Sub2API v1.0 - AI API 网关(二开初始版本,基于上游 Wei-Shaw/sub2api)
Release / update-version (push) Has been cancelled
Release / build-frontend (push) Has been cancelled
Release / release (push) Has been cancelled
Release / sync-version-file (push) Has been cancelled
CI / shell (push) Canceled after 0s
CI / test (push) Canceled after 0s
CI / frontend (push) Canceled after 0s
CI / golangci-lint (push) Canceled after 0s
Security Scan / backend-security (push) Canceled after 0s
Security Scan / frontend-security (push) Canceled after 0s
Release / update-version (push) Has been cancelled
Release / build-frontend (push) Has been cancelled
Release / release (push) Has been cancelled
Release / sync-version-file (push) Has been cancelled
CI / shell (push) Canceled after 0s
CI / test (push) Canceled after 0s
CI / frontend (push) Canceled after 0s
CI / golangci-lint (push) Canceled after 0s
Security Scan / backend-security (push) Canceled after 0s
Security Scan / frontend-security (push) Canceled after 0s
This commit is contained in:
@@ -0,0 +1,53 @@
|
||||
package middleware
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
"github.com/Wei-Shaw/sub2api/internal/service"
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
func AdminComplianceGuard(settingService *service.SettingService) gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
if settingService == nil || isAdminComplianceBypassPath(c.Request.URL.Path) {
|
||||
c.Next()
|
||||
return
|
||||
}
|
||||
|
||||
subject, ok := GetAuthSubjectFromContext(c)
|
||||
if !ok {
|
||||
AbortWithError(c, http.StatusUnauthorized, "UNAUTHORIZED", "Authorization required")
|
||||
return
|
||||
}
|
||||
|
||||
acknowledged, err := settingService.IsAdminComplianceAcknowledged(c.Request.Context(), subject.UserID)
|
||||
if err != nil {
|
||||
AbortWithError(c, http.StatusInternalServerError, "INTERNAL_ERROR", "Internal server error")
|
||||
return
|
||||
}
|
||||
if acknowledged {
|
||||
c.Next()
|
||||
return
|
||||
}
|
||||
|
||||
c.JSON(http.StatusLocked, gin.H{
|
||||
"code": "ADMIN_COMPLIANCE_ACK_REQUIRED",
|
||||
"message": "administrator compliance acknowledgement is required",
|
||||
"metadata": gin.H{
|
||||
"version": service.AdminComplianceVersion,
|
||||
"document_path_zh": service.AdminComplianceDocumentPathZH,
|
||||
"document_path_en": service.AdminComplianceDocumentPathEN,
|
||||
"document_url_zh": service.AdminComplianceDocumentURLZH,
|
||||
"document_url_en": service.AdminComplianceDocumentURLEN,
|
||||
},
|
||||
})
|
||||
c.Abort()
|
||||
}
|
||||
}
|
||||
|
||||
func isAdminComplianceBypassPath(path string) bool {
|
||||
path = strings.TrimSpace(path)
|
||||
return path == "/api/v1/admin/compliance" || strings.HasPrefix(path, "/api/v1/admin/compliance/")
|
||||
}
|
||||
Reference in New Issue
Block a user