defmodule ToweropsWeb.Router do use ToweropsWeb, :router import Phoenix.LiveDashboard.Router import ToweropsWeb.UserAuth pipeline :browser do plug :accepts, ["html"] plug :fetch_session plug :fetch_live_flash plug :put_root_layout, html: {ToweropsWeb.Layouts, :root} plug :protect_from_forgery plug :put_secure_browser_headers plug :fetch_current_scope_for_user end pipeline :api do plug :accepts, ["json"] end pipeline :agent_api do plug :accepts, ["json", "protobuf"] plug ToweropsWeb.Plugs.AgentAuth end # Health check endpoint for Kubernetes probes (no authentication required) scope "/", ToweropsWeb do get "/health", HealthController, :index end scope "/", ToweropsWeb do pipe_through :browser get "/", PageController, :home end # Agent API routes scope "/api/v1/agent", ToweropsWeb.Api do pipe_through :agent_api get "/config", AgentController, :get_config post "/metrics", AgentController, :submit_metrics post "/heartbeat", AgentController, :heartbeat end # WebAuthn API routes scope "/api/webauthn", ToweropsWeb do pipe_through [:browser] post "/authentication/challenge", UserCredentialController, :authentication_challenge post "/authenticate", UserCredentialController, :authenticate end scope "/api/webauthn", ToweropsWeb do pipe_through [:browser, :require_authenticated_user] post "/registration/challenge", UserCredentialController, :registration_challenge post "/register", UserCredentialController, :register end # Enable LiveDashboard in production with authentication scope "/dashboard" do pipe_through [:browser, :require_authenticated_user] live_dashboard "/", metrics: ToweropsWeb.Telemetry, ecto_repos: [Towerops.Repo] end # Enable Swoosh mailbox preview in development if Application.compile_env(:towerops, :dev_routes) do scope "/dev" do pipe_through :browser forward "/mailbox", Plug.Swoosh.MailboxPreview end end ## Authentication routes scope "/", ToweropsWeb do pipe_through [:browser, :redirect_if_user_is_authenticated] get "/users/register", UserRegistrationController, :new post "/users/register", UserRegistrationController, :create end scope "/", ToweropsWeb do pipe_through [:browser, :require_authenticated_user] get "/users/settings", UserSettingsController, :edit put "/users/settings", UserSettingsController, :update get "/users/settings/confirm-email/:token", UserSettingsController, :confirm_email delete "/users/credentials/:id", UserCredentialController, :delete end scope "/", ToweropsWeb do pipe_through [:browser] get "/users/log-in", UserSessionController, :new get "/users/log-in/:token", UserSessionController, :confirm post "/users/log-in", UserSessionController, :create delete "/users/log-out", UserSessionController, :delete end ## Admin routes (superuser only) scope "/", ToweropsWeb do pipe_through [:browser, :require_authenticated_user, :require_superuser] post "/admin/impersonate/:user_id", AdminController, :start_impersonate delete "/admin/impersonate", AdminController, :stop_impersonate end live_session :require_superuser, on_mount: [ {ToweropsWeb.UserAuth, :require_authenticated_user}, {ToweropsWeb.UserAuth, :require_superuser} ] do scope "/admin", ToweropsWeb.Admin do pipe_through [:browser, :require_authenticated_user, :require_superuser] live "/", DashboardLive, :index live "/users", UserLive.Index, :index live "/organizations", OrgLive.Index, :index end end ## Organization routes live_session :require_authenticated_user, on_mount: [{ToweropsWeb.UserAuth, :require_authenticated_user}] do scope "/", ToweropsWeb do pipe_through [:browser, :require_authenticated_user] live "/orgs", OrgLive.Index, :index live "/orgs/new", OrgLive.New, :new end end live_session :require_authenticated_user_and_organization, on_mount: [ {ToweropsWeb.UserAuth, :require_authenticated_user}, {ToweropsWeb.UserAuth, :load_current_organization} ] do scope "/orgs/:org_slug", ToweropsWeb do pipe_through [:browser, :require_authenticated_user, :load_current_organization] live "/", DashboardLive, :index live "/settings", Org.SettingsLive, :index # Site routes live "/sites", SiteLive.Index, :index live "/sites/new", SiteLive.Form, :new live "/sites/:id", SiteLive.Show, :show live "/sites/:id/edit", SiteLive.Form, :edit # Equipment routes live "/equipment", EquipmentLive.Index, :index live "/equipment/new", EquipmentLive.Form, :new live "/equipment/:id", EquipmentLive.Show, :show live "/equipment/:id/edit", EquipmentLive.Form, :edit live "/equipment/:id/graph/:sensor_type", GraphLive.Show, :show # Alert routes live "/alerts", AlertLive.Index, :index # Agent routes live "/agents", AgentLive.Index, :index live "/agents/:id", AgentLive.Show, :show end end end