6604ecb026
- feat: cross-user file access returns not-found instead of permission-denied - fix: repository delete now only affects active rows and returns ErrNotFound when no row changes; repeated deletes yield not-found - feat: parent directory operations (list, upload, create-dir, move) conceal ownership of other user's directories - test: update handler, service, repository, and integration tests to assert not-found behavior for cross-user and missing file operations
2.0 KiB
2.0 KiB
Roadmap
v0
| Feature | Status | Notes |
|---|---|---|
| CLI config management | ✅ | Viper YAML + env + flags, typed Duration config |
| JWT authentication | ✅ | access + refresh tokens, refresh token in DB, app passkey support |
| Web API foundation | ✅ | WebApp composition, Gin router, graceful shutdown, GET /api/v1/version |
| File upload/download/manage APIs | 🛠 WIP | REST API via Gin |
| Admin endpoints | 🛠 WIP | user service boundary in place for superusers |
| WebDAV | 🛠 WIP | future v0 or v1 |
Implementation Tasks
Package-level implementation order (each task includes unit tests):
internal/config— Viper loader, config struct ✅internal/app— runtime dependency container ✅internal/model— domain types, error codes ✅internal/api— protocol-neutral error kind to REST response mapping ✅internal/auth— JWT utils ✅internal/storage— backend interface + local fs with staged upload promotioninternal/repository— interfaces + GORM/SQLite impl ✅internal/service— auth, file, admin services ✅internal/middleware— logger, cors, auth ✅ (auth done; principal boundary enforced)internal/handler— auth, account, file, admin handlers 🛠 (HTTP DTO mapping in place)internal/server— Gin router, route registration, graceful shutdown ✅cmd/serve.go,cmd/config.go,cmd/status.go✅ (serve done)- Integration tests 🛠 (authenticated register → login → upload → list → download route flow covered with a small file; authentication bypass, invalid token, concealed cross-user resources, and strict delete boundaries covered)
- Architecture boundary tests ✅
Future
| Feature | Status | Notes |
|---|---|---|
| Image server | ⬜ plan | thumbnail generation |
| Pastebin & code snippets | ⬜ plan | in sharing context |
| S3 storage backend | ⬜ plan | new storage impl |
| Nextcloud-compatible API | ⬜ plan | new handler layer on existing services |