package handlers import ( "encoding/json" "go-backend/internal/auth" "go-backend/internal/database/sqlc" "log" "net/http" ) type SignUpRequest struct { Username string `json:"username"` Password string `json:"password"` Email string `json:"email"` } func (h *Handler) SignUpHandler(w http.ResponseWriter, r *http.Request) { if r.Method != http.MethodPost { http.Error(w, "Method not allowed", http.StatusMethodNotAllowed) return } var req SignUpRequest decoder := json.NewDecoder(r.Body) err := decoder.Decode(&req) if err != nil { http.Error(w, "Invalid request body", http.StatusBadRequest) return } if req.Username == "" || req.Password == "" || req.Email == "" { http.Error(w, "Invalid request body", http.StatusBadRequest) return } user, err := h.users.FindByUsername(r.Context(), req.Username) if err != nil { http.Error(w, "Internal server error", http.StatusInternalServerError) return } if user != nil { http.Error(w, "Username already taken", http.StatusBadRequest) return } hashedPassword, err := auth.HashPassword(req.Password) if err != nil { http.Error(w, "Internal server error", http.StatusInternalServerError) return } user, err = h.users.CreateUser(r.Context(), sqlc.InsertUserParams{Username: req.Username, Email: req.Email, PasswordHash: hashedPassword}) if err != nil { http.Error(w, "Internal server error", http.StatusInternalServerError) return } session, err := h.auth.CreateSession(r.Context(), user.ID) if err != nil { log.Printf("Error creating session: %v", err) http.Error(w, "Internal server error", http.StatusInternalServerError) return } cookie := &http.Cookie{ Name: "session", Value: session.Token, HttpOnly: true, SameSite: http.SameSiteLaxMode, MaxAge: 86400, // 24 hours Path: "/", } http.SetCookie(w, cookie) w.WriteHeader(http.StatusOK) w.Write([]byte("Success")) }