完善角色与消息权限:收紧板管内容处置,彻底删除仅站长,并统一管理删帖/评弹窗。

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-09-20 14:30:08 +08:00
parent 1f2e4b2a33
commit c0462a3500
37 changed files with 1340 additions and 472 deletions

View File

@@ -435,6 +435,13 @@ func (s *CommentService) Delete(actor *Actor, commentID, userID uint, opts Delet
if actor == nil || !actor.CanModerateBoard(post.BoardID) {
return ErrCommentForbidden
}
var author model.User
if err := s.db.Select("role").First(&author, comment.UserID).Error; err != nil {
return ErrCommentNotFound
}
if !actor.CanModerateAuthor(author.Role) {
return ErrAuthorProtected
}
deleteType = strings.TrimSpace(opts.DeleteType)
if !model.ValidPostDeleteType(deleteType) {
return ErrCommentInvalidType
@@ -490,6 +497,13 @@ func (s *CommentService) Restore(actor *Actor, commentID, userID uint) error {
return ErrCommentNotFound
}
if actor != nil && actor.CanModerateBoard(post.BoardID) {
var author model.User
if err := s.db.Select("role").First(&author, comment.UserID).Error; err != nil {
return ErrCommentNotFound
}
if !actor.CanModerateAuthor(author.Role) {
return ErrAuthorProtected
}
allowed = true
}
}
@@ -546,6 +560,9 @@ func (s *CommentService) collectDescendantIDs(comment model.Comment) []uint {
// Purge 硬删评论及子树(仅板块审核权);不占位;对尚未软删的已发布条递减 comment_count。
func (s *CommentService) Purge(actor *Actor, commentID, userID uint) error {
if actor == nil || !actor.CanPurgeContent() {
return ErrPurgeOwnerOnly
}
var comment model.Comment
if err := s.db.Unscoped().First(&comment, commentID).Error; err != nil {
return ErrCommentNotFound
@@ -554,7 +571,7 @@ func (s *CommentService) Purge(actor *Actor, commentID, userID uint) error {
if err := s.db.Select("id", "board_id").First(&post, comment.PostID).Error; err != nil {
return ErrCommentNotFound
}
if actor == nil || !actor.CanModerateBoard(post.BoardID) {
if !actor.CanModerateBoard(post.BoardID) {
return ErrCommentForbidden
}
_ = userID