refactor(storage): move file management routes from user to admin namespace

- Remove file list, stats, download, and deletion routes from '/api/v1/upload'
- Move these endpoints under '/api/v1/admin/uploads'
- Remove user-specific filtering from files query and statistics to aggregate system-wide uploads by default
- Allow admins to bypass ownership check when downloading private files
- Update backend unit tests, Swagger documentation, and frontend service client and components
This commit is contained in:
ryan
2026-06-13 16:04:21 +08:00
parent dbabe8b8d7
commit 8b19ffed90
13 changed files with 908 additions and 818 deletions
+3
View File
@@ -292,6 +292,9 @@ func checkPrivateFileOwner(c *gin.Context, ownerID uint64) error {
return err
}
}
if currUser.IsAdmin {
return nil
}
if currUser.ID != ownerID {
return errors.New("forbidden: cross-user access denied")
}