fix(panel): 本人与所有者账户的禁用和删除按钮提前锁定并说明原因,角色改为只读,后端拒绝改用专用错误码 self_protected 与 owner_protected

This commit is contained in:
Lemon-miaow committed 2026-09-25 13:20:01 +08:00
1 parent dee4d87fd1
commit fde677c07e
13 files changed
+269 -27

No files matched your search

+20 -3
View File
@@ -1170,7 +1170,16 @@ async function handleUserRoute(ctx: SessionContext): Promise<boolean> {
return true;
}
if (ctx.account.id === acc.id && body.role !== ctx.account.role) {
sendError(ctx.res, 403, "forbidden", "cannot change your own role");
sendError(ctx.res, 403, "self_protected", "cannot change your own role");
return true;
}
if (acc.role === "owner") {
sendError(
ctx.res,
403,
"owner_protected",
"the owner account's role cannot be changed from the panel"
);
return true;
}
acc.role = body.role;
@@ -1196,7 +1205,11 @@ async function handleUserRoute(ctx: SessionContext): Promise<boolean> {
// DELETE /api/v1/users/{id}
if (is("DELETE", ctx) && !subAction) {
if (ctx.account.id === acc.id) {
sendError(ctx.res, 403, "forbidden", "cannot delete your own account");
sendError(ctx.res, 403, "self_protected", "cannot delete your own account");
return true;
}
if (acc.role === "owner") {
sendError(ctx.res, 403, "owner_protected", "the owner account cannot be deleted from the panel");
return true;
}
const activeServers = ctx.state.servers.filter(
@@ -1226,10 +1239,14 @@ async function handleUserRoute(ctx: SessionContext): Promise<boolean> {
// POST /api/v1/users/{id}/disable
if (is("POST", ctx) && subAction === "disable") {
if (ctx.account.id === acc.id) {
sendError(ctx.res, 403, "forbidden", "cannot disable your own account");
sendError(ctx.res, 403, "self_protected", "cannot disable your own account");
return true;
}
const body = await readJSON<{ disabled: boolean }>(ctx.req);
if (acc.role === "owner" && body.disabled) {
sendError(ctx.res, 403, "owner_protected", "the owner account cannot be disabled from the panel");
return true;
}
acc.disabled = !!body.disabled;
acc.updated_at = new Date().toISOString();
sendJSON(ctx.res, 200, { id: `mock-${acc.id}`, disabled: acc.disabled });