* feat: add casbin admin permissions * feat: improve audit logging to associate logs with actual operators and target users * feat: enhance admin permissions and UI interactions for sensitive actions * Refactor authz RBAC and tighten channel permissions * Split channel authz field policy * Address channel authz review findings
21 lines
585 B
Go
21 lines
585 B
Go
package authz
|
|
|
|
import "github.com/QuantumNous/new-api/common"
|
|
|
|
// resolveSubjectRoles returns the role keys assigned to a subject. The mapping
|
|
// is derived from the caller's system role.
|
|
var resolveSubjectRoles = func(userID int, systemRole int) []string {
|
|
switch {
|
|
case systemRole >= common.RoleRootUser:
|
|
return []string{BuiltInRoleRoot}
|
|
case systemRole >= common.RoleAdminUser:
|
|
return []string{BuiltInRoleAdmin}
|
|
default:
|
|
return nil
|
|
}
|
|
}
|
|
|
|
// managedRoleKey is the role whose baseline per-user overrides are expressed
|
|
// relative to.
|
|
const managedRoleKey = BuiltInRoleAdmin
|