feat: add local auth billing and usage management
This commit is contained in:
1 parent
f642b5e71f
commit
196fdde83f
119 files changed
+15695
-2650
No files matched your search
+18
-11
@@ -1,6 +1,6 @@
|
||||
import { NextResponse, type NextRequest } from "next/server";
|
||||
import { SESSION_COOKIE_NAME, getAuthRuntimeConfig, safeNextPath } from "@/lib/auth/config";
|
||||
import { hasAdminAccess } from "@/lib/auth/permissions";
|
||||
import { hasAdminSessionAccess, hasSuperAdminAccess } from "@/lib/auth/permissions";
|
||||
import { parseSessionCookieValue, readChunkedCookieValue } from "@/lib/auth/session";
|
||||
|
||||
export async function middleware(request: NextRequest) {
|
||||
@@ -14,11 +14,17 @@ export async function middleware(request: NextRequest) {
|
||||
config.sessionSecret
|
||||
);
|
||||
if (session) {
|
||||
if (isAdminPath(pathname) && !hasAdminAccess(session.user)) {
|
||||
const access = requiredAccess(pathname);
|
||||
const allowed = access === "super"
|
||||
? hasSuperAdminAccess(session.user)
|
||||
: access === "admin"
|
||||
? hasAdminSessionAccess(session)
|
||||
: true;
|
||||
if (!allowed) {
|
||||
if (pathname.startsWith("/api/")) {
|
||||
return NextResponse.json({ error: "需要管理员权限。" }, { status: 403 });
|
||||
return NextResponse.json({ error: access === "super" ? "需要超级管理员权限。" : "需要管理员权限。" }, { status: 403 });
|
||||
}
|
||||
return NextResponse.redirect(new URL("/create", request.url));
|
||||
return NextResponse.redirect(new URL(access === "super" ? "/create" : "/create", request.url));
|
||||
}
|
||||
return NextResponse.next();
|
||||
}
|
||||
@@ -44,11 +50,15 @@ export const config = {
|
||||
"/logs/:path*",
|
||||
"/settings/:path*",
|
||||
"/accounts/:path*",
|
||||
"/usage/:path*",
|
||||
"/billing/:path*",
|
||||
"/image-edit/:path*",
|
||||
"/uploads/:path*",
|
||||
"/generated-results/:path*",
|
||||
"/api/assets/:path*",
|
||||
"/api/generations/:path*",
|
||||
"/api/usage/:path*",
|
||||
"/api/billing/:path*",
|
||||
"/api/logs/:path*",
|
||||
"/api/prompt/:path*",
|
||||
"/api/settings/:path*",
|
||||
@@ -56,11 +66,8 @@ export const config = {
|
||||
]
|
||||
};
|
||||
|
||||
function isAdminPath(pathname: string): boolean {
|
||||
return pathname.startsWith("/logs") ||
|
||||
pathname.startsWith("/settings") ||
|
||||
pathname.startsWith("/accounts") ||
|
||||
pathname.startsWith("/api/logs") ||
|
||||
pathname.startsWith("/api/settings") ||
|
||||
pathname.startsWith("/api/admin");
|
||||
function requiredAccess(pathname: string): "super" | "admin" | null {
|
||||
if (pathname.startsWith("/logs") || pathname.startsWith("/api/logs") || pathname.startsWith("/api/settings")) return "super";
|
||||
if (pathname.startsWith("/usage") || pathname.startsWith("/api/admin")) return "admin";
|
||||
return null;
|
||||
}
|
||||
Reference in new issue
Block a user