backup: pre-hardening baseline
This commit is contained in:
commit
9e4c612dcb
57 changed files with 10393 additions and 0 deletions
131
backend/internal/models/traefik.go
Normal file
131
backend/internal/models/traefik.go
Normal file
|
|
@ -0,0 +1,131 @@
|
|||
package models
|
||||
|
||||
import "time"
|
||||
|
||||
type Router struct {
|
||||
Name string `json:"name"`
|
||||
Provider string `json:"provider"`
|
||||
Rule string `json:"rule"`
|
||||
EntryPoints []string `json:"entry_points"`
|
||||
Service string `json:"service"`
|
||||
Middlewares []string `json:"middlewares"`
|
||||
Priority int `json:"priority"`
|
||||
TLS *RouterTLSConfig `json:"tls,omitempty"`
|
||||
Status string `json:"status"`
|
||||
Using []string `json:"using,omitempty"`
|
||||
}
|
||||
|
||||
type RouterTLSConfig struct {
|
||||
Options string `json:"options,omitempty"`
|
||||
CertResolver string `json:"cert_resolver,omitempty"`
|
||||
Domains []Domain `json:"domains,omitempty"`
|
||||
}
|
||||
|
||||
type Domain struct {
|
||||
Main string `json:"main"`
|
||||
SANs []string `json:"sans,omitempty"`
|
||||
}
|
||||
|
||||
type Service struct {
|
||||
Name string `json:"name"`
|
||||
Provider string `json:"provider"`
|
||||
Type string `json:"type"`
|
||||
LoadBalancer *LoadBalancer `json:"load_balancer,omitempty"`
|
||||
ServerStatus map[string]string `json:"server_status,omitempty"`
|
||||
Status string `json:"status"`
|
||||
}
|
||||
|
||||
type LoadBalancer struct {
|
||||
Servers []Server `json:"servers,omitempty"`
|
||||
Strategy string `json:"strategy,omitempty"`
|
||||
PassHostHeader *bool `json:"pass_host_header,omitempty"`
|
||||
HealthCheck *HealthCheck `json:"health_check,omitempty"`
|
||||
}
|
||||
|
||||
type Server struct {
|
||||
URL string `json:"url"`
|
||||
Weight *int `json:"weight,omitempty"`
|
||||
PreservePath bool `json:"preserve_path,omitempty"`
|
||||
}
|
||||
|
||||
type HealthCheck struct {
|
||||
Scheme string `json:"scheme,omitempty"`
|
||||
Path string `json:"path,omitempty"`
|
||||
Method string `json:"method,omitempty"`
|
||||
Status int `json:"status,omitempty"`
|
||||
Port int `json:"port,omitempty"`
|
||||
Interval string `json:"interval,omitempty"`
|
||||
Timeout string `json:"timeout,omitempty"`
|
||||
Hostname string `json:"hostname,omitempty"`
|
||||
FollowRedirects *bool `json:"follow_redirects,omitempty"`
|
||||
Headers map[string]string `json:"headers,omitempty"`
|
||||
}
|
||||
|
||||
type Middleware struct {
|
||||
Name string `json:"name"`
|
||||
Provider string `json:"provider"`
|
||||
Type string `json:"type"`
|
||||
Spec map[string]interface{} `json:"spec,omitempty"`
|
||||
Status string `json:"status"`
|
||||
}
|
||||
|
||||
type Certificate struct {
|
||||
Name string `json:"name"`
|
||||
CommonName string `json:"common_name"`
|
||||
SANs []string `json:"sans"`
|
||||
IssuerOrg string `json:"issuer_org"`
|
||||
IssuerCN string `json:"issuer_cn"`
|
||||
NotBefore time.Time `json:"not_before"`
|
||||
NotAfter time.Time `json:"not_after"`
|
||||
Status string `json:"status"`
|
||||
Provider string `json:"provider"`
|
||||
}
|
||||
|
||||
type EntryPoint struct {
|
||||
Name string `json:"name"`
|
||||
Address string `json:"address"`
|
||||
HTTP *EntryPointHTTP `json:"http,omitempty"`
|
||||
ForwardedHeaders *ForwardedHeaders `json:"forwarded_headers,omitempty"`
|
||||
}
|
||||
|
||||
type EntryPointHTTP struct {
|
||||
TLS *EntryPointTLS `json:"tls,omitempty"`
|
||||
Middlewares []string `json:"middlewares,omitempty"`
|
||||
RedirectToHTTPS bool `json:"redirect_to_https,omitempty"`
|
||||
}
|
||||
|
||||
type EntryPointTLS struct {
|
||||
CertResolver string `json:"cert_resolver,omitempty"`
|
||||
Domains []Domain `json:"domains,omitempty"`
|
||||
Options string `json:"options,omitempty"`
|
||||
}
|
||||
|
||||
type ForwardedHeaders struct {
|
||||
InsecureSkipVerify bool `json:"insecure_skip_verify,omitempty"`
|
||||
TrustedIPs []string `json:"trusted_ips,omitempty"`
|
||||
}
|
||||
|
||||
type Overview struct {
|
||||
HTTP struct {
|
||||
Routers Section `json:"routers"`
|
||||
Services Section `json:"services"`
|
||||
Middlewares Section `json:"middlewares"`
|
||||
} `json:"http"`
|
||||
TCP struct {
|
||||
Routers Section `json:"routers"`
|
||||
Services Section `json:"services"`
|
||||
Middlewares Section `json:"middlewares"`
|
||||
} `json:"tcp"`
|
||||
UDP struct {
|
||||
Routers Section `json:"routers"`
|
||||
Services Section `json:"services"`
|
||||
} `json:"udp"`
|
||||
Certificates *Section `json:"certificates,omitempty"`
|
||||
Providers []string `json:"providers,omitempty"`
|
||||
}
|
||||
|
||||
type Section struct {
|
||||
Total int `json:"total"`
|
||||
Warnings int `json:"warnings"`
|
||||
Errors int `json:"errors"`
|
||||
}
|
||||
56
backend/internal/models/user.go
Normal file
56
backend/internal/models/user.go
Normal file
|
|
@ -0,0 +1,56 @@
|
|||
package models
|
||||
|
||||
import (
|
||||
"database/sql"
|
||||
"time"
|
||||
)
|
||||
|
||||
type User struct {
|
||||
ID string `json:"id"`
|
||||
Username string `json:"username"`
|
||||
Email string `json:"email"`
|
||||
PasswordHash string `json:"-"`
|
||||
Role string `json:"role"`
|
||||
CreatedAt time.Time `json:"created_at"`
|
||||
UpdatedAt time.Time `json:"updated_at"`
|
||||
LastLogin sql.NullTime `json:"last_login,omitempty"`
|
||||
}
|
||||
|
||||
type Session struct {
|
||||
ID string `json:"id"`
|
||||
UserID string `json:"user_id"`
|
||||
CSRFToken string `json:"-"`
|
||||
CreatedAt time.Time `json:"created_at"`
|
||||
ExpiresAt time.Time `json:"expires_at"`
|
||||
}
|
||||
|
||||
type AuthResponse struct {
|
||||
User *User `json:"user"`
|
||||
Token string `json:"-"` // Not sent in JSON, only in cookie
|
||||
}
|
||||
|
||||
type LoginRequest struct {
|
||||
Username string `json:"username" binding:"required"`
|
||||
Password string `json:"password" binding:"required"`
|
||||
}
|
||||
|
||||
type UserRole string
|
||||
|
||||
const (
|
||||
RoleAdmin UserRole = "admin"
|
||||
RoleOperator UserRole = "operator"
|
||||
RoleViewer UserRole = "viewer"
|
||||
)
|
||||
|
||||
func (r UserRole) Can(permission string) bool {
|
||||
switch r {
|
||||
case RoleAdmin:
|
||||
return true
|
||||
case RoleOperator:
|
||||
return permission != "users:write" && permission != "settings:write"
|
||||
case RoleViewer:
|
||||
return permission == "config:read" || permission == "traefik:read"
|
||||
default:
|
||||
return false
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue