mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-04 15:06:37 +08:00
migrate frontend
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
import axios, {AxiosError, AxiosResponse, CancelTokenSource, InternalAxiosRequestConfig} from 'axios';
|
||||
import {toast} from 'sonner';
|
||||
import {apiConfig} from './config';
|
||||
import {apiConfig, getApiBaseUrl} from './config';
|
||||
import {
|
||||
ApiErrorBase,
|
||||
ForbiddenError,
|
||||
@@ -21,11 +21,24 @@ const apiClient = axios.create({
|
||||
baseURL: apiConfig.baseURL,
|
||||
timeout: apiConfig.timeout,
|
||||
withCredentials: apiConfig.withCredentials,
|
||||
// Fail fast on slash redirect loops between Next dev proxy and Gin legacy routes.
|
||||
maxRedirects: 5,
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
},
|
||||
});
|
||||
|
||||
/** Normalize legacy /api/* paths: strip trailing slash to avoid 308/301 loops in dev proxy. */
|
||||
function normalizeApiPath(url?: string): string | undefined {
|
||||
if (!url || !url.startsWith('/api/')) {
|
||||
return url;
|
||||
}
|
||||
if (url.length > 5 && url.endsWith('/')) {
|
||||
return url.replace(/\/+$/, '');
|
||||
}
|
||||
return url;
|
||||
}
|
||||
|
||||
/**
|
||||
* 请求取消令牌存储
|
||||
*/
|
||||
@@ -66,6 +79,12 @@ function getRequestKey(config: { method?: string; url?: string; data?: unknown }
|
||||
*/
|
||||
apiClient.interceptors.request.use(
|
||||
(config: InternalAxiosRequestConfig) => {
|
||||
// Browser must use same-origin relative URLs so Session Cookie hits Next rewrite (3010→3000).
|
||||
if (typeof window !== 'undefined') {
|
||||
config.baseURL = getApiBaseUrl();
|
||||
}
|
||||
config.url = normalizeApiPath(config.url);
|
||||
|
||||
const requestKey = getRequestKey(config);
|
||||
const source = axios.CancelToken.source();
|
||||
config.cancelToken = source.token;
|
||||
|
||||
@@ -28,7 +28,7 @@ func RequireRole(minRole int) gin.HandlerFunc {
|
||||
c.Abort()
|
||||
return
|
||||
}
|
||||
role := resolveRole(user)
|
||||
role := resolveRole(c, user)
|
||||
if role < minRole {
|
||||
Fail(c, "无权进行此操作,权限不足")
|
||||
c.Abort()
|
||||
@@ -50,10 +50,13 @@ func AdminAuth() gin.HandlerFunc { return RequireRole(RoleAdminUser) }
|
||||
// RootAuth requires role >= RootUser.
|
||||
func RootAuth() gin.HandlerFunc { return RequireRole(RoleRootUser) }
|
||||
|
||||
func resolveRole(user *model.User) int {
|
||||
func resolveRole(c *gin.Context, user *model.User) int {
|
||||
if user == nil {
|
||||
return 0
|
||||
}
|
||||
if tokenAdmin, ok := oauth.GetFromContext[bool](c, oauth.TokenAdminKey); ok && tokenAdmin {
|
||||
return RoleRootUser
|
||||
}
|
||||
if user.IsAdmin {
|
||||
return RoleRootUser
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user