hub v0.15.0: Phase 2 managed updates — per-customer controller-version floor

Operator sets a minimum controller version (FLOOR), per-customer defaulting to a
global floor; the report ACK returns the effective floor + latest_version so the
controller auto-updates to the floor when below it (latest stays the opt-in button).

- store: min_controller_version column + hub_settings global floor + Effective/
  Get/SetGlobal/SetMin resolution + config/env DEFAULT_MIN_CONTROLLER_VERSION
- handler: report ACK {min_controller_version, latest_version}; LatestVersionProvider
- web: global floor editor + per-customer override form + Floor column (English)
- tests: floor resolution + ACK + render; override-precedence red-proof verified

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FSZmmSFVzGwEzhYmxbkgBK
This commit is contained in:
2026-06-27 11:59:30 +02:00
parent ea09ead806
commit 30380a59f4
12 changed files with 614 additions and 111 deletions
+67
View File
@@ -0,0 +1,67 @@
package api
import (
"encoding/json"
"net/http"
"testing"
"gitea.dooplex.hu/admin/felhom-hub/internal/store"
)
type fakeLatest struct{ v string }
func (f fakeLatest) LatestVersion() string { return f.v }
// The controller report ACK advertises the effective floor + latest version (Phase 2).
func TestReportACK_FloorAndLatest(t *testing.T) {
h, st, _ := newTestHandler(t)
h.SetLatestVersionProvider(fakeLatest{v: "0.86.0"})
// Customer with a per-customer override; a global default also set (override must win in the ACK).
st.SetDefaultMinControllerVersion("0.85.0")
if err := st.SaveCustomerConfig(&store.CustomerConfig{
CustomerID: "c", RetrievalPassword: "pw", APIKey: "k", ConfigJSON: "{}",
MinControllerVersion: "0.87.0",
}); err != nil {
t.Fatalf("SaveCustomerConfig: %v", err)
}
rr := do(h, http.MethodPost, "/report", globalKey, `{"customer_id":"c"}`)
if rr.Code != http.StatusOK {
t.Fatalf("report status = %d, want 200 (body=%s)", rr.Code, rr.Body.String())
}
var ack map[string]interface{}
if err := json.Unmarshal(rr.Body.Bytes(), &ack); err != nil {
t.Fatalf("decode ACK: %v", err)
}
if ack["min_controller_version"] != "0.87.0" {
t.Errorf("ACK min_controller_version = %v, want 0.87.0 (override beats global)", ack["min_controller_version"])
}
if ack["latest_version"] != "0.86.0" {
t.Errorf("ACK latest_version = %v, want 0.86.0", ack["latest_version"])
}
}
// No floor configured anywhere → the ACK omits min_controller_version (Phase 2 inert).
func TestReportACK_NoFloorOmitted(t *testing.T) {
h, st, _ := newTestHandler(t)
if err := st.SaveCustomerConfig(&store.CustomerConfig{
CustomerID: "c", RetrievalPassword: "pw", APIKey: "k", ConfigJSON: "{}",
}); err != nil {
t.Fatalf("SaveCustomerConfig: %v", err)
}
rr := do(h, http.MethodPost, "/report", globalKey, `{"customer_id":"c"}`)
if rr.Code != http.StatusOK {
t.Fatalf("report status = %d, want 200", rr.Code)
}
var ack map[string]interface{}
json.Unmarshal(rr.Body.Bytes(), &ack)
if _, ok := ack["min_controller_version"]; ok {
t.Errorf("ACK should omit min_controller_version when no floor; got %v", ack["min_controller_version"])
}
// latest_version is also omitted when no provider wired.
if _, ok := ack["latest_version"]; ok {
t.Errorf("ACK should omit latest_version when no provider; got %v", ack["latest_version"])
}
}
+29
View File
@@ -24,6 +24,13 @@ type ConfigTemplateProvider interface {
Template() string
}
// LatestVersionProvider returns the latest controller image version known to the hub's registry
// checker (e.g. "0.86.0"), or "" if unknown. Satisfied by *web.VersionChecker; nil when the
// registry checker is disabled. Used to advertise latest on the controller report ACK.
type LatestVersionProvider interface {
LatestVersion() string
}
// Handler handles API endpoints for report ingest and customer queries.
type Handler struct {
store *store.Store
@@ -35,6 +42,13 @@ type Handler struct {
templateProvider ConfigTemplateProvider
dispatcher *notify.Dispatcher
assetsMgr *assets.Manager
latestVersion LatestVersionProvider
}
// SetLatestVersionProvider wires the registry version checker so the controller report ACK can
// advertise the latest available version (Phase 2). nil-safe (no latest_version field emitted).
func (h *Handler) SetLatestVersionProvider(p LatestVersionProvider) {
h.latestVersion = p
}
// New creates a new API handler.
@@ -267,6 +281,21 @@ func (h *Handler) handleReport(w http.ResponseWriter, r *http.Request) {
resp["customer_blocked"] = true
}
}
// Phase 2 managed updates: advertise the effective controller-version FLOOR (per-customer override
// else global default) and the latest available version. The controller compares its current
// version against the floor and auto-updates when below it (latest stays the customer's opt-in
// "update to latest" button — NOT the auto-target). Both fields are omitted when empty, so an old
// controller that ignores them, or a hub with no floor configured, behaves exactly as before.
if floor := h.store.EffectiveMinControllerVersion(payload.CustomerID); floor != "" {
resp["min_controller_version"] = floor
}
if h.latestVersion != nil {
if latest := h.latestVersion.LatestVersion(); latest != "" {
resp["latest_version"] = latest
}
}
w.Header().Set("Content-Type", "application/json")
w.WriteHeader(http.StatusOK)
json.NewEncoder(w).Encode(resp)
+111
View File
@@ -0,0 +1,111 @@
package store
import (
"io"
"log"
"path/filepath"
"testing"
)
func newFloorTestStore(t *testing.T) *Store {
t.Helper()
s, err := New(filepath.Join(t.TempDir(), "floor.db"), log.New(io.Discard, "", 0))
if err != nil {
t.Fatalf("store.New: %v", err)
}
t.Cleanup(func() { s.Close() })
return s
}
func mkCustomer(t *testing.T, s *Store, id, floor string) {
t.Helper()
if err := s.SaveCustomerConfig(&CustomerConfig{
CustomerID: id,
RetrievalPassword: "pw",
APIKey: "key-" + id,
ConfigJSON: "{}",
MinControllerVersion: floor,
}); err != nil {
t.Fatalf("SaveCustomerConfig(%s): %v", id, err)
}
}
// EffectiveMinControllerVersion: empty when nothing is set.
func TestEffectiveFloor_EmptyWhenUnset(t *testing.T) {
s := newFloorTestStore(t)
mkCustomer(t, s, "c", "")
if got := s.EffectiveMinControllerVersion("c"); got != "" {
t.Errorf("effective floor = %q, want empty (no override, no global)", got)
}
// Also empty for a customer with no config at all.
if got := s.EffectiveMinControllerVersion("ghost"); got != "" {
t.Errorf("effective floor for unknown customer = %q, want empty", got)
}
}
// The config/env default is the fallback global floor.
func TestEffectiveFloor_GlobalDefaultFallback(t *testing.T) {
s := newFloorTestStore(t)
s.SetDefaultMinControllerVersion("0.85.0")
mkCustomer(t, s, "c", "")
if got := s.EffectiveMinControllerVersion("c"); got != "0.85.0" {
t.Errorf("effective floor = %q, want 0.85.0 (global default)", got)
}
}
// A hub_settings row overrides the config/env default.
func TestGlobalFloor_DBOverridesDefault(t *testing.T) {
s := newFloorTestStore(t)
s.SetDefaultMinControllerVersion("0.85.0")
if err := s.SetGlobalMinControllerVersion("0.86.0"); err != nil {
t.Fatalf("SetGlobalMinControllerVersion: %v", err)
}
if got := s.GetGlobalMinControllerVersion(); got != "0.86.0" {
t.Errorf("global floor = %q, want 0.86.0 (DB beats default)", got)
}
// Clearing the row falls back to the default.
if err := s.SetGlobalMinControllerVersion(""); err != nil {
t.Fatalf("clear global floor: %v", err)
}
if got := s.GetGlobalMinControllerVersion(); got != "0.85.0" {
t.Errorf("global floor after clear = %q, want 0.85.0 (default)", got)
}
}
// Scenario C — per-customer override beats global. This is the companion RED-PROOF: it must FAIL if
// EffectiveMinControllerVersion ever returns the global when an override is set.
func TestEffectiveFloor_OverrideBeatsGlobal(t *testing.T) {
s := newFloorTestStore(t)
s.SetDefaultMinControllerVersion("0.85.0") // global
mkCustomer(t, s, "c", "0.87.0") // per-customer override
mkCustomer(t, s, "other", "") // no override → uses global
if got := s.EffectiveMinControllerVersion("c"); got != "0.87.0" {
t.Errorf("effective floor for c = %q, want 0.87.0 (override beats global)", got)
}
if got := s.EffectiveMinControllerVersion("other"); got != "0.85.0" {
t.Errorf("effective floor for other = %q, want 0.85.0 (global, no override)", got)
}
}
// SetMinControllerVersion round-trips and is preserved across an unrelated SaveCustomerConfig.
func TestSetMinControllerVersion_PreservedOnSave(t *testing.T) {
s := newFloorTestStore(t)
mkCustomer(t, s, "c", "")
if err := s.SetMinControllerVersion("c", "0.88.0"); err != nil {
t.Fatalf("SetMinControllerVersion: %v", err)
}
// A typical edit path: load, mutate an unrelated field, save.
cfg, _ := s.GetCustomerConfig("c")
if cfg.MinControllerVersion != "0.88.0" {
t.Fatalf("after Set, MinControllerVersion = %q, want 0.88.0", cfg.MinControllerVersion)
}
cfg.Email = "x@example.com"
if err := s.SaveCustomerConfig(cfg); err != nil {
t.Fatalf("SaveCustomerConfig: %v", err)
}
cfg2, _ := s.GetCustomerConfig("c")
if cfg2.MinControllerVersion != "0.88.0" {
t.Errorf("floor lost across save: %q, want 0.88.0", cfg2.MinControllerVersion)
}
}
+91 -11
View File
@@ -15,6 +15,17 @@ import (
type Store struct {
db *sql.DB
logger *log.Logger
// defaultMinControllerVersion is the config/env-supplied global FLOOR fallback (Phase 2 managed
// updates). Used only when neither a per-customer override nor a hub_settings row is set.
defaultMinControllerVersion string
}
// SetDefaultMinControllerVersion sets the config/env-supplied global floor fallback. Called once at
// startup from main (DEFAULT_MIN_CONTROLLER_VERSION). A hub_settings row, when present, takes
// precedence over this value (see GetGlobalMinControllerVersion).
func (s *Store) SetDefaultMinControllerVersion(v string) {
s.defaultMinControllerVersion = v
}
// CustomerSummary holds the latest status for a customer (for dashboard).
@@ -116,6 +127,25 @@ func (s *Store) migrate() error {
// v0.2.1: add status column to customer_configs (idempotent)
s.db.Exec("ALTER TABLE customer_configs ADD COLUMN status TEXT NOT NULL DEFAULT 'active'")
// v0.15.0: per-customer minimum controller version (the managed-update FLOOR). Empty = no
// per-customer override → the effective floor falls back to the global default (hub_settings /
// config). Idempotent.
s.db.Exec("ALTER TABLE customer_configs ADD COLUMN min_controller_version TEXT NOT NULL DEFAULT ''")
// v0.15.0: hub_settings — a tiny key/value table for operator-set globals that must survive
// restarts (currently only the global controller-version floor). The config/env DEFAULT_MIN_
// CONTROLLER_VERSION is the FALLBACK; a row here (set via the operator UI) overrides it.
_, err = s.db.Exec(`
CREATE TABLE IF NOT EXISTS hub_settings (
key TEXT PRIMARY KEY,
value TEXT NOT NULL DEFAULT '',
updated_at DATETIME NOT NULL DEFAULT (datetime('now'))
);
`)
if err != nil {
return err
}
// v0.3.0: events table for hub-native monitoring
_, err = s.db.Exec(`
CREATE TABLE IF NOT EXISTS events (
@@ -685,16 +715,19 @@ type CustomerConfig struct {
APIKey string
ConfigJSON string // JSON object with customer-specific override fields
Status string // "active" or "blocked"
CreatedAt time.Time
UpdatedAt time.Time
// MinControllerVersion is the per-customer minimum controller version (managed-update FLOOR
// override). Empty = use the global default. Set/cleared via the operator UI.
MinControllerVersion string
CreatedAt time.Time
UpdatedAt time.Time
}
// SaveCustomerConfig creates or updates a customer configuration.
func (s *Store) SaveCustomerConfig(cfg *CustomerConfig) error {
_, err := s.db.Exec(`
INSERT INTO customer_configs (customer_id, customer_name, domain, email,
retrieval_password, api_key, config_json, updated_at)
VALUES (?, ?, ?, ?, ?, ?, ?, datetime('now'))
retrieval_password, api_key, config_json, min_controller_version, updated_at)
VALUES (?, ?, ?, ?, ?, ?, ?, ?, datetime('now'))
ON CONFLICT(customer_id) DO UPDATE SET
customer_name = excluded.customer_name,
domain = excluded.domain,
@@ -702,9 +735,10 @@ func (s *Store) SaveCustomerConfig(cfg *CustomerConfig) error {
retrieval_password = excluded.retrieval_password,
api_key = excluded.api_key,
config_json = excluded.config_json,
min_controller_version = excluded.min_controller_version,
updated_at = datetime('now')`,
cfg.CustomerID, cfg.CustomerName, cfg.Domain, cfg.Email,
cfg.RetrievalPassword, cfg.APIKey, cfg.ConfigJSON,
cfg.RetrievalPassword, cfg.APIKey, cfg.ConfigJSON, cfg.MinControllerVersion,
)
return err
}
@@ -715,11 +749,11 @@ func (s *Store) GetCustomerConfig(customerID string) (*CustomerConfig, error) {
var createdAt, updatedAt string
err := s.db.QueryRow(`
SELECT customer_id, customer_name, domain, email,
retrieval_password, api_key, config_json, status, created_at, updated_at
retrieval_password, api_key, config_json, status, min_controller_version, created_at, updated_at
FROM customer_configs WHERE customer_id = ?`,
customerID,
).Scan(&cfg.CustomerID, &cfg.CustomerName, &cfg.Domain, &cfg.Email,
&cfg.RetrievalPassword, &cfg.APIKey, &cfg.ConfigJSON, &cfg.Status,
&cfg.RetrievalPassword, &cfg.APIKey, &cfg.ConfigJSON, &cfg.Status, &cfg.MinControllerVersion,
&createdAt, &updatedAt)
if err == sql.ErrNoRows {
return nil, nil
@@ -736,7 +770,7 @@ func (s *Store) GetCustomerConfig(customerID string) (*CustomerConfig, error) {
func (s *Store) ListCustomerConfigs() ([]CustomerConfig, error) {
rows, err := s.db.Query(`
SELECT customer_id, customer_name, domain, email,
retrieval_password, api_key, config_json, status, created_at, updated_at
retrieval_password, api_key, config_json, status, min_controller_version, created_at, updated_at
FROM customer_configs ORDER BY customer_id`)
if err != nil {
return nil, err
@@ -748,7 +782,7 @@ func (s *Store) ListCustomerConfigs() ([]CustomerConfig, error) {
var cfg CustomerConfig
var createdAt, updatedAt string
if err := rows.Scan(&cfg.CustomerID, &cfg.CustomerName, &cfg.Domain, &cfg.Email,
&cfg.RetrievalPassword, &cfg.APIKey, &cfg.ConfigJSON, &cfg.Status,
&cfg.RetrievalPassword, &cfg.APIKey, &cfg.ConfigJSON, &cfg.Status, &cfg.MinControllerVersion,
&createdAt, &updatedAt); err != nil {
return nil, err
}
@@ -772,11 +806,11 @@ func (s *Store) GetCustomerConfigByAPIKey(apiKey string) (*CustomerConfig, error
var createdAt, updatedAt string
err := s.db.QueryRow(`
SELECT customer_id, customer_name, domain, email,
retrieval_password, api_key, config_json, status, created_at, updated_at
retrieval_password, api_key, config_json, status, min_controller_version, created_at, updated_at
FROM customer_configs WHERE api_key = ?`,
apiKey,
).Scan(&cfg.CustomerID, &cfg.CustomerName, &cfg.Domain, &cfg.Email,
&cfg.RetrievalPassword, &cfg.APIKey, &cfg.ConfigJSON, &cfg.Status,
&cfg.RetrievalPassword, &cfg.APIKey, &cfg.ConfigJSON, &cfg.Status, &cfg.MinControllerVersion,
&createdAt, &updatedAt)
if err == sql.ErrNoRows {
return nil, nil
@@ -799,6 +833,52 @@ func (s *Store) SetCustomerConfigStatus(customerID, status string) error {
return err
}
// SetMinControllerVersion sets (or clears, with "") the per-customer controller-version floor
// override. The customer config must already exist.
func (s *Store) SetMinControllerVersion(customerID, version string) error {
_, err := s.db.Exec(`
UPDATE customer_configs SET min_controller_version = ?, updated_at = datetime('now')
WHERE customer_id = ?`,
version, customerID,
)
return err
}
// GetGlobalMinControllerVersion returns the operator-set global floor from hub_settings if present,
// else the config/env-supplied default. Empty string = no global floor.
func (s *Store) GetGlobalMinControllerVersion() string {
var v string
err := s.db.QueryRow(`SELECT value FROM hub_settings WHERE key = 'min_controller_version'`).Scan(&v)
if err == nil && v != "" {
return v
}
// No DB override (missing row or empty value) → fall back to the config/env default.
return s.defaultMinControllerVersion
}
// SetGlobalMinControllerVersion persists the operator-set global floor (overriding the config/env
// default). Pass "" to clear the override and fall back to the default.
func (s *Store) SetGlobalMinControllerVersion(version string) error {
_, err := s.db.Exec(`
INSERT INTO hub_settings (key, value, updated_at)
VALUES ('min_controller_version', ?, datetime('now'))
ON CONFLICT(key) DO UPDATE SET value = excluded.value, updated_at = datetime('now')`,
version,
)
return err
}
// EffectiveMinControllerVersion resolves the floor that actually applies to a customer: the
// per-customer override when set (non-empty), otherwise the global floor (hub_settings → config/env
// default). Returns "" when no floor applies at all (Phase 2 inert for that customer).
func (s *Store) EffectiveMinControllerVersion(customerID string) string {
cfg, err := s.GetCustomerConfig(customerID)
if err == nil && cfg != nil && cfg.MinControllerVersion != "" {
return cfg.MinControllerVersion
}
return s.GetGlobalMinControllerVersion()
}
// IsCustomerBlocked returns true if the customer config has status "blocked".
func (s *Store) IsCustomerBlocked(customerID string) bool {
var status string
+119 -8
View File
@@ -19,6 +19,24 @@ import (
var validCustomerID = regexp.MustCompile(`^[a-zA-Z0-9.\-]+$`)
// validSemver matches a bare X.Y.Z controller version (the floor format). Empty is also accepted by
// the floor handlers (clears the override).
var validSemver = regexp.MustCompile(`^\d+\.\d+\.\d+$`)
// normalizeFloorInput trims, strips a leading "v", and validates a floor version submitted from the
// operator UI. Returns (value, true) on a valid bare semver or empty string; (_, false) otherwise.
func normalizeFloorInput(raw string) (string, bool) {
v := strings.TrimSpace(raw)
v = strings.TrimPrefix(v, "v")
if v == "" {
return "", true
}
if !validSemver.MatchString(v) {
return "", false
}
return v, true
}
// customerListEntry is a merged view of a customer from both configs and reports.
type customerListEntry struct {
CustomerID string
@@ -30,6 +48,11 @@ type customerListEntry struct {
ControllerVersion string
TimeSinceReport time.Duration
ConfigCreatedAt time.Time
// Phase 2 managed-update floor
FloorOverride string // per-customer override ("" = none)
EffectiveFloor string // override else global ("" = no floor)
BelowFloor bool // current < effective floor (would auto-update)
}
// handleConfigList shows all customers (merged from configs + reports).
@@ -59,6 +82,7 @@ func (s *Server) handleConfigList(w http.ResponseWriter, r *http.Request) {
HasConfig: true,
IsBlocked: cfg.Status == "blocked",
ConfigCreatedAt: cfg.CreatedAt,
FloorOverride: cfg.MinControllerVersion,
}
}
@@ -94,6 +118,18 @@ func (s *Server) handleConfigList(w http.ResponseWriter, r *http.Request) {
}
}
// Phase 2 floor: resolve each customer's effective floor (override else global) + below-floor flag.
globalFloor := s.store.GetGlobalMinControllerVersion()
for _, e := range merged {
e.EffectiveFloor = e.FloorOverride
if e.EffectiveFloor == "" {
e.EffectiveFloor = globalFloor
}
if e.EffectiveFloor != "" && e.ControllerVersion != "" {
e.BelowFloor = compareVersions(e.EffectiveFloor, e.ControllerVersion) > 0
}
}
// Sort by customer_id
entries := make([]customerListEntry, 0, len(merged))
for _, e := range merged {
@@ -104,15 +140,19 @@ func (s *Server) handleConfigList(w http.ResponseWriter, r *http.Request) {
})
data := struct {
Customers []customerListEntry
ActiveNav string
Flash string
CSRFToken string
Customers []customerListEntry
GlobalFloor string
ActiveNav string
Flash string
CSRFToken string
CSRFField template.HTML
}{
Customers: entries,
ActiveNav: "configs",
Flash: r.URL.Query().Get("flash"),
CSRFToken: s.csrfToken(r),
Customers: entries,
GlobalFloor: globalFloor,
ActiveNav: "configs",
Flash: r.URL.Query().Get("flash"),
CSRFToken: s.csrfToken(r),
CSRFField: s.csrfField(r),
}
s.templates.ExecuteTemplate(w, "configs.html", data)
}
@@ -203,6 +243,19 @@ func (s *Server) handleCustomerUnified(w http.ResponseWriter, r *http.Request, c
}
}
// Phase 2 managed-update floor: per-customer override, the global default, the effective floor, and
// whether the box is currently below it (i.e. would auto-update on its next report).
floorOverride := ""
if cfg != nil {
floorOverride = cfg.MinControllerVersion
}
globalFloor := s.store.GetGlobalMinControllerVersion()
effectiveFloor := s.store.EffectiveMinControllerVersion(customerID)
belowFloor := false
if effectiveFloor != "" && customer != nil && customer.ControllerVersion != "" {
belowFloor = compareVersions(effectiveFloor, customer.ControllerVersion) > 0
}
// History, notifications, events
var history []store.CustomerSummary
var notifPrefs *store.NotificationPrefs
@@ -241,6 +294,12 @@ func (s *Server) handleCustomerUnified(w http.ResponseWriter, r *http.Request, c
UpdateAvailable bool
ControllerURL string
// Phase 2 managed-update floor controls
FloorOverride string // per-customer override ("" = none)
GlobalFloor string // global default (hub_settings → config/env)
EffectiveFloor string // override else global ("" = no floor)
BelowFloor bool // current < effective floor (would auto-update)
ConfigSyncStatus string // "in_sync", "mismatch", "unknown"
ConfigDiffCount int
@@ -296,6 +355,11 @@ func (s *Server) handleCustomerUnified(w http.ResponseWriter, r *http.Request, c
UpdateAvailable: updateAvailable,
ControllerURL: controllerURL,
FloorOverride: floorOverride,
GlobalFloor: globalFloor,
EffectiveFloor: effectiveFloor,
BelowFloor: belowFloor,
ConfigSyncStatus: configSyncStatus,
ConfigDiffCount: configDiffCount,
@@ -551,6 +615,53 @@ func (s *Server) handleUnblockCustomer(w http.ResponseWriter, r *http.Request, c
http.Redirect(w, r, "/customers/"+customerID+"?flash=unblocked", http.StatusSeeOther)
}
// handleSetGlobalFloor sets (or clears) the global controller-version floor (Phase 2 managed
// updates). Empty clears the hub_settings override, falling back to the config/env default.
func (s *Server) handleSetGlobalFloor(w http.ResponseWriter, r *http.Request) {
if err := r.ParseForm(); err != nil {
http.Error(w, "Bad request", http.StatusBadRequest)
return
}
v, ok := normalizeFloorInput(r.FormValue("min_controller_version"))
if !ok {
http.Redirect(w, r, "/configs?flash=floor_invalid", http.StatusSeeOther)
return
}
if err := s.store.SetGlobalMinControllerVersion(v); err != nil {
s.logger.Printf("[ERROR] Failed to set global floor: %v", err)
http.Error(w, "Internal error", http.StatusInternalServerError)
return
}
s.logger.Printf("[INFO] Global controller-version floor set to %q", v)
http.Redirect(w, r, "/configs?flash=floor_set", http.StatusSeeOther)
}
// handleSetCustomerFloor sets (or clears) a customer's per-customer controller-version floor
// override. Empty clears the override (the customer then uses the global floor).
func (s *Server) handleSetCustomerFloor(w http.ResponseWriter, r *http.Request, customerID string) {
cfg, err := s.store.GetCustomerConfig(customerID)
if err != nil || cfg == nil {
http.NotFound(w, r)
return
}
if err := r.ParseForm(); err != nil {
http.Error(w, "Bad request", http.StatusBadRequest)
return
}
v, ok := normalizeFloorInput(r.FormValue("min_controller_version"))
if !ok {
http.Redirect(w, r, "/customers/"+customerID+"?flash=floor_invalid", http.StatusSeeOther)
return
}
if err := s.store.SetMinControllerVersion(customerID, v); err != nil {
s.logger.Printf("[ERROR] Failed to set floor for %s: %v", customerID, err)
http.Error(w, "Internal error", http.StatusInternalServerError)
return
}
s.logger.Printf("[INFO] Customer %s controller-version floor override set to %q", customerID, v)
http.Redirect(w, r, "/customers/"+customerID+"?flash=floor_set", http.StatusSeeOther)
}
// handlePushConfig sends the generated YAML config to the controller.
func (s *Server) handlePushConfig(w http.ResponseWriter, r *http.Request, customerID string) {
cfg, err := s.store.GetCustomerConfig(customerID)
+47
View File
@@ -0,0 +1,47 @@
package web
import (
"bytes"
"io"
"log"
"path/filepath"
"testing"
"time"
"gitea.dooplex.hu/admin/felhom-hub/internal/store"
)
// Catches template SYNTAX errors (template.Must in New panics) and that the floor fields render on the
// two edited pages. Field-level execution errors surface as a non-nil ExecuteTemplate error.
func TestTemplates_FloorRender(t *testing.T) {
st, err := store.New(filepath.Join(t.TempDir(), "t.db"), log.New(io.Discard, "", 0))
if err != nil {
t.Fatalf("store.New: %v", err)
}
t.Cleanup(func() { st.Close() })
s := New(st, "", "", "test", time.Hour, log.New(io.Discard, "", 0)) // template.Must runs here
// configs.html — the list page data shape used by handleConfigList.
cfgData := struct {
Customers []customerListEntry
GlobalFloor string
ActiveNav string
Flash string
CSRFToken string
CSRFField string
}{
Customers: []customerListEntry{{
CustomerID: "c", EffectiveFloor: "0.87.0", FloorOverride: "0.87.0", BelowFloor: true,
ControllerVersion: "0.86.0", HasConfig: true,
}},
GlobalFloor: "0.86.0",
ActiveNav: "configs",
}
var buf bytes.Buffer
if err := s.templates.ExecuteTemplate(&buf, "configs.html", cfgData); err != nil {
t.Fatalf("render configs.html: %v", err)
}
if !bytes.Contains(buf.Bytes(), []byte("0.87.0")) || !bytes.Contains(buf.Bytes(), []byte("global floor")) {
t.Errorf("configs.html missing floor content")
}
}
+14
View File
@@ -230,6 +230,14 @@ func (s *Server) ServeHTTP(w http.ResponseWriter, r *http.Request) {
} else {
http.Error(w, "Method not allowed", http.StatusMethodNotAllowed)
}
case strings.HasPrefix(path, "/customers/") && strings.HasSuffix(path, "/floor"):
customerID := strings.TrimPrefix(path, "/customers/")
customerID = strings.TrimSuffix(customerID, "/floor")
if r.Method == http.MethodPost {
s.handleSetCustomerFloor(w, r, customerID)
} else {
http.Error(w, "Method not allowed", http.StatusMethodNotAllowed)
}
case strings.HasPrefix(path, "/customers/") && strings.HasSuffix(path, "/create-config"):
customerID := strings.TrimPrefix(path, "/customers/")
customerID = strings.TrimSuffix(customerID, "/create-config")
@@ -254,6 +262,12 @@ func (s *Server) ServeHTTP(w http.ResponseWriter, r *http.Request) {
} else {
s.handleConfigNewForm(w, r)
}
case path == "/configs/global-floor":
if r.Method == http.MethodPost {
s.handleSetGlobalFloor(w, r)
} else {
http.Error(w, "Method not allowed", http.StatusMethodNotAllowed)
}
case strings.HasPrefix(path, "/configs/") && strings.HasSuffix(path, "/delete"):
customerID := strings.TrimPrefix(path, "/configs/")
customerID = strings.TrimSuffix(customerID, "/delete")
+24 -1
View File
@@ -20,10 +20,28 @@
{{if .Flash}}
<div class="flash flash-success">
{{if eq .Flash "deleted"}}Customer configuration deleted.{{end}}
{{if eq .Flash "deleted"}}Customer configuration deleted.
{{else if eq .Flash "floor_set"}}Controller-version floor saved.
{{else if eq .Flash "floor_invalid"}}Invalid version — use X.Y.Z (or blank to clear).
{{end}}
</div>
{{end}}
<!-- Phase 2 managed updates: global controller-version floor -->
<div class="card" style="margin-bottom: 1rem; padding: 1rem; border: 1px solid #334155; border-radius: 8px;">
<h2 style="margin: 0 0 0.5rem;">Managed updates — global floor</h2>
<p style="font-size: 0.85em; color: #94a3b8; margin: 0 0 0.5rem;">
The minimum controller version every box auto-updates to (unless a per-customer override is set).
Boxes below the floor update on their next report — no customer action. Blank = no global floor.
</p>
<form method="POST" action="/configs/global-floor" style="display: flex; gap: 0.5rem; align-items: center; flex-wrap: wrap;">
{{.CSRFField}}
<input type="text" name="min_controller_version" value="{{.GlobalFloor}}" placeholder="e.g. 0.86.0 (blank = none)" style="padding: 0.3em 0.5em; width: 14em;">
<button class="btn btn-sm" type="submit">Save global floor</button>
<span style="font-size: 0.85em; color: #cbd5e1;">Current: {{if .GlobalFloor}}<code>v{{.GlobalFloor}}</code>{{else}}<span class="text-muted">unset</span>{{end}}</span>
</form>
</div>
<div style="display: flex; justify-content: space-between; align-items: center; margin-bottom: 1rem;">
<h2 style="margin: 0;">Customers</h2>
<a href="/configs/new" class="btn">+ Add Customer</a>
@@ -43,6 +61,7 @@
<th>Domain</th>
<th>Status</th>
<th>Version</th>
<th>Floor</th>
<th>Config</th>
</tr>
</thead>
@@ -64,6 +83,10 @@
{{end}}
</td>
<td>{{if .ControllerVersion}}<code>{{.ControllerVersion}}</code>{{else}}<span class="text-muted"></span>{{end}}</td>
<td>
{{if .EffectiveFloor}}<code>v{{.EffectiveFloor}}</code>{{if .FloorOverride}}<span class="text-muted" style="font-size:0.8em;"> (override)</span>{{end}}{{if .BelowFloor}}<span style="color:#f59e0b;" title="below floor — will auto-update"></span>{{end}}
{{else}}<span class="text-muted"></span>{{end}}
</td>
<td>
{{if .HasConfig}}
<span class="config-badge config-badge-managed">MANAGED</span>
@@ -433,6 +433,30 @@
</div>
{{end}}
</div>
<!-- Phase 2 managed-update floor (operator-enforced minimum) -->
<div class="info-grid" style="margin-top: 0.75rem; border-top: 1px solid #334155; padding-top: 0.75rem;">
<div class="info-item">
<span class="label">Effective floor (min. version)</span>
<span class="value">
{{if .EffectiveFloor}}v{{.EffectiveFloor}}
{{if .BelowFloor}}<span style="color: #f59e0b; margin-left: 0.3em;">● below floor — will auto-update</span>
{{else}}<span style="color: #94a3b8; margin-left: 0.3em;">— at/above floor</span>{{end}}
{{else}}<span style="color: #94a3b8;">none (Phase 2 inert)</span>{{end}}
</span>
</div>
<div class="info-item">
<span class="label">Global floor</span>
<span class="value">{{if .GlobalFloor}}v{{.GlobalFloor}}{{else}}<span style="color: #94a3b8;">unset</span>{{end}}</span>
</div>
</div>
<form method="POST" action="/customers/{{.CustomerID}}/floor" style="margin-top: 0.5rem; display: flex; gap: 0.5rem; align-items: center; flex-wrap: wrap;">
{{.CSRFField}}
<label style="font-size: 0.85em; color: #cbd5e1;">Per-customer override</label>
<input type="text" name="min_controller_version" value="{{.FloorOverride}}" placeholder="e.g. 0.87.0 (blank = use global)" style="padding: 0.3em 0.5em; font-size: 0.85em; width: 14em;">
<button class="btn btn-outline btn-sm" type="submit">Save floor</button>
<span style="font-size: 0.8em; color: #94a3b8;">Boxes below the effective floor auto-update on their next report. Blank clears the override.</span>
</form>
{{if and .HasConfig .ConfigSyncStatus}}
<div class="info-item" style="margin-top: 0.5rem;">
<span class="label">Config Sync</span>