mirror of
https://github.com/QuantumNous/new-api.git
synced 2026-09-12 23:30:35 +00:00
feat: better admin permissions (#5755)
* feat: add casbin admin permissions * feat: improve audit logging to associate logs with actual operators and target users * feat: enhance admin permissions and UI interactions for sensitive actions * Refactor authz RBAC and tighten channel permissions * Split channel authz field policy * Address channel authz review findings
This commit is contained in:
@@ -0,0 +1,27 @@
|
||||
package authz
|
||||
|
||||
import "strconv"
|
||||
|
||||
// Permission identifies a single action on a resource.
|
||||
type Permission struct {
|
||||
Resource string
|
||||
Action string
|
||||
}
|
||||
|
||||
// PermissionsMap is a resource -> action -> allowed lookup.
|
||||
type PermissionsMap map[string]map[string]bool
|
||||
|
||||
const (
|
||||
EffectAllow = "allow"
|
||||
EffectDeny = "deny"
|
||||
)
|
||||
|
||||
// UserSubject is the casbin subject string for a single user.
|
||||
func UserSubject(userID int) string {
|
||||
return "user:" + strconv.Itoa(userID)
|
||||
}
|
||||
|
||||
// RoleSubject is the casbin subject string for a role.
|
||||
func RoleSubject(roleKey string) string {
|
||||
return "role:" + roleKey
|
||||
}
|
||||
Reference in New Issue
Block a user