后端: Go(Gin+GORM+MySQL+Redis) - 17张业务表(yz_pw_前缀), 自动迁移 - JWT认证(3小时) + 盐+MD5密码 + 图形验证码 - 班级CRUD/加入(8人姓名验证/邀请码)/审核/30天自动清理 - 系统配置(16项)/菜单管理(动态路由)/数据统计 - 文件MD5去重/数据隔离/账号封禁/敏感词DFA检测 前端: Vue3+Vite+Element Plus+Less+ECharts+FontAwesome - 动态路由(数据库菜单驱动) - 蓝白配色, H5响应式 - 登录/注册/忘记密码/个人中心 - 班级创建向导/详情/加入/列表 - 管理后台: 审核/配置/菜单/统计/用户/敏感词 数据库: MySQL 10.31.100.3:3306/photowall 管理员: hero920103 / 920103
83 lines
1.6 KiB
Go
83 lines
1.6 KiB
Go
package middleware
|
|
|
|
import (
|
|
"strings"
|
|
|
|
"photowall/pkg/jwt"
|
|
"photowall/pkg/response"
|
|
|
|
"github.com/gin-gonic/gin"
|
|
)
|
|
|
|
// Context keys
|
|
const (
|
|
CtxUserID = "user_id"
|
|
CtxUsername = "username"
|
|
CtxRole = "role"
|
|
)
|
|
|
|
// Auth JWT 认证中间件
|
|
func Auth(jm *jwt.Manager) gin.HandlerFunc {
|
|
return func(c *gin.Context) {
|
|
header := c.GetHeader("Authorization")
|
|
if header == "" {
|
|
response.Unauthorized(c, "未登录")
|
|
c.Abort()
|
|
return
|
|
}
|
|
parts := strings.SplitN(header, " ", 2)
|
|
if len(parts) != 2 || !strings.EqualFold(parts[0], "Bearer") {
|
|
response.Unauthorized(c, "认证格式错误")
|
|
c.Abort()
|
|
return
|
|
}
|
|
claims, err := jm.Parse(parts[1])
|
|
if err != nil {
|
|
response.Unauthorized(c, "登录已过期,请重新登录")
|
|
c.Abort()
|
|
return
|
|
}
|
|
c.Set(CtxUserID, claims.UserID)
|
|
c.Set(CtxUsername, claims.Username)
|
|
c.Set(CtxRole, claims.Role)
|
|
c.Next()
|
|
}
|
|
}
|
|
|
|
// AdminOnly 平台管理员权限
|
|
func AdminOnly() gin.HandlerFunc {
|
|
return func(c *gin.Context) {
|
|
role, _ := c.Get(CtxRole)
|
|
if role != "admin" {
|
|
response.Forbidden(c, "需要平台管理员权限")
|
|
c.Abort()
|
|
return
|
|
}
|
|
c.Next()
|
|
}
|
|
}
|
|
|
|
// CurrentUserID 从 context 取当前用户ID
|
|
func CurrentUserID(c *gin.Context) uint {
|
|
v, ok := c.Get(CtxUserID)
|
|
if !ok {
|
|
return 0
|
|
}
|
|
id, _ := v.(uint)
|
|
return id
|
|
}
|
|
|
|
// CurrentUsername 从 context 取当前用户名
|
|
func CurrentUsername(c *gin.Context) string {
|
|
v, _ := c.Get(CtxUsername)
|
|
s, _ := v.(string)
|
|
return s
|
|
}
|
|
|
|
// CurrentRole 从 context 取当前角色
|
|
func CurrentRole(c *gin.Context) string {
|
|
v, _ := c.Get(CtxRole)
|
|
s, _ := v.(string)
|
|
return s
|
|
}
|