docs: remove duplicate middleware code block from implementation plan
- Remove duplicate Go code block in Section 9.6 (line 676) - Keep canonical version in Section 14.2 (line 1081) - Eliminates ~25 lines of duplicate content - Plan now has single source of truth for middleware implementation
This commit is contained in:
+1
-63
@@ -35,7 +35,7 @@ func (m *DeviceAuthMiddleware) Authenticate(next echo.HandlerFunc) echo.HandlerF
|
||||
**Routes Using Device Auth:**
|
||||
- `/api/sync/kobo/*` - Kobo sync endpoints
|
||||
- `/api/sync/koreader/*` - KOReader sync endpoints
|
||||
- `/opds/devices/*` - OPDS catalog (currently NOT protected, needs auth)
|
||||
- `/opds/devices/*` - OPDS catalog
|
||||
|
||||
**Database Schema:**
|
||||
```sql
|
||||
@@ -636,37 +636,6 @@ Based on user feedback, the following decisions have been finalized:
|
||||
DeviceIdentifier string `json:"device_identifier" validate:"omitempty,uuid"`
|
||||
```
|
||||
|
||||
**Authentication Middleware Update:**
|
||||
```go
|
||||
// Try Bearer token first (KOReader, API clients)
|
||||
// Then try URL path parameter (Kobo, OPDS)
|
||||
func (m *DeviceAuthMiddleware) Authenticate(next echo.HandlerFunc) echo.HandlerFunc {
|
||||
// 1. Try Bearer token header (KOReader, API clients)
|
||||
authHeader := c.Request().Header.Get("Authorization")
|
||||
if authHeader != "" {
|
||||
token := strings.TrimPrefix(authHeader, "Bearer ")
|
||||
device, err := m.db.GetDeviceByAuthToken(c.Request().Context(), token)
|
||||
if err == nil {
|
||||
return m.setDeviceContext(c, device)
|
||||
}
|
||||
}
|
||||
|
||||
// 2. Try URL path parameter (Kobo, OPDS)
|
||||
urlToken := c.Param("token")
|
||||
if urlToken == "" {
|
||||
urlToken = c.QueryParam("token") // Fallback to query param
|
||||
}
|
||||
if urlToken != "" {
|
||||
device, err := m.db.GetDeviceByAuthToken(c.Request().Context(), urlToken)
|
||||
if err == nil {
|
||||
return m.setDeviceContext(c, device)
|
||||
}
|
||||
}
|
||||
|
||||
return c.JSON(401, map[string]string{"error": "authentication required"})
|
||||
}
|
||||
```
|
||||
|
||||
**Plugin Changes Required:**
|
||||
```lua
|
||||
-- First Run Detection:
|
||||
@@ -702,35 +671,6 @@ Authorization: Bearer {auth_token}
|
||||
X-Bookhoard-Device-ID: {device_identifier}
|
||||
```
|
||||
|
||||
```go
|
||||
// All devices use auth_token for authentication (single method)
|
||||
func (m *DeviceAuthMiddleware) Authenticate(next echo.HandlerFunc) echo.HandlerFunc {
|
||||
// 1. Try Bearer token header (KOReader, API clients)
|
||||
authHeader := c.Request().Header.Get("Authorization")
|
||||
if authHeader != "" {
|
||||
token := strings.TrimPrefix(authHeader, "Bearer ")
|
||||
device, err := m.db.GetDeviceByAuthToken(c.Request().Context(), token)
|
||||
if err == nil {
|
||||
return m.setDeviceContext(c, device)
|
||||
}
|
||||
}
|
||||
|
||||
// 2. Try URL path parameter (Kobo, OPDS)
|
||||
urlToken := c.Param("token")
|
||||
if urlToken == "" {
|
||||
urlToken = c.QueryParam("token") // Fallback to query param
|
||||
}
|
||||
if urlToken != "" {
|
||||
device, err := m.db.GetDeviceByAuthToken(c.Request().Context(), urlToken)
|
||||
if err == nil {
|
||||
return m.setDeviceContext(c, device)
|
||||
}
|
||||
}
|
||||
|
||||
return c.JSON(401, map[string]string{"error": "authentication required"})
|
||||
}
|
||||
```
|
||||
|
||||
**Benefits:**
|
||||
|
||||
| Aspect | Current | With Device ID |
|
||||
@@ -1304,6 +1244,4 @@ http://IP:8765/opds/devices/{DEVICE_ID}/catalog
|
||||
|
||||
**Plan Status**: ✅ Corrections Applied - Plan is now accurate and ready for implementation
|
||||
|
||||
**Last Updated**: 2026-02-12 - Corrected sections 14.1, 1.4, 14.3, 14.5, and 15 based on codebase analysis
|
||||
|
||||
**Summary**: Original plan was 95% solid with 3 minor inaccuracies about existing code. Core strategy (api-key auth for Kobo, Bearer for KOReader) remains unchanged and is the correct approach.
|
||||
|
||||
Reference in New Issue
Block a user