feat: add management token permissions

This commit is contained in:
Entropy.Xu
2026-05-07 23:48:29 +08:00
parent 6f620d92be
commit cc5cb3475e
34 changed files with 2212 additions and 100 deletions
@@ -8,6 +8,20 @@ pub(super) fn classify_admin_basic_family_route(
normalized_path_no_trailing: &str,
) -> Option<ClassifiedRoute> {
if method == http::Method::GET
&& matches!(
normalized_path,
"/api/admin/management-tokens/permissions/catalog"
| "/api/admin/management-tokens/permissions/catalog/"
)
{
Some(classified(
"admin_proxy",
"management_tokens_manage",
"permissions_catalog",
"admin:management_tokens",
false,
))
} else if method == http::Method::GET
&& matches!(
normalized_path,
"/api/admin/management-tokens" | "/api/admin/management-tokens/"
@@ -20,6 +34,19 @@ pub(super) fn classify_admin_basic_family_route(
"admin:management_tokens",
false,
))
} else if method == http::Method::POST
&& matches!(
normalized_path,
"/api/admin/management-tokens" | "/api/admin/management-tokens/"
)
{
Some(classified(
"admin_proxy",
"management_tokens_manage",
"create_token",
"admin:management_tokens",
false,
))
} else if method == http::Method::GET
&& normalized_path.starts_with("/api/admin/management-tokens/")
{
@@ -30,6 +57,16 @@ pub(super) fn classify_admin_basic_family_route(
"admin:management_tokens",
false,
))
} else if method == http::Method::PUT
&& normalized_path.starts_with("/api/admin/management-tokens/")
{
Some(classified(
"admin_proxy",
"management_tokens_manage",
"update_token",
"admin:management_tokens",
false,
))
} else if method == http::Method::DELETE
&& normalized_path.starts_with("/api/admin/management-tokens/")
{
@@ -40,6 +77,17 @@ pub(super) fn classify_admin_basic_family_route(
"admin:management_tokens",
false,
))
} else if method == http::Method::POST
&& normalized_path.starts_with("/api/admin/management-tokens/")
&& normalized_path.ends_with("/regenerate")
{
Some(classified(
"admin_proxy",
"management_tokens_manage",
"regenerate_token",
"admin:management_tokens",
false,
))
} else if method == http::Method::PATCH
&& normalized_path.starts_with("/api/admin/management-tokens/")
&& normalized_path.ends_with("/status")