mirror of
https://github.com/truewhile/MeBox.git
synced 2026-10-01 20:16:36 +08:00
feat: merge conflict resolution, site management, UI fixes
This commit is contained in:
@@ -0,0 +1,95 @@
|
||||
// Package middleware — Emby API 兼容层认证中间件。
|
||||
// 支持 X-Emby-Token / Bearer / URL token / Username+Password 四种认证方式。
|
||||
package middleware
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"net/http"
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
"github.com/golang-jwt/jwt/v5"
|
||||
)
|
||||
|
||||
// EmbyCtxUserID 是 Emby 认证中间件设置的用户 ID 上下文键。
|
||||
const EmbyCtxUserID = "emby_user_id"
|
||||
|
||||
// EmbyAuthRequired Emby 认证中间件。
|
||||
// 按优先级尝试以下认证方式:
|
||||
// 1. X-Emby-Token 请求头
|
||||
// 2. Authorization: Bearer <token> 请求头
|
||||
// 3. ?token=<token> URL 参数
|
||||
// 4. (仅 AuthenticateByName 端点)POST body 中的 Username+Password
|
||||
func EmbyAuthRequired(secret string) gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
token := ""
|
||||
|
||||
// 1. X-Emby-Token 头
|
||||
if t := c.GetHeader("X-Emby-Token"); t != "" {
|
||||
token = t
|
||||
}
|
||||
|
||||
// 2. Authorization: Bearer <token> 或 Emby <token>
|
||||
if token == "" {
|
||||
if authHeader := c.GetHeader("Authorization"); authHeader != "" {
|
||||
// Strip "Bearer " or "Emby " prefix
|
||||
for _, prefix := range []string{"Bearer ", "Emby "} {
|
||||
if len(authHeader) > len(prefix) && authHeader[:len(prefix)] == prefix {
|
||||
token = authHeader[len(prefix):]
|
||||
break
|
||||
}
|
||||
}
|
||||
if token == "" {
|
||||
token = authHeader
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// 3. URL 参数 token
|
||||
if token == "" {
|
||||
if t := c.Query("token"); t != "" {
|
||||
token = t
|
||||
}
|
||||
}
|
||||
|
||||
if token == "" {
|
||||
c.JSON(http.StatusUnauthorized, gin.H{
|
||||
"Code": 40101,
|
||||
"Message": "Unauthorized",
|
||||
})
|
||||
c.Abort()
|
||||
return
|
||||
}
|
||||
|
||||
// 解析 JWT
|
||||
claims := &Claims{}
|
||||
parsed, err := jwt.ParseWithClaims(token, claims, func(t *jwt.Token) (interface{}, error) {
|
||||
if _, ok := t.Method.(*jwt.SigningMethodHMAC); !ok {
|
||||
return nil, errors.New("unexpected signing method")
|
||||
}
|
||||
return []byte(secret), nil
|
||||
})
|
||||
|
||||
if err != nil || !parsed.Valid || claims.UserID == "" {
|
||||
c.JSON(http.StatusUnauthorized, gin.H{
|
||||
"Code": 40101,
|
||||
"Message": "Invalid token",
|
||||
})
|
||||
c.Abort()
|
||||
return
|
||||
}
|
||||
|
||||
c.Set(EmbyCtxUserID, claims.UserID)
|
||||
c.Set(CtxUserID, claims.UserID)
|
||||
c.Set(CtxUserRole, claims.Role)
|
||||
c.Set(CtxUserTier, claims.Tier)
|
||||
c.Next()
|
||||
}
|
||||
}
|
||||
|
||||
// GetEmbyUserID 从上下文中获取 Emby 用户 ID。
|
||||
func GetEmbyUserID(c *gin.Context) string {
|
||||
if uid, exists := c.Get(EmbyCtxUserID); exists {
|
||||
return uid.(string)
|
||||
}
|
||||
return ""
|
||||
}
|
||||
@@ -1,5 +1,5 @@
|
||||
// Package middleware exposes Gin middlewares used by the HTTP server:
|
||||
// request logging, CORS, JWT authentication and admin guard.
|
||||
// Package middleware 暴露 Gin 中间件,用于 HTTP 服务器:
|
||||
// 请求日志、CORS、JWT 认证、管理员守卫和权限检查。
|
||||
package middleware
|
||||
|
||||
import (
|
||||
@@ -17,6 +17,7 @@ import (
|
||||
const (
|
||||
CtxUserID = "ctx_user_id"
|
||||
CtxUserRole = "ctx_user_role"
|
||||
CtxUserTier = "ctx_user_tier"
|
||||
)
|
||||
|
||||
// RequestLogger logs one structured line per request.
|
||||
@@ -65,6 +66,7 @@ func CORS(origins []string) gin.HandlerFunc {
|
||||
type Claims struct {
|
||||
UserID string `json:"uid"`
|
||||
Role string `json:"role"`
|
||||
Tier string `json:"tier,omitempty"`
|
||||
jwt.RegisteredClaims
|
||||
}
|
||||
|
||||
@@ -74,7 +76,7 @@ func AuthRequired(secret string) gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
raw := extractToken(c)
|
||||
if raw == "" {
|
||||
c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{"error": "missing token"})
|
||||
c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{"code": 40101, "message": "missing token"})
|
||||
return
|
||||
}
|
||||
claims := &Claims{}
|
||||
@@ -85,11 +87,12 @@ func AuthRequired(secret string) gin.HandlerFunc {
|
||||
return []byte(secret), nil
|
||||
})
|
||||
if err != nil || claims.UserID == "" {
|
||||
c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{"error": "invalid token"})
|
||||
c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{"code": 40101, "message": "invalid token"})
|
||||
return
|
||||
}
|
||||
c.Set(CtxUserID, claims.UserID)
|
||||
c.Set(CtxUserRole, claims.Role)
|
||||
c.Set(CtxUserTier, claims.Tier)
|
||||
c.Next()
|
||||
}
|
||||
}
|
||||
@@ -99,13 +102,65 @@ func AdminRequired() gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
role, _ := c.Get(CtxUserRole)
|
||||
if role != "admin" {
|
||||
c.AbortWithStatusJSON(http.StatusForbidden, gin.H{"error": "admin only"})
|
||||
c.AbortWithStatusJSON(http.StatusForbidden, gin.H{"code": 40301, "message": "admin only"})
|
||||
return
|
||||
}
|
||||
c.Next()
|
||||
}
|
||||
}
|
||||
|
||||
// PlusOrAdminRequired enforces role == "admin" or tier == "plus".
|
||||
func PlusOrAdminRequired() gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
role, _ := c.Get(CtxUserRole)
|
||||
tier, _ := c.Get(CtxUserTier)
|
||||
if role != "admin" && tier != "plus" {
|
||||
c.AbortWithStatusJSON(http.StatusForbidden, gin.H{"code": 40301, "message": "plus or admin only"})
|
||||
return
|
||||
}
|
||||
c.Next()
|
||||
}
|
||||
}
|
||||
|
||||
// GetUserID extracts the user ID from the Gin context.
|
||||
func GetUserID(c *gin.Context) string {
|
||||
if uid, exists := c.Get(CtxUserID); exists {
|
||||
return uid.(string)
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
// GetUserRole extracts the user role from the Gin context.
|
||||
func GetUserRole(c *gin.Context) string {
|
||||
if role, exists := c.Get(CtxUserRole); exists {
|
||||
return role.(string)
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
// GetUserTier extracts the user tier from the Gin context.
|
||||
func GetUserTier(c *gin.Context) string {
|
||||
if tier, exists := c.Get(CtxUserTier); exists {
|
||||
return tier.(string)
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
// IsAdmin checks if the current user is an admin.
|
||||
func IsAdmin(c *gin.Context) bool {
|
||||
return GetUserRole(c) == "admin"
|
||||
}
|
||||
|
||||
// IsPlus checks if the current user is a plus subscriber.
|
||||
func IsPlus(c *gin.Context) bool {
|
||||
return GetUserTier(c) == "plus" || GetUserRole(c) == "admin"
|
||||
}
|
||||
|
||||
// IsSuperUser checks if the current user is a super user (admin or plus).
|
||||
func IsSuperUser(c *gin.Context) bool {
|
||||
return IsAdmin(c) || IsPlus(c)
|
||||
}
|
||||
|
||||
func extractToken(c *gin.Context) string {
|
||||
if h := c.GetHeader("Authorization"); strings.HasPrefix(h, "Bearer ") {
|
||||
return strings.TrimSpace(strings.TrimPrefix(h, "Bearer "))
|
||||
|
||||
@@ -0,0 +1,111 @@
|
||||
// Package middleware — 权限检查中间件。
|
||||
// 注意:实际的权限检查在 handler 层通过 PermissionService 实现。
|
||||
// 此中间件主要用于设置上下文和基本的角色/等级检查。
|
||||
package middleware
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
// RequirePermission 创建权限检查中间件标记。
|
||||
// 实际的权限检查由 handler 中的 PermissionService 执行。
|
||||
// 此中间件确保请求已经过身份验证。
|
||||
func RequirePermission(permissionKey string) gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
userID := GetUserID(c)
|
||||
role := GetUserRole(c)
|
||||
tier := GetUserTier(c)
|
||||
|
||||
if userID == "" {
|
||||
c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{
|
||||
"code": 40101,
|
||||
"message": "authentication required",
|
||||
"data": nil,
|
||||
})
|
||||
return
|
||||
}
|
||||
|
||||
// admin 和 plus 用户拥有所有权限
|
||||
if role == "admin" || tier == "plus" {
|
||||
c.Next()
|
||||
return
|
||||
}
|
||||
|
||||
// 将权限键存储到上下文中供 handler 使用
|
||||
c.Set("permission_key", permissionKey)
|
||||
c.Next()
|
||||
}
|
||||
}
|
||||
|
||||
// RequireAnyPermission 创建需要任意一个权限的中间件标记。
|
||||
func RequireAnyPermission(permissionKeys ...string) gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
userID := GetUserID(c)
|
||||
role := GetUserRole(c)
|
||||
tier := GetUserTier(c)
|
||||
|
||||
if userID == "" {
|
||||
c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{
|
||||
"code": 40101,
|
||||
"message": "authentication required",
|
||||
"data": nil,
|
||||
})
|
||||
return
|
||||
}
|
||||
|
||||
// admin 和 plus 用户拥有所有权限
|
||||
if role == "admin" || tier == "plus" {
|
||||
c.Next()
|
||||
return
|
||||
}
|
||||
|
||||
// 将权限键数组存储到上下文中供 handler 使用
|
||||
c.Set("permission_keys", permissionKeys)
|
||||
c.Next()
|
||||
}
|
||||
}
|
||||
|
||||
// RequireAllPermissions 创建需要所有权限的中间件标记。
|
||||
func RequireAllPermissions(permissionKeys ...string) gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
userID := GetUserID(c)
|
||||
role := GetUserRole(c)
|
||||
tier := GetUserTier(c)
|
||||
|
||||
if userID == "" {
|
||||
c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{
|
||||
"code": 40101,
|
||||
"message": "authentication required",
|
||||
"data": nil,
|
||||
})
|
||||
return
|
||||
}
|
||||
|
||||
// admin 和 plus 用户拥有所有权限
|
||||
if role == "admin" || tier == "plus" {
|
||||
c.Next()
|
||||
return
|
||||
}
|
||||
|
||||
c.Set("permission_keys", permissionKeys)
|
||||
c.Next()
|
||||
}
|
||||
}
|
||||
|
||||
// GetPermissionKey 从上下文中获取存储的权限键。
|
||||
func GetPermissionKey(c *gin.Context) string {
|
||||
if key, exists := c.Get("permission_key"); exists {
|
||||
return key.(string)
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
// GetPermissionKeys 从上下文中获取存储的权限键数组。
|
||||
func GetPermissionKeys(c *gin.Context) []string {
|
||||
if keys, exists := c.Get("permission_keys"); exists {
|
||||
return keys.([]string)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
Reference in New Issue
Block a user