HH-437: harden production auth and tenant authorization (#84)

* HH-437 harden auth and account authorization

* HH-437 reject revoked platform access

---------

Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
Rogee
2026-08-21 19:13:10 +08:00
committed by GitHub
co-authored by rogee
parent 04c1654086
commit cf263d10b4
22 changed files with 442 additions and 90 deletions
@@ -80,7 +80,7 @@ func (h *PlatformAccountHandler) List(c *gin.Context) {
// Reference: Chatwoot Platform::Api::V1::AccountsController#show
// Requires: Permissible verification
func (h *PlatformAccountHandler) Show(c *gin.Context) {
accountID, err := parseUintParam(c, "id")
accountID, err := parseUintAnyParam(c, "account_id", "id")
if err != nil {
response.AbortWithStatusError(c, http.StatusBadRequest, response.ErrBadRequest, "invalid account ID")
return
@@ -154,7 +154,7 @@ func (h *PlatformAccountHandler) Create(c *gin.Context) {
// Reference: Chatwoot Platform::Api::V1::AccountsController#update
// Requires: Permissible verification
func (h *PlatformAccountHandler) Update(c *gin.Context) {
accountID, err := parseUintParam(c, "id")
accountID, err := parseUintAnyParam(c, "account_id", "id")
if err != nil {
response.AbortWithStatusError(c, http.StatusBadRequest, response.ErrBadRequest, "invalid account ID")
return
@@ -212,7 +212,7 @@ func (h *PlatformAccountHandler) Update(c *gin.Context) {
// Reference: Chatwoot Platform::Api::V1::AccountsController#destroy
// Requires: Permissible verification
func (h *PlatformAccountHandler) Destroy(c *gin.Context) {
accountID, err := parseUintParam(c, "id")
accountID, err := parseUintAnyParam(c, "account_id", "id")
if err != nil {
response.AbortWithStatusError(c, http.StatusBadRequest, response.ErrBadRequest, "invalid account ID")
return