HTTP API toolkit
Four packages that cover the usual plumbing of a JSON API built on Fiber v2 and GORM.
Generic CRUD
api/generic — list, get, create and delete routes for any GORM model, with paging, validation and safe errors.
JWT middleware
api/middlewares — Keycloak token verification, role checks and claim getters.
HTTP client
api/client — a tiny resty wrapper for calling other JSON services with a bearer token.
Responses
api/models — the OK / KO envelopes every endpoint returns.
Request flow
sequenceDiagram
participant C as Client
participant J as JwtProtected
participant R as RoleCheck
participant H as Handler
participant S as Store
C->>J: Bearer token
J->>J: signature · exp · iss/aud
J--xC: 401 invalid token
J->>R: verified claims
R--xC: 403 missing role
R->>H: next()
H->>S: Get(id) as bound param
S-->>H: row · not found · error
H-->>C: 200 · 404 · 500 internal error
Rejections (--x) stop the chain. Error details stay in the server log; the client only gets
the status and a generic message.