mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-09-29 05:56:38 +08:00
fix(upload): apply login middleware to /f/:id route
/f/:id had no LoginRequired middleware, so AuthUserObjKey was never populated and GetCurrentUser/GetUserIDFromContext could not authenticate even logged-in users, returning 401 未登录 on private files. Add loginMW.
This commit is contained in:
@@ -91,7 +91,8 @@ func (p *Plugin) Apply(ctx *core.Context) error {
|
||||
ctx.Migrations().Register("upload", uploadMigrations)
|
||||
|
||||
// 1. Register File Server Routes
|
||||
ctx.Router().GET("/f/:id", filesrv.ServeFileByID)
|
||||
// TIP: loginMW populates AuthUserObjKey so private files can be checked for ownership.
|
||||
ctx.Router().GET("/f/:id", loginMW, filesrv.ServeFileByID)
|
||||
|
||||
// 2. Register User/Admin Upload HTTP Routes
|
||||
uploadGroup := ctx.Router().Group("/api/v1/upload", loginMW)
|
||||
|
||||
Reference in New Issue
Block a user