mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-06 23:56:37 +08:00
fix(auth): register CAP scope, 400 on captcha, 403 for permission
Navigating from login reused a send_email_code token on register. Captcha failure used 401 so the client stored /register as the post-login target and never left the page. Permission denials now return 403, and the API client no longer wipes the session on 401.
This commit is contained in:
@@ -8,6 +8,7 @@ import (
|
||||
"Wavelet/core"
|
||||
"Wavelet/core/contracts"
|
||||
"Wavelet/core/extpoints"
|
||||
"Wavelet/pkg/ginutil"
|
||||
"Wavelet/plugins/domain/upload/filesrv"
|
||||
"Wavelet/plugins/domain/upload/handler"
|
||||
"Wavelet/plugins/domain/upload/shared"
|
||||
@@ -66,13 +67,25 @@ func (p *Plugin) Apply(ctx *core.Context) error {
|
||||
return nil
|
||||
})
|
||||
|
||||
// 0. Resolve auth service for middleware
|
||||
var authSvc contracts.AuthService
|
||||
if err := core.Using[contracts.AuthService](ctx, func(svc contracts.AuthService) { authSvc = svc }); err != nil {
|
||||
return err
|
||||
denyAuth := ginutil.AuthUnavailable()
|
||||
loginMW := func(c *gin.Context) {
|
||||
if svc := shared.GetAuthService(c.Request.Context()); svc != nil {
|
||||
if mw, ok := svc.RequireAuthMiddleware().(gin.HandlerFunc); ok && mw != nil {
|
||||
mw(c)
|
||||
return
|
||||
}
|
||||
}
|
||||
denyAuth(c)
|
||||
}
|
||||
adminMW := func(c *gin.Context) {
|
||||
if svc := shared.GetAuthService(c.Request.Context()); svc != nil {
|
||||
if mw, ok := svc.RequireAdminMiddleware().(gin.HandlerFunc); ok && mw != nil {
|
||||
mw(c)
|
||||
return
|
||||
}
|
||||
}
|
||||
denyAuth(c)
|
||||
}
|
||||
loginMW := authSvc.RequireAuthMiddleware().(gin.HandlerFunc)
|
||||
adminMW := authSvc.RequireAdminMiddleware().(gin.HandlerFunc)
|
||||
|
||||
// 0a. Register migrations
|
||||
ctx.Migrations().Register("upload", uploadMigrations)
|
||||
|
||||
Reference in New Issue
Block a user