mirror of
				https://github.com/labring/FastGPT.git
				synced 2025-10-20 18:54:09 +00:00 
			
		
		
		
	 1aebe5f185
			
		
	
	1aebe5f185
	
	
	
		
			
			* feat: add customize toolkit (#3205) * chaoyang * fix-auth * add toolkit * add order * plugin usage * fix * delete console: * Fix: Fix fullscreen preview top positioning and improve Markdown rendering logic (#3247) * 完成任务:修复全屏预览顶部固定问题,优化 Markdown 渲染逻辑 * 有问题修改 * 问题再修改 * 修正问题 * fix: plugin standalone display issue (#3254) * 4.8.15 test (#3246) * o1 config * perf: system plugin code * 调整系统插件代码。增加html 渲染安全配置。 (#3258) * perf: base64 picker * perf: list app or dataset * perf: plugin config code * 小窗适配等问题 (#3257) * 小窗适配等问题 * git问题 * 小窗剩余问题 * feat: system plugin auth and lock version (#3265) * feat: system plugin auth and lock version * update comment * 4.8.15 test (#3267) * tmp log * perf: login direct * perf: iframe html code * remove log * fix: plugin standalone display (#3277) * refactor: 页面拆分&i18n拆分 (#3281) * refactor: account组件拆成独立页面 * script: 新增i18n json文件创建脚本 * refactor: 页面i18n拆分 * i18n: add en&hant * 4.8.15 test (#3285) * tmp log * remove log * fix: watch avatar refresh * perf: i18n code * fix(plugin): use intro instead of userguide (#3290) * Universal SSO (#3292) * tmp log * remove log * feat: common oauth * readme * perf: sso provider * remove sso code * perf: refresh plugins * feat: add api dataset (#3272) * add api-dataset * fix api-dataset * fix api dataset * fix ts * perf: create collection code (#3301) * tmp log * remove log * perf: i18n change * update version doc * feat: question guide from chatId * perf: create collection code * fix: request api * fix: request api * fix: tts auth and response type (#3303) * perf: md splitter * fix: tts auth and response type * fix: api file dataset (#3307) * perf: api dataset init (#3310) * perf: collection schema * perf: api dataset init * refactor: 团队管理独立页面 (#3302) * ui: 团队管理独立页面 * 代码优化 * fix * perf: sync collection and ui check (#3314) * perf: sync collection * remove script * perf: update api server * perf: api dataset parent * perf: team ui * perf: team 18n * update team ui * perf: ui check * perf: i18n * fix: debug variables & cronjob & system plugin callback load (#3315) * fix: debug variables & cronjob & system plugin callback load * fix type * fix * fix * fix: plugin dataset quote;perf: system variables init (#3316) * fix: plugin dataset quote * perf: system variables init * perf: node templates ui;fix: dataset import ui (#3318) * fix: dataset import ui * perf: node templates ui * perf: ui refresh * feat:套餐改名和套餐跳转配置 (#3309) * fixing:except Sidebar * 去除了多余的代码 * 修正了套餐说明的代码 * 修正了误删除的show_git代码 * 修正了名字部分等代码 * 修正了问题,遗留了其他和ui讨论不一致的部分 * 4.8.15 test (#3319) * remove log * pref: bill ui * pref: bill ui * perf: log * html渲染文档 (#3270) * html渲染文档 * 文档有点小问题 * feat: doc (#3322) * 集合重训练 (#3282) * rebaser * 一点补充 * 小问题 * 其他问题修正,删除集合保留文件的参数还没找到... * reTraining * delete uesless * 删除了一行错误代码 * 集合重训练部分 * fixing * 删除console代码 * feat: navbar item config (#3326) * perf: custom navbar code;perf: retraining code;feat: api dataset and dataset api doc (#3329) * feat: api dataset and dataset api doc * perf: retraining code * perf: custom navbar code * fix: ts (#3330) * fix: ts * fix: ts * retraining ui * perf: api collection filter * perf: retrining button --------- Co-authored-by: heheer <heheer@sealos.io> Co-authored-by: Jiangween <145003935+Jiangween@users.noreply.github.com> Co-authored-by: papapatrick <109422393+Patrickill@users.noreply.github.com>
		
			
				
	
	
		
			164 lines
		
	
	
		
			4.0 KiB
		
	
	
	
		
			TypeScript
		
	
	
	
	
	
			
		
		
	
	
			164 lines
		
	
	
		
			4.0 KiB
		
	
	
	
		
			TypeScript
		
	
	
	
	
	
| /* Auth app permission */
 | |
| import { MongoApp } from '../../../core/app/schema';
 | |
| import { AppDetailType } from '@fastgpt/global/core/app/type.d';
 | |
| import { parseHeaderCert } from '../controller';
 | |
| import { PerResourceTypeEnum } from '@fastgpt/global/support/permission/constant';
 | |
| import { AppErrEnum } from '@fastgpt/global/common/error/code/app';
 | |
| import { getTmbInfoByTmbId } from '../../user/team/controller';
 | |
| import { getResourcePermission } from '../controller';
 | |
| import { AppPermission } from '@fastgpt/global/support/permission/app/controller';
 | |
| import { PermissionValueType } from '@fastgpt/global/support/permission/type';
 | |
| import { AppFolderTypeList } from '@fastgpt/global/core/app/constants';
 | |
| import { ParentIdType } from '@fastgpt/global/common/parentFolder/type';
 | |
| import { splitCombinePluginId } from '../../../core/app/plugin/controller';
 | |
| import { PluginSourceEnum } from '@fastgpt/global/core/plugin/constants';
 | |
| import { AuthModeType, AuthResponseType } from '../type';
 | |
| import { AppDefaultPermissionVal } from '@fastgpt/global/support/permission/app/constant';
 | |
| 
 | |
| export const authPluginByTmbId = async ({
 | |
|   tmbId,
 | |
|   appId,
 | |
|   per
 | |
| }: {
 | |
|   tmbId: string;
 | |
|   appId: string;
 | |
|   per: PermissionValueType;
 | |
| }) => {
 | |
|   const { source } = await splitCombinePluginId(appId);
 | |
|   if (source === PluginSourceEnum.personal) {
 | |
|     const { app } = await authAppByTmbId({
 | |
|       appId,
 | |
|       tmbId,
 | |
|       per
 | |
|     });
 | |
| 
 | |
|     return app;
 | |
|   }
 | |
| 
 | |
|   // commercial custom plugin already checked in "getSystemPluginTemplateById"
 | |
| };
 | |
| 
 | |
| export const authAppByTmbId = async ({
 | |
|   tmbId,
 | |
|   appId,
 | |
|   per,
 | |
|   isRoot
 | |
| }: {
 | |
|   tmbId: string;
 | |
|   appId: string;
 | |
|   per: PermissionValueType;
 | |
|   isRoot?: boolean;
 | |
| }): Promise<{
 | |
|   app: AppDetailType;
 | |
| }> => {
 | |
|   const { teamId, permission: tmbPer } = await getTmbInfoByTmbId({ tmbId });
 | |
| 
 | |
|   const app = await (async () => {
 | |
|     const app = await MongoApp.findOne({ _id: appId }).lean();
 | |
| 
 | |
|     if (!app) {
 | |
|       return Promise.reject(AppErrEnum.unExist);
 | |
|     }
 | |
| 
 | |
|     if (isRoot) {
 | |
|       return {
 | |
|         ...app,
 | |
|         permission: new AppPermission({ isOwner: true })
 | |
|       };
 | |
|     }
 | |
| 
 | |
|     if (String(app.teamId) !== teamId) {
 | |
|       return Promise.reject(AppErrEnum.unAuthApp);
 | |
|     }
 | |
| 
 | |
|     const isOwner = tmbPer.isOwner || String(app.tmbId) === String(tmbId);
 | |
| 
 | |
|     const { Per } = await (async () => {
 | |
|       if (isOwner) {
 | |
|         return {
 | |
|           Per: new AppPermission({ isOwner: true })
 | |
|         };
 | |
|       }
 | |
| 
 | |
|       if (
 | |
|         AppFolderTypeList.includes(app.type) ||
 | |
|         app.inheritPermission === false ||
 | |
|         !app.parentId
 | |
|       ) {
 | |
|         // 1. is a folder. (Folders have compeletely permission)
 | |
|         // 2. inheritPermission is false.
 | |
|         // 3. is root folder/app.
 | |
|         const rp = await getResourcePermission({
 | |
|           teamId,
 | |
|           tmbId,
 | |
|           resourceId: appId,
 | |
|           resourceType: PerResourceTypeEnum.app
 | |
|         });
 | |
|         const Per = new AppPermission({ per: rp ?? AppDefaultPermissionVal, isOwner });
 | |
|         return {
 | |
|           Per
 | |
|         };
 | |
|       } else {
 | |
|         // is not folder and inheritPermission is true and is not root folder.
 | |
|         const { app: parent } = await authAppByTmbId({
 | |
|           tmbId,
 | |
|           appId: app.parentId,
 | |
|           per
 | |
|         });
 | |
| 
 | |
|         const Per = new AppPermission({
 | |
|           per: parent.permission.value,
 | |
|           isOwner
 | |
|         });
 | |
|         return {
 | |
|           Per
 | |
|         };
 | |
|       }
 | |
|     })();
 | |
| 
 | |
|     if (!Per.checkPer(per)) {
 | |
|       return Promise.reject(AppErrEnum.unAuthApp);
 | |
|     }
 | |
| 
 | |
|     return {
 | |
|       ...app,
 | |
|       permission: Per
 | |
|     };
 | |
|   })();
 | |
| 
 | |
|   return { app };
 | |
| };
 | |
| 
 | |
| export const authApp = async ({
 | |
|   appId,
 | |
|   per,
 | |
|   ...props
 | |
| }: AuthModeType & {
 | |
|   appId: ParentIdType;
 | |
|   per: PermissionValueType;
 | |
| }): Promise<
 | |
|   AuthResponseType & {
 | |
|     app: AppDetailType;
 | |
|   }
 | |
| > => {
 | |
|   const result = await parseHeaderCert(props);
 | |
|   const { tmbId } = result;
 | |
| 
 | |
|   if (!appId) {
 | |
|     return Promise.reject(AppErrEnum.unExist);
 | |
|   }
 | |
| 
 | |
|   const { app } = await authAppByTmbId({
 | |
|     tmbId,
 | |
|     appId,
 | |
|     per,
 | |
|     isRoot: result.isRoot
 | |
|   });
 | |
| 
 | |
|   return {
 | |
|     ...result,
 | |
|     permission: app.permission,
 | |
|     app
 | |
|   };
 | |
| };
 |