fix(platform): harden auth and build integration
This commit is contained in:
@@ -99,7 +99,9 @@ export function useProjectionStream(opts: ProjectionStreamOptions = {}) {
|
||||
|
||||
if (es) return
|
||||
try {
|
||||
es = new EventSource(url)
|
||||
// withCredentials:让浏览器把 httpOnly 鉴权 Cookie (simple.auth.token) 随 SSE 一起带上,
|
||||
// 配合后端给 /api/sl/* 反代加的鉴权(EventSource 无法设置 Authorization header,只能靠 Cookie)。
|
||||
es = new EventSource(url, { withCredentials: true })
|
||||
} catch {
|
||||
scheduleReconnect()
|
||||
return
|
||||
|
||||
@@ -89,7 +89,11 @@ export const useAuthStore = defineStore('auth', {
|
||||
(s) =>
|
||||
(widgetId: string): 'hidden' | 'readonly' | 'interactive' => {
|
||||
const grant = s.effectivePermissions?.visibleWidgets.find((w) => w.widgetId === widgetId)
|
||||
return grant?.visibility ?? 'interactive'
|
||||
if (grant) return grant.visibility
|
||||
// fail-safe:未显式授权的控件不再默认放开为 interactive(曾导致受限账号越权)。
|
||||
// 超级管理员(allowedOps 含 '*')默认 interactive;其余账号默认 readonly(可见不可改)。
|
||||
const ops = s.effectivePermissions?.allowedOps ?? []
|
||||
return ops.includes('*') ? 'interactive' : 'readonly'
|
||||
},
|
||||
/**
|
||||
* 当前用户在当前 scope 下是否可访问指定页面(route.name)。
|
||||
|
||||
Reference in New Issue
Block a user