Merge remote-tracking branch 'origin/main'

# Conflicts:
#	internal/httpapi/dist/assets/index-CL42Ur3_.css
#	internal/httpapi/dist/assets/index-CbqC9m-j.js
#	internal/httpapi/dist/assets/index-RFHYrCiX.css
#	internal/httpapi/dist/assets/index-jvouiCgh.css
#	internal/httpapi/dist/index.html
#	internal/store/store.go
#	web/src/api.ts
#	web/src/views/ClusterView.vue
This commit is contained in:
JianFeeeee
2026-08-24 23:30:19 +08:00
28 changed files with 1143 additions and 1084 deletions

View File

@ -31,6 +31,8 @@ type Handler struct {
BinDir string
User string
Password string
// Sessions issues the UI login cookies (see session.go).
Sessions *SessionStore
// InstallBinary downloads and activates a frpc binary. Set by the app to
// avoid an import cycle with the install package.
@ -127,10 +129,15 @@ func NewServeMux(h *Handler) (http.Handler, error) {
// Account & API key management (admin only).
mux.HandleFunc(apiPrefix+"/me", h.auth("read")(h.handleMe))
mux.HandleFunc(apiPrefix+"/users", h.auth("admin")(h.handleUsers))
mux.HandleFunc(apiPrefix+"/users/", h.auth("admin")(h.handleUserByName))
mux.HandleFunc(apiPrefix+"/apikeys", h.auth("admin")(h.handleApiKeys))
mux.HandleFunc(apiPrefix+"/apikeys/", h.auth("admin")(h.handleApiKeyByID))
// UI session login/logout. Deliberately NOT behind auth(): login must be
// reachable without credentials, and logout must work even when the
// session is already gone.
mux.HandleFunc(apiPrefix+"/login", h.handleLogin)
mux.HandleFunc(apiPrefix+"/logout", h.handleLogout)
mux.HandleFunc(apiPrefix+"/users", h.auth("superadmin")(h.handleUsers))
mux.HandleFunc(apiPrefix+"/users/", h.auth("superadmin")(h.handleUserByName))
mux.HandleFunc(apiPrefix+"/apikeys", h.auth("superadmin")(h.handleApiKeys))
mux.HandleFunc(apiPrefix+"/apikeys/", h.auth("superadmin")(h.handleApiKeyByID))
// M6: peer-to-peer binary exchange endpoint (Basic Auth, same creds).
// Not under /api so peers hit it directly; auth still applied. Peers