Allow three OAuth consent levels and cache agent permission checks

This commit is contained in:
陈煜 committed 2026-10-05 21:35:37 +08:00
1 parent 794274d31b
commit daf9b458af
10 files changed
+245 -22

No files matched your search

+4 -2
View File
@@ -155,8 +155,10 @@ export class AgentManagementController {
});
return { ok: true };
}
@Get('authorizations/:id') pending(@Param('id') id: string) {
return this.oauth.pending(z.string().uuid().parse(id));
@Get('authorizations/:id') async pending(@Req() r: UserRequest, @Param('id') id: string) {
const result = await this.oauth.pending(z.string().uuid().parse(id));
const user = await this.db.user.findUniqueOrThrow({ where: { id: r.userId } });
return { ...result, canWrite: user.role !== 'readonly' };
}
@Post('authorizations/:id') async consent(
@Req() r: UserRequest,
+14 -2
View File
@@ -162,6 +162,12 @@ export class AgentOAuth implements OAuthServerProvider {
name: client?.client_name,
redirectUri: p.redirectUri,
scopes: p.scopes,
availableScopes: [
'read',
'draft',
'write',
...p.scopes.filter((s: string) => s.startsWith('hidden_')),
],
resource: p.resource,
};
}
@@ -188,8 +194,14 @@ export class AgentOAuth implements OAuthServerProvider {
allowed.some((s: string) => ['draft', 'write', 'hidden_write'].includes(s))
)
throw new ForbiddenException('只读账号只能授予查询权限');
if (allowed.some((scope: string) => !parameters.scopes.includes(scope)))
throw new BadRequestException('不能授予客户端未请求的权限');
// The owner explicitly chooses the ordinary permission level on the consent page.
// Hidden access still requires a corresponding client request and separate consent.
if (
allowed.some(
(scope: string) => scope.startsWith('hidden_') && !parameters.scopes.includes(scope),
)
)
throw new BadRequestException('不能授予客户端未请求的隐藏权限');
const code = secret();
const changed = await this.db.agentAuthorization.updateMany({
where: { id, status: 'pending', expiresAt: { gt: new Date() } },