chore: 去掉未上线前的旧兼容垫片,板块流收口到首页
鉴权只认 cookie、SEO 只走 Next、sort 与推荐对齐;删除 Bearer、Go sitemap、post_type 回填等冗余路径。 Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -3,9 +3,7 @@ package middleware
|
||||
import (
|
||||
"errors"
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
"github.com/freefire/jiang13-bbs/model"
|
||||
"github.com/freefire/jiang13-bbs/service"
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
@@ -60,27 +58,6 @@ func (m *AuthMiddleware) RequireAuth() gin.HandlerFunc {
|
||||
}
|
||||
}
|
||||
|
||||
// RequireAdmin 必须管理员(保留兼容;等价于"管理员及以上",不含纯板块管理员)
|
||||
func (m *AuthMiddleware) RequireAdmin() gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
user, ok := m.parseToken(c)
|
||||
if !ok {
|
||||
if c.GetBool(AccountBannedKey) {
|
||||
bannedJSON(c)
|
||||
return
|
||||
}
|
||||
c.AbortWithStatusJSON(http.StatusUnauthorized, gin.H{"error": "未登录"})
|
||||
return
|
||||
}
|
||||
if model.RoleLevel(model.Role(user.Role)) < model.RoleLevel(model.RoleAdmin) {
|
||||
c.AbortWithStatusJSON(http.StatusForbidden, gin.H{"error": "需要管理员权限"})
|
||||
return
|
||||
}
|
||||
c.Set("user", user)
|
||||
c.Next()
|
||||
}
|
||||
}
|
||||
|
||||
// ActorKey 实时权限快照在 gin.Context 中的键
|
||||
const ActorKey = "actor"
|
||||
|
||||
@@ -121,20 +98,13 @@ func (m *AuthMiddleware) RequirePerm(perm string) gin.HandlerFunc {
|
||||
}
|
||||
|
||||
// parseToken 解析并校验 token:
|
||||
// 1. 优先从 HttpOnly cookie 读取,回退 Authorization header
|
||||
// 1. 从 HttpOnly cookie(j13_token / 生产 __Host-j13_token)读取
|
||||
// 2. 校验 JWT 签名和过期
|
||||
// 3. 查 DB 实时校验 token_version 和 banned 状态
|
||||
func (m *AuthMiddleware) parseToken(c *gin.Context) (*service.UserClaims, bool) {
|
||||
tokenStr, err := c.Cookie(service.CookieName)
|
||||
if err != nil || tokenStr == "" {
|
||||
auth := c.GetHeader("Authorization")
|
||||
if auth == "" {
|
||||
return nil, false
|
||||
}
|
||||
tokenStr = strings.TrimPrefix(auth, "Bearer ")
|
||||
if tokenStr == auth {
|
||||
return nil, false
|
||||
}
|
||||
return nil, false
|
||||
}
|
||||
claims, err := m.auth.ParseToken(tokenStr)
|
||||
if err != nil {
|
||||
|
||||
@@ -32,9 +32,6 @@ func SecurityHeaders() gin.HandlerFunc {
|
||||
// 控制 Referer 信息泄露
|
||||
c.Header("Referrer-Policy", "strict-origin-when-cross-origin")
|
||||
|
||||
// XSS 防护(旧浏览器兼容,现代浏览器靠 CSP)
|
||||
c.Header("X-XSS-Protection", "1; mode=block")
|
||||
|
||||
// 禁止浏览器缓存敏感页面(可按需覆盖)
|
||||
// c.Header("Cache-Control", "no-store, no-cache, must-revalidate, max-age=0")
|
||||
|
||||
|
||||
Reference in New Issue
Block a user