package main import ( "crypto/subtle" "embed" "html/template" "io/fs" "log" "net/http" "strconv" "time" ) //go:embed templates var templateFS embed.FS //go:embed static var staticFS embed.FS // recentCount is how many series the "Continue reading" strip shows. const recentCount = 5 // webHandler serves the browser UI: full pages at / and htmx fragments at /ui/. // It is a separate handler from bookmarkHandler because the two speak different // representations (HTML versus JSON) to different clients under different auth. type webHandler struct { store *Store tmpl *template.Template key []byte password string limiter *loginLimiter } // listView is what every list-rendering template receives. type listView struct { Tab string // "all" or "fav" Recent []Bookmark Items []Bookmark } // loginView is what the login template receives. type loginView struct { Error string } // newWebHandler parses every template up front so a broken one kills the // process at startup rather than the first request that touches it. func newWebHandler(store *Store, cfg Config) (*webHandler, error) { tmpl, err := template.ParseFS(templateFS, "templates/*.html") if err != nil { return nil, err } return &webHandler{ store: store, tmpl: tmpl, key: sessionKey(cfg.Token), password: cfg.WebPassword, limiter: newLoginLimiter(), }, nil } func (h *webHandler) register(mux *http.ServeMux) { mux.HandleFunc("GET /{$}", h.index) mux.HandleFunc("POST /login", h.login) mux.HandleFunc("POST /logout", h.logout) mux.Handle("GET /static/", staticHandler()) mux.HandleFunc("GET /ui/list", h.requireSession(h.uiList)) } // staticHandler serves the embedded assets. The vendored htmx build and the // stylesheet change only on deploy, so a long max-age is safe; a redeploy // changes the binary and the browser revalidates on its own schedule. func staticHandler() http.Handler { sub, err := fs.Sub(staticFS, "static") if err != nil { panic("embed static: " + err.Error()) } files := http.FileServer(http.FS(sub)) return http.StripPrefix("/static/", http.HandlerFunc( func(w http.ResponseWriter, r *http.Request) { w.Header().Set("Cache-Control", "public, max-age=3600") files.ServeHTTP(w, r) })) } // authed reports whether the request carries a valid session cookie. func (h *webHandler) authed(r *http.Request) bool { c, err := r.Cookie(sessionCookieName) return err == nil && verifySession(h.key, c.Value, time.Now().UnixMilli()) } // requireSession guards the fragment endpoints. It answers 401 rather than // redirecting, because htmx swaps whatever body it receives into the page and a // redirected login page would be spliced into the card list. func (h *webHandler) requireSession(next http.HandlerFunc) http.HandlerFunc { return func(w http.ResponseWriter, r *http.Request) { if !h.authed(r) { http.Error(w, "unauthorized", http.StatusUnauthorized) return } next(w, r) } } func (h *webHandler) render(w http.ResponseWriter, status int, name string, data any) { w.Header().Set("Content-Type", "text/html; charset=utf-8") w.WriteHeader(status) if err := h.tmpl.ExecuteTemplate(w, name, data); err != nil { // The status line is already sent, so this can only be logged. log.Printf("render %s: %v", name, err) } } // index renders the list, or the login page when there is no session. The login // page is served at / with status 200 rather than as a redirect to a separate // URL: one page, no redirect loop to reason about. func (h *webHandler) index(w http.ResponseWriter, r *http.Request) { if !h.authed(r) { h.render(w, http.StatusOK, "login", loginView{}) return } view, err := h.buildListView(r.URL.Query().Get("tab")) if err != nil { log.Printf("index: %v", err) http.Error(w, "internal error", http.StatusInternalServerError) return } h.render(w, http.StatusOK, "app", view) } // buildListView loads the list once and derives both the tab-filtered items and // the recent strip from it. The strip always reflects overall recency, not the // active tab, so it is built before filtering. func (h *webHandler) buildListView(tab string) (listView, error) { all, err := h.store.List() // already ordered updated_at DESC if err != nil { return listView{}, err } recent := all if len(recent) > recentCount { recent = recent[:recentCount] } items := all if tab == "fav" { items = []Bookmark{} for _, b := range all { if b.Favorite { items = append(items, b) } } } else { tab = "all" } return listView{Tab: tab, Recent: recent, Items: items}, nil } func (h *webHandler) uiList(w http.ResponseWriter, r *http.Request) { view, err := h.buildListView(r.URL.Query().Get("tab")) if err != nil { log.Printf("ui list: %v", err) http.Error(w, "internal error", http.StatusInternalServerError) return } h.render(w, http.StatusOK, "list", view) } func (h *webHandler) login(w http.ResponseWriter, r *http.Request) { ip := clientIP(r) if wait := h.limiter.retryAfter(ip, time.Now()); wait > 0 { secs := int(wait.Seconds()) + 1 w.Header().Set("Retry-After", strconv.Itoa(secs)) h.render(w, http.StatusTooManyRequests, "login", loginView{ Error: "Too many attempts. Try again in " + strconv.Itoa((secs+59)/60) + " min.", }) return } if err := r.ParseForm(); err != nil { http.Error(w, "invalid form", http.StatusBadRequest) return } got := r.PostFormValue("password") if subtle.ConstantTimeCompare([]byte(got), []byte(h.password)) != 1 { h.limiter.fail(ip, time.Now()) h.render(w, http.StatusUnauthorized, "login", loginView{Error: "Wrong password."}) return } h.limiter.reset(ip) setSessionCookie(w, r, h.key) http.Redirect(w, r, "/", http.StatusSeeOther) } func (h *webHandler) logout(w http.ResponseWriter, r *http.Request) { clearSessionCookie(w, r) http.Redirect(w, r, "/", http.StatusSeeOther) }