Commit Graph
7 Commits
Author SHA1 Message Date
arnefandCopilot 952a4c9b52 Trigger docker workflow on develop branch instead of main
Docker Image bauen und veröffentlichen / docker (push) Successful in 2m49s
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-08-14 22:01:57 +02:00
arnefandCopilot d60d3a703e Add Docker image and multi-arch build workflow
- Add multi-stage Dockerfile (alpine, non-root, builds server+admin binaries)
- Add .dockerignore
- Add GitHub Actions workflow (also read by Gitea Actions) building and
  pushing linux/amd64 + linux/arm64 images to git.arnef.de/arnef/ebooks

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-08-14 21:53:39 +02:00
arnefandCopilot c877abf302 style: .btn als flex-Button mit konsistentem Styling
Ermöglicht die Verwendung von .btn auf <button>-Elementen
(nicht nur <a>-Links) mit einheitlicher Ausrichtung, Schrift
und Cursor.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-08-14 21:32:19 +02:00
arnefandCopilot 817763887a refactor: replace can_upload boolean with role-based access control
Introduces a three-tier role hierarchy: reader < uploader < admin.

- internal/users/role.go: Role type, roleLevel map, AtLeast(min),
  ParseRole() — new roles added by inserting into roleLevel only
- internal/users/store.go: versioned migrations via _schema_version table;
  v2 migration adds 'role' column and migrates existing can_upload data;
  SetRole() replaces SetUpload(); Session carries Role instead of CanUpload
- internal/web/middleware.go: generic requireRole(minRole) middleware
  replaces the ad-hoc requireUpload
- internal/web/handlers.go: upload routes use requireRole(RoleUploader);
  listBooks derives canUpload from sess.Role.AtLeast(RoleUploader)
- cmd/admin/main.go: user add --role <reader|uploader|admin>,
  user set-role replaces user set-upload
- README, copilot-instructions updated

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-08-11 19:43:39 +02:00
arnefandCopilot a66c370de4 feat: add authentication and book upload
- Session-based login (username/password, 30-day cookie)
- SQLite user store with bcrypt password hashing (modernc.org/sqlite)
- Per-user upload permission (can_upload flag)
- Admin CLI (cmd/admin) for user management:
  user add/list/delete/set-upload
- Upload handler for EPUB/PDF with path-traversal protection
- All routes protected by requireAuth middleware;
  /upload additionally requires requireUpload
- Login/logout UI, upload form, logout button in header
- New env var: USERS_DB (default: users.db, gitignored)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-08-11 19:11:40 +02:00
arnef a936c61ba3 update pages_templ 2026-08-08 13:36:19 +02:00
arnef 060d822654 use latest templ and ignore content of books dir 2026-08-06 17:18:23 +02:00