Files
mygo/docs/server/roadmap.md
T
ld 6604ecb026 feat(file): conceal file resource existence from other users
- feat: cross-user file access returns not-found instead of
  permission-denied
- fix: repository delete now only affects active rows and returns
  ErrNotFound when no row changes; repeated deletes yield not-found
- feat: parent directory operations (list, upload, create-dir, move)
  conceal ownership of other user's directories
- test: update handler, service, repository, and integration tests to
  assert not-found behavior for cross-user and missing file operations
2026-07-16 00:06:31 +08:00

2.0 KiB

Roadmap

v0

Feature Status Notes
CLI config management Viper YAML + env + flags, typed Duration config
JWT authentication access + refresh tokens, refresh token in DB, app passkey support
Web API foundation WebApp composition, Gin router, graceful shutdown, GET /api/v1/version
File upload/download/manage APIs 🛠 WIP REST API via Gin
Admin endpoints 🛠 WIP user service boundary in place for superusers
WebDAV 🛠 WIP future v0 or v1

Implementation Tasks

Package-level implementation order (each task includes unit tests):

  1. internal/config — Viper loader, config struct
  2. internal/app — runtime dependency container
  3. internal/model — domain types, error codes
  4. internal/api — protocol-neutral error kind to REST response mapping
  5. internal/auth — JWT utils
  6. internal/storage — backend interface + local fs with staged upload promotion
  7. internal/repository — interfaces + GORM/SQLite impl
  8. internal/service — auth, file, admin services
  9. internal/middleware — logger, cors, auth (auth done; principal boundary enforced)
  10. internal/handler — auth, account, file, admin handlers 🛠 (HTTP DTO mapping in place)
  11. internal/server — Gin router, route registration, graceful shutdown
  12. cmd/serve.go, cmd/config.go, cmd/status.go (serve done)
  13. Integration tests 🛠 (authenticated register → login → upload → list → download route flow covered with a small file; authentication bypass, invalid token, concealed cross-user resources, and strict delete boundaries covered)
  14. Architecture boundary tests

Future

Feature Status Notes
Image server plan thumbnail generation
Pastebin & code snippets plan in sharing context
S3 storage backend plan new storage impl
Nextcloud-compatible API plan new handler layer on existing services