mirror of
https://github.com/phishingclub/phishingclub.git
synced 2026-10-03 14:06:51 +02:00
add preemtive permission handlers
Signed-off-by: RonniSkansing <rskansing@gmail.com>
This commit is contained in:
3 files changed
+40
-5
No files matched your search
@@ -15,6 +15,7 @@ import (
|
||||
"github.com/gin-gonic/gin"
|
||||
"github.com/google/uuid"
|
||||
"github.com/phishingclub/phishingclub/api"
|
||||
"github.com/phishingclub/phishingclub/data"
|
||||
"github.com/phishingclub/phishingclub/errs"
|
||||
"github.com/phishingclub/phishingclub/model"
|
||||
"github.com/phishingclub/phishingclub/service"
|
||||
@@ -58,6 +59,25 @@ func (c *Common) handleSession(
|
||||
return session, user, true
|
||||
}
|
||||
|
||||
// handleGlobalAuthorization checks the session holds the global permission.
|
||||
// On a server error or a failed authorization it writes the response and
|
||||
// returns false.
|
||||
func (c *Common) handleGlobalAuthorization(
|
||||
g *gin.Context,
|
||||
session *model.Session,
|
||||
) bool {
|
||||
isAuthorized, err := service.IsAuthorized(session, data.PERMISSION_ALLOW_GLOBAL)
|
||||
if err != nil && !errors.Is(err, errs.ErrAuthorizationFailed) {
|
||||
_ = handleServerError(g, c.Response, err)
|
||||
return false
|
||||
}
|
||||
if !isAuthorized {
|
||||
c.Response.Unauthorized(g)
|
||||
return false
|
||||
}
|
||||
return true
|
||||
}
|
||||
|
||||
// HandleParseRequest parses the request and returns true if successful
|
||||
// if the request is not parsable, a 400 response is sent
|
||||
func (c *Common) handleParseRequest(
|
||||
|
||||
Reference in new issue
Block a user