refactor(storage): move file management routes from user to admin namespace

- Remove file list, stats, download, and deletion routes from '/api/v1/upload'
- Move these endpoints under '/api/v1/admin/uploads'
- Remove user-specific filtering from files query and statistics to aggregate system-wide uploads by default
- Allow admins to bypass ownership check when downloading private files
- Update backend unit tests, Swagger documentation, and frontend service client and components
This commit is contained in:
ryan
2026-06-13 16:04:21 +08:00
parent dbabe8b8d7
commit 8b19ffed90
13 changed files with 908 additions and 818 deletions
+185 -172
View File
@@ -925,7 +925,7 @@ definitions:
$ref: '#/definitions/upload.distributionItem'
type: array
type: object
upload.listMyFilesResponse:
upload.listFilesResponse:
properties:
items:
items:
@@ -2673,6 +2673,190 @@ paths:
summary: 下载并应用应用更新
tags:
- admin
/api/v1/admin/uploads:
get:
description: 分页获取系统上传的文件列表,支持文件名关键词、业务类型、扩展名、上传用户ID过滤
parameters:
- description: 页码(默认 1)
in: query
name: page
type: integer
- description: 每页数量(默认 20,最大 100)
in: query
name: page_size
type: integer
- description: 文件名关键词(模糊匹配)
in: query
name: keyword
type: string
- description: 业务分类过滤
in: query
name: type
type: string
- description: 扩展名过滤
in: query
name: extension
type: string
- description: 上传用户 ID
format: int64
in: query
name: user_id
type: integer
produces:
- application/json
responses:
"200":
description: 查询成功
schema:
allOf:
- $ref: '#/definitions/util.ResponseAny'
- properties:
data:
$ref: '#/definitions/upload.listFilesResponse'
type: object
"401":
description: 未登录
schema:
$ref: '#/definitions/util.ResponseAny'
"403":
description: 无管理员权限
schema:
$ref: '#/definitions/util.ResponseAny'
security:
- SessionCookie: []
summary: 获取文件列表
tags:
- admin
/api/v1/admin/uploads/{id}:
delete:
description: 将文件状态置为 deleted(软删除),不会立即清理底层存储对象
parameters:
- description: 文件 ID
in: path
name: id
required: true
type: string
produces:
- application/json
responses:
"200":
description: 删除成功
schema:
$ref: '#/definitions/util.ResponseAny'
"403":
description: 无权操作
schema:
$ref: '#/definitions/util.ResponseAny'
"404":
description: 文件不存在
schema:
$ref: '#/definitions/util.ResponseAny'
security:
- SessionCookie: []
summary: 删除文件
tags:
- admin
/api/v1/admin/uploads/download/{id}:
get:
description: 根据文件 ID 获取文件,以附件形式 (Attachment) 强制开启客户端浏览器下载
parameters:
- description: 文件 ID
in: path
name: id
required: true
type: string
- description: 图片质量 (low, medium, high, origin),默认为 origin
in: query
name: quality
type: string
produces:
- application/octet-stream
responses:
"200":
description: 成功下载文件
schema:
type: file
"400":
description: 参数错误
schema:
$ref: '#/definitions/util.ResponseAny'
"404":
description: 文件不存在
schema:
$ref: '#/definitions/util.ResponseAny'
"500":
description: 服务内部错误
schema:
$ref: '#/definitions/util.ResponseAny'
security:
- SessionCookie: []
summary: 下载单文件
tags:
- admin
/api/v1/admin/uploads/download/batch:
post:
consumes:
- application/json
description: 传入多个文件 ID,后台实时将其打包压缩为 ZIP 流并输出,自动处理文件名重复冲突
parameters:
- description: 包含文件 ID 数组 of string 的请求体
in: body
name: request
required: true
schema:
$ref: '#/definitions/upload.batchDownloadRequest'
produces:
- application/octet-stream
responses:
"200":
description: 成功下载打包后的 ZIP
schema:
type: file
"400":
description: 参数错误
schema:
$ref: '#/definitions/util.ResponseAny'
"500":
description: 打包失败
schema:
$ref: '#/definitions/util.ResponseAny'
security:
- SessionCookie: []
summary: 批量打包下载
tags:
- admin
/api/v1/admin/uploads/stats:
get:
description: 返回系统级的总文件数、占用大小、最近 7 天新增趋势、文件类型/格式分布等数据
produces:
- application/json
responses:
"200":
description: 获取成功
schema:
allOf:
- $ref: '#/definitions/util.ResponseAny'
- properties:
data:
$ref: '#/definitions/upload.fileStatsResponse'
type: object
"401":
description: 未登录
schema:
$ref: '#/definitions/util.ResponseAny'
"403":
description: 无管理员权限
schema:
$ref: '#/definitions/util.ResponseAny'
"500":
description: 内部错误
schema:
$ref: '#/definitions/util.ResponseAny'
security:
- SessionCookie: []
summary: 获取文件统计数据
tags:
- admin
/api/v1/admin/uploads/types:
get:
description: 返回数据库中所有已上传文件实际拥有的业务类型列表
@@ -3286,177 +3470,6 @@ paths:
summary: 上传文件
tags:
- upload
/api/v1/upload/{id}:
delete:
description: 将文件状态置为 deleted(软删除),不会立即清理底层存储对象
parameters:
- description: 文件 ID
in: path
name: id
required: true
type: string
produces:
- application/json
responses:
"200":
description: 删除成功
schema:
$ref: '#/definitions/util.ResponseAny'
"403":
description: 无权操作
schema:
$ref: '#/definitions/util.ResponseAny'
"404":
description: 文件不存在
schema:
$ref: '#/definitions/util.ResponseAny'
security:
- SessionCookie: []
summary: 删除文件
tags:
- upload
/api/v1/upload/download/{id}:
get:
description: 根据文件 ID 获取文件,以附件形式 (Attachment) 强制开启客户端浏览器下载
parameters:
- description: 文件 ID
in: path
name: id
required: true
type: string
- description: 图片质量 (low, medium, high, origin),默认为 origin
in: query
name: quality
type: string
produces:
- application/octet-stream
responses:
"200":
description: 成功下载文件
schema:
type: file
"400":
description: 参数错误
schema:
$ref: '#/definitions/util.ResponseAny'
"404":
description: 文件不存在
schema:
$ref: '#/definitions/util.ResponseAny'
"500":
description: 服务内部错误
schema:
$ref: '#/definitions/util.ResponseAny'
security:
- SessionCookie: []
summary: 下载单文件
tags:
- upload
/api/v1/upload/download/batch:
post:
consumes:
- application/json
description: 传入多个文件 ID,后台实时将其打包压缩为 ZIP 流并输出,自动处理文件名重复冲突
parameters:
- description: 包含文件 ID 数组的请求体
in: body
name: request
required: true
schema:
$ref: '#/definitions/upload.batchDownloadRequest'
produces:
- application/octet-stream
responses:
"200":
description: 成功下载打包后的 ZIP
schema:
type: file
"400":
description: 参数错误
schema:
$ref: '#/definitions/util.ResponseAny'
"500":
description: 打包失败
schema:
$ref: '#/definitions/util.ResponseAny'
security:
- SessionCookie: []
summary: 批量打包下载
tags:
- upload
/api/v1/upload/my:
get:
description: 分页获取当前登录用户上传的文件,支持文件名关键词、业务类型、扩展名过滤
parameters:
- description: 页码(默认 1)
in: query
name: page
type: integer
- description: 每页数量(默认 20,最大 100)
in: query
name: page_size
type: integer
- description: 文件名关键词(模糊匹配)
in: query
name: keyword
type: string
- description: 业务分类过滤
in: query
name: type
type: string
- description: 扩展名过滤
in: query
name: extension
type: string
produces:
- application/json
responses:
"200":
description: 查询成功
schema:
allOf:
- $ref: '#/definitions/util.ResponseAny'
- properties:
data:
$ref: '#/definitions/upload.listMyFilesResponse'
type: object
"401":
description: 未登录
schema:
$ref: '#/definitions/util.ResponseAny'
security:
- SessionCookie: []
summary: 获取我的文件列表
tags:
- upload
/api/v1/upload/stats:
get:
description: 返回当前用户的总文件数、占用大小、最近 7 天新增趋势、文件类型/格式分布等数据
produces:
- application/json
responses:
"200":
description: 获取成功
schema:
allOf:
- $ref: '#/definitions/util.ResponseAny'
- properties:
data:
$ref: '#/definitions/upload.fileStatsResponse'
type: object
"401":
description: 未登录
schema:
$ref: '#/definitions/util.ResponseAny'
"500":
description: 内部错误
schema:
$ref: '#/definitions/util.ResponseAny'
security:
- SessionCookie: []
summary: 获取文件统计数据
tags:
- upload
/api/v1/user-info:
get:
description: 返回当前登录用户的基本信息及余额数据,需要登录。包括用户 ID、用户名、信任等级、各类余额信息等。