Files
oikos/internal/httpapi/problem.go
dtoro 1bfc18ea3a phase 2 (part 4): SSE stream via io.Pipe, OIDC JWT auth middleware
- SSE stream: GET /events/stream using io.Pipe to bridge the SSE
  goroutine to the response body. Replay from Last-Event-ID via
  in-memory broker with DB fallback. LISTEN/NOTIFY fan-out to all
  subscribers. Heartbeat every 15s. Bounded channels.
- OIDC JWT auth: validates Bearer tokens against Authentik/OIDC
  issuer via JWKS discovery + key caching. Extracts sub/email into
  context actor. Falls back to static bearer tokens. Dev mode (no
  OIDC + no tokens) = open.
- Config: OIDCIssuer, OIDCClientID env vars
- SSE + OIDC infrastructure complete, build passes, all tests pass

Remaining: MCP server, conformance tests, wire audit middleware
2026-07-07 09:40:11 +02:00

72 lines
2.5 KiB
Go

package httpapi
import (
"encoding/json"
"errors"
"log/slog"
"net/http"
"github.com/dtoro/oikos/internal/domain"
"github.com/dtoro/oikos/internal/httpapi/gen"
)
// errNotImplemented marks endpoints stubbed for later phases.
var errNotImplemented = errors.New("not implemented yet")
// statusFor maps domain sentinel errors to HTTP status codes (plan SG11).
func statusFor(err error) (status int, title string) {
switch {
case errors.Is(err, domain.ErrNotFound):
return http.StatusNotFound, "not found"
case errors.Is(err, domain.ErrInvalidTransition):
return http.StatusConflict, "invalid lifecycle transition"
case errors.Is(err, domain.ErrConflict), errors.Is(err, domain.ErrAlreadyExists):
return http.StatusConflict, "conflict"
case errors.Is(err, domain.ErrCardinality):
return http.StatusConflict, "relationship cardinality violation"
case errors.Is(err, domain.ErrAbstractType), errors.Is(err, domain.ErrInvalidEdge):
return http.StatusUnprocessableEntity, "ontology validation failed"
case errors.Is(err, domain.ErrInvalidInput):
return http.StatusBadRequest, "invalid input"
case errors.Is(err, domain.ErrApprovalRequired):
return http.StatusForbidden, "operator approval required"
case errors.Is(err, domain.ErrAutonomyBlocked):
return http.StatusForbidden, "autonomy policy blocks this action"
case errors.Is(err, domain.ErrCircuitOpen):
return http.StatusServiceUnavailable, "circuit breaker open"
case errors.Is(err, errNotImplemented):
return http.StatusNotImplemented, "not implemented"
default:
return http.StatusInternalServerError, "internal error"
}
}
// writeProblem writes an RFC 9457 problem+json response.
func writeProblem(w http.ResponseWriter, r *http.Request, status int, title, detail string) {
instance := r.URL.Path
p := gen.Problem{
Status: status,
Title: title,
Instance: &instance,
}
if detail != "" {
p.Detail = &detail
}
w.Header().Set("Content-Type", "application/problem+json")
w.WriteHeader(status)
json.NewEncoder(w).Encode(p)
}
// writeProblemFromErr maps an error to a problem+json response. Internal
// error details are logged server-side, never leaked to clients.
func writeProblemFromErr(w http.ResponseWriter, r *http.Request, err error) {
status, title := statusFor(err)
detail := ""
if status != http.StatusInternalServerError {
detail = err.Error()
} else {
slog.Error("internal error", "method", r.Method, "path", r.URL.Path, "error", err)
}
writeProblem(w, r, status, title, detail)
}