AccessToken 默认非管理员权限

This commit is contained in:
ryan
2026-06-10 22:36:17 +08:00
parent bff9e8811d
commit 983228227e
15 changed files with 107 additions and 21 deletions
+2
View File
@@ -14,6 +14,8 @@ const (
UserNameKey = "username"
UserIDKey = "user_id"
UserObjKey = "user_obj"
TokenAuthKey = "token_auth" // 标记当前请求是否通过 Access Token 鉴权
TokenAdminKey = "token_admin" // Access Token 本身是否具有管理员权限
PendingOAuthSourceIDKey = "pending_oauth_source_id"
PendingOAuthExternalIDKey = "pending_oauth_external_id"
PendingOAuthExternalUsernameKey = "pending_oauth_external_username"
+6
View File
@@ -45,6 +45,8 @@ func LoginRequired() gin.HandlerFunc {
var user model.User
var authenticated bool
var tokenAuth bool
var tokenAdmin bool
if tokenStr != "" {
tokenHash := model.HashToken(tokenStr)
@@ -52,6 +54,8 @@ func LoginRequired() gin.HandlerFunc {
if err := db.DB(ctx).Where("token_hash = ?", tokenHash).First(&tokenRecord).Error; err == nil {
if err := db.DB(ctx).Where("id = ? AND is_active = ?", tokenRecord.UserID, true).First(&user).Error; err == nil {
authenticated = true
tokenAuth = true
tokenAdmin = tokenRecord.IsAdmin
// update token last used time
now := time.Now()
db.DB(ctx).Model(&tokenRecord).Update("last_used_at", &now)
@@ -80,6 +84,8 @@ func LoginRequired() gin.HandlerFunc {
// set user info
util.SetToContext(c, UserObjKey, &user)
util.SetToContext(c, TokenAuthKey, tokenAuth)
util.SetToContext(c, TokenAdminKey, tokenAdmin)
// next
c.Next()