feat(编辑角色): editor 只能写并发布自己的文章
- D1 users 加 role 列(''/editor/admin),与 is_admin 成对写入 - Worker routes/editor.ts 放行 admin+editor,反代注入 X-Editor-Uid/User/Role(昵称 encodeURIComponent) - editor-api 引入 identify():身份取自注入头或本机会话;文章归属记 frontmatter author_id - 编辑发布改精确 pathspec(只提交自己文章目录),管理员保持全量;空 pathspec 显式拦截 - 国内机直连登录改为转发 CF /user/access_token 校验,CF 不可达回退本机管理员 - handoff 签名覆盖身份(ts/uid/name/role),防编辑一键跳转变管理员 - admin.js:编辑只渲染「文章编辑」tab、作者框只读;用户管理加角色下拉 + 新建用户
This commit is contained in:
1 parent
57dbfe6968
commit
39677e7b40
14 files changed
+1172
-139
No files matched your search
@@ -2,6 +2,7 @@ import type { Env, UserRow } from '../types';
|
||||
import { findUserByEmail, findUserByName, findUserByNameEmail, rateLimit } from '../lib/db';
|
||||
import { cookNotify, cookUser } from '../lib/cook';
|
||||
import { isAdminByNameEmail, signToken, verifyPassword } from '../lib/session';
|
||||
import { roleOf } from '../lib/role';
|
||||
import { fail, getClientIP, isEmail, now, ok, okMsg, qp, readBody, trimTo } from '../lib/util';
|
||||
import type { Ctx } from '../router';
|
||||
|
||||
@@ -97,7 +98,7 @@ export async function userStatus(ctx: Ctx): Promise<Response> {
|
||||
const email = qp(url, 'email');
|
||||
|
||||
if (user) {
|
||||
return ok({ is_admin: !!user.is_admin, is_login: true });
|
||||
return ok({ is_admin: !!user.is_admin, role: roleOf(user), is_login: true });
|
||||
}
|
||||
if (name && email) {
|
||||
return ok({ is_admin: await isAdminByNameEmail(env, name, email), is_login: false });
|
||||
|
||||
Reference in new issue
Block a user