feat: add local auth billing and usage management

This commit is contained in:
inman committed 2026-08-12 12:13:06 +08:00
1 parent f642b5e71f
commit 196fdde83f
119 files changed
+15695 -2650

No files matched your search

+18 -11
View File
@@ -1,6 +1,6 @@
import { NextResponse, type NextRequest } from "next/server";
import { SESSION_COOKIE_NAME, getAuthRuntimeConfig, safeNextPath } from "@/lib/auth/config";
import { hasAdminAccess } from "@/lib/auth/permissions";
import { hasAdminSessionAccess, hasSuperAdminAccess } from "@/lib/auth/permissions";
import { parseSessionCookieValue, readChunkedCookieValue } from "@/lib/auth/session";
export async function middleware(request: NextRequest) {
@@ -14,11 +14,17 @@ export async function middleware(request: NextRequest) {
config.sessionSecret
);
if (session) {
if (isAdminPath(pathname) && !hasAdminAccess(session.user)) {
const access = requiredAccess(pathname);
const allowed = access === "super"
? hasSuperAdminAccess(session.user)
: access === "admin"
? hasAdminSessionAccess(session)
: true;
if (!allowed) {
if (pathname.startsWith("/api/")) {
return NextResponse.json({ error: "需要管理员权限。" }, { status: 403 });
return NextResponse.json({ error: access === "super" ? "需要超级管理员权限。" : "需要管理员权限。" }, { status: 403 });
}
return NextResponse.redirect(new URL("/create", request.url));
return NextResponse.redirect(new URL(access === "super" ? "/create" : "/create", request.url));
}
return NextResponse.next();
}
@@ -44,11 +50,15 @@ export const config = {
"/logs/:path*",
"/settings/:path*",
"/accounts/:path*",
"/usage/:path*",
"/billing/:path*",
"/image-edit/:path*",
"/uploads/:path*",
"/generated-results/:path*",
"/api/assets/:path*",
"/api/generations/:path*",
"/api/usage/:path*",
"/api/billing/:path*",
"/api/logs/:path*",
"/api/prompt/:path*",
"/api/settings/:path*",
@@ -56,11 +66,8 @@ export const config = {
]
};
function isAdminPath(pathname: string): boolean {
return pathname.startsWith("/logs") ||
pathname.startsWith("/settings") ||
pathname.startsWith("/accounts") ||
pathname.startsWith("/api/logs") ||
pathname.startsWith("/api/settings") ||
pathname.startsWith("/api/admin");
function requiredAccess(pathname: string): "super" | "admin" | null {
if (pathname.startsWith("/logs") || pathname.startsWith("/api/logs") || pathname.startsWith("/api/settings")) return "super";
if (pathname.startsWith("/usage") || pathname.startsWith("/api/admin")) return "admin";
return null;
}