Allow three OAuth consent levels and cache agent permission checks
This commit is contained in:
1 parent
794274d31b
commit
daf9b458af
10 files changed
+245
-22
No files matched your search
@@ -155,8 +155,10 @@ export class AgentManagementController {
|
||||
});
|
||||
return { ok: true };
|
||||
}
|
||||
@Get('authorizations/:id') pending(@Param('id') id: string) {
|
||||
return this.oauth.pending(z.string().uuid().parse(id));
|
||||
@Get('authorizations/:id') async pending(@Req() r: UserRequest, @Param('id') id: string) {
|
||||
const result = await this.oauth.pending(z.string().uuid().parse(id));
|
||||
const user = await this.db.user.findUniqueOrThrow({ where: { id: r.userId } });
|
||||
return { ...result, canWrite: user.role !== 'readonly' };
|
||||
}
|
||||
@Post('authorizations/:id') async consent(
|
||||
@Req() r: UserRequest,
|
||||
|
||||
@@ -162,6 +162,12 @@ export class AgentOAuth implements OAuthServerProvider {
|
||||
name: client?.client_name,
|
||||
redirectUri: p.redirectUri,
|
||||
scopes: p.scopes,
|
||||
availableScopes: [
|
||||
'read',
|
||||
'draft',
|
||||
'write',
|
||||
...p.scopes.filter((s: string) => s.startsWith('hidden_')),
|
||||
],
|
||||
resource: p.resource,
|
||||
};
|
||||
}
|
||||
@@ -188,8 +194,14 @@ export class AgentOAuth implements OAuthServerProvider {
|
||||
allowed.some((s: string) => ['draft', 'write', 'hidden_write'].includes(s))
|
||||
)
|
||||
throw new ForbiddenException('只读账号只能授予查询权限');
|
||||
if (allowed.some((scope: string) => !parameters.scopes.includes(scope)))
|
||||
throw new BadRequestException('不能授予客户端未请求的权限');
|
||||
// The owner explicitly chooses the ordinary permission level on the consent page.
|
||||
// Hidden access still requires a corresponding client request and separate consent.
|
||||
if (
|
||||
allowed.some(
|
||||
(scope: string) => scope.startsWith('hidden_') && !parameters.scopes.includes(scope),
|
||||
)
|
||||
)
|
||||
throw new BadRequestException('不能授予客户端未请求的隐藏权限');
|
||||
const code = secret();
|
||||
const changed = await this.db.agentAuthorization.updateMany({
|
||||
where: { id, status: 'pending', expiresAt: { gt: new Date() } },
|
||||
|
||||
Reference in new issue
Block a user