package middleware import ( "bufio" "bytes" "mime" "net" "net/http" "path/filepath" "strconv" "strings" swaggerFiles "github.com/swaggo/files" "github.com/gin-gonic/gin" ) func SwaggerHandler() gin.HandlerFunc { return func(c *gin.Context) { rawPath := c.Request.URL.Path relPath := strings.TrimPrefix(rawPath, "/swagger") if relPath == "" || relPath == "/" { relPath = "/index.html" } c.Request.URL.Path = relPath defer func() { c.Request.URL.Path = rawPath }() isCSS := strings.HasSuffix(relPath, "swagger-ui.css") underlying := c.Writer crw := &captureResponseWriter{ ginWriter: underlying, code: 200, } c.Writer = crw swaggerFiles.Handler.ServeHTTP(crw, c.Request) c.Writer = underlying h := underlying.Header() h.Set("X-Content-Type-Options", "nosniff") h.Set("X-Frame-Options", "DENY") h.Set("X-XSS-Protection", "1; mode=block") h.Set("Referrer-Policy", "strict-origin-when-cross-origin") h.Set("Content-Security-Policy", "default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:") if isCSS && crw.code == 200 && crw.buf.Len() > 0 { body := append(crw.buf.Bytes(), []byte(brandingCSS)...) h.Set("Content-Length", strconv.Itoa(len(body))) h.Set("Content-Type", "text/css; charset=utf-8") underlying.WriteHeader(crw.code) underlying.Write(body) return } if crw.buf.Len() > 0 { ext := filepath.Ext(relPath) if ct := mime.TypeByExtension(ext); ct != "" { h.Set("Content-Type", ct) } h.Del("Content-Length") underlying.WriteHeader(crw.code) underlying.Write(crw.buf.Bytes()) return } underlying.WriteHeader(crw.code) } } type captureResponseWriter struct { ginWriter gin.ResponseWriter code int buf bytes.Buffer } func (w *captureResponseWriter) Header() http.Header { return w.ginWriter.Header() } func (w *captureResponseWriter) Write(b []byte) (int, error) { return w.buf.Write(b) } func (w *captureResponseWriter) WriteHeader(code int) { w.code = code } func (w *captureResponseWriter) WriteString(s string) (int, error) { return w.buf.WriteString(s) } func (w *captureResponseWriter) Status() int { return w.code } func (w *captureResponseWriter) Size() int { return w.buf.Len() } func (w *captureResponseWriter) Written() bool { return w.buf.Len() > 0 } func (w *captureResponseWriter) WriteHeaderNow() {} func (w *captureResponseWriter) Pusher() http.Pusher { return nil } func (w *captureResponseWriter) Hijack() (net.Conn, *bufio.ReadWriter, error) { return w.ginWriter.Hijack() } func (w *captureResponseWriter) CloseNotify() <-chan bool { return w.ginWriter.CloseNotify() } func (w *captureResponseWriter) Flush() {} const brandingCSS = ` /* MengStack API branding — replace Swagger SmartBear logo */ .topbar { display: flex !important; align-items: center !important; background-color: #1b1b1f !important; padding: 8px 20px !important; min-height: 50px !important; position: relative !important; } .topbar > * { visibility: hidden !important; width: 0 !important; height: 0 !important; overflow: hidden !important; margin: 0 !important; padding: 0 !important; flex: 0 !important; } .topbar::before { content: "MengStack API \6587\6863" !important; visibility: visible !important; width: auto !important; height: auto !important; overflow: visible !important; flex: 0 0 auto !important; color: #fff !important; font-size: 20px !important; font-weight: 700 !important; font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, sans-serif !important; letter-spacing: 1px !important; text-decoration: none !important; position: absolute !important; left: 20px !important; top: 50% !important; transform: translateY(-50%) !important; } .topbar::after { content: "v0.3.0" !important; visibility: visible !important; width: auto !important; height: auto !important; overflow: visible !important; flex: 0 0 auto !important; color: rgba(255,255,255,0.5) !important; font-size: 12px !important; font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, sans-serif !important; position: absolute !important; left: 230px !important; top: 50% !important; transform: translateY(-50%) !important; } .swagger-ui { margin-top: 0 !important; } `