H-263 restore PostgreSQL E2E coverage (#41)

Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
Rogee
2026-08-18 00:55:45 +08:00
committed by GitHub
co-authored by rogee
parent 9555397b6b
commit a3b01e664e
12 changed files with 222 additions and 266 deletions
+8 -6
View File
@@ -85,12 +85,14 @@ var AgentDefaultPermissions = PermissionMatrixMap{
// AdministratorPermissions defines the permission matrix for administrator role.
// All dimensions are set to "full".
var AdministratorPermissions = PermissionMatrixMap{
DimensionConversationManage: PermissionFull,
DimensionConversationDelete: PermissionFull,
DimensionContactManage: PermissionFull,
DimensionReportManage: PermissionFull,
DimensionKnowledgeBaseManage: PermissionFull,
DimensionAutomationManage: PermissionFull,
DimensionConversationManage: PermissionFull,
DimensionConversationUnassignedManage: PermissionFull,
DimensionConversationParticipatingManage: PermissionFull,
DimensionConversationDelete: PermissionFull,
DimensionContactManage: PermissionFull,
DimensionReportManage: PermissionFull,
DimensionKnowledgeBaseManage: PermissionFull,
DimensionAutomationManage: PermissionFull,
}
// ToJSON serializes the permission matrix to JSON bytes (for JSONB storage).
+7 -10
View File
@@ -7,7 +7,6 @@ import (
"time"
"github.com/gin-gonic/gin"
"github.com/golang-jwt/jwt/v5"
"github.com/gochat/gochat/internal/auth"
"github.com/gochat/gochat/internal/config"
@@ -119,14 +118,12 @@ func AuthMiddlewareWithServiceAndDB(jwtSvc *auth.JWTService, db *gorm.DB) gin.Ha
// DEPRECATED: Prefer JWTService.GenerateTokenPair which produces proper typed Claims.
// Kept for backward compatibility with existing test helpers.
func GenerateToken(cfg *config.JWTConfig, userID uint, accountID uint, role string) (string, error) {
claims := jwt.MapClaims{
"user_id": userID,
"account_id": accountID,
"role": role,
"exp": time.Now().Add(cfg.ExpiryDuration()).Unix(),
"iat": time.Now().Unix(),
pair, err := auth.NewJWTService(cfg).GenerateTokenPair(&model.User{
Base: model.Base{ID: userID},
Provider: "email",
}, accountID, role)
if err != nil {
return "", err
}
token := jwt.NewWithClaims(jwt.SigningMethodHS256, claims)
return token.SignedString([]byte(cfg.Secret))
return pair.AccessToken, nil
}
+8
View File
@@ -199,6 +199,14 @@ func setCSRFTokenCookie(c *gin.Context, token string, cfg CSRFConfig) {
if maxAge <= 0 {
maxAge = 3600
}
switch strings.ToLower(cfg.CookieSameSite) {
case "lax":
c.SetSameSite(http.SameSiteLaxMode)
case "none":
c.SetSameSite(http.SameSiteNoneMode)
default:
c.SetSameSite(http.SameSiteStrictMode)
}
c.SetCookie(
cfg.CookieName,