refactor(api): remove 5 dead routes + stale deprecation markers

An audit (backend /api routes vs SvelteKit frontend usage, adversarially
verified across the whole repo) found these 5 routes have ZERO callers — no
frontend, no test, no protocol layer, no internal caller — and are superseded:

- GET  /api/folders/paginated            no-op duplicate of GET /api/folders
                                         (discards the page arg); superseded by
                                         the cursor-paginated /{id}/resources.
- POST /api/dedup/upload                 superseded by /api/files/upload, which
                                         does the identical CDC dedup ingest.
- POST /api/people/{id}/hide             the hide-person toggle was never built
                                         into the UI (is_hidden never read).
- GET  /api/admin/settings/general       never called anywhere.
- GET  /api/admin/settings/registration  only the PUT is used; the GET had no
                                         caller (PUT kept).

Removes each route, its handler + _impl, the now-orphaned DedupUploadResponse
DTO + its two serialization tests, the set_hidden service method (only caller
was hide_person), and the OpenAPI path/schema registrations.

Also cleans 4 stale markers: two #[allow(deprecated)] that no longer suppress
anything (zero #[deprecated] remain), the "Legacy folder endpoints (contents,
listing)" comment (both already removed), and a "Re-export AppError for backward
compatibility" comment describing a re-export that doesn't exist.

Net -323 lines. The 31 other unused-by-frontend routes (device-code auth,
CardDAV contact-groups, people/photos & music WIP, dedup/admin debug, i18n,
openapi.json) are intentional surface and were left untouched.

cargo clippy --all-features --all-targets -D warnings: clean. cargo test: 446 passed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
DioCrafts
2026-06-21 11:35:09 +02:00
parent 0cfa1212ff
commit 8981c1dfb9
8 changed files with 4 additions and 327 deletions
+1 -172
View File
@@ -1,6 +1,6 @@
use axum::{
body::Body,
extract::{Json, Multipart, Path, State},
extract::{Json, Path, State},
http::{Response, StatusCode, header},
response::IntoResponse,
};
@@ -9,7 +9,6 @@ use utoipa::ToSchema;
use crate::common::di::AppState;
use crate::interfaces::middleware::auth::AuthUser;
use crate::interfaces::upload_ingest;
use std::sync::Arc;
/// Global application state for dependency injection
@@ -57,21 +56,6 @@ pub struct HashBatchResponse {
pub owned: Vec<String>,
}
/// Response for upload with dedup endpoint
#[derive(Debug, Serialize, ToSchema)]
pub struct DedupUploadResponse {
/// Whether this was a new file or an existing one
pub is_new: bool,
/// The BLAKE3 hash of the content
pub hash: String,
/// The size of the content in bytes
pub size: u64,
/// Bytes saved by deduplication (0 if new file)
pub bytes_saved: u64,
/// Current reference count for this blob
pub ref_count: u32,
}
/// Response for dedup stats endpoint
#[derive(Debug, Serialize, ToSchema)]
pub struct StatsResponse {
@@ -223,101 +207,6 @@ impl DedupHandler {
.into_response()
}
/// Upload content with automatic deduplication (streaming).
///
/// Streams the multipart field straight into the CDC chunk store —
/// chunking, BLAKE3 hashing and dedup checks happen while the bytes
/// arrive (no temp file, no re-read; peak RAM is bounded regardless
/// of file size).
///
/// POST /api/dedup/upload
pub(super) async fn upload_with_dedup_impl(
State(state): State<GlobalState>,
_auth_user: AuthUser,
mut multipart: Multipart,
) -> impl IntoResponse {
let dedup = &state.core.dedup_service;
// Process multipart form
while let Some(field) = multipart.next_field().await.unwrap_or(None) {
let name = field.name().unwrap_or("").to_string();
if name == "file" {
let content_type = field
.content_type()
.unwrap_or("application/octet-stream")
.to_string();
let filename = field.file_name().unwrap_or("unnamed").to_string();
// ── Stream into the CDC chunk store ──────────────────
let source = upload_ingest::multipart_field_stream(field);
let ingested = match upload_ingest::ingest_stream_to_cas(
source,
dedup,
&filename,
&content_type,
usize::MAX,
None,
)
.await
{
Ok(ingested) => ingested,
Err(e) => {
tracing::warn!("Dedup upload ingest failed: {}", e.message);
return e.into_response();
}
};
if ingested.size == 0 {
upload_ingest::discard_ingested(dedup, &ingested).await;
return Response::builder()
.status(StatusCode::BAD_REQUEST)
.header(header::CONTENT_TYPE, "application/json")
.body(Body::from(r#"{"error": "Empty file not allowed"}"#))
.unwrap()
.into_response();
}
let metadata = dedup.get_blob_metadata(&ingested.hash).await;
let response = DedupUploadResponse {
is_new: ingested.is_new_blob,
hash: ingested.hash.clone(),
size: ingested.size,
bytes_saved: ingested.bytes_saved,
ref_count: metadata.map(|m| m.ref_count).unwrap_or(1),
};
tracing::info!(
"🔗 Dedup upload: hash={}, new={}, saved={}",
ingested.hash,
ingested.is_new_blob,
ingested.bytes_saved
);
return Response::builder()
.status(if ingested.is_new_blob {
StatusCode::CREATED
} else {
StatusCode::OK
})
.header(header::CONTENT_TYPE, "application/json")
.body(Body::from(serde_json::to_string(&response).unwrap()))
.unwrap()
.into_response();
}
}
Response::builder()
.status(StatusCode::BAD_REQUEST)
.header(header::CONTENT_TYPE, "application/json")
.body(Body::from(
r#"{"error": "No file field found in multipart form"}"#,
))
.unwrap()
.into_response()
}
/// Get deduplication statistics
///
/// GET /api/dedup/stats
@@ -562,27 +451,6 @@ pub async fn check_hashes_batch(
DedupHandler::check_hashes_batch_impl(state, auth_user, body).await
}
#[utoipa::path(
post,
path = "/api/dedup/upload",
request_body(content_type = "multipart/form-data", description = "Multipart form with a 'file' field"),
responses(
(status = 201, description = "New blob stored", body = DedupUploadResponse),
(status = 200, description = "Blob already existed (dedup hit)", body = DedupUploadResponse),
(status = 400, description = "No file field or empty file"),
(status = 500, description = "Upload failed"),
),
tag = "dedup",
security(("bearerAuth" = []))
)]
pub async fn upload_with_dedup(
state: State<GlobalState>,
auth_user: AuthUser,
multipart: Multipart,
) -> impl IntoResponse {
DedupHandler::upload_with_dedup_impl(state, auth_user, multipart).await
}
#[utoipa::path(
get,
path = "/api/dedup/stats",
@@ -803,45 +671,6 @@ mod tests {
assert!(!tokio::fs::try_exists(&temp_path).await.unwrap_or(true));
}
/// Verify the DedupUploadResponse serializes correctly for new blobs.
#[test]
fn dedup_upload_response_serialization_new_blob() {
let response = DedupUploadResponse {
is_new: true,
hash: "a".repeat(64),
size: 1024,
bytes_saved: 0,
ref_count: 1,
};
let json = serde_json::to_string(&response).unwrap();
let parsed: serde_json::Value = serde_json::from_str(&json).unwrap();
assert_eq!(parsed["is_new"], true);
assert_eq!(parsed["size"], 1024);
assert_eq!(parsed["bytes_saved"], 0);
assert_eq!(parsed["ref_count"], 1);
}
/// Verify the DedupUploadResponse serializes correctly for dedup hits.
#[test]
fn dedup_upload_response_serialization_dedup_hit() {
let response = DedupUploadResponse {
is_new: false,
hash: "b".repeat(64),
size: 2048,
bytes_saved: 2048,
ref_count: 3,
};
let json = serde_json::to_string(&response).unwrap();
let parsed: serde_json::Value = serde_json::from_str(&json).unwrap();
assert_eq!(parsed["is_new"], false);
assert_eq!(parsed["bytes_saved"], 2048);
assert_eq!(parsed["ref_count"], 3);
}
#[test]
fn valid_blob_hash_accepts_64_hex_only() {
assert!(is_valid_blob_hash(&"abcdef0123456789".repeat(4))); // 64 hex chars