mirror of
https://github.com/fawney19/Aether.git
synced 2026-09-02 17:30:23 +08:00
- 删除全部 Python 源码 (src/) 及 Alembic 迁移脚本,归档至 _deprecated_py_src/ - 重构 Rust gateway ai_pipeline: 拆分 planner/finalize 模块,新增 contracts/adaptation 层 - 重组 handlers 模块为 admin/public/proxy/internal/shared 子模块结构 - 新增 executor 模块,引入 Rust 原生数据库迁移 (aether-data/migrations) - 简化 CI/Docker 构建流程,移除 base image 二级构建,统一为单一 app image - 移除 Python 相关基础设施文件 (entrypoint.sh, gunicorn_conf.py, Dockerfile.base)
28 lines
972 B
Python
28 lines
972 B
Python
from fastapi import HTTPException
|
||
|
||
from src.models.database import UserRole
|
||
|
||
from .adapter import ApiAdapter, ApiMode
|
||
from .context import ApiRequestContext
|
||
|
||
|
||
class AdminApiAdapter(ApiAdapter):
|
||
"""管理员端点适配器基类,提供统一的权限校验。"""
|
||
|
||
mode = ApiMode.ADMIN
|
||
required_roles: tuple[UserRole, ...] = (UserRole.ADMIN,)
|
||
|
||
def authorize(self, context: ApiRequestContext) -> None:
|
||
user = context.user
|
||
if not user:
|
||
raise HTTPException(status_code=401, detail="未登录")
|
||
|
||
# 检查是否使用独立余额Key访问管理接口
|
||
if context.api_key and context.api_key.is_standalone:
|
||
raise HTTPException(
|
||
status_code=403, detail="独立余额Key不允许访问管理接口,仅可用于代理请求"
|
||
)
|
||
|
||
if not any(user.role == role for role in self.required_roles):
|
||
raise HTTPException(status_code=403, detail="需要管理员权限")
|