feat: complete remaining Go backend modules

This commit is contained in:
2026-08-14 00:02:43 +08:00
parent cea2751dc5
commit aef5a97165
145 changed files with 18376 additions and 199 deletions

View File

@@ -45,18 +45,34 @@ func (err *PlatformAuthError) Error() string {
}
type PlatformAuthorizer struct {
state AuthState
resolver SessionResolver
now func() time.Time
state AuthState
resolver SessionResolver
now func() time.Time
localDevelopmentFallback bool
}
type PlatformAuthorizerOption func(*PlatformAuthorizer)
// WithLocalDevelopmentFallback controls the privileged demo identity used by
// the explicit local backend. Production composition disables it even when a
// legacy auth environment value says authentication is optional.
func WithLocalDevelopmentFallback(enabled bool) PlatformAuthorizerOption {
return func(authorizer *PlatformAuthorizer) { authorizer.localDevelopmentFallback = enabled }
}
// NewPlatformAuthorizer creates the single HTTP-side platform authentication
// seam shared by protected route Modules.
func NewPlatformAuthorizer(state AuthState, resolver SessionResolver) (*PlatformAuthorizer, error) {
func NewPlatformAuthorizer(state AuthState, resolver SessionResolver, options ...PlatformAuthorizerOption) (*PlatformAuthorizer, error) {
if state.Configured && resolver == nil {
return nil, fmt.Errorf("platform authorization: configured authentication requires a session resolver")
}
return &PlatformAuthorizer{state: state, resolver: resolver, now: time.Now}, nil
authorizer := &PlatformAuthorizer{state: state, resolver: resolver, now: time.Now, localDevelopmentFallback: true}
for _, option := range options {
if option != nil {
option(authorizer)
}
}
return authorizer, nil
}
// Authorize returns either a database-refreshed platform Session, the exact
@@ -83,9 +99,15 @@ func (authorizer *PlatformAuthorizer) Authorize(r *http.Request, requirement Pla
}
}
if !authorizer.state.Required {
if !authorizer.state.Required && authorizer.localDevelopmentFallback {
return authorizePlatformRole(authorizer.localSession(), requirement)
}
if !authorizer.state.Required {
return identity.Session{}, &PlatformAuthError{
Kind: PlatformUnauthenticated, Status: http.StatusUnauthorized,
Message: "请先登录。",
}
}
if !authorizer.state.Configured {
return identity.Session{}, &PlatformAuthError{
Kind: PlatformConfigurationError, Status: http.StatusServiceUnavailable,