mirror of
https://github.com/go-vikunja/vikunja.git
synced 2026-07-20 21:14:30 -05:00
Add the admin + license gate for /api/v2 and ship the first gated resource, GET /api/v2/admin/projects (AdminProjectList). The gate reuses the existing v1 middleware functions unchanged — RequireFeature(license.FeatureAdminPanel) and RequireInstanceAdmin(), both of which serve 404 on failure. Rather than splitting the single v2 Huma API into a separate gated sub-group (which would split the OpenAPI spec and drop admin operations from /api/v2/openapi.json), the gate is applied as a path-scoped Echo middleware on the shared /api/v2 group, firing only for /api/v2/admin/* and after the token middleware. This preserves v1's 404-not-403 semantics and keeps admin routes in the unified v2 spec and Scalar docs. AdminProjectList lists every project on the instance (archived included), behind the gate. Adds doc:/readOnly: tags to the shared Project model so it documents correctly as a v2 schema. Tests in pkg/webtests/huma_admin_test.go (TestHumaAdminProjects) cover all three personas: non-admin -> 404, admin without feature -> 404, admin with feature -> 200 list, plus unauthenticated -> 401.
44 KiB
44 KiB