mirror of
https://github.com/go-admin-team/go-admin.git
synced 2026-10-01 21:27:14 +00:00
AuthCheckRole walks CasbinExclude for every non-admin request, and used casbin's util.KeyMatch2 to test each entry. That delegates to util.RegexMatch, which is regexp.MatchString - it compiles its pattern on every call - so a 32-entry list cost about 2,566 allocations per request before the request reached Enforce. Test the method first, which rules out most entries with a string compare, and take the path test from go-admin-core, whose KeyMatch2 answers the same thing without recompiling. The scan drops to 52ns and no allocations. The loop moves out of AuthCheckRole so the tests exercise the code a request runs rather than a copy of it, and an allocation budget fails if the uncached matcher comes back.