feat(custom-roles): align chatwoot permissions

This commit is contained in:
2026-06-05 11:14:38 +08:00
parent b5f2a47ef8
commit 8b3b532c65
20 changed files with 681 additions and 226 deletions
+59 -8
View File
@@ -5,9 +5,9 @@ import (
"github.com/gin-gonic/gin"
"github.com/gochat/gochat/internal/model"
"github.com/gochat/gochat/internal/service"
applogger "github.com/gochat/gochat/pkg/logger"
"github.com/gochat/gochat/pkg/pagination"
"github.com/gochat/gochat/pkg/response"
)
@@ -36,16 +36,19 @@ func (h *CustomRoleHandler) List(c *gin.Context) {
response.AbortWithStatusError(c, http.StatusUnauthorized, response.ErrUnauthorized, "account not identified")
return
}
if !isCustomRoleAdmin(c) {
response.AbortWithStatusError(c, http.StatusUnauthorized, response.ErrUnauthorized, "administrator role required")
return
}
pg := pagination.Parse(c)
roles, total, err := h.svc.List(c.Request.Context(), accountID, pg.Page, pg.PerPage)
roles, _, err := h.svc.List(c.Request.Context(), accountID, 1, 10000)
if err != nil {
applogger.L().Errorf("List custom roles for account %d: %v", accountID, err)
handleServiceError(c, err)
return
}
response.OKWithMeta(c, roles, pg.Page, pg.PerPage, total)
c.JSON(http.StatusOK, serializeCustomRoles(roles))
}
// Create creates a new custom role for an account.
@@ -57,6 +60,10 @@ func (h *CustomRoleHandler) Create(c *gin.Context) {
response.AbortWithStatusError(c, http.StatusUnauthorized, response.ErrUnauthorized, "account not identified")
return
}
if !isCustomRoleAdmin(c) {
response.AbortWithStatusError(c, http.StatusUnauthorized, response.ErrUnauthorized, "administrator role required")
return
}
var wrapper struct {
CustomRole service.CreateCustomRoleRequest `json:"custom_role"`
@@ -80,7 +87,7 @@ func (h *CustomRoleHandler) Create(c *gin.Context) {
AuditedChanges: role,
})
response.Created(c, role)
c.JSON(http.StatusOK, serializeCustomRole(role))
}
// Get returns a single custom role by ID.
@@ -91,6 +98,10 @@ func (h *CustomRoleHandler) Get(c *gin.Context) {
response.AbortWithStatusError(c, http.StatusUnauthorized, response.ErrUnauthorized, "account not identified")
return
}
if !isCustomRoleAdmin(c) {
response.AbortWithStatusError(c, http.StatusUnauthorized, response.ErrUnauthorized, "administrator role required")
return
}
id, err := parseUintParam(c, "id")
if err != nil {
@@ -105,7 +116,7 @@ func (h *CustomRoleHandler) Get(c *gin.Context) {
return
}
response.OK(c, role)
c.JSON(http.StatusOK, serializeCustomRole(role))
}
// Update updates an existing custom role.
@@ -117,6 +128,10 @@ func (h *CustomRoleHandler) Update(c *gin.Context) {
response.AbortWithStatusError(c, http.StatusUnauthorized, response.ErrUnauthorized, "account not identified")
return
}
if !isCustomRoleAdmin(c) {
response.AbortWithStatusError(c, http.StatusUnauthorized, response.ErrUnauthorized, "administrator role required")
return
}
id, err := parseUintParam(c, "id")
if err != nil {
@@ -146,7 +161,7 @@ func (h *CustomRoleHandler) Update(c *gin.Context) {
AuditedChanges: role,
})
response.OK(c, role)
c.JSON(http.StatusOK, serializeCustomRole(role))
}
// Delete soft-deletes a custom role.
@@ -157,6 +172,10 @@ func (h *CustomRoleHandler) Delete(c *gin.Context) {
response.AbortWithStatusError(c, http.StatusUnauthorized, response.ErrUnauthorized, "account not identified")
return
}
if !isCustomRoleAdmin(c) {
response.AbortWithStatusError(c, http.StatusUnauthorized, response.ErrUnauthorized, "administrator role required")
return
}
id, err := parseUintParam(c, "id")
if err != nil {
@@ -177,7 +196,7 @@ func (h *CustomRoleHandler) Delete(c *gin.Context) {
AuditedChanges: gin.H{"id": id},
})
response.NoContent(c)
c.Status(http.StatusOK)
}
// RegisterCustomRoleRoutes registers custom role routes on a gin.RouterGroup.
@@ -191,3 +210,35 @@ func RegisterCustomRoleRoutes(rg *gin.RouterGroup, h *CustomRoleHandler) {
customRoles.DELETE("/:id", h.Delete)
}
}
func isCustomRoleAdmin(c *gin.Context) bool {
role := getRole(c)
return role == "administrator" || role == "super_admin"
}
func serializeCustomRoles(roles []model.CustomRole) []gin.H {
items := make([]gin.H, 0, len(roles))
for i := range roles {
items = append(items, serializeCustomRole(&roles[i]))
}
return items
}
func serializeCustomRole(role *model.CustomRole) gin.H {
permissions, err := role.GetPermissionKeys()
if err != nil {
permissions = []model.PermissionDimension{}
}
permissionStrings := make([]string, 0, len(permissions))
for _, key := range permissions {
permissionStrings = append(permissionStrings, string(key))
}
return gin.H{
"id": role.ID,
"name": role.Name,
"description": role.Description,
"permissions": permissionStrings,
"created_at": role.CreatedAt,
"updated_at": role.UpdatedAt,
}
}