feat: complete remaining Go backend modules
This commit is contained in:
@@ -45,18 +45,34 @@ func (err *PlatformAuthError) Error() string {
|
||||
}
|
||||
|
||||
type PlatformAuthorizer struct {
|
||||
state AuthState
|
||||
resolver SessionResolver
|
||||
now func() time.Time
|
||||
state AuthState
|
||||
resolver SessionResolver
|
||||
now func() time.Time
|
||||
localDevelopmentFallback bool
|
||||
}
|
||||
|
||||
type PlatformAuthorizerOption func(*PlatformAuthorizer)
|
||||
|
||||
// WithLocalDevelopmentFallback controls the privileged demo identity used by
|
||||
// the explicit local backend. Production composition disables it even when a
|
||||
// legacy auth environment value says authentication is optional.
|
||||
func WithLocalDevelopmentFallback(enabled bool) PlatformAuthorizerOption {
|
||||
return func(authorizer *PlatformAuthorizer) { authorizer.localDevelopmentFallback = enabled }
|
||||
}
|
||||
|
||||
// NewPlatformAuthorizer creates the single HTTP-side platform authentication
|
||||
// seam shared by protected route Modules.
|
||||
func NewPlatformAuthorizer(state AuthState, resolver SessionResolver) (*PlatformAuthorizer, error) {
|
||||
func NewPlatformAuthorizer(state AuthState, resolver SessionResolver, options ...PlatformAuthorizerOption) (*PlatformAuthorizer, error) {
|
||||
if state.Configured && resolver == nil {
|
||||
return nil, fmt.Errorf("platform authorization: configured authentication requires a session resolver")
|
||||
}
|
||||
return &PlatformAuthorizer{state: state, resolver: resolver, now: time.Now}, nil
|
||||
authorizer := &PlatformAuthorizer{state: state, resolver: resolver, now: time.Now, localDevelopmentFallback: true}
|
||||
for _, option := range options {
|
||||
if option != nil {
|
||||
option(authorizer)
|
||||
}
|
||||
}
|
||||
return authorizer, nil
|
||||
}
|
||||
|
||||
// Authorize returns either a database-refreshed platform Session, the exact
|
||||
@@ -83,9 +99,15 @@ func (authorizer *PlatformAuthorizer) Authorize(r *http.Request, requirement Pla
|
||||
}
|
||||
}
|
||||
|
||||
if !authorizer.state.Required {
|
||||
if !authorizer.state.Required && authorizer.localDevelopmentFallback {
|
||||
return authorizePlatformRole(authorizer.localSession(), requirement)
|
||||
}
|
||||
if !authorizer.state.Required {
|
||||
return identity.Session{}, &PlatformAuthError{
|
||||
Kind: PlatformUnauthenticated, Status: http.StatusUnauthorized,
|
||||
Message: "请先登录。",
|
||||
}
|
||||
}
|
||||
if !authorizer.state.Configured {
|
||||
return identity.Session{}, &PlatformAuthError{
|
||||
Kind: PlatformConfigurationError, Status: http.StatusServiceUnavailable,
|
||||
|
||||
Reference in New Issue
Block a user