feat: add authentication and book upload

- Session-based login (username/password, 30-day cookie)
- SQLite user store with bcrypt password hashing (modernc.org/sqlite)
- Per-user upload permission (can_upload flag)
- Admin CLI (cmd/admin) for user management:
  user add/list/delete/set-upload
- Upload handler for EPUB/PDF with path-traversal protection
- All routes protected by requireAuth middleware;
  /upload additionally requires requireUpload
- Login/logout UI, upload form, logout button in header
- New env var: USERS_DB (default: users.db, gitignored)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
2026-08-11 19:11:40 +02:00
co-authored by Copilot
parent a8b31dae8a
commit a66c370de4
13 changed files with 1115 additions and 111 deletions
+9 -1
View File
@@ -6,15 +6,23 @@ import (
"os"
"github.com/arnef/ebooks/internal/library"
"github.com/arnef/ebooks/internal/users"
"github.com/arnef/ebooks/internal/web"
)
func main() {
booksDir := getenv("BOOKS_DIR", "books")
addr := getenv("ADDR", ":8080")
usersDB := getenv("USERS_DB", "users.db")
store, err := users.Open(usersDB)
if err != nil {
log.Fatalf("users db: %v", err)
}
defer store.Close()
lib := library.New(booksDir)
h := web.NewHandler(lib)
h := web.NewHandler(lib, store)
mux := http.NewServeMux()
h.RegisterRoutes(mux)