mirror of
https://github.com/Sagit-chu/flvx.git
synced 2026-09-28 07:36:38 +08:00
a43653f252
* feat: restrict user permissions and multi-node IP constraints - Non-admin users cannot set speedId or inPort on forward create/update - Multi-entrance tunnels disable custom listen IP for forwards - Multi-exit tunnels disable custom connect IP - Multi-node hop chains disable custom connect IP per hop - Remove tunnel-first-IP fallback in forward ingress resolution - Add contract tests for non-admin permission restrictions Entire-Checkpoint: 133693290660 * fix: allow non-admin users to submit null speedId and zero inPort - Backend: Check speedId is not nil before rejecting non-admin requests - Backend: Only reject inPort if value > 0 for non-admin users - Frontend: Only include speedId and inPort in payload for admin users - Tests: Add contract tests for null speedId and zero inPort cases
19 lines
720 B
Plaintext
19 lines
720 B
Plaintext
## 分析结果
|
|
|
|
### 当前状态
|
|
- **角色系统**: `roleID == 0` 为管理员,`roleID != 0` 为普通用户
|
|
- **问题**: 普通用户在创建/编辑转发时可设置 `speedId`(限速) 和 `inPort`(自定义端口)
|
|
|
|
### 实施方案
|
|
|
|
**后端修改** (`go-backend/internal/http/handler/mutations.go`):
|
|
- `forwardCreate`: 检查 `roleID != 0` 时拒绝 `speedId` 和 `inPort`
|
|
- `forwardUpdate`: 检查 `actorRole != 0` 时拒绝 `speedId` 和 `inPort`
|
|
|
|
**前端修改** (`vite-frontend/src/pages/forward.tsx`):
|
|
- 限速规则选择器和入口端口输入框使用 `{isAdmin && (...)}` 条件渲染
|
|
|
|
**测试**:
|
|
- 添加契约测试验证权限限制
|
|
|
|
计划文档: `plans/009-restrict-user-forward-permissions.md` |