H-263 restore PostgreSQL E2E coverage (#41)
Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
@@ -85,12 +85,14 @@ var AgentDefaultPermissions = PermissionMatrixMap{
|
||||
// AdministratorPermissions defines the permission matrix for administrator role.
|
||||
// All dimensions are set to "full".
|
||||
var AdministratorPermissions = PermissionMatrixMap{
|
||||
DimensionConversationManage: PermissionFull,
|
||||
DimensionConversationDelete: PermissionFull,
|
||||
DimensionContactManage: PermissionFull,
|
||||
DimensionReportManage: PermissionFull,
|
||||
DimensionKnowledgeBaseManage: PermissionFull,
|
||||
DimensionAutomationManage: PermissionFull,
|
||||
DimensionConversationManage: PermissionFull,
|
||||
DimensionConversationUnassignedManage: PermissionFull,
|
||||
DimensionConversationParticipatingManage: PermissionFull,
|
||||
DimensionConversationDelete: PermissionFull,
|
||||
DimensionContactManage: PermissionFull,
|
||||
DimensionReportManage: PermissionFull,
|
||||
DimensionKnowledgeBaseManage: PermissionFull,
|
||||
DimensionAutomationManage: PermissionFull,
|
||||
}
|
||||
|
||||
// ToJSON serializes the permission matrix to JSON bytes (for JSONB storage).
|
||||
|
||||
@@ -7,7 +7,6 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
"github.com/golang-jwt/jwt/v5"
|
||||
|
||||
"github.com/gochat/gochat/internal/auth"
|
||||
"github.com/gochat/gochat/internal/config"
|
||||
@@ -119,14 +118,12 @@ func AuthMiddlewareWithServiceAndDB(jwtSvc *auth.JWTService, db *gorm.DB) gin.Ha
|
||||
// DEPRECATED: Prefer JWTService.GenerateTokenPair which produces proper typed Claims.
|
||||
// Kept for backward compatibility with existing test helpers.
|
||||
func GenerateToken(cfg *config.JWTConfig, userID uint, accountID uint, role string) (string, error) {
|
||||
claims := jwt.MapClaims{
|
||||
"user_id": userID,
|
||||
"account_id": accountID,
|
||||
"role": role,
|
||||
"exp": time.Now().Add(cfg.ExpiryDuration()).Unix(),
|
||||
"iat": time.Now().Unix(),
|
||||
pair, err := auth.NewJWTService(cfg).GenerateTokenPair(&model.User{
|
||||
Base: model.Base{ID: userID},
|
||||
Provider: "email",
|
||||
}, accountID, role)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
token := jwt.NewWithClaims(jwt.SigningMethodHS256, claims)
|
||||
return token.SignedString([]byte(cfg.Secret))
|
||||
return pair.AccessToken, nil
|
||||
}
|
||||
|
||||
@@ -199,6 +199,14 @@ func setCSRFTokenCookie(c *gin.Context, token string, cfg CSRFConfig) {
|
||||
if maxAge <= 0 {
|
||||
maxAge = 3600
|
||||
}
|
||||
switch strings.ToLower(cfg.CookieSameSite) {
|
||||
case "lax":
|
||||
c.SetSameSite(http.SameSiteLaxMode)
|
||||
case "none":
|
||||
c.SetSameSite(http.SameSiteNoneMode)
|
||||
default:
|
||||
c.SetSameSite(http.SameSiteStrictMode)
|
||||
}
|
||||
|
||||
c.SetCookie(
|
||||
cfg.CookieName,
|
||||
|
||||
Reference in New Issue
Block a user