Feat v0.2.5 ui polish dead code #9

Merged
xcaliber merged 20 commits from feat/v0.2.5-ui-polish-dead-code into main 2026-03-27 14:16:36 +00:00
2 changed files with 22 additions and 1 deletions
Showing only changes of commit 2b3a3f08ef - Show all commits

View File

@@ -142,6 +142,21 @@ func parseAndValidateJWT(tokenString string, jwtSecret string) (*Claims, bool) {
return claims, true
}
// UserIDFromCookie extracts the user ID from the sb_token cookie without
// requiring authentication. Returns "" if no valid token is found.
// Used by unauthenticated routes that want optional user context.
func UserIDFromCookie(c *gin.Context, jwtSecret string) string {
cookie, err := c.Cookie("sb_token")
if err != nil || cookie == "" {
return ""
}
claims, ok := parseAndValidateJWT(cookie, jwtSecret)
if !ok {
return ""
}
return claims.UserID
}
// ─── Auth middleware ─────────────────────────────────────────
// Auth returns a Gin middleware that validates JWT bearer tokens and

View File

@@ -6,6 +6,8 @@ import (
"net/http"
"github.com/gin-gonic/gin"
"switchboard-core/middleware"
)
// SeedSurfaces writes core surface manifests to the registry table.
@@ -92,9 +94,13 @@ func (e *Engine) EnabledSurfaceIDs() []string {
// DefaultSurfaceRedirect returns a handler for GET / that redirects to the
// configured default surface, falling back to the first enabled extension
// surface, then /welcome.
//
// This route has no auth middleware, so we opportunistically read the JWT
// from the cookie to check user preferences. If the cookie is missing or
// invalid, user preference is skipped (falls through to global default).
func (e *Engine) DefaultSurfaceRedirect() gin.HandlerFunc {
return func(c *gin.Context) {
userID := c.GetString("user_id")
userID := middleware.UserIDFromCookie(c, e.cfg.JWTSecret)
target := e.resolveDefaultSurface(c.Request.Context(), userID)
c.Redirect(http.StatusTemporaryRedirect, e.cfg.BasePath+target)
}