- view_json["schema"] = schema_json;
- // Add settings
- nlohmann::json create_settings_json = {
- {"is_default", result.view->settings.is_default},
- {"show_in_sidebar", result.view->settings.show_in_sidebar},
- {"show_create_button", result.view->settings.show_create_button},
- {"show_edit_button", result.view->settings.show_edit_button},
- {"icon", result.view->settings.icon},
- {"filters", result.view->settings.filters},
- {"sort", result.view->settings.sort},
- {"quick_create_mode", result.view->settings.quick_create_mode},
- {"quick_edit_mode", result.view->settings.quick_edit_mode}
- };
- if (!result.view->settings.quick_create_fields.empty()) {
- create_settings_json["quick_create_fields"] = result.view->settings.quick_create_fields;
- }
- if (!result.view->settings.quick_edit_fields.empty()) {
- create_settings_json["quick_edit_fields"] = result.view->settings.quick_edit_fields;
- }
- view_json["settings"] = create_settings_json;
- res.status = 201;
- res.set_content(view_json.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Create view error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleListViews(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID from path
- std::string workspace_id = req.matches[1].str();
- // Verify workspace exists
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Check access: must be member OR have system:views:read permission
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kViewsRead);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no access to this workspace"})", "application/json");
- return;
- }
- // Check if ViewService is available
- if (!viewService_) {
- res.status = 503;
- res.set_content(R"({"error":"View service not available"})", "application/json");
- return;
- }
- try {
- ViewListResult result;
- // Check if filtering by collection
- if (req.has_param("collection")) {
- std::string collection_name = req.get_param_value("collection");
- result = viewService_->ListViewsForCollection(workspace_id, collection_name);
- } else {
- result = viewService_->ListViews(workspace_id);
- }
- if (!result.success) {
- res.status = 500;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- nlohmann::json views_json = nlohmann::json::array();
- for (const auto& view : result.views) {
- nlohmann::json view_json = {
- {"id", view.id},
- {"workspace_id", view.workspace_id},
- {"name", view.name},
- {"collection_name", view.collection_name},
- {"created_at", view.created_at},
- {"updated_at", view.updated_at}
- };
- // Add schema summary (fields count and title)
- view_json["schema"] = {
- {"title", view.schema.title},
- {"field_count", view.schema.fields.size()}
- };
- // Add settings
- nlohmann::json settings_json = {
- {"is_default", view.settings.is_default},
- {"show_in_sidebar", view.settings.show_in_sidebar},
- {"show_create_button", view.settings.show_create_button},
- {"show_edit_button", view.settings.show_edit_button},
- {"icon", view.settings.icon},
- {"quick_create_mode", view.settings.quick_create_mode},
- {"quick_edit_mode", view.settings.quick_edit_mode}
- };
- if (!view.settings.quick_create_fields.empty()) {
- settings_json["quick_create_fields"] = view.settings.quick_create_fields;
- }
- if (!view.settings.quick_edit_fields.empty()) {
- settings_json["quick_edit_fields"] = view.settings.quick_edit_fields;
- }
- view_json["settings"] = settings_json;
- views_json.push_back(view_json);
- }
- nlohmann::json response = {{"views", views_json}};
- res.set_content(response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("List views error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleGetView(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and view ID from path
- std::string workspace_id = req.matches[1].str();
- std::string view_id = req.matches[2].str();
- // Verify workspace exists
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Check access: must be member OR have system:views:read permission
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kViewsRead);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no access to this workspace"})", "application/json");
- return;
- }
- // Check if ViewService is available
- if (!viewService_) {
- res.status = 503;
- res.set_content(R"({"error":"View service not available"})", "application/json");
- return;
- }
- try {
- auto result = viewService_->GetView(workspace_id, view_id);
- if (!result.success || !result.view) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Build full response with view info
- nlohmann::json view_json = {
- {"id", result.view->id},
- {"workspace_id", result.view->workspace_id},
- {"name", result.view->name},
- {"collection_name", result.view->collection_name},
- {"created_at", result.view->created_at},
- {"updated_at", result.view->updated_at}
- };
- // Add schema
- nlohmann::json schema_json = {
- {"title", result.view->schema.title},
- {"description", result.view->schema.description},
- {"layout", result.view->schema.layout}
- };
- nlohmann::json fields_json = nlohmann::json::array();
- for (const auto& field : result.view->schema.fields) {
- nlohmann::json field_json = {
- {"name", field.name},
- {"type", FieldTypeToString(field.type)},
- {"label", field.label},
- {"description", field.description},
- {"required", field.required},
- {"display_order", field.display_order},
- {"widget", field.widget},
- {"group", field.group}
- };
- if (!field.default_value.is_null()) {
- field_json["default_value"] = field.default_value;
- }
- if (!field.options.is_null()) {
- field_json["options"] = field.options;
- }
- if (!field.reference_collection.empty()) {
- field_json["reference_collection"] = field.reference_collection;
- }
- if (!field.computed_expression.empty()) {
- field_json["computed_expression"] = field.computed_expression;
- }
- fields_json.push_back(field_json);
- }
- schema_json["fields"] = fields_json;
- view_json["schema"] = schema_json;
- // Add settings
- nlohmann::json settings_json = {
- {"is_default", result.view->settings.is_default},
- {"show_in_sidebar", result.view->settings.show_in_sidebar},
- {"show_create_button", result.view->settings.show_create_button},
- {"show_edit_button", result.view->settings.show_edit_button},
- {"icon", result.view->settings.icon},
- {"filters", result.view->settings.filters},
- {"sort", result.view->settings.sort},
- {"quick_create_mode", result.view->settings.quick_create_mode},
- {"quick_edit_mode", result.view->settings.quick_edit_mode}
- };
- if (!result.view->settings.quick_create_fields.empty()) {
- settings_json["quick_create_fields"] = result.view->settings.quick_create_fields;
- }
- if (!result.view->settings.quick_edit_fields.empty()) {
- settings_json["quick_edit_fields"] = result.view->settings.quick_edit_fields;
- }
- view_json["settings"] = settings_json;
- res.set_content(view_json.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Get view error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleUpdateView(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and view ID from path
- std::string workspace_id = req.matches[1].str();
- std::string view_id = req.matches[2].str();
- // Verify workspace exists
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Requires system:views:update permission OR workspace membership
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kViewsUpdate);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no access to this workspace"})", "application/json");
- return;
- }
- // Check if ViewService is available
- if (!viewService_) {
- res.status = 503;
- res.set_content(R"({"error":"View service not available"})", "application/json");
- return;
- }
- // Parse request body
- nlohmann::json body;
- try {
- body = nlohmann::json::parse(req.body);
- } catch (const nlohmann::json::parse_error& /*e*/) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- return;
- }
- try {
- UpdateViewRequest request;
- request.workspace_id = workspace_id;
- request.id = view_id;
- if (body.contains("name") && body["name"].is_string()) {
- request.name = body["name"].get<std::string>();
- }
- if (body.contains("collection_name") && body["collection_name"].is_string()) {
- request.collection_name = body["collection_name"].get<std::string>();
- }
- // Parse schema if provided
- if (body.contains("schema") && body["schema"].is_object()) {
- ViewSchema schema;
- const auto& schema_json = body["schema"];
- schema.title = schema_json.value("title", "");
- schema.description = schema_json.value("description", "");
- schema.layout = schema_json.value("layout", nlohmann::json::object());
- if (schema_json.contains("fields") && schema_json["fields"].is_array()) {
- for (const auto& field_json : schema_json["fields"]) {
- SchemaField field;
- field.name = field_json.value("name", "");
- field.type = StringToFieldType(field_json.value("type", "text"));
- field.label = field_json.value("label", "");
- field.description = field_json.value("description", "");
- field.required = field_json.value("required", false);
- field.display_order = field_json.value("display_order", 0);
- field.widget = field_json.value("widget", "");
- field.group = field_json.value("group", "");
- field.default_value = field_json.value("default_value", nlohmann::json());
- field.options = field_json.value("options", nlohmann::json());
- field.reference_collection = field_json.value("reference_collection", "");
- field.computed_expression = field_json.value("computed_expression", "");
- schema.fields.push_back(field);
- }
- }
- request.schema = schema;
- }
- // Parse settings if provided
- if (body.contains("settings") && body["settings"].is_object()) {
- ViewSettings settings;
- const auto& settings_json = body["settings"];
- settings.is_default = settings_json.value("is_default", false);
- settings.show_in_sidebar = settings_json.value("show_in_sidebar", true);
- settings.show_create_button = settings_json.value("show_create_button", true);
- settings.icon = settings_json.value("icon", "");
- settings.filters = settings_json.value("filters", nlohmann::json::object());
- settings.sort = settings_json.value("sort", nlohmann::json::object());
- settings.quick_create_mode = settings_json.value("quick_create_mode", "modal");
- settings.quick_edit_mode = settings_json.value("quick_edit_mode", "modal");
- settings.show_edit_button = settings_json.value("show_edit_button", true);
- if (settings_json.contains("quick_create_fields") && settings_json["quick_create_fields"].is_array()) {
- for (const auto& field : settings_json["quick_create_fields"]) {
- if (field.is_string()) {
- settings.quick_create_fields.push_back(field.get<std::string>());
- }
- }
- }
- if (settings_json.contains("quick_edit_fields") && settings_json["quick_edit_fields"].is_array()) {
- for (const auto& field : settings_json["quick_edit_fields"]) {
- if (field.is_string()) {
- settings.quick_edit_fields.push_back(field.get<std::string>());
- }
- }
- }
- request.settings = settings;
- }
- auto result = viewService_->UpdateView(request);
- if (!result.success || !result.view) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Build response with updated view info
- nlohmann::json view_json = {
- {"id", result.view->id},
- {"workspace_id", result.view->workspace_id},
- {"name", result.view->name},
- {"collection_name", result.view->collection_name},
- {"created_at", result.view->created_at},
- {"updated_at", result.view->updated_at}
- };
- // Add schema
- nlohmann::json schema_json = {
- {"title", result.view->schema.title},
- {"description", result.view->schema.description},
- {"layout", result.view->schema.layout}
- };
- nlohmann::json fields_json = nlohmann::json::array();
- for (const auto& field : result.view->schema.fields) {
- nlohmann::json field_json = {
- {"name", field.name},
- {"type", FieldTypeToString(field.type)},
- {"label", field.label},
- {"description", field.description},
- {"required", field.required},
- {"display_order", field.display_order},
- {"widget", field.widget},
- {"group", field.group}
- };
- if (!field.default_value.is_null()) {
- field_json["default_value"] = field.default_value;
- }
- if (!field.options.is_null()) {
- field_json["options"] = field.options;
- }
- if (!field.reference_collection.empty()) {
- field_json["reference_collection"] = field.reference_collection;
- }
- if (!field.computed_expression.empty()) {
- field_json["computed_expression"] = field.computed_expression;
- }
- fields_json.push_back(field_json);
- }
- schema_json["fields"] = fields_json;
- view_json["schema"] = schema_json;
- // Add settings
- nlohmann::json settings_json = {
- {"is_default", result.view->settings.is_default},
- {"show_in_sidebar", result.view->settings.show_in_sidebar},
- {"show_create_button", result.view->settings.show_create_button},
- {"show_edit_button", result.view->settings.show_edit_button},
- {"icon", result.view->settings.icon},
- {"filters", result.view->settings.filters},
- {"sort", result.view->settings.sort},
- {"quick_create_mode", result.view->settings.quick_create_mode},
- {"quick_edit_mode", result.view->settings.quick_edit_mode}
- };
- if (!result.view->settings.quick_create_fields.empty()) {
- settings_json["quick_create_fields"] = result.view->settings.quick_create_fields;
- }
- if (!result.view->settings.quick_edit_fields.empty()) {
- settings_json["quick_edit_fields"] = result.view->settings.quick_edit_fields;
- }
- view_json["settings"] = settings_json;
- res.set_content(view_json.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Update view error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleDeleteView(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and view ID from path
- std::string workspace_id = req.matches[1].str();
- std::string view_id = req.matches[2].str();
- // Verify workspace exists
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Requires system:views:delete permission OR workspace membership
- bool is_member = (std::find(auth_user->workspace_ids.begin(),
- auth_user->workspace_ids.end(),
- workspace_id) != auth_user->workspace_ids.end());
- bool has_system_access = authorizationService_->HasPermission(*auth_user, permissions::kViewsDelete);
- if (!is_member && !has_system_access) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no access to this workspace"})", "application/json");
- return;
- }
- // Check if ViewService is available
- if (!viewService_) {
- res.status = 503;
- res.set_content(R"({"error":"View service not available"})", "application/json");
- return;
- }
- try {
- auto result = viewService_->DeleteView(workspace_id, view_id);
- if (!result.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- res.set_content(R"({"message":"View deleted successfully"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Delete view error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- // ============================================================================
- // Page Routes
- // ============================================================================
- void HttpServer::SetupPageRoutes() {
- // POST /api/workspaces/:workspace_id/pages - Create a new page
- httpServer_->Post(R"(/api/workspaces/([^/]+)/pages$)",
- [this](const httplib::Request& req, httplib::Response& res) {
- HandleCreatePage(req, res);
- });
- // GET /api/workspaces/:workspace_id/pages - List all pages
- httpServer_->Get(R"(/api/workspaces/([^/]+)/pages$)",
- [this](const httplib::Request& req, httplib::Response& res) {
- HandleListPages(req, res);
- });
- // GET /api/workspaces/:workspace_id/pages/sidebar - List sidebar pages
- httpServer_->Get(R"(/api/workspaces/([^/]+)/pages/sidebar$)",
- [this](const httplib::Request& req, httplib::Response& res) {
- HandleListSidebarPages(req, res);
- });
- // GET /api/workspaces/:workspace_id/pages/slug/:slug - Get page by slug
- httpServer_->Get(R"(/api/workspaces/([^/]+)/pages/slug/([^/]+)$)",
- [this](const httplib::Request& req, httplib::Response& res) {
- HandleGetPageBySlug(req, res);
- });
- // GET /api/workspaces/:workspace_id/pages/:page_id - Get a specific page
- httpServer_->Get(R"(/api/workspaces/([^/]+)/pages/([^/]+)$)",
- [this](const httplib::Request& req, httplib::Response& res) {
- HandleGetPage(req, res);
- });
- // PATCH /api/workspaces/:workspace_id/pages/:page_id - Update a page
- httpServer_->Patch(R"(/api/workspaces/([^/]+)/pages/([^/]+)$)",
- [this](const httplib::Request& req, httplib::Response& res) {
- HandleUpdatePage(req, res);
- });
- // PATCH /api/workspaces/:workspace_id/pages/:page_id/share - Update page sharing
- httpServer_->Patch(R"(/api/workspaces/([^/]+)/pages/([^/]+)/share$)",
- [this](const httplib::Request& req, httplib::Response& res) {
- HandleUpdatePageSharing(req, res);
- });
- // DELETE /api/workspaces/:workspace_id/pages/:page_id - Delete a page
- httpServer_->Delete(R"(/api/workspaces/([^/]+)/pages/([^/]+)$)",
- [this](const httplib::Request& req, httplib::Response& res) {
- HandleDeletePage(req, res);
- });
- spdlog::info("Page routes configured");
- }
- void HttpServer::HandleCreatePage(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID from path
- std::string workspace_id = req.matches[1].str();
- // Verify workspace exists
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Check permission to create pages
- if (!authorizationService_->CanCreatePage(*auth_user, workspace_id)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - insufficient permissions to create pages"})", "application/json");
- return;
- }
- // Check if PageService is available
- if (!pageService_) {
- res.status = 503;
- res.set_content(R"({"error":"Page service not available"})", "application/json");
- return;
- }
- // Parse request body
- nlohmann::json body;
- try {
- body = nlohmann::json::parse(req.body);
- } catch (const nlohmann::json::parse_error& /*e*/) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- return;
- }
- // Validate required fields
- if (!body.contains("name") || !body["name"].is_string()) {
- res.status = 400;
- res.set_content(R"({"error":"name is required"})", "application/json");
- return;
- }
- try {
- CreatePageRequest request;
- request.workspace_id = workspace_id;
- request.name = body["name"].get<std::string>();
- request.slug = body.value("slug", "");
- request.created_by = auth_user->user_id; // Set owner to current user
- // Parse layout if provided
- if (body.contains("layout") && body["layout"].is_object()) {
- const auto& layout_json = body["layout"];
- request.layout.version = layout_json.value("version", 1);
- request.layout.grid_columns = layout_json.value("grid_columns", 12);
- if (layout_json.contains("components") && layout_json["components"].is_array()) {
- for (const auto& comp_json : layout_json["components"]) {
- LayoutComponent comp;
- comp.id = comp_json.value("id", "");
- comp.type = comp_json.value("type", "");
- comp.config = comp_json.value("config", nlohmann::json::object());
- if (comp_json.contains("position") && comp_json["position"].is_object()) {
- const auto& pos = comp_json["position"];
- comp.position.x = pos.value("x", 0);
- comp.position.y = pos.value("y", 0);
- comp.position.width = pos.value("width", 12);
- comp.position.height = pos.value("height", 1);
- }
- request.layout.components.push_back(comp);
- }
- }
- }
- // Parse settings if provided
- if (body.contains("settings") && body["settings"].is_object()) {
- const auto& settings_json = body["settings"];
- request.settings.show_in_sidebar = settings_json.value("show_in_sidebar", true);
- request.settings.icon = settings_json.value("icon", "");
- request.settings.menu_order = settings_json.value("menu_order", 0);
- }
- auto result = pageService_->CreatePage(request);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Build response with page info
- nlohmann::json page_json = {
- {"id", result.page->id},
- {"workspace_id", result.page->workspace_id},
- {"name", result.page->name},
- {"slug", result.page->slug},
- {"created_at", result.page->created_at},
- {"updated_at", result.page->updated_at},
- {"created_by", result.page->created_by},
- {"shared_with_groups", result.page->shared_with_groups}
- };
- // Add layout
- nlohmann::json layout_json = {
- {"version", result.page->layout.version},
- {"grid_columns", result.page->layout.grid_columns}
- };
- nlohmann::json components_json = nlohmann::json::array();
- for (const auto& comp : result.page->layout.components) {
- nlohmann::json comp_json = {
- {"id", comp.id},
- {"type", comp.type},
- {"position", {
- {"x", comp.position.x},
- {"y", comp.position.y},
- {"width", comp.position.width},
- {"height", comp.position.height}
- }},
- {"config", comp.config}
- };
- components_json.push_back(comp_json);
- }
- layout_json["components"] = components_json;
- page_json["layout"] = layout_json;
- // Add settings
- page_json["settings"] = {
- {"show_in_sidebar", result.page->settings.show_in_sidebar},
- {"icon", result.page->settings.icon},
- {"menu_order", result.page->settings.menu_order}
- };
- res.status = 201;
- res.set_content(page_json.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Create page error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleListPages(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID from path
- std::string workspace_id = req.matches[1].str();
- // Verify workspace exists
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Check if PageService is available
- if (!pageService_) {
- res.status = 503;
- res.set_content(R"({"error":"Page service not available"})", "application/json");
- return;
- }
- try {
- auto result = pageService_->ListPages(workspace_id);
- if (!result.success) {
- res.status = 500;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Filter pages based on user permissions
- nlohmann::json pages_json = nlohmann::json::array();
- for (const auto& page : result.pages) {
- // Check if user can view this page
- if (!authorizationService_->CanViewPage(*auth_user, workspace_id,
- page.created_by, page.shared_with_groups)) {
- continue; // Skip pages user cannot view
- }
- nlohmann::json page_json = {
- {"id", page.id},
- {"workspace_id", page.workspace_id},
- {"name", page.name},
- {"slug", page.slug},
- {"created_at", page.created_at},
- {"updated_at", page.updated_at},
- {"created_by", page.created_by},
- {"shared_with_groups", page.shared_with_groups},
- {"settings", {
- {"show_in_sidebar", page.settings.show_in_sidebar},
- {"icon", page.settings.icon},
- {"menu_order", page.settings.menu_order}
- }}
- };
- pages_json.push_back(page_json);
- }
- nlohmann::json response = {{"pages", pages_json}};
- res.set_content(response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("List pages error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleListSidebarPages(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID from path
- std::string workspace_id = req.matches[1].str();
- // Verify workspace exists
- auto ws_result = workspaceService_->GetWorkspace(workspace_id);
- if (!ws_result.success) {
- res.status = 404;
- res.set_content(R"({"error":"Workspace not found"})", "application/json");
- return;
- }
- // Check if PageService is available
- if (!pageService_) {
- res.status = 503;
- res.set_content(R"({"error":"Page service not available"})", "application/json");
- return;
- }
- try {
- auto result = pageService_->ListSidebarPages(workspace_id);
- if (!result.success) {
- res.status = 500;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Filter pages based on user permissions
- nlohmann::json pages_json = nlohmann::json::array();
- for (const auto& page : result.pages) {
- // Check if user can view this page
- if (!authorizationService_->CanViewPage(*auth_user, workspace_id,
- page.created_by, page.shared_with_groups)) {
- continue; // Skip pages user cannot view
- }
- nlohmann::json page_json = {
- {"id", page.id},
- {"workspace_id", page.workspace_id},
- {"name", page.name},
- {"slug", page.slug},
- {"created_by", page.created_by},
- {"settings", {
- {"show_in_sidebar", page.settings.show_in_sidebar},
- {"icon", page.settings.icon},
- {"menu_order", page.settings.menu_order}
- }}
- };
- pages_json.push_back(page_json);
- }
- nlohmann::json response = {{"pages", pages_json}};
- res.set_content(response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("List sidebar pages error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleGetPageBySlug(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and slug from path
- std::string workspace_id = req.matches[1].str();
- std::string slug = req.matches[2].str();
- // Check if PageService is available
- if (!pageService_) {
- res.status = 503;
- res.set_content(R"({"error":"Page service not available"})", "application/json");
- return;
- }
- try {
- auto result = pageService_->GetPageBySlug(workspace_id, slug);
- if (!result.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Check if user can view this page
- if (!authorizationService_->CanViewPage(*auth_user, workspace_id,
- result.page->created_by, result.page->shared_with_groups)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no access to this page"})", "application/json");
- return;
- }
- // Build full response with layout
- nlohmann::json page_json = {
- {"id", result.page->id},
- {"workspace_id", result.page->workspace_id},
- {"name", result.page->name},
- {"slug", result.page->slug},
- {"created_at", result.page->created_at},
- {"updated_at", result.page->updated_at},
- {"created_by", result.page->created_by},
- {"shared_with_groups", result.page->shared_with_groups}
- };
- // Add layout
- nlohmann::json layout_json = {
- {"version", result.page->layout.version},
- {"grid_columns", result.page->layout.grid_columns}
- };
- nlohmann::json components_json = nlohmann::json::array();
- for (const auto& comp : result.page->layout.components) {
- nlohmann::json comp_json = {
- {"id", comp.id},
- {"type", comp.type},
- {"position", {
- {"x", comp.position.x},
- {"y", comp.position.y},
- {"width", comp.position.width},
- {"height", comp.position.height}
- }},
- {"config", comp.config}
- };
- components_json.push_back(comp_json);
- }
- layout_json["components"] = components_json;
- page_json["layout"] = layout_json;
- // Add settings
- page_json["settings"] = {
- {"show_in_sidebar", result.page->settings.show_in_sidebar},
- {"icon", result.page->settings.icon},
- {"menu_order", result.page->settings.menu_order}
- };
- res.set_content(page_json.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Get page by slug error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleGetPage(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and page ID from path
- std::string workspace_id = req.matches[1].str();
- std::string page_id = req.matches[2].str();
- // Check if PageService is available
- if (!pageService_) {
- res.status = 503;
- res.set_content(R"({"error":"Page service not available"})", "application/json");
- return;
- }
- try {
- auto result = pageService_->GetPage(workspace_id, page_id);
- if (!result.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Check if user can view this page
- if (!authorizationService_->CanViewPage(*auth_user, workspace_id,
- result.page->created_by, result.page->shared_with_groups)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - no access to this page"})", "application/json");
- return;
- }
- // Build full response with layout
- nlohmann::json page_json = {
- {"id", result.page->id},
- {"workspace_id", result.page->workspace_id},
- {"name", result.page->name},
- {"slug", result.page->slug},
- {"created_at", result.page->created_at},
- {"updated_at", result.page->updated_at},
- {"created_by", result.page->created_by},
- {"shared_with_groups", result.page->shared_with_groups}
- };
- // Add layout
- nlohmann::json layout_json = {
- {"version", result.page->layout.version},
- {"grid_columns", result.page->layout.grid_columns}
- };
- nlohmann::json components_json = nlohmann::json::array();
- for (const auto& comp : result.page->layout.components) {
- nlohmann::json comp_json = {
- {"id", comp.id},
- {"type", comp.type},
- {"position", {
- {"x", comp.position.x},
- {"y", comp.position.y},
- {"width", comp.position.width},
- {"height", comp.position.height}
- }},
- {"config", comp.config}
- };
- components_json.push_back(comp_json);
- }
- layout_json["components"] = components_json;
- page_json["layout"] = layout_json;
- // Add settings
- page_json["settings"] = {
- {"show_in_sidebar", result.page->settings.show_in_sidebar},
- {"icon", result.page->settings.icon},
- {"menu_order", result.page->settings.menu_order}
- };
- res.set_content(page_json.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Get page error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleUpdatePage(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and page ID from path
- std::string workspace_id = req.matches[1].str();
- std::string page_id = req.matches[2].str();
- // Check if PageService is available
- if (!pageService_) {
- res.status = 503;
- res.set_content(R"({"error":"Page service not available"})", "application/json");
- return;
- }
- // Get existing page to check ownership
- auto existing = pageService_->GetPage(workspace_id, page_id);
- if (!existing.success || !existing.page) {
- res.status = 404;
- res.set_content(R"({"error":"Page not found"})", "application/json");
- return;
- }
- // Check permission to edit
- if (!authorizationService_->CanEditPage(*auth_user, workspace_id, existing.page->created_by)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - insufficient permissions to edit this page"})", "application/json");
- return;
- }
- // Parse request body
- nlohmann::json body;
- try {
- body = nlohmann::json::parse(req.body);
- } catch (const nlohmann::json::parse_error& /*e*/) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- return;
- }
- try {
- UpdatePageRequest request;
- request.workspace_id = workspace_id;
- request.id = page_id;
- if (body.contains("name") && body["name"].is_string()) {
- request.name = body["name"].get<std::string>();
- }
- if (body.contains("slug") && body["slug"].is_string()) {
- request.slug = body["slug"].get<std::string>();
- }
- // Parse layout if provided
- if (body.contains("layout") && body["layout"].is_object()) {
- PageLayout layout;
- const auto& layout_json = body["layout"];
- layout.version = layout_json.value("version", 1);
- layout.grid_columns = layout_json.value("grid_columns", 12);
- if (layout_json.contains("components") && layout_json["components"].is_array()) {
- for (const auto& comp_json : layout_json["components"]) {
- LayoutComponent comp;
- comp.id = comp_json.value("id", "");
- comp.type = comp_json.value("type", "");
- comp.config = comp_json.value("config", nlohmann::json::object());
- if (comp_json.contains("position") && comp_json["position"].is_object()) {
- const auto& pos = comp_json["position"];
- comp.position.x = pos.value("x", 0);
- comp.position.y = pos.value("y", 0);
- comp.position.width = pos.value("width", 12);
- comp.position.height = pos.value("height", 1);
- }
- layout.components.push_back(comp);
- }
- }
- request.layout = layout;
- }
- // Parse settings if provided
- if (body.contains("settings") && body["settings"].is_object()) {
- PageSettings settings;
- const auto& settings_json = body["settings"];
- settings.show_in_sidebar = settings_json.value("show_in_sidebar", true);
- settings.icon = settings_json.value("icon", "");
- settings.menu_order = settings_json.value("menu_order", 0);
- request.settings = settings;
- }
- auto result = pageService_->UpdatePage(request);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Build response with page info
- nlohmann::json page_json = {
- {"id", result.page->id},
- {"workspace_id", result.page->workspace_id},
- {"name", result.page->name},
- {"slug", result.page->slug},
- {"created_at", result.page->created_at},
- {"updated_at", result.page->updated_at},
- {"created_by", result.page->created_by},
- {"shared_with_groups", result.page->shared_with_groups}
- };
- // Add layout
- nlohmann::json layout_json = {
- {"version", result.page->layout.version},
- {"grid_columns", result.page->layout.grid_columns}
- };
- nlohmann::json components_json = nlohmann::json::array();
- for (const auto& comp : result.page->layout.components) {
- nlohmann::json comp_json = {
- {"id", comp.id},
- {"type", comp.type},
- {"position", {
- {"x", comp.position.x},
- {"y", comp.position.y},
- {"width", comp.position.width},
- {"height", comp.position.height}
- }},
- {"config", comp.config}
- };
- components_json.push_back(comp_json);
- }
- layout_json["components"] = components_json;
- page_json["layout"] = layout_json;
- // Add settings
- page_json["settings"] = {
- {"show_in_sidebar", result.page->settings.show_in_sidebar},
- {"icon", result.page->settings.icon},
- {"menu_order", result.page->settings.menu_order}
- };
- res.set_content(page_json.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Update page error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleUpdatePageSharing(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and page ID from path
- std::string workspace_id = req.matches[1].str();
- std::string page_id = req.matches[2].str();
- // Check if PageService is available
- if (!pageService_) {
- res.status = 503;
- res.set_content(R"({"error":"Page service not available"})", "application/json");
- return;
- }
- // Get existing page to check ownership
- auto existing = pageService_->GetPage(workspace_id, page_id);
- if (!existing.success || !existing.page) {
- res.status = 404;
- res.set_content(R"({"error":"Page not found"})", "application/json");
- return;
- }
- // Check permission to share
- if (!authorizationService_->CanSharePage(*auth_user, workspace_id, existing.page->created_by)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - insufficient permissions to share this page"})", "application/json");
- return;
- }
- // Parse request body
- nlohmann::json body;
- try {
- body = nlohmann::json::parse(req.body);
- } catch (const nlohmann::json::parse_error& /*e*/) {
- res.status = 400;
- res.set_content(R"({"error":"Invalid JSON body"})", "application/json");
- return;
- }
- // Validate shared_with_groups field
- if (!body.contains("shared_with_groups") || !body["shared_with_groups"].is_array()) {
- res.status = 400;
- res.set_content(R"({"error":"shared_with_groups array is required"})", "application/json");
- return;
- }
- try {
- std::vector<std::string> shared_with_groups;
- for (const auto& group : body["shared_with_groups"]) {
- if (group.is_string()) {
- shared_with_groups.push_back(group.get<std::string>());
- }
- }
- auto result = pageService_->UpdatePageSharing(workspace_id, page_id, shared_with_groups);
- if (!result.success) {
- res.status = 400;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- // Build response
- nlohmann::json response = {
- {"id", result.page->id},
- {"shared_with_groups", result.page->shared_with_groups},
- {"message", "Page sharing updated successfully"}
- };
- res.set_content(response.dump(), "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Update page sharing error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- void HttpServer::HandleDeletePage(const httplib::Request& req, httplib::Response& res) {
- // Authenticate the request
- auto auth_user = AuthenticateRequest(req);
- if (!auth_user) {
- res.status = 401;
- res.set_content(R"({"error":"Unauthorized"})", "application/json");
- return;
- }
- // Extract workspace ID and page ID from path
- std::string workspace_id = req.matches[1].str();
- std::string page_id = req.matches[2].str();
- // Check if PageService is available
- if (!pageService_) {
- res.status = 503;
- res.set_content(R"({"error":"Page service not available"})", "application/json");
- return;
- }
- // Get existing page to check ownership
- auto existing = pageService_->GetPage(workspace_id, page_id);
- if (!existing.success || !existing.page) {
- res.status = 404;
- res.set_content(R"({"error":"Page not found"})", "application/json");
- return;
- }
- // Check permission to delete
- if (!authorizationService_->CanDeletePage(*auth_user, workspace_id, existing.page->created_by)) {
- res.status = 403;
- res.set_content(R"({"error":"Forbidden - insufficient permissions to delete this page"})", "application/json");
- return;
- }
- try {
- auto result = pageService_->DeletePage(workspace_id, page_id);
- if (!result.success) {
- res.status = 404;
- nlohmann::json error_response = {{"error", result.error}};
- res.set_content(error_response.dump(), "application/json");
- return;
- }
- res.set_content(R"({"message":"Page deleted successfully"})", "application/json");
- } catch (const std::exception& e) {
- spdlog::error("Delete page error: {}", e.what());
- res.status = 500;
- res.set_content(R"({"error":"Internal server error"})", "application/json");
- }
- }
- } // namespace smartbotic::webserver
|