mirror of
https://github.com/labring/FastGPT.git
synced 2026-05-14 01:08:04 +08:00
a499d05a02
* feat: migrate chat files to s3 (#5802) * feat: migrate chat files to s3 * feat: add delete jobs for deleting s3 files * chore: improvements * fix: lockfile * fix: imports * feat: add ttl for those uploaded files but not send yet * feat: init bullmq worker * fix: s3 key * perf: s3 internal url * remove env * fix: re-sign a new url * fix: re-sign a new url * perf: s3 code --------- Co-authored-by: archer <545436317@qq.com> * update pacakge * feat: add more file type for uploading (#5807) * fix: re-sign a new url * wip: file selector * feat: add more file type for uploading * feat: migrate chat files to s3 (#5802) * feat: migrate chat files to s3 * feat: add delete jobs for deleting s3 files * chore: improvements * fix: lockfile * fix: imports * feat: add ttl for those uploaded files but not send yet * feat: init bullmq worker * fix: s3 key * perf: s3 internal url * remove env * fix: re-sign a new url * fix: re-sign a new url * perf: s3 code --------- Co-authored-by: archer <545436317@qq.com> * fix: limit minmax available file upload number * perf: file select modal code * fix: fileselect refresh * fix: ts --------- Co-authored-by: archer <545436317@qq.com> * bugfix: chat page (#5809) * fix: upload avatar * fix: chat page username display issue and setting button visibility * doc * Markdown match base64 performance * feat: improve global variables(time, file, dataset) (#5804) * feat: improve global variables(time, file, dataset) * feat: optimize code * perf: time variables code * fix: model, file * fix: hide file upload * fix: ts * hide dataset select --------- Co-authored-by: archer <545436317@qq.com> * perf: insert training queue * perf: s3 upload error i18n * fix: share page s3 * fix: timeselector ui error * var update node * Timepicker ui * feat: plugin support password * fix: password disabled UX * fix: button size * fix: no model cache for chat page (#5820) * rename function * fix: workflow bug * fix: interactive loop * fix test * perf: common textare no richtext * move system plugin config (#5803) (#5813) * move system plugin config (#5803) * move system plugin config * extract tag bar * filter * tool detail temp * marketplace * params * fix * type * search * tags render * status * ui * code * connect to backend (#5815) * feat: marketplace apis & type definitions (#5817) * chore: marketplace init * chore: marketplace list api type * chore: detail api * marketplace & import * feat: marketplace ui (#5826) * temp * marketplace * import * feat: detail return readme * chore: cache data expire 10 mins * chore: update docs * feat: marketplace ui --------- Co-authored-by: heheer <zhiyu44@qq.com> * feat: marketplace (#5830) * temp * marketplace * chore: tool list tag filter * chore: adjust --------- Co-authored-by: heheer <zhiyu44@qq.com> * tool detail drawer * remove tag filter * fix * fix * fix build * update pnpm-lock * fix type * perf code * marketplace router * fix build * navbar icon * fix ui * fix init * docs: marketplace/plugin (#5832) * temp * marketplace * docs(plugin): system tool docs --------- Co-authored-by: heheer <zhiyu44@qq.com> * default url * feat: i18n/ docker build (#5833) * chore: docker build * feat: i18n selector * fix * fix * fix: i18n parse * fix: i18n parse --------- Co-authored-by: heheer <heheer@sealos.io> Co-authored-by: Finley Ge <32237950+FinleyGe@users.noreply.github.com> Co-authored-by: heheer <zhiyu44@qq.com> * marketplace url * update action * market place code * market place code * title * fix: nextconfig * fix: copilot review * Remove bypassable regex-based XSS sanitization from marketplace search (#5835) * Initial plan * Remove problematic regex-based XSS sanitization from search inputs Co-authored-by: c121914yu <50446880+c121914yu@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: c121914yu <50446880+c121914yu@users.noreply.github.com> * feat: tool tag openapi * api check * fix: tsc * fix: ts * fix: lock * sdk version * ts * sdk version * remove invalid tip * perf: export data add timezone * perf: admin plugin api move * perf: tool code * move tag code * perf: marketplace and team plugin code * remove workflow invalid request * rename global tool code * rename global tool code * rename api * fix some bugs (#5841) * fix some bugs * fix * perf: Tag filter * fix: ts * fix: ts --------- Co-authored-by: archer <545436317@qq.com> * perf: Concat function * fix: workflow snapshot push * fix: ts type * fix: login to config/* * fix: ts * fix: model avatar (#5848) * fix: model avatar * fix: ts * fix: avatar migration to s3 * update lock * fix: avatar redirect --------- Co-authored-by: archer <545436317@qq.com> * fix tool detail (#5847) * fix tool detail * init script * fix build * perf: plugin detail modal * change tooltags to tags * fix icon --------- Co-authored-by: archer <545436317@qq.com> * fix tag filter scroll (#5852) * fix create app plugin & import info (#5853) * tag size * rename toolkit * download url * import plugin status (#5854) * init doc * fix: init shell --------- Co-authored-by: 伍闲犬 <whoeverimf5@gmail.com> Co-authored-by: Zeng Qingwen <143274079+fishwww-ww@users.noreply.github.com> Co-authored-by: heheer <heheer@sealos.io> Co-authored-by: Finley Ge <32237950+FinleyGe@users.noreply.github.com> Co-authored-by: heheer <zhiyu44@qq.com> Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
166 lines
4.1 KiB
TypeScript
166 lines
4.1 KiB
TypeScript
/* Auth app permission */
|
|
import { MongoApp } from '../../../core/app/schema';
|
|
import { type AppDetailType } from '@fastgpt/global/core/app/type.d';
|
|
import {
|
|
NullRoleVal,
|
|
PerResourceTypeEnum,
|
|
ReadPermissionVal,
|
|
ReadRoleVal
|
|
} from '@fastgpt/global/support/permission/constant';
|
|
import { AppErrEnum } from '@fastgpt/global/common/error/code/app';
|
|
import { getTmbInfoByTmbId } from '../../user/team/controller';
|
|
import { getTmbPermission } from '../controller';
|
|
import { AppPermission } from '@fastgpt/global/support/permission/app/controller';
|
|
import { type PermissionValueType } from '@fastgpt/global/support/permission/type';
|
|
import { AppFolderTypeList, AppTypeEnum } from '@fastgpt/global/core/app/constants';
|
|
import { type ParentIdType } from '@fastgpt/global/common/parentFolder/type';
|
|
import { AppToolSourceEnum } from '@fastgpt/global/core/app/tool/constants';
|
|
import { type AuthModeType, type AuthResponseType } from '../type';
|
|
import { splitCombineToolId } from '@fastgpt/global/core/app/tool/utils';
|
|
import { AppReadChatLogPerVal } from '@fastgpt/global/support/permission/app/constant';
|
|
import { parseHeaderCert } from '../auth/common';
|
|
import { sumPer } from '@fastgpt/global/support/permission/utils';
|
|
|
|
export const authPluginByTmbId = async ({
|
|
tmbId,
|
|
appId,
|
|
per
|
|
}: {
|
|
tmbId: string;
|
|
appId: string;
|
|
per: PermissionValueType;
|
|
}) => {
|
|
const { source } = splitCombineToolId(appId);
|
|
if (source === AppToolSourceEnum.personal) {
|
|
const { app } = await authAppByTmbId({
|
|
appId,
|
|
tmbId,
|
|
per
|
|
});
|
|
|
|
return app;
|
|
}
|
|
};
|
|
|
|
export const authAppByTmbId = async ({
|
|
tmbId,
|
|
appId,
|
|
per,
|
|
isRoot
|
|
}: {
|
|
tmbId: string;
|
|
appId: string;
|
|
per: PermissionValueType;
|
|
isRoot?: boolean;
|
|
}): Promise<{
|
|
app: AppDetailType;
|
|
}> => {
|
|
const { teamId, permission: tmbPer } = await getTmbInfoByTmbId({ tmbId });
|
|
|
|
const app = await (async () => {
|
|
const app = await MongoApp.findOne({ _id: appId }).lean();
|
|
|
|
if (!app) {
|
|
return Promise.reject(AppErrEnum.unExist);
|
|
}
|
|
|
|
if (isRoot) {
|
|
return {
|
|
...app,
|
|
permission: new AppPermission({ isOwner: true })
|
|
};
|
|
}
|
|
|
|
if (String(app.teamId) !== teamId) {
|
|
return Promise.reject(AppErrEnum.unAuthApp);
|
|
}
|
|
|
|
if (app.type === AppTypeEnum.hidden) {
|
|
if (per === AppReadChatLogPerVal) {
|
|
if (!tmbPer.hasManagePer) {
|
|
return Promise.reject(AppErrEnum.unAuthApp);
|
|
}
|
|
} else if (per !== ReadPermissionVal) {
|
|
return Promise.reject(AppErrEnum.unAuthApp);
|
|
}
|
|
|
|
return {
|
|
...app,
|
|
permission: new AppPermission({ isOwner: false, role: ReadRoleVal })
|
|
};
|
|
}
|
|
|
|
const isOwner = tmbPer.isOwner || String(app.tmbId) === String(tmbId);
|
|
|
|
const isGetParentClb =
|
|
app.inheritPermission && !AppFolderTypeList.includes(app.type) && !!app.parentId;
|
|
|
|
const [folderPer = NullRoleVal, myPer = NullRoleVal] = await Promise.all([
|
|
isGetParentClb
|
|
? getTmbPermission({
|
|
teamId,
|
|
tmbId,
|
|
resourceId: app.parentId!,
|
|
resourceType: PerResourceTypeEnum.app
|
|
})
|
|
: NullRoleVal,
|
|
getTmbPermission({
|
|
teamId,
|
|
tmbId,
|
|
resourceId: appId,
|
|
resourceType: PerResourceTypeEnum.app
|
|
})
|
|
]);
|
|
|
|
const Per = new AppPermission({ role: sumPer(folderPer, myPer), isOwner });
|
|
|
|
if (app.favourite || app.quick) {
|
|
Per.addRole(ReadRoleVal);
|
|
}
|
|
|
|
if (!Per.checkPer(per)) {
|
|
return Promise.reject(AppErrEnum.unAuthApp);
|
|
}
|
|
|
|
return {
|
|
...app,
|
|
permission: Per
|
|
};
|
|
})();
|
|
|
|
return { app };
|
|
};
|
|
|
|
export const authApp = async ({
|
|
appId,
|
|
per,
|
|
...props
|
|
}: AuthModeType & {
|
|
appId: ParentIdType;
|
|
per: PermissionValueType;
|
|
}): Promise<
|
|
AuthResponseType<AppPermission> & {
|
|
app: AppDetailType;
|
|
}
|
|
> => {
|
|
const result = await parseHeaderCert(props);
|
|
const { tmbId } = result;
|
|
|
|
if (!appId) {
|
|
return Promise.reject(AppErrEnum.unExist);
|
|
}
|
|
|
|
const { app } = await authAppByTmbId({
|
|
tmbId,
|
|
appId,
|
|
per,
|
|
isRoot: result.isRoot
|
|
});
|
|
|
|
return {
|
|
...result,
|
|
permission: app.permission,
|
|
app
|
|
};
|
|
};
|