Release v0.5.2
- Add admin content consistency diagnostics - Add admin-migrate CLI - Harden RBAC for API endpoints - Normalize multi-tenant storage paths - Improve backup and restore compatibility - Fix administrator routing consistency - Improve doctor and stats commands
This commit is contained in:
1 parent
a32c0fd7ca
commit
2761863c14
14 files changed
+437
-75
No files matched your search
@@ -4,11 +4,42 @@ use crate::state::AppState;
|
||||
use axum::{
|
||||
extract::{FromRef, FromRequestParts},
|
||||
http::{request::Parts, StatusCode},
|
||||
Json,
|
||||
};
|
||||
|
||||
// Extractor: Authenticate API requests using Bearer token
|
||||
pub struct ApiUser(pub ApiActor);
|
||||
|
||||
impl ApiUser {
|
||||
pub fn require_admin(
|
||||
&self,
|
||||
) -> Result<&crate::models::User, (StatusCode, Json<crate::web::api::ApiError>)> {
|
||||
match &self.0 {
|
||||
ApiActor::Admin(u) => Ok(u),
|
||||
_ => Err((
|
||||
StatusCode::FORBIDDEN,
|
||||
Json(crate::web::api::ApiError {
|
||||
error: "Admin privileges required".to_string(),
|
||||
}),
|
||||
)),
|
||||
}
|
||||
}
|
||||
|
||||
pub fn require_tenant(
|
||||
&self,
|
||||
) -> Result<&crate::models::TenantUser, (StatusCode, Json<crate::web::api::ApiError>)> {
|
||||
match &self.0 {
|
||||
ApiActor::User(u) => Ok(u),
|
||||
_ => Err((
|
||||
StatusCode::FORBIDDEN,
|
||||
Json(crate::web::api::ApiError {
|
||||
error: "Tenant privileges required".to_string(),
|
||||
}),
|
||||
)),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[axum::async_trait]
|
||||
impl<S> FromRequestParts<S> for ApiUser
|
||||
where
|
||||
|
||||
Reference in new issue
Block a user