HH-548: allow Super Admin sessions to load platform lists (#125)

* fix(HH-548): authorize super admin platform lists

* fix(HH-548): limit dual auth to platform lists

---------

Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
Rogee
2026-08-23 20:21:05 +08:00
committed by GitHub
co-authored by rogee
parent eb83d241fe
commit 8d5d019bb5
8 changed files with 279 additions and 6 deletions
@@ -41,9 +41,18 @@ func NewPlatformAccountHandler(
// GET /platform/api/v1/accounts
// Reference: Chatwoot Platform::Api::V1::AccountsController#index
func (h *PlatformAccountHandler) List(c *gin.Context) {
platformAppID := getPlatformAppID(c)
page := pagination.Parse(c)
if c.GetBool("is_super_admin") {
accounts, total, err := h.accountRepo.FindAll(c.Request.Context(), page.Offset, page.PerPage)
if err != nil {
response.AbortWithStatusError(c, http.StatusInternalServerError, response.ErrInternal, err.Error())
return
}
response.OKWithMeta(c, accounts, page.Page, page.PerPage, total)
return
}
platformAppID := getPlatformAppID(c)
permissibles, err := h.permissibleRepo.FindByPlatformAppID(c.Request.Context(), platformAppID)
if err != nil {
response.AbortWithStatusError(c, http.StatusInternalServerError, response.ErrInternal, err.Error())