server: Go 服务器(REST+WSS 网关+JWT+Argon2+配对+素材直链+任务状态机);修复并发下线 send-on-closed-channel、下发查询 SQL 优先级、配对码原子占用、上传体积上限、JWT 默认密钥告警
This commit is contained in:
@@ -0,0 +1,38 @@
|
||||
package middleware
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
"gorm.io/gorm"
|
||||
|
||||
"everypublish/server/internal/api/response"
|
||||
"everypublish/server/internal/models"
|
||||
)
|
||||
|
||||
// Audit 审计埋点:处理器调用 response.Audit(c, action, resource, detail) 声明,
|
||||
// 本中间件在请求成功(2xx)后落库。
|
||||
func Audit(db *gorm.DB) gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
c.Next()
|
||||
metaRaw, exists := c.Get("audit")
|
||||
if !exists {
|
||||
return
|
||||
}
|
||||
meta, ok := metaRaw.(response.AuditMeta)
|
||||
if !ok || c.Writer.Status() >= http.StatusBadRequest {
|
||||
return
|
||||
}
|
||||
detail, _ := json.Marshal(meta.Detail)
|
||||
log := models.AuditLog{
|
||||
WorkspaceID: c.GetUint64("wsid"),
|
||||
UserID: c.GetUint64("uid"),
|
||||
Action: meta.Action,
|
||||
Resource: meta.Resource,
|
||||
Detail: string(detail),
|
||||
IP: c.ClientIP(),
|
||||
}
|
||||
_ = db.Create(&log).Error
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,47 @@
|
||||
package middleware
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
|
||||
"everypublish/server/internal/api/response"
|
||||
"everypublish/server/internal/auth"
|
||||
"everypublish/server/internal/config"
|
||||
)
|
||||
|
||||
// AuthRequired 校验访问令牌并把声明写入上下文
|
||||
func AuthRequired(cfg *config.Config) gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
header := c.GetHeader("Authorization")
|
||||
if !strings.HasPrefix(header, "Bearer ") {
|
||||
response.Fail(c, http.StatusUnauthorized, 1002, "未登录或令牌缺失")
|
||||
c.Abort()
|
||||
return
|
||||
}
|
||||
claims, err := auth.ParseAccess(cfg.JWTSecret, strings.TrimPrefix(header, "Bearer "))
|
||||
if err != nil {
|
||||
response.Fail(c, http.StatusUnauthorized, 1002, "令牌无效或已过期")
|
||||
c.Abort()
|
||||
return
|
||||
}
|
||||
c.Set("uid", claims.UID)
|
||||
c.Set("wsid", claims.WorkspaceID)
|
||||
c.Set("role", claims.Role)
|
||||
c.Set("mrole", claims.MemberRole)
|
||||
c.Next()
|
||||
}
|
||||
}
|
||||
|
||||
// AdminRequired 平台管理员守卫(D7 挂载 admin 路由)
|
||||
func AdminRequired() gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
if c.GetString("role") != "admin" {
|
||||
response.Fail(c, http.StatusForbidden, 1003, "无平台管理权限")
|
||||
c.Abort()
|
||||
return
|
||||
}
|
||||
c.Next()
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user