fix(auth): encode snowflake user ids as strings in session and /user-info

Registered users get snowflake ids above JS MAX_SAFE_INTEGER.
/user-info emitted them as JSON numbers and login stored uint64 in
the session. Both now use decimal strings. Tests cover admin vs
non-admin cookie access to /user/self, /user-info, and /upload/my.
This commit is contained in:
ryan
2026-09-02 19:56:10 +08:00
parent c27da41b64
commit df6aa9ff4d
7 changed files with 339 additions and 25 deletions
+2 -2
View File
@@ -108,7 +108,7 @@ func Login(c *gin.Context) {
}
sess := sessions.Default(c)
sess.Set(contracts.AuthUserIDKey, user.ID)
sess.Set(contracts.AuthUserIDKey, strconv.FormatUint(user.ID, 10))
sess.Set(contracts.AuthUserNameKey, user.Username)
needChange := user.NeedChangePassword || user.IsPlaintextPassword()
user.NeedChangePassword = needChange
@@ -154,7 +154,7 @@ func Register(c *gin.Context) {
}
sess := sessions.Default(c)
sess.Set(contracts.AuthUserIDKey, newUser.ID)
sess.Set(contracts.AuthUserIDKey, strconv.FormatUint(newUser.ID, 10))
sess.Set(contracts.AuthUserNameKey, newUser.Username)
if err := sess.Save(); err != nil {
logger.ErrorF(c.Request.Context(), "save session failed on register: %v", err)