package blog import ( "database/sql" "encoding/json" "fmt" "github.com/go-chi/chi" "github.com/go-chi/jwtauth" "github.com/go-chi/render" "github.com/gosimple/slug" "net/http" "strings" "time" ) var ( DB *sql.DB TokenAuth *jwtauth.JWTAuth ) type BlogPost struct { ID int `json:"id",db:"id"` Title string `json:"title",db:"title"` Slug string `json:"slug",db:"slug"` Author string `json:"author",db:"author"` Content string `json:"content",db:"content"` DatePublished time.Time `json:"date", db:"date"` Updated bool `json:"updated", db:"updated"` UpdateTime time.Time `json:"update_time", db:"update_time"` } type Tag struct { TagList string `json:"tags"` } type NewBlogPost struct { Title string `json:"title",db:"title"` Content string `json:"content",db:"content"` Tags string `json:"tags"` Author string `json:"author",db:"author"` } type ReturnError struct { Message string `json:"error"` } type ReturnSuccess struct { Message string `json:"success"` ID int `json:"id"` } func Init() { createPostsTable := ` CREATE TABLE IF NOT EXISTS posts (id SERIAL PRIMARY KEY, title text, slug text, author text REFERENCES users (username), content text, date timestamp, updated bool, update_time timestamp)` DB.Exec(createPostsTable) createTagsTable := ` CREATE TABLE IF NOT EXISTS tags (id SERIAL PRIMARY KEY, tag text, article_id int REFERENCES posts (id))` DB.Exec(createTagsTable) } func Routes() *chi.Mux { r := chi.NewRouter() r.Group(func(r chi.Router) { r.Use(jwtauth.Verifier(TokenAuth)) r.Use(jwtauth.Authenticator) r.Post("/", createBlogPost) r.Patch("/by-id/{id}", updateBlogPostById) }) r.Get("/", getBlogPosts) r.Get("/{slug}", getBlogPostBySlug) r.Get("/by-id/{id}", getBlogPostById) r.Get("/by-tag/{tag}", getBlogPostsByTag) r.Get("/by-author/{author}", getBlogPostsByAuthor) return r } func createBlogPost(w http.ResponseWriter, r *http.Request) { returnError := ReturnError{} newBlogPost := &NewBlogPost{} // basic checks _, claims, _ := jwtauth.FromContext(r.Context()) username := claims["username"].(string) err := json.NewDecoder(r.Body).Decode(newBlogPost) if err != nil { returnError.Message = "unknown error, try again later" w.WriteHeader(http.StatusBadRequest) return } if newBlogPost.Title == "" { returnError.Message = "title is required" w.WriteHeader(http.StatusBadRequest) render.JSON(w, r, returnError) return } if newBlogPost.Content == "" { returnError.Message = "content is required" w.WriteHeader(http.StatusBadRequest) render.JSON(w, r, returnError) return } as := slug.Make(newBlogPost.Title) slugCheck := DB.QueryRow("SELECT id FROM posts WHERE slug=$1", as) // wow this is ugly. someone pls send help. // checking to ensure the same slug doesn't exist... scr := 0 err = slugCheck.Scan(&scr) if err == nil { returnError.Message = "slug already exists" w.WriteHeader(http.StatusBadRequest) render.JSON(w, r, returnError) return } if err != nil { if err != sql.ErrNoRows { returnError.Message = "something is super broken..." w.WriteHeader(http.StatusInternalServerError) return } } s := `INSERT INTO posts (title, slug, author, content, date, updated, update_time) VALUES ($1, $2, $3, $4, $5, $6, $7) RETURNING id` article_id := 0 // write the row and get back the id err = DB.QueryRow(s, newBlogPost.Title, as, username, newBlogPost.Content, time.Now().UTC(), false, time.Now().UTC()).Scan(&article_id) if err != nil { if err == sql.ErrNoRows { returnError.Message = "something is super broken..." w.WriteHeader(http.StatusInternalServerError) render.JSON(w, r, returnError) return } returnError.Message = "something is super broken..." w.WriteHeader(http.StatusInternalServerError) render.JSON(w, r, returnError) return } // if the article has tags if newBlogPost.Tags != "" { t := `INSERT INTO tags (tag, article_id) VALUES ($1, $2)` tags := strings.Split(newBlogPost.Tags, ",") for i := range tags { DB.Exec(t, tags[i], article_id) } } returnSuccess := ReturnSuccess{Message: "post created", ID: article_id} w.WriteHeader(http.StatusCreated) render.JSON(w, r, returnSuccess) return } func updateBlogPostById(w http.ResponseWriter, r *http.Request) { returnError := ReturnError{} // Get the actual post id := chi.URLParam(r, "id") result := DB.QueryRow("SELECT id, title, slug, author, content, date FROM posts WHERE id=$1", id) post := BlogPost{} err := result.Scan(&post.ID, &post.Title, &post.Slug, &post.Author, &post.Content, &post.DatePublished) if err != nil { if err == sql.ErrNoRows { returnError.Message = "blog post requested for update not found" w.WriteHeader(http.StatusInternalServerError) render.JSON(w, r, returnError) return } returnError.Message = "something is super broken..." w.WriteHeader(http.StatusInternalServerError) render.JSON(w, r, returnError) return } // Verify the post belongs to the requester _, claims, _ := jwtauth.FromContext(r.Context()) username := claims["username"].(string) if username != post.Author { w.WriteHeader(http.StatusUnauthorized) return } // update the post struct err = json.NewDecoder(r.Body).Decode(&post) s := ` UPDATE posts SET title = $1, content = $2, updated = $3, update_time = $4 WHERE id = $5` // write the row update _, err = DB.Exec(s, post.Title, post.Content, true, time.Now().UTC(), post.ID) if err != nil { returnError.Message = "something is super broken..." w.WriteHeader(http.StatusInternalServerError) render.JSON(w, r, returnError) return } returnSuccess := ReturnSuccess{Message: "post updated", ID: post.ID} w.WriteHeader(http.StatusOK) render.JSON(w, r, returnSuccess) return } func getBlogPosts(w http.ResponseWriter, r *http.Request) { return } func getBlogPostBySlug(w http.ResponseWriter, r *http.Request) { returnError := ReturnError{} slug := chi.URLParam(r, "slug") result := DB.QueryRow("SELECT id, title, slug, author, content, date, updated, update_time FROM posts WHERE slug=$1", slug) post := BlogPost{} err := result.Scan(&post.ID, &post.Title, &post.Slug, &post.Author, &post.Content, &post.DatePublished, &post.Updated, &post.UpdateTime) if err != nil { fmt.Println(err) returnError.Message = "post not found" w.WriteHeader(http.StatusBadRequest) render.JSON(w, r, returnError) return } w.WriteHeader(http.StatusOK) render.JSON(w, r, post) return } func getBlogPostById(w http.ResponseWriter, r *http.Request) { returnError := ReturnError{} id := chi.URLParam(r, "id") result := DB.QueryRow("SELECT id, title, slug, author, content, date, updated, update_time FROM posts WHERE id=$1", id) post := BlogPost{} err := result.Scan(&post.ID, &post.Title, &post.Slug, &post.Author, &post.Content, &post.DatePublished, &post.Updated, &post.UpdateTime) if err != nil { fmt.Println(err) returnError.Message = "post not found" w.WriteHeader(http.StatusBadRequest) render.JSON(w, r, returnError) return } w.WriteHeader(http.StatusOK) render.JSON(w, r, post) return } func getBlogPostsByTag(w http.ResponseWriter, r *http.Request) { return } func getBlogPostsByAuthor(w http.ResponseWriter, r *http.Request) { return } func getRssFeed(w http.ResponseWriter, r *http.Request) { return }