mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-05 15:26:36 +08:00
fix(openflare): align admin permission model with Wavelet
Unify OpenFlare console auth to user.IsAdmin and token_admin instead of the legacy Admin/Root role tiers. Route groups now use apiutil.AdminMiddlewares (LoginRequired + LoginAdminRequired) so admin checks cannot be skipped. Add middleware tests and extend integration coverage for 401/404/400 responses.
This commit is contained in:
@@ -6,32 +6,12 @@ package apiutil
|
||||
import (
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/admin"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/oauth"
|
||||
"github.com/Rain-kl/Wavelet/internal/common"
|
||||
"github.com/Rain-kl/Wavelet/internal/common/response"
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
// AdminRequired ensures the caller is logged in as a Wavelet administrator.
|
||||
func AdminRequired() gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
user, err := oauth.GetUserFromRequest(c)
|
||||
if err != nil {
|
||||
response.AbortUnauthorized(c, common.UnAuthorized)
|
||||
return
|
||||
}
|
||||
oauth.SetToContext(c, oauth.UserObjKey, user)
|
||||
|
||||
if tokenAuth, _ := oauth.GetFromContext[bool](c, oauth.TokenAuthKey); tokenAuth {
|
||||
tokenAdmin, _ := oauth.GetFromContext[bool](c, oauth.TokenAdminKey)
|
||||
if !tokenAdmin {
|
||||
response.AbortNotFound(c, admin.TokenAdminRequired)
|
||||
return
|
||||
}
|
||||
}
|
||||
if !user.IsAdmin {
|
||||
response.AbortNotFound(c, admin.AdminRequired)
|
||||
return
|
||||
}
|
||||
c.Next()
|
||||
}
|
||||
// AdminMiddlewares returns Wavelet-standard middlewares for OpenFlare console routes.
|
||||
// OpenFlare no longer distinguishes Admin vs Root tiers; all management endpoints share
|
||||
// the same gate: user.IsAdmin for session users, token_admin for Access Token callers.
|
||||
func AdminMiddlewares() []gin.HandlerFunc {
|
||||
return []gin.HandlerFunc{oauth.LoginRequired(), admin.LoginAdminRequired()}
|
||||
}
|
||||
Reference in New Issue
Block a user