Files
new-api/service/authz/assignment.go
T
Calcium-Ion 4aee5f7d5a feat: better admin permissions (#5755)
* feat: add casbin admin permissions

* feat: improve audit logging to associate logs with actual operators and target users

* feat: enhance admin permissions and UI interactions for sensitive actions

* Refactor authz RBAC and tighten channel permissions

* Split channel authz field policy

* Address channel authz review findings
2026-06-27 17:01:59 +08:00

21 lines
585 B
Go

package authz
import "github.com/QuantumNous/new-api/common"
// resolveSubjectRoles returns the role keys assigned to a subject. The mapping
// is derived from the caller's system role.
var resolveSubjectRoles = func(userID int, systemRole int) []string {
switch {
case systemRole >= common.RoleRootUser:
return []string{BuiltInRoleRoot}
case systemRole >= common.RoleAdminUser:
return []string{BuiltInRoleAdmin}
default:
return nil
}
}
// managedRoleKey is the role whose baseline per-user overrides are expressed
// relative to.
const managedRoleKey = BuiltInRoleAdmin