fix(admin): support HttpOnly cookie auth in admin_guard
admin_guard() only checked Authorization: Bearer header, ignoring the oxicloud_access HttpOnly cookie used by browser sessions. All admin endpoints (dashboard, OIDC settings, etc.) returned 401 for logged-in users. Fall back to cookie_auth::extract_cookie_value() when no Bearer token is present.
This commit is contained in:
@@ -50,12 +50,18 @@ async fn admin_guard(state: &AppState, headers: &HeaderMap) -> Result<(String, S
|
|||||||
let token = headers
|
let token = headers
|
||||||
.get(header::AUTHORIZATION)
|
.get(header::AUTHORIZATION)
|
||||||
.and_then(|v| v.to_str().ok())
|
.and_then(|v| v.to_str().ok())
|
||||||
.and_then(|v| v.strip_prefix("Bearer "))
|
.and_then(|v| v.strip_prefix("Bearer ").map(|s| s.to_string()))
|
||||||
|
.or_else(|| {
|
||||||
|
crate::interfaces::api::cookie_auth::extract_cookie_value(
|
||||||
|
headers,
|
||||||
|
crate::interfaces::api::cookie_auth::ACCESS_COOKIE,
|
||||||
|
)
|
||||||
|
})
|
||||||
.ok_or_else(|| AppError::unauthorized("Authorization token required"))?;
|
.ok_or_else(|| AppError::unauthorized("Authorization token required"))?;
|
||||||
|
|
||||||
let claims = auth
|
let claims = auth
|
||||||
.token_service
|
.token_service
|
||||||
.validate_token(token)
|
.validate_token(&token)
|
||||||
.map_err(|e| AppError::unauthorized(format!("Invalid token: {}", e)))?;
|
.map_err(|e| AppError::unauthorized(format!("Invalid token: {}", e)))?;
|
||||||
|
|
||||||
if claims.role != "admin" {
|
if claims.role != "admin" {
|
||||||
|
|||||||
Reference in New Issue
Block a user