管理员免登录直接评论:后台会话映射站主身份(免审核、不可被禁言)+ 评论作者字段对齐后端 user

- 公开 API 解析顺序:读者 cookie → 管理员 cookie(provider=admin 站主读者,名字取站点作者名)
- 站主发评论跳过禁言与审核;后台禁言接口拒绝站主身份
- CommentItem 读 c.author 改为 c.user(后端实际字段),站主徽章按 provider 判断
This commit is contained in:
Sakurasan
2026-09-28 00:43:25 +08:00
parent 0929f880e3
commit 1a2db5ddac
5 changed files with 80 additions and 37 deletions
+5
View File
@@ -876,6 +876,11 @@ func (a *API) adminReaderBan(w http.ResponseWriter, r *http.Request, id int64) {
httpx.BadRequest(w, "invalid body")
return
}
// 站主身份(管理员会话映射出来的读者)不允许禁言
if rd, err := a.Store.GetReader(id); err == nil && rd.Provider == "admin" {
httpx.BadRequest(w, "不能禁言站主身份")
return
}
if err := a.Store.SetReaderBanned(id, in.Banned); err != nil {
if errors.Is(err, store.ErrNotFound) {
httpx.NotFound(w)