mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-09 09:06:36 +08:00
fix(auth): register CAP scope, 400 on captcha, 403 for permission
Navigating from login reused a send_email_code token on register. Captcha failure used 401 so the client stored /register as the post-login target and never left the page. Permission denials now return 403, and the API client no longer wipes the session on 401.
This commit is contained in:
@@ -399,3 +399,30 @@ func TestAuthWhitelistMiddleware(t *testing.T) {
|
||||
engine.ServeHTTP(w2, req2)
|
||||
assert.Equal(t, http.StatusUnauthorized, w2.Code)
|
||||
}
|
||||
|
||||
func TestAdminRequiredReturnsForbiddenForLoggedInNonAdmin(t *testing.T) {
|
||||
gin.SetMode(gin.TestMode)
|
||||
db := setupTestDB(t)
|
||||
require.NoError(t, db.Create(&testUser{ID: 42, Username: "member", IsActive: true, IsAdmin: false}).Error)
|
||||
|
||||
svc := newTestAuthService(t, db)
|
||||
mw, ok := svc.RequireAdminMiddleware().(gin.HandlerFunc)
|
||||
require.True(t, ok)
|
||||
|
||||
engine := newSessionEngine()
|
||||
engine.Use(func(c *gin.Context) {
|
||||
session := sessions.Default(c)
|
||||
session.Set(auth.UserIDKey, uint64(42))
|
||||
require.NoError(t, session.Save())
|
||||
c.Next()
|
||||
})
|
||||
engine.Use(mw)
|
||||
engine.GET("/admin-only", func(c *gin.Context) {
|
||||
c.JSON(http.StatusOK, response.OK("ok"))
|
||||
})
|
||||
|
||||
w := httptest.NewRecorder()
|
||||
engine.ServeHTTP(w, httptest.NewRequest(http.MethodGet, "/admin-only", nil))
|
||||
assert.Equal(t, http.StatusForbidden, w.Code)
|
||||
assert.Contains(t, w.Body.String(), "权限不足")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user