管理员免登录直接评论:后台会话映射站主身份(免审核、不可被禁言)+ 评论作者字段对齐后端 user

- 公开 API 解析顺序:读者 cookie → 管理员 cookie(provider=admin 站主读者,名字取站点作者名)
- 站主发评论跳过禁言与审核;后台禁言接口拒绝站主身份
- CommentItem 读 c.author 改为 c.user(后端实际字段),站主徽章按 provider 判断
This commit is contained in:
Sakurasan
2026-09-28 00:43:25 +08:00
parent 0929f880e3
commit 1a2db5ddac
5 changed files with 80 additions and 37 deletions
+4 -1
View File
@@ -63,6 +63,8 @@ func main() {
// 评论区的读者会话(cookie one_reader),30 天有效
readerSessions := auth.NewReaderSessions(cfg.SessionSec, 30*24*time.Hour)
// 后台管理员会话(cookie one_session),前台评论也用它识别站主身份
adminSessions := admin.NewSessions(cfg.SessionSec, 7*24*time.Hour)
public := &api.API{
Store: st,
@@ -70,8 +72,9 @@ func main() {
Blobs: blobs,
ReaderSessions: readerSessions,
GH: auth.GitHub{ClientID: cfg.GitHubClientID, ClientSecret: cfg.GitHubClientSecret},
AdminSessions: adminSessions,
}
adminAPI := admin.NewAPI(st, cfg, admin.NewSessions(cfg.SessionSec, 7*24*time.Hour))
adminAPI := admin.NewAPI(st, cfg, adminSessions)
adminAPI.Blobs = blobs
adminAPI.Blobs = blobs