package api import ( "context" "encoding/json" "fmt" "net/http" "net/url" "sort" "strings" "drivervault/apiserver/internal/models" ) // Access levels a user can have on a car. accessNone means no access at all. const ( accessNone = "" accessRead = "read" accessWrite = "write" accessOwner = "owner" ) // carAccessLevel reports the requesting user's permission on a car: "owner" if // they own it, otherwise the permission from any car_shares grant ("read"/ // "write"), otherwise "" (no access). It also returns the car record so callers // that already need it avoid a second fetch. func (s *Server) carAccessLevel(ctx context.Context, userID, carID string) (string, *carRecord, error) { var rec carRecord if err := s.pb.GetOne(ctx, colCars, carID, &rec); err != nil { return accessNone, nil, err } if rec.Owner == userID { return accessOwner, &rec, nil } perm, err := s.sharePermission(ctx, carID, userID) if err != nil { return accessNone, &rec, err } return perm, &rec, nil } // sharePermission returns the permission ("read"/"write") granted to userID on // carID via car_shares, or "" if there is no grant. func (s *Server) sharePermission(ctx context.Context, carID, userID string) (string, error) { res, err := s.pb.List(ctx, colShares, url.Values{ "filter": {fmt.Sprintf("car='%s' && user='%s'", carID, userID)}, "perPage": {"1"}, }) if err != nil { return "", err } var recs []shareRecord if err := json.Unmarshal(res.Items, &recs); err != nil || len(recs) == 0 { return "", err } return recs[0].Permission, nil } func canWrite(level string) bool { return level == accessOwner || level == accessWrite } // requireCarAccess enforces that the current user's access to carID meets the // minimum `need` (accessRead = any access, accessWrite = write or owner, // accessOwner = owner only). On failure it writes the HTTP response and returns // false, so callers can `if !s.requireCarAccess(...) { return }`. func (s *Server) requireCarAccess(w http.ResponseWriter, r *http.Request, carID, need string) bool { if carID == "" { writeError(w, http.StatusBadRequest, "car is required") return false } level, _, err := s.carAccessLevel(r.Context(), s.currentUserID(r), carID) if err != nil { writePBError(w, err) return false } var ok bool switch need { case accessWrite: ok = canWrite(level) case accessOwner: ok = level == accessOwner default: // accessRead / any ok = level != accessNone } if !ok { writeError(w, http.StatusForbidden, "you do not have access to this car") return false } return true } func (s *Server) listCars(w http.ResponseWriter, r *http.Request) { me := s.currentUserID(r) // Cars the user owns. ownedRes, err := s.pb.List(r.Context(), colCars, url.Values{ "filter": {fmt.Sprintf("owner='%s'", me)}, "sort": {"name"}, "perPage": {"200"}, }) if err != nil { writePBError(w, err) return } var owned []carRecord if err := json.Unmarshal(ownedRes.Items, &owned); err != nil { writeError(w, http.StatusInternalServerError, err.Error()) return } out := make([]models.Car, 0, len(owned)) for _, rec := range owned { m := rec.toModel() m.Access = accessOwner out = append(out, m) } // Cars shared with the user (each grant → fetch the car, annotate access). sharesRes, err := s.pb.List(r.Context(), colShares, url.Values{ "filter": {fmt.Sprintf("user='%s'", me)}, "perPage": {"200"}, }) if err != nil { writePBError(w, err) return } var shares []shareRecord if err := json.Unmarshal(sharesRes.Items, &shares); err != nil { writeError(w, http.StatusInternalServerError, err.Error()) return } for _, sh := range shares { var rec carRecord if err := s.pb.GetOne(r.Context(), colCars, sh.Car, &rec); err != nil { continue // grant points at a deleted car; skip defensively } m := rec.toModel() m.Access = sh.Permission out = append(out, m) } // Hand the garage back in the order the user arranged it. Best effort: if the // profile can't be read, the default order (owned by name, then shared) still // renders a usable garage. if rec, err := s.fetchUser(r, me); err == nil { applyCarOrder(out, rec.carOrder()) } writeJSON(w, http.StatusOK, out) } // applyCarOrder sorts cars into the user's arranged order, in place. Cars the // arrangement doesn't mention — a car added or shared since the last drag — keep // their relative order and follow the arranged ones, so a new car shows up at // the end rather than jumping into the middle. func applyCarOrder(cars []models.Car, order []string) { if len(order) == 0 || len(cars) < 2 { return } rank := make(map[string]int, len(order)) for i, id := range order { rank[id] = i } sort.SliceStable(cars, func(i, j int) bool { ri, oki := rank[cars[i].ID] rj, okj := rank[cars[j].ID] if oki != okj { return oki // an arranged car sorts before an unarranged one } if !oki { return false // both unarranged: leave them as they are } return ri < rj }) } func (s *Server) getCar(w http.ResponseWriter, r *http.Request) { level, rec, err := s.carAccessLevel(r.Context(), s.currentUserID(r), r.PathValue("id")) if err != nil { writePBError(w, err) return } if level == accessNone { writeError(w, http.StatusForbidden, "you do not have access to this car") return } m := rec.toModel() m.Access = level writeJSON(w, http.StatusOK, m) } func (s *Server) createCar(w http.ResponseWriter, r *http.Request) { var in models.Car if err := decodeJSON(r, &in); err != nil { writeError(w, http.StatusBadRequest, err.Error()) return } if in.Name == "" { writeError(w, http.StatusBadRequest, "name is required") return } applyCarDefaults(&in) // Owner is always the authenticated user; ignore any client-supplied owner. payload := carPayload(in) payload["owner"] = s.currentUserID(r) var rec carRecord if err := s.pb.Create(r.Context(), colCars, payload, &rec); err != nil { writePBError(w, err) return } m := rec.toModel() m.Access = accessOwner writeJSON(w, http.StatusCreated, m) } func (s *Server) updateCar(w http.ResponseWriter, r *http.Request) { var in models.Car if err := decodeJSON(r, &in); err != nil { writeError(w, http.StatusBadRequest, err.Error()) return } level, _, err := s.carAccessLevel(r.Context(), s.currentUserID(r), r.PathValue("id")) if err != nil { writePBError(w, err) return } if !canWrite(level) { writeError(w, http.StatusForbidden, "you cannot edit this car") return } // carPayload deliberately omits owner, so a PATCH never reassigns ownership. var rec carRecord if err := s.pb.Update(r.Context(), colCars, r.PathValue("id"), carPayload(in), &rec); err != nil { writePBError(w, err) return } m := rec.toModel() m.Access = level writeJSON(w, http.StatusOK, m) } // hideableCarTabs are the car-detail tabs that can be switched off. "info" is // deliberately absent: it is the car itself, and a page with no tabs left would // be a dead end. var hideableCarTabs = map[string]bool{ "provider": true, "services": true, "technical": true, "maintenance": true, "fuel": true, "charging": true, "documents": true, "parts": true, "reminders": true, } // arrangeableCarTabs are the tabs a car's page can be rearranged into, which is // the hideable ones plus Information: it cannot be switched off, but there is no // reason it has to stay at the front. Derived from hideableCarTabs so the two // sets cannot drift as tabs are added. var arrangeableCarTabs = func() map[string]bool { out := make(map[string]bool, len(hideableCarTabs)+1) for key := range hideableCarTabs { out[key] = true } out["info"] = true return out }() // hideableCarFields are the Information rows that can be switched off — every // one of them, since unlike the tabs there is no row the page needs to keep. // Mirrors the car.info.* labels the web app renders. var hideableCarFields = map[string]bool{ "oilSpec": true, "transmissionOil": true, "differentialOil": true, "brakeFluid": true, "coolant": true, "odometer": true, "serviceInterval": true, "nextDue": true, "registrationPlate": true, "registrationCountry": true, "vin": true, "fuelType": true, "buildDate": true, "firstRegistration": true, } // arrangeableCarMetrics are the headline readings on the connected-service tab, // and so the keys a car's arrangement of them may name. Derived from the reading // specs in vehicleproviders.go rather than written out again, so the set cannot // drift from what that panel actually shows. var arrangeableCarMetrics = func() map[string]bool { out := make(map[string]bool, len(headlineMetricSpecs)+len(unmeasuredMetricKeys)) for _, spec := range headlineMetricSpecs { out[spec.key] = true } for _, key := range unmeasuredMetricKeys { out[key] = true } return out }() // normalizeKeys validates a list of tab or field keys against the keys that // exist, trimming blanks and duplicates. Unknown keys are rejected rather than // ignored: they can only come from a stale or wrong client, and dropping them // silently would hide the mistake while the page carried on as before. func normalizeKeys(in []string, allowed map[string]bool, what string) ([]string, error) { out := make([]string, 0, len(in)) seen := make(map[string]bool, len(in)) for _, key := range in { key = strings.TrimSpace(key) if key == "" || seen[key] { continue } if !allowed[key] { return nil, fmt.Errorf("%q is not a car %s", key, what) } seen[key] = true out = append(out, key) } return out, nil } // PUT /api/cars/{id}/view — choose what this car's page shows: which tabs, which // rows of the Information tab, and the order the tabs, the Information rows and // the connected service's headline readings are laid out in. Body: {hiddenTabs?: // [...], hiddenFields?: [...], tabOrder?: [...], fieldOrder?: [...], // metricOrder?: [...]}; only the lists present are written, so a client can // rearrange one group without resending the others. Its own endpoint rather than fields on the car edit, so an ordinary // save of the car form — which sends every other field — can never reveal // something somebody deliberately switched off. Needs write access: the choice // belongs to the car, so it is the same permission as editing it. func (s *Server) updateCarView(w http.ResponseWriter, r *http.Request) { var in struct { HiddenTabs *[]string `json:"hiddenTabs"` HiddenFields *[]string `json:"hiddenFields"` TabOrder *[]string `json:"tabOrder"` FieldOrder *[]string `json:"fieldOrder"` MetricOrder *[]string `json:"metricOrder"` } if err := decodeJSON(r, &in); err != nil { writeError(w, http.StatusBadRequest, err.Error()) return } level, _, err := s.carAccessLevel(r.Context(), s.currentUserID(r), r.PathValue("id")) if err != nil { writePBError(w, err) return } if !canWrite(level) { writeError(w, http.StatusForbidden, "you cannot edit this car") return } payload := map[string]any{} if in.HiddenTabs != nil { tabs, err := normalizeKeys(*in.HiddenTabs, hideableCarTabs, "tab") if err != nil { writeError(w, http.StatusBadRequest, err.Error()) return } payload["hidden_tabs"] = tabs } if in.HiddenFields != nil { fields, err := normalizeKeys(*in.HiddenFields, hideableCarFields, "field") if err != nil { writeError(w, http.StatusBadRequest, err.Error()) return } payload["hidden_fields"] = fields } if in.TabOrder != nil { // A wider set than the hidden tabs: Information is arrangeable although it // cannot be switched off. A partial list is accepted, and the tabs it // leaves out follow the arranged ones — which is what puts a tab added in // a later release at the end rather than in the middle of somebody's bar. order, err := normalizeKeys(*in.TabOrder, arrangeableCarTabs, "tab") if err != nil { writeError(w, http.StatusBadRequest, err.Error()) return } payload["tab_order"] = order } if in.FieldOrder != nil { // The same key set as the hidden fields, since every Information row can // be moved. A partial list is accepted rather than demanding all 14: the // rows it leaves out follow the arranged ones, which is also what makes a // row added in a later release land at the end instead of the middle. order, err := normalizeKeys(*in.FieldOrder, hideableCarFields, "field") if err != nil { writeError(w, http.StatusBadRequest, err.Error()) return } payload["field_order"] = order } if in.MetricOrder != nil { // A partial list again, and here it is the normal case: the client can // only arrange the readings the provider actually reported, so one it // reports later — an EV range on a car that was parked unplugged — joins // at the end rather than displacing the arrangement. order, err := normalizeKeys(*in.MetricOrder, arrangeableCarMetrics, "reading") if err != nil { writeError(w, http.StatusBadRequest, err.Error()) return } payload["metric_order"] = order } if len(payload) == 0 { writeError(w, http.StatusBadRequest, "no changes provided") return } var rec carRecord if err := s.pb.Update(r.Context(), colCars, r.PathValue("id"), payload, &rec); err != nil { writePBError(w, err) return } m := rec.toModel() m.Access = level writeJSON(w, http.StatusOK, m) } func (s *Server) deleteCar(w http.ResponseWriter, r *http.Request) { level, _, err := s.carAccessLevel(r.Context(), s.currentUserID(r), r.PathValue("id")) if err != nil { writePBError(w, err) return } if level != accessOwner { writeError(w, http.StatusForbidden, "only the owner can delete this car") return } if err := s.pb.Delete(r.Context(), colCars, r.PathValue("id")); err != nil { writePBError(w, err) return } w.WriteHeader(http.StatusNoContent) } // applyCarDefaults fills the spreadsheet's default maintenance intervals when // the client didn't specify them. func applyCarDefaults(c *models.Car) { if c.ServiceIntervalDays <= 0 { c.ServiceIntervalDays = 365 } if c.ServiceIntervalKm <= 0 { c.ServiceIntervalKm = 15000 } if c.TechnicalCheckIntervalDays <= 0 { c.TechnicalCheckIntervalDays = models.DefaultTechnicalCheckIntervalDays } }