fix(auth): register CAP scope, 400 on captcha, 403 for permission

Navigating from login reused a send_email_code token on register.
Captcha failure used 401 so the client stored /register as the
post-login target and never left the page. Permission denials now
return 403, and the API client no longer wipes the session on 401.
This commit is contained in:
ryan
2026-09-02 18:26:22 +08:00
parent df7ad453cc
commit b7e5e811d1
11 changed files with 129 additions and 52 deletions
@@ -399,3 +399,30 @@ func TestAuthWhitelistMiddleware(t *testing.T) {
engine.ServeHTTP(w2, req2)
assert.Equal(t, http.StatusUnauthorized, w2.Code)
}
func TestAdminRequiredReturnsForbiddenForLoggedInNonAdmin(t *testing.T) {
gin.SetMode(gin.TestMode)
db := setupTestDB(t)
require.NoError(t, db.Create(&testUser{ID: 42, Username: "member", IsActive: true, IsAdmin: false}).Error)
svc := newTestAuthService(t, db)
mw, ok := svc.RequireAdminMiddleware().(gin.HandlerFunc)
require.True(t, ok)
engine := newSessionEngine()
engine.Use(func(c *gin.Context) {
session := sessions.Default(c)
session.Set(auth.UserIDKey, uint64(42))
require.NoError(t, session.Save())
c.Next()
})
engine.Use(mw)
engine.GET("/admin-only", func(c *gin.Context) {
c.JSON(http.StatusOK, response.OK("ok"))
})
w := httptest.NewRecorder()
engine.ServeHTTP(w, httptest.NewRequest(http.MethodGet, "/admin-only", nil))
assert.Equal(t, http.StatusForbidden, w.Code)
assert.Contains(t, w.Body.String(), "权限不足")
}