mirror of
https://github.com/go-admin-team/go-admin.git
synced 2026-09-29 04:27:17 +00:00
Every generator route was reachable by any account that could log in: the /gen and /db routes were in CasbinExclude, and the /sys/tables routes were mounted without AuthCheckRole. Any user could read and change any table's configuration and, in dev mode, generate files from it. All thirteen now go through AuthCheckRole. admin is let through as before; another role needs the generator's menus, whose APIs the previous commit binds and grants. The captcha, registered alongside them, stays public.
37 lines
1.3 KiB
Go
37 lines
1.3 KiB
Go
package middleware
|
|
|
|
type UrlInfo struct {
|
|
Url string
|
|
Method string
|
|
}
|
|
|
|
// CasbinExclude casbin 排除的路由列表
|
|
var CasbinExclude = []UrlInfo{
|
|
{Url: "/api/v1/dict/type-option-select", Method: "GET"},
|
|
{Url: "/api/v1/dict-data/option-select", Method: "GET"},
|
|
{Url: "/api/v1/deptTree", Method: "GET"},
|
|
{Url: "/api/v1/getCaptcha", Method: "GET"},
|
|
{Url: "/api/v1/getinfo", Method: "GET"},
|
|
{Url: "/api/v1/menuTreeselect", Method: "GET"},
|
|
{Url: "/api/v1/menurole", Method: "GET"},
|
|
{Url: "/api/v1/menuids", Method: "GET"},
|
|
{Url: "/api/v1/roleMenuTreeselect/:roleId", Method: "GET"},
|
|
{Url: "/api/v1/roleDeptTreeselect/:roleId", Method: "GET"},
|
|
{Url: "/api/v1/configKey/:configKey", Method: "GET"},
|
|
{Url: "/api/v1/app-config", Method: "GET"},
|
|
{Url: "/api/v1/user/profile", Method: "GET"},
|
|
{Url: "/info", Method: "GET"},
|
|
{Url: "/api/v1/login", Method: "POST"},
|
|
{Url: "/api/v1/logout", Method: "POST"},
|
|
{Url: "/api/v1/user/avatar", Method: "POST"},
|
|
{Url: "/api/v1/user/pwd", Method: "PUT"},
|
|
{Url: "/api/v1/metrics", Method: "GET"},
|
|
{Url: "/api/v1/health", Method: "GET"},
|
|
{Url: "/api/v1/ready", Method: "GET"},
|
|
{Url: "/", Method: "GET"},
|
|
{Url: "/api/v1/server-monitor", Method: "GET"},
|
|
{Url: "/api/v1/public/uploadFile", Method: "POST"},
|
|
{Url: "/api/v1/user/pwd/set", Method: "PUT"},
|
|
{Url: "/api/v1/sys-user", Method: "PUT"},
|
|
}
|