feat: better admin permissions (#5755)
* feat: add casbin admin permissions * feat: improve audit logging to associate logs with actual operators and target users * feat: enhance admin permissions and UI interactions for sensitive actions * Refactor authz RBAC and tighten channel permissions * Split channel authz field policy * Address channel authz review findings
This commit is contained in:
@@ -0,0 +1,20 @@
|
||||
package authz
|
||||
|
||||
import "github.com/QuantumNous/new-api/common"
|
||||
|
||||
// resolveSubjectRoles returns the role keys assigned to a subject. The mapping
|
||||
// is derived from the caller's system role.
|
||||
var resolveSubjectRoles = func(userID int, systemRole int) []string {
|
||||
switch {
|
||||
case systemRole >= common.RoleRootUser:
|
||||
return []string{BuiltInRoleRoot}
|
||||
case systemRole >= common.RoleAdminUser:
|
||||
return []string{BuiltInRoleAdmin}
|
||||
default:
|
||||
return nil
|
||||
}
|
||||
}
|
||||
|
||||
// managedRoleKey is the role whose baseline per-user overrides are expressed
|
||||
// relative to.
|
||||
const managedRoleKey = BuiltInRoleAdmin
|
||||
Reference in New Issue
Block a user