api-router.go 19 KB


  1. package router
  2. import (
  3. "github.com/QuantumNous/new-api/controller"
  4. "github.com/QuantumNous/new-api/middleware"
  5. // Import oauth package to register providers via init()
  6. _ "github.com/QuantumNous/new-api/oauth"
  7. "github.com/gin-contrib/gzip"
  8. "github.com/gin-gonic/gin"
  9. )
  10. func SetApiRouter(router *gin.Engine) {
  11. apiRouter := router.Group("/api")
  12. apiRouter.Use(gzip.Gzip(gzip.DefaultCompression))
  13. apiRouter.Use(middleware.BodyStorageCleanup()) // 清理请求体存储
  14. apiRouter.Use(middleware.GlobalAPIRateLimit())
  15. {
  16. apiRouter.GET("/setup", controller.GetSetup)
  17. apiRouter.POST("/setup", controller.PostSetup)
  18. apiRouter.GET("/status", controller.GetStatus)
  19. apiRouter.GET("/uptime/status", controller.GetUptimeKumaStatus)
  20. apiRouter.GET("/models", middleware.UserAuth(), controller.DashboardListModels)
  21. apiRouter.GET("/status/test", middleware.AdminAuth(), controller.TestStatus)
  22. apiRouter.GET("/notice", controller.GetNotice)
  23. apiRouter.GET("/user-agreement", controller.GetUserAgreement)
  24. apiRouter.GET("/privacy-policy", controller.GetPrivacyPolicy)
  25. apiRouter.GET("/about", controller.GetAbout)
  26. //apiRouter.GET("/midjourney", controller.GetMidjourney)
  27. apiRouter.GET("/home_page_content", controller.GetHomePageContent)
  28. apiRouter.GET("/pricing", middleware.TryUserAuth(), controller.GetPricing)
  29. apiRouter.GET("/verification", middleware.EmailVerificationRateLimit(), middleware.TurnstileCheck(), controller.SendEmailVerification)
  30. apiRouter.GET("/reset_password", middleware.CriticalRateLimit(), middleware.TurnstileCheck(), controller.SendPasswordResetEmail)
  31. apiRouter.POST("/user/reset", middleware.CriticalRateLimit(), controller.ResetPassword)
  32. // OAuth routes - specific routes must come before :provider wildcard
  33. apiRouter.GET("/oauth/state", middleware.CriticalRateLimit(), controller.GenerateOAuthCode)
  34. apiRouter.GET("/oauth/email/bind", middleware.CriticalRateLimit(), controller.EmailBind)
  35. // Non-standard OAuth (WeChat, Telegram) - keep original routes
  36. apiRouter.GET("/oauth/wechat", middleware.CriticalRateLimit(), controller.WeChatAuth)
  37. apiRouter.GET("/oauth/wechat/bind", middleware.CriticalRateLimit(), controller.WeChatBind)
  38. apiRouter.GET("/oauth/telegram/login", middleware.CriticalRateLimit(), controller.TelegramLogin)
  39. apiRouter.GET("/oauth/telegram/bind", middleware.CriticalRateLimit(), controller.TelegramBind)
  40. // Standard OAuth providers (GitHub, Discord, OIDC, LinuxDO) - unified route
  41. apiRouter.GET("/oauth/:provider", middleware.CriticalRateLimit(), controller.HandleOAuth)
  42. apiRouter.GET("/ratio_config", middleware.CriticalRateLimit(), controller.GetRatioConfig)
  43. apiRouter.POST("/stripe/webhook", controller.StripeWebhook)
  44. apiRouter.POST("/creem/webhook", controller.CreemWebhook)
  45. // Universal secure verification routes
  46. apiRouter.POST("/verify", middleware.UserAuth(), middleware.CriticalRateLimit(), controller.UniversalVerify)
  47. userRoute := apiRouter.Group("/user")
  48. {
  49. userRoute.POST("/register", middleware.CriticalRateLimit(), middleware.TurnstileCheck(), controller.Register)
  50. userRoute.POST("/login", middleware.CriticalRateLimit(), middleware.TurnstileCheck(), controller.Login)
  51. userRoute.POST("/login/2fa", middleware.CriticalRateLimit(), controller.Verify2FALogin)
  52. userRoute.POST("/passkey/login/begin", middleware.CriticalRateLimit(), controller.PasskeyLoginBegin)
  53. userRoute.POST("/passkey/login/finish", middleware.CriticalRateLimit(), controller.PasskeyLoginFinish)
  54. //userRoute.POST("/tokenlog", middleware.CriticalRateLimit(), controller.TokenLog)
  55. userRoute.GET("/logout", controller.Logout)
  56. userRoute.POST("/epay/notify", controller.EpayNotify)
  57. userRoute.GET("/epay/notify", controller.EpayNotify)
  58. userRoute.GET("/groups", controller.GetUserGroups)
  59. selfRoute := userRoute.Group("/")
  60. selfRoute.Use(middleware.UserAuth())
  61. {
  62. selfRoute.GET("/self/groups", controller.GetUserGroups)
  63. selfRoute.GET("/self", controller.GetSelf)
  64. selfRoute.GET("/models", controller.GetUserModels)
  65. selfRoute.PUT("/self", controller.UpdateSelf)
  66. selfRoute.DELETE("/self", controller.DeleteSelf)
  67. selfRoute.GET("/token", controller.GenerateAccessToken)
  68. selfRoute.GET("/passkey", controller.PasskeyStatus)
  69. selfRoute.POST("/passkey/register/begin", controller.PasskeyRegisterBegin)
  70. selfRoute.POST("/passkey/register/finish", controller.PasskeyRegisterFinish)
  71. selfRoute.POST("/passkey/verify/begin", controller.PasskeyVerifyBegin)
  72. selfRoute.POST("/passkey/verify/finish", controller.PasskeyVerifyFinish)
  73. selfRoute.DELETE("/passkey", controller.PasskeyDelete)
  74. selfRoute.GET("/aff", controller.GetAffCode)
  75. selfRoute.GET("/topup/info", controller.GetTopUpInfo)
  76. selfRoute.GET("/topup/self", controller.GetUserTopUps)
  77. selfRoute.POST("/topup", middleware.CriticalRateLimit(), controller.TopUp)
  78. selfRoute.POST("/pay", middleware.CriticalRateLimit(), controller.RequestEpay)
  79. selfRoute.POST("/amount", controller.RequestAmount)
  80. selfRoute.POST("/stripe/pay", middleware.CriticalRateLimit(), controller.RequestStripePay)
  81. selfRoute.POST("/stripe/amount", controller.RequestStripeAmount)
  82. selfRoute.POST("/creem/pay", middleware.CriticalRateLimit(), controller.RequestCreemPay)
  83. selfRoute.POST("/aff_transfer", controller.TransferAffQuota)
  84. selfRoute.PUT("/setting", controller.UpdateUserSetting)
  85. // 2FA routes
  86. selfRoute.GET("/2fa/status", controller.Get2FAStatus)
  87. selfRoute.POST("/2fa/setup", controller.Setup2FA)
  88. selfRoute.POST("/2fa/enable", controller.Enable2FA)
  89. selfRoute.POST("/2fa/disable", controller.Disable2FA)
  90. selfRoute.POST("/2fa/backup_codes", controller.RegenerateBackupCodes)
  91. // Check-in routes
  92. selfRoute.GET("/checkin", controller.GetCheckinStatus)
  93. selfRoute.POST("/checkin", middleware.TurnstileCheck(), controller.DoCheckin)
  94. // Custom OAuth bindings
  95. selfRoute.GET("/oauth/bindings", controller.GetUserOAuthBindings)
  96. selfRoute.DELETE("/oauth/bindings/:provider_id", controller.UnbindCustomOAuth)
  97. }
  98. adminRoute := userRoute.Group("/")
  99. adminRoute.Use(middleware.AdminAuth())
  100. {
  101. adminRoute.GET("/", controller.GetAllUsers)
  102. adminRoute.GET("/topup", controller.GetAllTopUps)
  103. adminRoute.POST("/topup/complete", controller.AdminCompleteTopUp)
  104. adminRoute.GET("/search", controller.SearchUsers)
  105. adminRoute.GET("/:id", controller.GetUser)
  106. adminRoute.POST("/", controller.CreateUser)
  107. adminRoute.POST("/manage", controller.ManageUser)
  108. adminRoute.PUT("/", controller.UpdateUser)
  109. adminRoute.DELETE("/:id", controller.DeleteUser)
  110. adminRoute.DELETE("/:id/reset_passkey", controller.AdminResetPasskey)
  111. // Admin 2FA routes
  112. adminRoute.GET("/2fa/stats", controller.Admin2FAStats)
  113. adminRoute.DELETE("/:id/2fa", controller.AdminDisable2FA)
  114. }
  115. }
  116. // Subscription billing (plans, purchase, admin management)
  117. subscriptionRoute := apiRouter.Group("/subscription")
  118. subscriptionRoute.Use(middleware.UserAuth())
  119. {
  120. subscriptionRoute.GET("/plans", controller.GetSubscriptionPlans)
  121. subscriptionRoute.GET("/self", controller.GetSubscriptionSelf)
  122. subscriptionRoute.PUT("/self/preference", controller.UpdateSubscriptionPreference)
  123. subscriptionRoute.POST("/epay/pay", middleware.CriticalRateLimit(), controller.SubscriptionRequestEpay)
  124. subscriptionRoute.POST("/stripe/pay", middleware.CriticalRateLimit(), controller.SubscriptionRequestStripePay)
  125. subscriptionRoute.POST("/creem/pay", middleware.CriticalRateLimit(), controller.SubscriptionRequestCreemPay)
  126. }
  127. subscriptionAdminRoute := apiRouter.Group("/subscription/admin")
  128. subscriptionAdminRoute.Use(middleware.AdminAuth())
  129. {
  130. subscriptionAdminRoute.GET("/plans", controller.AdminListSubscriptionPlans)
  131. subscriptionAdminRoute.POST("/plans", controller.AdminCreateSubscriptionPlan)
  132. subscriptionAdminRoute.PUT("/plans/:id", controller.AdminUpdateSubscriptionPlan)
  133. subscriptionAdminRoute.PATCH("/plans/:id", controller.AdminUpdateSubscriptionPlanStatus)
  134. subscriptionAdminRoute.POST("/bind", controller.AdminBindSubscription)
  135. // User subscription management (admin)
  136. subscriptionAdminRoute.GET("/users/:id/subscriptions", controller.AdminListUserSubscriptions)
  137. subscriptionAdminRoute.POST("/users/:id/subscriptions", controller.AdminCreateUserSubscription)
  138. subscriptionAdminRoute.POST("/user_subscriptions/:id/invalidate", controller.AdminInvalidateUserSubscription)
  139. subscriptionAdminRoute.DELETE("/user_subscriptions/:id", controller.AdminDeleteUserSubscription)
  140. }
  141. // Subscription payment callbacks (no auth)
  142. apiRouter.POST("/subscription/epay/notify", controller.SubscriptionEpayNotify)
  143. apiRouter.GET("/subscription/epay/notify", controller.SubscriptionEpayNotify)
  144. apiRouter.GET("/subscription/epay/return", controller.SubscriptionEpayReturn)
  145. apiRouter.POST("/subscription/epay/return", controller.SubscriptionEpayReturn)
  146. optionRoute := apiRouter.Group("/option")
  147. optionRoute.Use(middleware.RootAuth())
  148. {
  149. optionRoute.GET("/", controller.GetOptions)
  150. optionRoute.PUT("/", controller.UpdateOption)
  151. optionRoute.GET("/channel_affinity_cache", controller.GetChannelAffinityCacheStats)
  152. optionRoute.DELETE("/channel_affinity_cache", controller.ClearChannelAffinityCache)
  153. optionRoute.POST("/rest_model_ratio", controller.ResetModelRatio)
  154. optionRoute.POST("/migrate_console_setting", controller.MigrateConsoleSetting) // 用于迁移检测的旧键,下个版本会删除
  155. }
  156. // Custom OAuth provider management (admin only)
  157. customOAuthRoute := apiRouter.Group("/custom-oauth-provider")
  158. customOAuthRoute.Use(middleware.RootAuth())
  159. {
  160. customOAuthRoute.GET("/", controller.GetCustomOAuthProviders)
  161. customOAuthRoute.GET("/:id", controller.GetCustomOAuthProvider)
  162. customOAuthRoute.POST("/", controller.CreateCustomOAuthProvider)
  163. customOAuthRoute.PUT("/:id", controller.UpdateCustomOAuthProvider)
  164. customOAuthRoute.DELETE("/:id", controller.DeleteCustomOAuthProvider)
  165. }
  166. performanceRoute := apiRouter.Group("/performance")
  167. performanceRoute.Use(middleware.RootAuth())
  168. {
  169. performanceRoute.GET("/stats", controller.GetPerformanceStats)
  170. performanceRoute.DELETE("/disk_cache", controller.ClearDiskCache)
  171. performanceRoute.POST("/reset_stats", controller.ResetPerformanceStats)
  172. performanceRoute.POST("/gc", controller.ForceGC)
  173. }
  174. ratioSyncRoute := apiRouter.Group("/ratio_sync")
  175. ratioSyncRoute.Use(middleware.RootAuth())
  176. {
  177. ratioSyncRoute.GET("/channels", controller.GetSyncableChannels)
  178. ratioSyncRoute.POST("/fetch", controller.FetchUpstreamRatios)
  179. }
  180. channelRoute := apiRouter.Group("/channel")
  181. channelRoute.Use(middleware.AdminAuth())
  182. {
  183. channelRoute.GET("/", controller.GetAllChannels)
  184. channelRoute.GET("/search", controller.SearchChannels)
  185. channelRoute.GET("/models", controller.ChannelListModels)
  186. channelRoute.GET("/models_enabled", controller.EnabledListModels)
  187. channelRoute.GET("/:id", controller.GetChannel)
  188. channelRoute.POST("/:id/key", middleware.RootAuth(), middleware.CriticalRateLimit(), middleware.DisableCache(), middleware.SecureVerificationRequired(), controller.GetChannelKey)
  189. channelRoute.GET("/test", controller.TestAllChannels)
  190. channelRoute.GET("/test/:id", controller.TestChannel)
  191. channelRoute.GET("/update_balance", controller.UpdateAllChannelsBalance)
  192. channelRoute.GET("/update_balance/:id", controller.UpdateChannelBalance)
  193. channelRoute.POST("/", controller.AddChannel)
  194. channelRoute.PUT("/", controller.UpdateChannel)
  195. channelRoute.DELETE("/disabled", controller.DeleteDisabledChannel)
  196. channelRoute.POST("/tag/disabled", controller.DisableTagChannels)
  197. channelRoute.POST("/tag/enabled", controller.EnableTagChannels)
  198. channelRoute.PUT("/tag", controller.EditTagChannels)
  199. channelRoute.DELETE("/:id", controller.DeleteChannel)
  200. channelRoute.POST("/batch", controller.DeleteChannelBatch)
  201. channelRoute.POST("/fix", controller.FixChannelsAbilities)
  202. channelRoute.GET("/fetch_models/:id", controller.FetchUpstreamModels)
  203. channelRoute.POST("/fetch_models", controller.FetchModels)
  204. channelRoute.POST("/codex/oauth/start", controller.StartCodexOAuth)
  205. channelRoute.POST("/codex/oauth/complete", controller.CompleteCodexOAuth)
  206. channelRoute.POST("/:id/codex/oauth/start", controller.StartCodexOAuthForChannel)
  207. channelRoute.POST("/:id/codex/oauth/complete", controller.CompleteCodexOAuthForChannel)
  208. channelRoute.POST("/:id/codex/refresh", controller.RefreshCodexChannelCredential)
  209. channelRoute.GET("/:id/codex/usage", controller.GetCodexChannelUsage)
  210. channelRoute.POST("/ollama/pull", controller.OllamaPullModel)
  211. channelRoute.POST("/ollama/pull/stream", controller.OllamaPullModelStream)
  212. channelRoute.DELETE("/ollama/delete", controller.OllamaDeleteModel)
  213. channelRoute.GET("/ollama/version/:id", controller.OllamaVersion)
  214. channelRoute.POST("/batch/tag", controller.BatchSetChannelTag)
  215. channelRoute.GET("/tag/models", controller.GetTagModels)
  216. channelRoute.POST("/copy/:id", controller.CopyChannel)
  217. channelRoute.POST("/multi_key/manage", controller.ManageMultiKeys)
  218. }
  219. tokenRoute := apiRouter.Group("/token")
  220. tokenRoute.Use(middleware.UserAuth())
  221. {
  222. tokenRoute.GET("/", controller.GetAllTokens)
  223. tokenRoute.GET("/search", middleware.SearchRateLimit(), controller.SearchTokens)
  224. tokenRoute.GET("/:id", controller.GetToken)
  225. tokenRoute.POST("/", controller.AddToken)
  226. tokenRoute.PUT("/", controller.UpdateToken)
  227. tokenRoute.DELETE("/:id", controller.DeleteToken)
  228. tokenRoute.POST("/batch", controller.DeleteTokenBatch)
  229. }
  230. usageRoute := apiRouter.Group("/usage")
  231. usageRoute.Use(middleware.CORS(), middleware.CriticalRateLimit())
  232. {
  233. tokenUsageRoute := usageRoute.Group("/token")
  234. tokenUsageRoute.Use(middleware.TokenAuthReadOnly())
  235. {
  236. tokenUsageRoute.GET("/", controller.GetTokenUsage)
  237. }
  238. }
  239. redemptionRoute := apiRouter.Group("/redemption")
  240. redemptionRoute.Use(middleware.AdminAuth())
  241. {
  242. redemptionRoute.GET("/", controller.GetAllRedemptions)
  243. redemptionRoute.GET("/search", controller.SearchRedemptions)
  244. redemptionRoute.GET("/:id", controller.GetRedemption)
  245. redemptionRoute.POST("/", controller.AddRedemption)
  246. redemptionRoute.PUT("/", controller.UpdateRedemption)
  247. redemptionRoute.DELETE("/invalid", controller.DeleteInvalidRedemption)
  248. redemptionRoute.DELETE("/:id", controller.DeleteRedemption)
  249. }
  250. logRoute := apiRouter.Group("/log")
  251. logRoute.GET("/", middleware.AdminAuth(), controller.GetAllLogs)
  252. logRoute.DELETE("/", middleware.AdminAuth(), controller.DeleteHistoryLogs)
  253. logRoute.GET("/stat", middleware.AdminAuth(), controller.GetLogsStat)
  254. logRoute.GET("/self/stat", middleware.UserAuth(), controller.GetLogsSelfStat)
  255. logRoute.GET("/channel_affinity_usage_cache", middleware.AdminAuth(), controller.GetChannelAffinityUsageCacheStats)
  256. logRoute.GET("/search", middleware.AdminAuth(), controller.SearchAllLogs)
  257. logRoute.GET("/self", middleware.UserAuth(), controller.GetUserLogs)
  258. logRoute.GET("/self/search", middleware.UserAuth(), middleware.SearchRateLimit(), controller.SearchUserLogs)
  259. dataRoute := apiRouter.Group("/data")
  260. dataRoute.GET("/", middleware.AdminAuth(), controller.GetAllQuotaDates)
  261. dataRoute.GET("/self", middleware.UserAuth(), controller.GetUserQuotaDates)
  262. logRoute.Use(middleware.CORS(), middleware.CriticalRateLimit())
  263. {
  264. logRoute.GET("/token", middleware.TokenAuthReadOnly(), controller.GetLogByKey)
  265. }
  266. groupRoute := apiRouter.Group("/group")
  267. groupRoute.Use(middleware.AdminAuth())
  268. {
  269. groupRoute.GET("/", controller.GetGroups)
  270. }
  271. prefillGroupRoute := apiRouter.Group("/prefill_group")
  272. prefillGroupRoute.Use(middleware.AdminAuth())
  273. {
  274. prefillGroupRoute.GET("/", controller.GetPrefillGroups)
  275. prefillGroupRoute.POST("/", controller.CreatePrefillGroup)
  276. prefillGroupRoute.PUT("/", controller.UpdatePrefillGroup)
  277. prefillGroupRoute.DELETE("/:id", controller.DeletePrefillGroup)
  278. }
  279. mjRoute := apiRouter.Group("/mj")
  280. mjRoute.GET("/self", middleware.UserAuth(), controller.GetUserMidjourney)
  281. mjRoute.GET("/", middleware.AdminAuth(), controller.GetAllMidjourney)
  282. taskRoute := apiRouter.Group("/task")
  283. {
  284. taskRoute.GET("/self", middleware.UserAuth(), controller.GetUserTask)
  285. taskRoute.GET("/", middleware.AdminAuth(), controller.GetAllTask)
  286. }
  287. vendorRoute := apiRouter.Group("/vendors")
  288. vendorRoute.Use(middleware.AdminAuth())
  289. {
  290. vendorRoute.GET("/", controller.GetAllVendors)
  291. vendorRoute.GET("/search", controller.SearchVendors)
  292. vendorRoute.GET("/:id", controller.GetVendorMeta)
  293. vendorRoute.POST("/", controller.CreateVendorMeta)
  294. vendorRoute.PUT("/", controller.UpdateVendorMeta)
  295. vendorRoute.DELETE("/:id", controller.DeleteVendorMeta)
  296. }
  297. modelsRoute := apiRouter.Group("/models")
  298. modelsRoute.Use(middleware.AdminAuth())
  299. {
  300. modelsRoute.GET("/sync_upstream/preview", controller.SyncUpstreamPreview)
  301. modelsRoute.POST("/sync_upstream", controller.SyncUpstreamModels)
  302. modelsRoute.GET("/missing", controller.GetMissingModels)
  303. modelsRoute.GET("/", controller.GetAllModelsMeta)
  304. modelsRoute.GET("/search", controller.SearchModelsMeta)
  305. modelsRoute.GET("/:id", controller.GetModelMeta)
  306. modelsRoute.POST("/", controller.CreateModelMeta)
  307. modelsRoute.PUT("/", controller.UpdateModelMeta)
  308. modelsRoute.DELETE("/:id", controller.DeleteModelMeta)
  309. }
  310. // Deployments (model deployment management)
  311. deploymentsRoute := apiRouter.Group("/deployments")
  312. deploymentsRoute.Use(middleware.AdminAuth())
  313. {
  314. deploymentsRoute.GET("/settings", controller.GetModelDeploymentSettings)
  315. deploymentsRoute.POST("/settings/test-connection", controller.TestIoNetConnection)
  316. deploymentsRoute.GET("/", controller.GetAllDeployments)
  317. deploymentsRoute.GET("/search", controller.SearchDeployments)
  318. deploymentsRoute.POST("/test-connection", controller.TestIoNetConnection)
  319. deploymentsRoute.GET("/hardware-types", controller.GetHardwareTypes)
  320. deploymentsRoute.GET("/locations", controller.GetLocations)
  321. deploymentsRoute.GET("/available-replicas", controller.GetAvailableReplicas)
  322. deploymentsRoute.POST("/price-estimation", controller.GetPriceEstimation)
  323. deploymentsRoute.GET("/check-name", controller.CheckClusterNameAvailability)
  324. deploymentsRoute.POST("/", controller.CreateDeployment)
  325. deploymentsRoute.GET("/:id", controller.GetDeployment)
  326. deploymentsRoute.GET("/:id/logs", controller.GetDeploymentLogs)
  327. deploymentsRoute.GET("/:id/containers", controller.ListDeploymentContainers)
  328. deploymentsRoute.GET("/:id/containers/:container_id", controller.GetContainerDetails)
  329. deploymentsRoute.PUT("/:id", controller.UpdateDeployment)
  330. deploymentsRoute.PUT("/:id/name", controller.UpdateDeploymentName)
  331. deploymentsRoute.POST("/:id/extend", controller.ExtendDeployment)
  332. deploymentsRoute.DELETE("/:id", controller.DeleteDeployment)
  333. }
  334. }
  335. }