refactor(api): remove 5 deprecated list endpoints superseded by /resources
The normalized cursor-paginated /resources API is live and the bundled
frontend already uses it for favorites, recent, trash and grants. These five
deprecated old-format endpoints had no remaining frontend or protocol
consumers (the Nextcloud handlers call the service layer directly, not these
HTTP routes), so remove them for a uniform API and less duplicate listing
logic:
- GET /api/folders/{id}/contents → use /api/folders/{id}/resources
- GET /api/folders/{id}/contents/paginated → use /api/folders/{id}/resources
- GET /api/favorites → use /api/favorites/resources
- GET /api/recent → use /api/recent/resources
- GET /api/trash → use /api/trash/resources
Removes the HTTP handlers, their routes, OpenAPI path registrations, and the
now-dead list_folder_contents{,_paginated}_impl helpers + unused imports. The
underlying service methods (favorites_service.get_favorites,
trash_service.get_trash_items, etc.) are KEPT — the Nextcloud OCS/trashbin
handlers depend on them.
Deliberately NOT removed: GET /api/folders/{id}/listing. It is still the Files
view's primary data path and offers ETag/304 conditional caching plus
one-shot favorite/share badge sets that /resources does not yet provide;
migrating it needs a separate parity pass on /resources first.
Updates the OpenAPI structure test and the two docs that referenced the
removed paths. `cargo clippy -D warnings` clean; 443 lib tests pass; OpenAPI
regenerates with the 5 paths gone and the /resources replacements present.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -6,7 +6,7 @@ use axum::{
|
||||
};
|
||||
use serde::Deserialize;
|
||||
use std::sync::Arc;
|
||||
use tracing::{error, info, warn};
|
||||
use tracing::{error, info};
|
||||
use utoipa::ToSchema;
|
||||
|
||||
use crate::application::dtos::display_helpers::{
|
||||
@@ -37,52 +37,6 @@ pub struct BatchFavoritesRequest {
|
||||
pub items: Vec<BatchFavoriteItem>,
|
||||
}
|
||||
|
||||
/// Handler for favorite-related API endpoints
|
||||
///
|
||||
/// # Deprecated
|
||||
/// Use `GET /api/favorites/resources` instead. This endpoint is kept for
|
||||
/// backwards compatibility but will be removed in a future release.
|
||||
#[deprecated = "Use GET /api/favorites/resources instead"]
|
||||
#[utoipa::path(
|
||||
get,
|
||||
path = "/api/favorites",
|
||||
responses(
|
||||
(status = 200, description = "List of favorites (deprecated — use /api/favorites/resources)", body = Vec<crate::application::dtos::favorites_dto::FavoriteItemDto>)
|
||||
),
|
||||
security(("bearerAuth" = [])),
|
||||
tag = "favorites"
|
||||
)]
|
||||
pub async fn get_favorites(
|
||||
State(favorites_service): State<Arc<FavoritesService>>,
|
||||
auth_user: AuthUser,
|
||||
) -> impl IntoResponse {
|
||||
let user_id = auth_user.id;
|
||||
warn!(
|
||||
"Deprecated endpoint called: GET /api/favorites — use GET /api/favorites/resources instead"
|
||||
);
|
||||
|
||||
match favorites_service.get_favorites(user_id).await {
|
||||
Ok(favorites) => {
|
||||
info!(
|
||||
"Retrieved {} favorites for user {}",
|
||||
favorites.len(),
|
||||
auth_user.id
|
||||
);
|
||||
(StatusCode::OK, Json(serde_json::json!(favorites))).into_response()
|
||||
}
|
||||
Err(err) => {
|
||||
error!("Error retrieving favorites: {}", err);
|
||||
(
|
||||
StatusCode::INTERNAL_SERVER_ERROR,
|
||||
Json(serde_json::json!({
|
||||
"error": "Failed to retrieve favorites"
|
||||
})),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Add an item to user's favorites
|
||||
#[utoipa::path(
|
||||
post,
|
||||
|
||||
@@ -111,16 +111,6 @@ impl FolderHandler {
|
||||
Self::list_folders_scoped(service, None, &auth_user).await
|
||||
}
|
||||
|
||||
/// Lists contents of a specific folder by its ID.
|
||||
/// Scoped to the authenticated user's folders.
|
||||
pub(super) async fn list_folder_contents_impl(
|
||||
State(service): State<AppState>,
|
||||
auth_user: AuthUser,
|
||||
Path(id): Path<String>,
|
||||
) -> axum::response::Response {
|
||||
Self::list_folders_scoped(service, Some(&id), &auth_user).await
|
||||
}
|
||||
|
||||
/// Lists root folders with pagination.
|
||||
/// Scoped to the authenticated user — only returns folders owned by this user.
|
||||
pub(super) async fn list_root_folders_paginated_impl(
|
||||
@@ -131,22 +121,6 @@ impl FolderHandler {
|
||||
Self::list_folders_scoped(service, None, &auth_user).await
|
||||
}
|
||||
|
||||
/// Lists sub-folders inside a folder with pagination.
|
||||
pub(super) async fn list_folder_contents_paginated_impl(
|
||||
State(service): State<AppState>,
|
||||
auth_user: AuthUser,
|
||||
Path(id): Path<String>,
|
||||
pagination: Query<PaginationRequestDto>,
|
||||
) -> axum::response::Response {
|
||||
match service
|
||||
.list_folders_paginated_with_perms(Some(&id), auth_user.id, &pagination)
|
||||
.await
|
||||
{
|
||||
Ok(paginated_result) => (StatusCode::OK, Json(paginated_result)).into_response(),
|
||||
Err(err) => AppError::from(err).into_response(),
|
||||
}
|
||||
}
|
||||
|
||||
/// Internal helper: lists folders scoped to the authenticated user.
|
||||
/// Uses `list_folders_for_owner` — the DB query filters by `user_id`,
|
||||
/// so no data from other users ever leaves the database.
|
||||
@@ -525,30 +499,6 @@ pub async fn list_root_folders(
|
||||
FolderHandler::list_root_folders_impl(state, auth_user).await
|
||||
}
|
||||
|
||||
#[deprecated = "Use /api/folders/{id}/resources instead"]
|
||||
#[utoipa::path(
|
||||
get,
|
||||
path = "/api/folders/{id}/contents",
|
||||
params(("id" = String, Path, description = "Folder ID")),
|
||||
responses(
|
||||
(status = 200, description = "List of sub-folders", body = Vec<FolderDto>),
|
||||
(status = 404, description = "Folder not found"),
|
||||
),
|
||||
security(("bearerAuth" = [])),
|
||||
tag = "folders"
|
||||
)]
|
||||
#[allow(deprecated)]
|
||||
pub async fn list_folder_contents(
|
||||
state: State<AppState>,
|
||||
auth_user: AuthUser,
|
||||
path: Path<String>,
|
||||
) -> axum::response::Response {
|
||||
tracing::warn!(
|
||||
"Deprecated endpoint called: GET /api/folders/{{id}}/contents — use GET /api/folders/{{id}}/resources?resource_types=folder instead"
|
||||
);
|
||||
FolderHandler::list_folder_contents_impl(state, auth_user, path).await
|
||||
}
|
||||
|
||||
#[utoipa::path(
|
||||
get,
|
||||
path = "/api/folders/paginated",
|
||||
@@ -567,34 +517,6 @@ pub async fn list_root_folders_paginated(
|
||||
FolderHandler::list_root_folders_paginated_impl(state, auth_user, pagination).await
|
||||
}
|
||||
|
||||
#[deprecated = "Use /api/folders/{id}/resources instead"]
|
||||
#[utoipa::path(
|
||||
get,
|
||||
path = "/api/folders/{id}/contents/paginated",
|
||||
params(
|
||||
("id" = String, Path, description = "Folder ID"),
|
||||
PaginationRequestDto,
|
||||
),
|
||||
responses(
|
||||
(status = 200, description = "Paginated list of sub-folders"),
|
||||
(status = 404, description = "Folder not found"),
|
||||
),
|
||||
security(("bearerAuth" = [])),
|
||||
tag = "folders"
|
||||
)]
|
||||
#[allow(deprecated)]
|
||||
pub async fn list_folder_contents_paginated(
|
||||
state: State<AppState>,
|
||||
auth_user: AuthUser,
|
||||
path: Path<String>,
|
||||
pagination: Query<PaginationRequestDto>,
|
||||
) -> axum::response::Response {
|
||||
tracing::warn!(
|
||||
"Deprecated endpoint called: GET /api/folders/{{id}}/contents/paginated — use GET /api/folders/{{id}}/resources instead"
|
||||
);
|
||||
FolderHandler::list_folder_contents_paginated_impl(state, auth_user, path, pagination).await
|
||||
}
|
||||
|
||||
#[deprecated = "Use /api/folders/{id}/resources instead"]
|
||||
#[utoipa::path(
|
||||
get,
|
||||
|
||||
@@ -4,9 +4,8 @@ use axum::{
|
||||
http::StatusCode,
|
||||
response::IntoResponse,
|
||||
};
|
||||
use serde::Deserialize;
|
||||
use std::sync::Arc;
|
||||
use tracing::{error, info, warn};
|
||||
use tracing::{error, info};
|
||||
|
||||
use crate::application::dtos::display_helpers::{
|
||||
category_for, format_file_size, icon_class_for, icon_special_class_for,
|
||||
@@ -24,50 +23,6 @@ use crate::interfaces::errors::AppError;
|
||||
use crate::interfaces::middleware::auth::AuthUser;
|
||||
use uuid::Uuid;
|
||||
|
||||
/// Query parameters for getting recent items
|
||||
#[derive(Deserialize)]
|
||||
pub struct GetRecentParams {
|
||||
#[serde(default)]
|
||||
limit: Option<i32>,
|
||||
}
|
||||
|
||||
/// Get user's recent items (deprecated — use `GET /api/recent/resources` instead)
|
||||
#[deprecated = "Use GET /api/recent/resources instead"]
|
||||
#[utoipa::path(
|
||||
get,
|
||||
path = "/api/recent",
|
||||
responses(
|
||||
(status = 200, description = "List of recent items", body = Vec<crate::application::dtos::recent_dto::RecentItemDto>)
|
||||
),
|
||||
security(("bearerAuth" = [])),
|
||||
tag = "recent"
|
||||
)]
|
||||
pub async fn get_recent_items(
|
||||
State(recent_service): State<Arc<RecentService>>,
|
||||
auth_user: AuthUser,
|
||||
Query(params): Query<GetRecentParams>,
|
||||
) -> impl IntoResponse {
|
||||
let user_id = auth_user.id;
|
||||
warn!("Deprecated endpoint called: GET /api/recent — use GET /api/recent/resources instead");
|
||||
|
||||
match recent_service.get_recent_items(user_id, params.limit).await {
|
||||
Ok(items) => {
|
||||
info!("Retrieved {} recent items for user", items.len());
|
||||
(StatusCode::OK, Json(items)).into_response()
|
||||
}
|
||||
Err(err) => {
|
||||
error!("Error retrieving recent items: {}", err);
|
||||
(
|
||||
StatusCode::INTERNAL_SERVER_ERROR,
|
||||
Json(serde_json::json!({
|
||||
"error": "Failed to retrieve recent items"
|
||||
})),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Record access to an item
|
||||
#[utoipa::path(
|
||||
post,
|
||||
|
||||
@@ -12,69 +12,6 @@ use crate::interfaces::errors::AppError;
|
||||
use crate::interfaces::middleware::auth::AuthUser;
|
||||
use std::sync::Arc;
|
||||
|
||||
/// Gets all items in the trash for the current user.
|
||||
///
|
||||
/// # Deprecated
|
||||
/// Use `GET /api/trash/resources` instead. This endpoint is kept for
|
||||
/// backwards compatibility but will be removed in a future release.
|
||||
#[deprecated = "Use GET /api/trash/resources instead"]
|
||||
#[utoipa::path(
|
||||
get,
|
||||
path = "/api/trash",
|
||||
responses(
|
||||
(status = 200, description = "List of trashed items (deprecated — use /api/trash/resources)"),
|
||||
(status = 501, description = "Trash feature not enabled")
|
||||
),
|
||||
security(("bearerAuth" = [])),
|
||||
tag = "trash"
|
||||
)]
|
||||
#[instrument(skip_all)]
|
||||
pub async fn get_trash_items(
|
||||
State(state): State<Arc<AppState>>,
|
||||
auth_user: AuthUser,
|
||||
) -> (StatusCode, Json<serde_json::Value>) {
|
||||
// SECURITY: Always use the authenticated user's ID from the JWT token.
|
||||
// Never allow user ID override via query parameters to prevent
|
||||
// privilege escalation attacks.
|
||||
let effective_user = auth_user.id;
|
||||
|
||||
warn!(
|
||||
"Deprecated endpoint called: GET /api/trash — use GET /api/trash/resources instead (user {effective_user})"
|
||||
);
|
||||
|
||||
debug!("Request to list trash items for user {}", effective_user);
|
||||
|
||||
let trash_service = match state.trash_service.as_ref() {
|
||||
Some(service) => service,
|
||||
None => {
|
||||
return (
|
||||
StatusCode::NOT_IMPLEMENTED,
|
||||
Json(json!({
|
||||
"error": "Trash feature is not enabled"
|
||||
})),
|
||||
);
|
||||
}
|
||||
};
|
||||
|
||||
let result = trash_service.get_trash_items(effective_user).await;
|
||||
|
||||
match result {
|
||||
Ok(items) => {
|
||||
debug!("Found {} items in trash", items.len());
|
||||
(StatusCode::OK, Json(json!(items)))
|
||||
}
|
||||
Err(e) => {
|
||||
error!("Error retrieving trash items: {:?}", e);
|
||||
(
|
||||
StatusCode::INTERNAL_SERVER_ERROR,
|
||||
Json(json!({
|
||||
"error": "Error retrieving trash items"
|
||||
})),
|
||||
)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Cursor-paginated list of a user's trashed resources.
|
||||
///
|
||||
/// Sorts by `deletion_date` (default — soonest expiry first), `trashed_at`
|
||||
|
||||
Reference in New Issue
Block a user