mirror of
https://github.com/labring/FastGPT.git
synced 2025-10-21 03:10:50 +00:00

* add logs chart (#5352) * charts * chart data * log chart * delete * rename api * fix * move api * fix * fix * pro config * fix * feat: Repository interaction (#5356) * feat: 1好像功能没问题了,明天再测 * feat: 2 解决了昨天遗留的bug,但全选按钮又bug了 * feat: 3 第三版,解决了全选功能bug * feat: 4 第四版,下面改小细节 * feat: 5 我勒个痘 * feat: 6 * feat: 6 pr * feat: 7 * feat: 8 * feat: 9 * feat: 10 * feat: 11 * feat: 12 * perf: checkbox ui * refactor: tweak login loyout (#5357) Co-authored-by: Archer <545436317@qq.com> * login ui * app chat log chart pro display (#5392) * app chat log chart pro display * add canopen props * perf: pro tag tip * perf: pro tag tip * feat: openrouter provider (#5406) * perf: login ui * feat: openrouter provider * provider * perf: custom error throw * perf: emb batch (#5407) * perf: emb batch * perf: vector retry * doc * doc (#5411) * doc * fix: team folder will add to workflow * fix: generateToc shell * Tool price (#5376) * resolve conflicts for cherry-pick * fix i18n * Enhance system plugin template data structure and update ToolSelectModal to include CostTooltip component * refactor: update systemKeyCost type to support array of objects in plugin and workflow types * refactor: simplify systemKeyCost type across plugin and workflow types to a single number * refactor: streamline systemKeyCost handling in plugin and workflow components * fix * fix * perf: toolset price config;fix: workflow array selector ui (#5419) * fix: workflow array selector ui * update default model tip * perf: toolset price config * doc * fix: test * Refactor/chat (#5418) * refactor: add homepage configuration; add home chat page; add side bar animated collapse and layout * fix: fix lint rules * chore: improve logics and code * chore: more clearer logics * chore: adjust api --------- Co-authored-by: Archer <545436317@qq.com> * perf: chat setting code * del history * logo image * perf: home chat ui * feat: enhance chat response handling with external links and user info (#5427) * feat: enhance chat response handling with external links and user info * fix * cite code * perf: toolset add in workflow * fix: test * fix: search paraentId * Fix/chat (#5434) * wip: rebase了upstream * wip: adapt mobile UI * fix: fix chat page logic and UI * fix: fix UI and improve some logics * fix: model selector missing logo; vision model to retrieve file * perf: role selector * fix: chat ui * optimize export app chat log (#5436) * doc * chore: move components to proper directory; fix the api to get app list (#5437) * chore: improve team app panel display form (#5438) * feat: add home chat log tab * chore: improve team app panel display form * chore: improve log panel * fix: spec * doc * fix: log permission * fix: dataset schema required * add loading status * remove ui weight * manage log * fix: log detail per * doc * fix: log menu * rename permission * bg color * fix: app log per * fix: log key selector * fix: log * doc --------- Co-authored-by: heheer <zhiyu44@qq.com> Co-authored-by: colnii <1286949794@qq.com> Co-authored-by: 伍闲犬 <76519998+xqvvu@users.noreply.github.com> Co-authored-by: Ctrlz <143257420+ctrlz526@users.noreply.github.com> Co-authored-by: 伍闲犬 <whoeverimf5@gmail.com> Co-authored-by: heheer <heheer@sealos.io>
181 lines
4.4 KiB
TypeScript
181 lines
4.4 KiB
TypeScript
/* Auth app permission */
|
|
import { MongoApp } from '../../../core/app/schema';
|
|
import { type AppDetailType } from '@fastgpt/global/core/app/type.d';
|
|
import { parseHeaderCert } from '../controller';
|
|
import {
|
|
PerResourceTypeEnum,
|
|
ReadPermissionVal,
|
|
ReadRoleVal
|
|
} from '@fastgpt/global/support/permission/constant';
|
|
import { AppErrEnum } from '@fastgpt/global/common/error/code/app';
|
|
import { getTmbInfoByTmbId } from '../../user/team/controller';
|
|
import { getResourcePermission } from '../controller';
|
|
import { AppPermission } from '@fastgpt/global/support/permission/app/controller';
|
|
import { type PermissionValueType } from '@fastgpt/global/support/permission/type';
|
|
import { AppFolderTypeList, AppTypeEnum } from '@fastgpt/global/core/app/constants';
|
|
import { type ParentIdType } from '@fastgpt/global/common/parentFolder/type';
|
|
import { PluginSourceEnum } from '@fastgpt/global/core/app/plugin/constants';
|
|
import { type AuthModeType, type AuthResponseType } from '../type';
|
|
import { splitCombinePluginId } from '@fastgpt/global/core/app/plugin/utils';
|
|
import { AppReadChatLogPerVal } from '@fastgpt/global/support/permission/app/constant';
|
|
|
|
export const authPluginByTmbId = async ({
|
|
tmbId,
|
|
appId,
|
|
per
|
|
}: {
|
|
tmbId: string;
|
|
appId: string;
|
|
per: PermissionValueType;
|
|
}) => {
|
|
const { source } = splitCombinePluginId(appId);
|
|
if (source === PluginSourceEnum.personal) {
|
|
const { app } = await authAppByTmbId({
|
|
appId,
|
|
tmbId,
|
|
per
|
|
});
|
|
|
|
return app;
|
|
}
|
|
};
|
|
|
|
export const authAppByTmbId = async ({
|
|
tmbId,
|
|
appId,
|
|
per,
|
|
isRoot
|
|
}: {
|
|
tmbId: string;
|
|
appId: string;
|
|
per: PermissionValueType;
|
|
isRoot?: boolean;
|
|
}): Promise<{
|
|
app: AppDetailType;
|
|
}> => {
|
|
const { teamId, permission: tmbPer } = await getTmbInfoByTmbId({ tmbId });
|
|
|
|
const app = await (async () => {
|
|
const app = await MongoApp.findOne({ _id: appId }).lean();
|
|
|
|
if (!app) {
|
|
return Promise.reject(AppErrEnum.unExist);
|
|
}
|
|
|
|
if (isRoot) {
|
|
return {
|
|
...app,
|
|
permission: new AppPermission({ isOwner: true })
|
|
};
|
|
}
|
|
|
|
if (String(app.teamId) !== teamId) {
|
|
return Promise.reject(AppErrEnum.unAuthApp);
|
|
}
|
|
|
|
if (app.type === AppTypeEnum.hidden) {
|
|
if (per === AppReadChatLogPerVal) {
|
|
if (!tmbPer.hasManagePer) {
|
|
return Promise.reject(AppErrEnum.unAuthApp);
|
|
}
|
|
} else if (per !== ReadPermissionVal) {
|
|
return Promise.reject(AppErrEnum.unAuthApp);
|
|
}
|
|
|
|
return {
|
|
...app,
|
|
permission: new AppPermission({ isOwner: false, role: ReadRoleVal })
|
|
};
|
|
}
|
|
|
|
const isOwner = tmbPer.isOwner || String(app.tmbId) === String(tmbId);
|
|
|
|
const { Per } = await (async () => {
|
|
if (isOwner) {
|
|
return {
|
|
Per: new AppPermission({ isOwner: true })
|
|
};
|
|
}
|
|
|
|
if (
|
|
AppFolderTypeList.includes(app.type) ||
|
|
app.inheritPermission === false ||
|
|
!app.parentId
|
|
) {
|
|
// 1. is a folder. (Folders have completely permission)
|
|
// 2. inheritPermission is false.
|
|
// 3. is root folder/app.
|
|
const role = await getResourcePermission({
|
|
teamId,
|
|
tmbId,
|
|
resourceId: appId,
|
|
resourceType: PerResourceTypeEnum.app
|
|
});
|
|
const Per = new AppPermission({ role, isOwner });
|
|
return {
|
|
Per
|
|
};
|
|
} else {
|
|
// is not folder and inheritPermission is true and is not root folder.
|
|
const { app: parent } = await authAppByTmbId({
|
|
tmbId,
|
|
appId: app.parentId,
|
|
per
|
|
});
|
|
|
|
const Per = new AppPermission({
|
|
role: parent.permission.role,
|
|
isOwner
|
|
});
|
|
return {
|
|
Per
|
|
};
|
|
}
|
|
})();
|
|
|
|
if (!Per.checkPer(per)) {
|
|
return Promise.reject(AppErrEnum.unAuthApp);
|
|
}
|
|
|
|
return {
|
|
...app,
|
|
permission: Per
|
|
};
|
|
})();
|
|
|
|
return { app };
|
|
};
|
|
|
|
export const authApp = async ({
|
|
appId,
|
|
per,
|
|
...props
|
|
}: AuthModeType & {
|
|
appId: ParentIdType;
|
|
per: PermissionValueType;
|
|
}): Promise<
|
|
AuthResponseType<AppPermission> & {
|
|
app: AppDetailType;
|
|
}
|
|
> => {
|
|
const result = await parseHeaderCert(props);
|
|
const { tmbId } = result;
|
|
|
|
if (!appId) {
|
|
return Promise.reject(AppErrEnum.unExist);
|
|
}
|
|
|
|
const { app } = await authAppByTmbId({
|
|
tmbId,
|
|
appId,
|
|
per,
|
|
isRoot: result.isRoot
|
|
});
|
|
|
|
return {
|
|
...result,
|
|
permission: app.permission,
|
|
app
|
|
};
|
|
};
|