add preemtive permission handlers

Signed-off-by: RonniSkansing <rskansing@gmail.com>
This commit is contained in:
RonniSkansing committed 2026-10-01 20:25:18 +02:00
1 parent 52c57808ad
commit efea8ce2fc
3 files changed
+40 -5

No files matched your search

+8 -2
View File
@@ -12,10 +12,13 @@ type GeoIP struct {
// GetMetadata returns the available country codes for the filter UI
func (c *GeoIP) GetMetadata(g *gin.Context) {
_, _, ok := c.handleSession(g)
session, _, ok := c.handleSession(g)
if !ok {
return
}
if !c.handleGlobalAuthorization(g, session) {
return
}
codes := ipdata.Get().CountryCodes()
@@ -28,10 +31,13 @@ func (c *GeoIP) GetMetadata(g *gin.Context) {
// Lookup performs a country lookup for the provided IP address
func (c *GeoIP) Lookup(g *gin.Context) {
_, _, ok := c.handleSession(g)
session, _, ok := c.handleSession(g)
if !ok {
return
}
if !c.handleGlobalAuthorization(g, session) {
return
}
ip := g.Query("ip")
if ip == "" {
+12 -3
View File
@@ -58,10 +58,13 @@ func (c *IPData) Remove(g *gin.Context) {
// SearchASN returns ASNs matching the query for the filter typeahead
func (c *IPData) SearchASN(g *gin.Context) {
_, _, ok := c.handleSession(g)
session, _, ok := c.handleSession(g)
if !ok {
return
}
if !c.handleGlobalAuthorization(g, session) {
return
}
q := g.Query("q")
limit := 25
if v := g.Query("limit"); v != "" {
@@ -75,10 +78,13 @@ func (c *IPData) SearchASN(g *gin.Context) {
// LookupASN returns the autonomous systems that announce the given IP address
func (c *IPData) LookupASN(g *gin.Context) {
_, _, ok := c.handleSession(g)
session, _, ok := c.handleSession(g)
if !ok {
return
}
if !c.handleGlobalAuthorization(g, session) {
return
}
ip := g.Query("ip")
if ip == "" {
c.Response.BadRequest(g)
@@ -102,10 +108,13 @@ type ResolveASNRequest struct {
// ResolveASNs returns the details of the given ASNs that exist in the dataset.
// ASNs that are absent are left out, which lets the UI flag orphaned entries.
func (c *IPData) ResolveASNs(g *gin.Context) {
_, _, ok := c.handleSession(g)
session, _, ok := c.handleSession(g)
if !ok {
return
}
if !c.handleGlobalAuthorization(g, session) {
return
}
var req ResolveASNRequest
if ok := c.handleParseRequest(g, &req); !ok {
return
+20
View File
@@ -15,6 +15,7 @@ import (
"github.com/gin-gonic/gin"
"github.com/google/uuid"
"github.com/phishingclub/phishingclub/api"
"github.com/phishingclub/phishingclub/data"
"github.com/phishingclub/phishingclub/errs"
"github.com/phishingclub/phishingclub/model"
"github.com/phishingclub/phishingclub/service"
@@ -58,6 +59,25 @@ func (c *Common) handleSession(
return session, user, true
}
// handleGlobalAuthorization checks the session holds the global permission.
// On a server error or a failed authorization it writes the response and
// returns false.
func (c *Common) handleGlobalAuthorization(
g *gin.Context,
session *model.Session,
) bool {
isAuthorized, err := service.IsAuthorized(session, data.PERMISSION_ALLOW_GLOBAL)
if err != nil && !errors.Is(err, errs.ErrAuthorizationFailed) {
_ = handleServerError(g, c.Response, err)
return false
}
if !isAuthorized {
c.Response.Unauthorized(g)
return false
}
return true
}
// HandleParseRequest parses the request and returns true if successful
// if the request is not parsable, a 400 response is sent
func (c *Common) handleParseRequest(