From 40c2212dd3d7a589a6068f29dd295120fbf006aa Mon Sep 17 00:00:00 2001 From: ryan Date: Wed, 2 Sep 2026 20:32:33 +0800 Subject: [PATCH] fix(upload): apply login middleware to /f/:id route MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit /f/:id had no LoginRequired middleware, so AuthUserObjKey was never populated and GetCurrentUser/GetUserIDFromContext could not authenticate even logged-in users, returning 401 未登录 on private files. Add loginMW. --- backend/plugins/domain/upload/plugin.go | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/backend/plugins/domain/upload/plugin.go b/backend/plugins/domain/upload/plugin.go index 16a06442..2a7b95eb 100644 --- a/backend/plugins/domain/upload/plugin.go +++ b/backend/plugins/domain/upload/plugin.go @@ -91,7 +91,8 @@ func (p *Plugin) Apply(ctx *core.Context) error { ctx.Migrations().Register("upload", uploadMigrations) // 1. Register File Server Routes - ctx.Router().GET("/f/:id", filesrv.ServeFileByID) + // TIP: loginMW populates AuthUserObjKey so private files can be checked for ownership. + ctx.Router().GET("/f/:id", loginMW, filesrv.ServeFileByID) // 2. Register User/Admin Upload HTTP Routes uploadGroup := ctx.Router().Group("/api/v1/upload", loginMW)