//! Router assembly and route module declarations. pub mod audit; pub mod auth; pub mod backups; pub mod client_profiles; pub mod diagnostics; pub mod firewall; pub mod interfaces; pub mod networks; pub mod peers; pub mod reconcile; pub mod routing; pub mod system; pub mod ui; pub mod ws; use crate::auth::middleware::require_auth; use crate::state::AppState; use axum::Router; use axum::middleware::from_fn_with_state; use axum::routing::{delete, get, post, put}; use tower_http::compression::CompressionLayer; use tower_http::trace::TraceLayer; /// Build the complete Axum API Router with all public, protected, and UI routes. pub fn build_api_router(state: AppState) -> Router { // 1. Protected routes (require authenticated admin via session or token) let protected_router = Router::new() // Auth management .route("/auth/session", get(auth::session_handler)) .route("/auth/password", post(auth::change_password_handler)) .route("/auth/tokens", post(auth::create_token_handler)) .route("/auth/tokens", get(auth::list_tokens_handler)) .route("/auth/tokens/{id}", delete(auth::revoke_token_handler)) // System .route("/system", get(system::system_overview_handler)) .route("/system/live-state", get(system::live_state_handler)) .route("/system/settings", get(system::list_settings_handler)) .route("/system/settings", put(system::upsert_setting_handler)) // Interfaces .route("/interfaces", get(interfaces::list_interfaces_handler)) .route("/interfaces", post(interfaces::create_interface_handler)) .route("/interfaces/{id}", get(interfaces::get_interface_handler)) .route( "/interfaces/{id}", put(interfaces::update_interface_handler), ) .route( "/interfaces/{id}", delete(interfaces::delete_interface_handler), ) .route( "/interfaces/{id}/enable", post(interfaces::enable_interface_handler), ) .route( "/interfaces/{id}/disable", post(interfaces::disable_interface_handler), ) .route( "/interfaces/{id}/status", get(interfaces::interface_status_handler), ) .route( "/interfaces/{id}/peers", get(peers::list_peers_for_interface_handler), ) .route("/interfaces/{id}/peers", post(peers::create_peer_handler)) // Peers .route("/peers", get(peers::list_peers_handler)) .route("/peers/{id}", get(peers::get_peer_handler)) .route("/peers/{id}", put(peers::update_peer_handler)) .route("/peers/{id}", delete(peers::delete_peer_handler)) .route("/peers/{id}/enable", post(peers::enable_peer_handler)) .route("/peers/{id}/disable", post(peers::disable_peer_handler)) .route("/peers/{id}/revoke", post(peers::revoke_peer_handler)) .route("/peers/{id}/expire", post(peers::expire_peer_handler)) .route( "/peers/{id}/lifecycle", get(peers::get_peer_lifecycle_handler), ) .route( "/peers/{id}/config", get(peers::download_peer_config_handler), ) .route("/peers/{id}/qr", get(peers::get_peer_qr_handler)) // Networks .route("/networks", get(networks::list_networks_handler)) .route("/networks", post(networks::create_network_handler)) .route("/networks/{id}", get(networks::get_network_handler)) .route("/networks/{id}", put(networks::update_network_handler)) .route("/networks/{id}", delete(networks::delete_network_handler)) .route( "/networks/{id}/available", get(networks::list_available_ips_handler), ) .route( "/networks/{id}/allocations", get(networks::list_allocations_handler), ) // Routes .route("/routes", get(routing::list_routes_handler)) .route("/routes", post(routing::create_route_handler)) .route("/routes/{id}", get(routing::get_route_handler)) .route("/routes/{id}", put(routing::update_route_handler)) .route("/routes/{id}", delete(routing::delete_route_handler)) // Firewall .route( "/firewall/rules", get(firewall::list_firewall_rules_handler), ) .route( "/firewall/rules", post(firewall::create_firewall_rule_handler), ) .route( "/firewall/rules/{id}", get(firewall::get_firewall_rule_handler), ) .route( "/firewall/rules/{id}", put(firewall::update_firewall_rule_handler), ) .route( "/firewall/rules/{id}", delete(firewall::delete_firewall_rule_handler), ) .route( "/firewall/rules/{id}/enable", post(firewall::enable_firewall_rule_handler), ) .route( "/firewall/rules/{id}/disable", post(firewall::disable_firewall_rule_handler), ) // Diagnostics .route("/diagnostics/all", get(diagnostics::diagnose_all_handler)) .route( "/diagnostics/{subsystem}", get(diagnostics::diagnose_subsystem_handler), ) // Client Profiles .route( "/client-profiles", get(client_profiles::list_client_profiles_handler), ) .route( "/client-profiles/providers", get(client_profiles::list_providers_handler), ) .route( "/client-profiles/devices", get(client_profiles::list_devices_handler), ) .route( "/client-profiles/{id}", get(client_profiles::get_client_profile_handler), ) .route( "/client-profiles/resolve", post(client_profiles::resolve_client_profile_handler), ) // Audit .route("/audit", get(audit::list_audit_events_handler)) // Backups .route("/backups", get(backups::list_backups_handler)) .route("/backups", post(backups::create_backup_record_handler)) .route("/backups/create", post(backups::trigger_backup_handler)) .route("/backups/{id}", get(backups::get_backup_handler)) .route( "/backups/{id}/download", get(backups::download_backup_handler), ) .route( "/backups/{id}/restore", post(backups::restore_backup_handler), ) .route("/backups/{id}", delete(backups::delete_backup_handler)) // Reconcile .route( "/reconcile/plan", get(reconcile::get_reconciliation_plan_handler), ) .route( "/reconcile/apply", post(reconcile::apply_reconciliation_handler), ) // Attach authentication middleware .route_layer(from_fn_with_state(state.auth.clone(), require_auth)); // 2. Public API routes (no authentication required) let public_router = Router::new() .route("/auth/login", post(auth::login_handler)) .route("/auth/logout", post(auth::logout_handler)) .route("/system/health", get(system::health_handler)) .route("/system/version", get(system::version_handler)) .route("/ws", get(ws::ws_handler)); // 3. Web UI routes and assets let ui_router = Router::new() .route("/", get(ui::index_handler)) .route("/ui", get(ui::index_handler)) .route("/assets/style.css", get(ui::stylesheet_handler)); // 4. Nest all under root and /api/v1 and attach global middleware ui_router .nest("/api/v1", public_router.merge(protected_router)) .layer(TraceLayer::new_for_http()) .layer(CompressionLayer::new()) .with_state(state) }