HH-548: allow Super Admin sessions to load platform lists (#125)

* fix(HH-548): authorize super admin platform lists

* fix(HH-548): limit dual auth to platform lists

---------

Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
Rogee
2026-08-23 20:21:05 +08:00
committed by GitHub
co-authored by rogee
parent eb83d241fe
commit 8d5d019bb5
8 changed files with 279 additions and 6 deletions
@@ -275,9 +275,18 @@ func handlePlatformError(c *gin.Context, err error) {
// GET /platform/api/v1/users
// Reference: Chatwoot Platform::Api::V1::UsersController#index (lists permissibles)
func (h *PlatformUserHandler) List(c *gin.Context) {
platformAppID := getPlatformAppID(c)
page := pagination.Parse(c)
if c.GetBool("is_super_admin") {
users, total, err := h.svc.ListUsers(c.Request.Context(), page.Offset, page.PerPage)
if err != nil {
response.AbortWithStatusError(c, http.StatusInternalServerError, response.ErrInternal, err.Error())
return
}
response.OKWithMeta(c, users, page.Page, page.PerPage, total)
return
}
platformAppID := getPlatformAppID(c)
users, err := h.svc.ListPermissibleUsers(c.Request.Context(), platformAppID)
if err != nil {
response.AbortWithStatusError(c, http.StatusInternalServerError, response.ErrInternal, err.Error())