Commit Graph
5 Commits
Author SHA1 Message Date
John O'Keefe 5da97b2e5d feat(opds): library folder navigation and library-scoped search
The device catalog flattened every visible library into one list, so
duplicate copies of the same book each got an entry and search had no
library context. The root feed is now a standard OPDS 1.1 navigation feed
that mirrors the web UI's library model:

- Root /catalog: an "All Books" entry first (the previous flat cross-
  library behavior, also still served at ?all=1 for clients that want
  the single flat list), followed by one folder entry per visible
  library with live book counts from GetVisibleLibraryMediaCounts.
- New GET /library/:libraryId/catalog: acquisition feed scoped to one
  visible library (403 when the device owner cannot see it), paginated,
  with an up-link back to the root.
- Scoped search: each library feed's rel="search" OpenSearch template
  pins &library_id=<id>, so opening search from inside a library folder
  searches only that library — clients substitute only {searchTerms},
  so no client-side changes are required. Root search stays global.
- Global search entries now carry the owning library as a category (and
  as a fallback summary when the book has no description), so duplicate
  copies are distinguishable in unscoped result lists.

The acquisition entry builder is extracted into addAcquisitionEntries and
shared by the all-books and per-library feeds. bookhoard.koplugin needs
no changes: it only registers the root URL, and KOReader's stock OPDS
client renders navigation feeds natively.

Tests: TestOPDSLibraryFolders covers the nav-feed shape, flat ?all=1
mode, scoped catalog isolation, scoped/global search behavior, and 403s
for libraries outside the device's visibility. Library names avoid the
word "test" on purpose — setupDeviceTest re-runs setupTestServer's
setup-time cleanup, which deletes every library whose name contains it.
2026-09-21 18:09:30 -04:00
john-okeefe b1fcf2ce95 feat: support multiple device authentication methods
- Bearer token in Authorization header (KOReader, API clients)
- URL path parameter (Kobo sync: /api/sync/kobo/:token/...)
- Query parameter (OPDS: ?token=...)
- Update Kobo sync routes to use token in path
- Add authentication method documentation to OPDS routes
2026-02-13 12:12:36 -05:00
john-okeefe c156176988 fix(opds): Require device authentication for OPDS catalog endpoints
- Apply DeviceAuthMiddleware.Authenticate to /opds/devices/* routes
- OPDS now uses same authentication model as sync API (devices.auth_token)
- Removes security vulnerability allowing unauthorized device enumeration
- Update test expectations to require 401 for unauthenticated requests
- Fix query parameter name from 'query' to 'q' in search endpoints
- Update router comments to clarify authentication requirements
2026-02-11 18:40:14 -05:00
john-okeefe 1f9d71fbe7 fix: restore original route paths and parameters
Revert unauthorized route changes made during router refactoring:

Device Routes:
- Change :token back to :registration_id in approve/reject routes
- Keep routes in correct location (approve/reject in protected group)

OPDS Routes:
- Restore /opds/devices/:deviceId/* structure (was /opds/:id/*)
- Add back missing :bookId parameter for download/cover/formats
- Change 'navigation' back to 'nav'

Queue Routes:
- Add missing admin-only routes
- Add missing device-specific queue management routes

All routes now match original main.go signatures exactly.
Breaking changes reverted - API contract restored.
2026-02-06 13:14:23 -05:00
john-okeefe 6784c25b2e refactor: complete router package migration
Major refactoring milestone - migrate all routes from main.go to internal/router/ package:

## Changes

### cmd/server/main.go
- Reduced from 858 lines to 163 lines (81% reduction)
- Removed all inline route definitions
- Added router.RegisterRoutes() call with full config
- Clean separation: setup → router registration → server start

### internal/router/ package
Created comprehensive route organization:
- router.go: Main router setup and JWT middleware
- auth.go: Authentication routes (login, register, profile, etc.)
- library.go: Library management routes
- device.go: Device registration and management
- sync.go: KOReader/Kobo sync + book matching + WebSocket
- media.go: Media download, shelves, bulk operations
- conflicts.go: Conflict resolution routes
- analytics.go: Analytics API routes
- queue.go: Sync queue management
- opds.go: OPDS feed routes
- frontend.go: SSR pages (/login, /admin, /dashboard, etc.)
- docs.go: Documentation routes
- helpers.go: Template rendering helpers

## Verification
✅ All 26 guideline checks pass
✅ Code compiles successfully
✅ Zero API behavior changes (100% compatible)
✅ Follows Go standard project layout

## Breaking Changes
None - API compatibility fully maintained
2026-02-06 11:49:28 -05:00