feat(copilot): finish configuration center
This commit is contained in:
@@ -3,6 +3,7 @@ package auth
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/golang-jwt/jwt/v5"
|
||||
@@ -17,9 +18,10 @@ import (
|
||||
// Claims represents JWT token claims.
|
||||
type Claims struct {
|
||||
UserID uint `json:"user_id"`
|
||||
AccountID uint `json:"account_id"` // current active account
|
||||
Role string `json:"role"` // agent/administrator/custom_role
|
||||
Provider string `json:"provider"` // email/google/saml
|
||||
AccountID uint `json:"account_id"` // current active account
|
||||
Role string `json:"role"` // agent/administrator/custom_role
|
||||
UserType string `json:"user_type,omitempty"` // user/super_admin platform identity
|
||||
Provider string `json:"provider"` // email/google/saml
|
||||
CustomRoleID uint `json:"custom_role_id,omitempty"` // enterprise custom role
|
||||
jwt.RegisteredClaims
|
||||
}
|
||||
@@ -45,14 +47,26 @@ func NewJWTService(cfg *config.JWTConfig) *JWTService {
|
||||
// Access Token: 15min expiry with full Claims
|
||||
// Refresh Token: 7 days expiry, only UserID + Provider
|
||||
func (s *JWTService) GenerateTokenPair(user *model.User, accountID uint, role string) (*TokenPair, error) {
|
||||
userType := "user"
|
||||
typeValue := strings.ToLower(strings.ReplaceAll(strings.TrimSpace(user.Type), "_", ""))
|
||||
if user.Role == "super_admin" || role == "super_admin" || typeValue == "superadmin" {
|
||||
userType = "super_admin"
|
||||
}
|
||||
|
||||
// Access Token
|
||||
accessExpiry := time.Now().Add(time.Duration(s.cfg.ExpiryHours) * time.Hour)
|
||||
accessClaims := &Claims{
|
||||
UserID: user.ID,
|
||||
AccountID: accountID,
|
||||
Role: role,
|
||||
Provider: user.Provider,
|
||||
CustomRoleID: func() uint { if user.CustomRoleID != nil { return *user.CustomRoleID }; return 0 }(),
|
||||
UserID: user.ID,
|
||||
AccountID: accountID,
|
||||
Role: role,
|
||||
UserType: userType,
|
||||
Provider: user.Provider,
|
||||
CustomRoleID: func() uint {
|
||||
if user.CustomRoleID != nil {
|
||||
return *user.CustomRoleID
|
||||
}
|
||||
return 0
|
||||
}(),
|
||||
RegisteredClaims: jwt.RegisteredClaims{
|
||||
ExpiresAt: jwt.NewNumericDate(accessExpiry),
|
||||
IssuedAt: jwt.NewNumericDate(time.Now()),
|
||||
@@ -161,4 +175,4 @@ func (s *JWTService) RefreshAccessToken(refreshTokenString string, accountID uin
|
||||
}
|
||||
|
||||
return s.GenerateTokenPair(user, accountID, role)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user