fix(guest): add playCollection permission so guests can Play All playlist/album (#103)

- New guest flag playCollection (default OFF), gates play-playlist/play-album
- Keeps playNow's non-destructive semantics intact (Play All clears the queue)
- Admin-toggleable in Settings → 游客模式; default-off, backward-compatible
- Frontend: gate the 播放全部 button on the flag + surface 403 as a toast
  instead of failing silently (the silent-failure half of the issue)
This commit is contained in:
saopig1 committed 2026-06-29 12:12:47 +08:00
1 parent e2fa288f48
commit 70c0273ae7
11 files changed
+61 -22

No files matched your search

+2 -2
View File
@@ -265,7 +265,7 @@ export function createPlayerRouter(
// Play a playlist by ID — stores metadata only, resolves URL for first song
// Respects current play mode (random = pick random first song)
router.post("/:botId/play-playlist", authorize({ capability: "player.control" }), async (req, res) => {
router.post("/:botId/play-playlist", authorize({ capability: "player.control", guestFlag: "playCollection" }), async (req, res) => {
try {
const bot = (req as any).bot;
const { playlistId, platform } = req.body;
@@ -352,7 +352,7 @@ export function createPlayerRouter(
});
// Play an album by ID — mirrors play-playlist but calls getAlbumSongs
router.post("/:botId/play-album", authorize({ capability: "player.control" }), async (req, res) => {
router.post("/:botId/play-album", authorize({ capability: "player.control", guestFlag: "playCollection" }), async (req, res) => {
try {
const bot = (req as any).bot;
const { albumId, platform } = req.body;