mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-02 04:52:50 +08:00
Merge PR #80: feat(perm) fine-grained account permissions
Conflict resolution + cross-PR integration: - player.ts: kept #88's POST /:botId/fm route AND gated it with requirePermission('player.control') so the new control endpoint honors #80's permission model (it was added without gating). - bot.ts: kept #81's relocated /settings routes (the relocation fixes the GET /settings shadow bug) and dropped #80's now-duplicate bottom copy; gated POST /settings with requirePermission('bot.manage'). - Navbar.vue: composed #82's dedicated-link scope with #80's permission filter — displayedBots is now the INTERSECTION (scope ∩ controllable allow-list). - database.ts: kept BOTH new table sets (#87 favorite_playlists + #80 user_permissions/user_bot_access). - bot.test.ts: updated to createRequireAuth(sessions, permissions) for #80's new two-arg signature. #80 review fixes (credential exposure / IDOR, adversarially verified): - GET /:id/config now requires bot.manage + bot access AND redacts ts6ApiKey + identity from the response (was readable by any authenticated member). - GET /:id and GET /:id/avatar now require bot access (were ungated read oracles).
This commit is contained in:
commit
bea2f92508
32 files changed
+2225
-137
No files matched your search
+6
-1
@@ -12,6 +12,7 @@ import type { Logger } from "../logger.js";
|
||||
|
||||
import type { ServerProtocol } from "../ts-protocol/client.js";
|
||||
import type { AvatarStore } from "../data/avatars.js";
|
||||
import type { PermissionStore } from "../data/permissions.js";
|
||||
|
||||
/**
|
||||
* Run bot.connect() with a hard deadline. If the handshake hangs (e.g. the
|
||||
@@ -76,6 +77,7 @@ export class BotManager extends EventEmitter {
|
||||
private config: BotConfig;
|
||||
private logger: Logger;
|
||||
private avatarStore: AvatarStore;
|
||||
private permissions: PermissionStore;
|
||||
|
||||
constructor(
|
||||
neteaseProvider: MusicProvider,
|
||||
@@ -84,7 +86,8 @@ export class BotManager extends EventEmitter {
|
||||
database: BotDatabase,
|
||||
config: BotConfig,
|
||||
logger: Logger,
|
||||
avatarStore: AvatarStore
|
||||
avatarStore: AvatarStore,
|
||||
permissions: PermissionStore
|
||||
) {
|
||||
super();
|
||||
this.neteaseProvider = neteaseProvider;
|
||||
@@ -95,6 +98,7 @@ export class BotManager extends EventEmitter {
|
||||
this.config = config;
|
||||
this.logger = logger;
|
||||
this.avatarStore = avatarStore;
|
||||
this.permissions = permissions;
|
||||
}
|
||||
|
||||
async createBot(params: CreateBotParams): Promise<BotInstance> {
|
||||
@@ -152,6 +156,7 @@ export class BotManager extends EventEmitter {
|
||||
this.bots.delete(id);
|
||||
}
|
||||
this.database.deleteBotInstance(id);
|
||||
this.permissions.pruneBot(id);
|
||||
this.emit("botInstanceRemoved", id);
|
||||
this.logger.info({ botId: id }, "Bot instance removed");
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user