package middleware import ( "net/http" "github.com/gin-gonic/gin" "everypublish/server/internal/api/response" ) // WorkspaceRoles enforces the member role from the current JWT. Resource // handlers still apply workspace_id predicates; this middleware only handles // the action-level permission boundary. func WorkspaceRoles(roles ...string) gin.HandlerFunc { allowed := make(map[string]struct{}, len(roles)) for _, role := range roles { allowed[role] = struct{}{} } return func(c *gin.Context) { if _, ok := allowed[c.GetString("mrole")]; !ok { response.Fail(c, http.StatusForbidden, 1003, "当前角色无权执行此操作") c.Abort() return } c.Next() } }