yao/openapi/oauth/acl/acl.go
Max 0e260ffb6a Enhance OAuth guard with authorized info handling and ACL integration
- Updated the OAuth guard to set authorized information in the context using the new authorized package.
- Refactored the GetAuthorizedInfo function to utilize the authorized.GetInfo method, improving clarity and maintainability.
- Enhanced the ACL implementation by adding scope resolution logic in the Enforce method, ensuring proper access control based on user roles and scopes.
- Improved error handling and logging during ACL operations, providing better insights into access decisions.
2025-10-20 08:50:20 +08:00

49 lines
855 B
Go

package acl
import (
"github.com/yaoapp/kun/log"
)
// Global is the global ACL enforcer
var Global Enforcer = nil
// New creates a new ACL enforcer
func New(config *Config) (Enforcer, error) {
if config == nil {
config = &DefaultConfig
}
acl := &ACL{
Config: config,
}
// Load scope manager if ACL is enabled
if config.Enabled {
// Load scope manager
manager, err := LoadScopes()
if err != nil {
return nil, err
}
acl.Scope = manager
log.Info("[ACL] Scope manager loaded successfully")
}
return acl, nil
}
// Load loads the ACL enforcer
func Load(config *Config) (Enforcer, error) {
enforcer, err := New(config)
if err != nil {
return nil, err
}
Global = enforcer
return Global, nil
}
// Enabled returns true if the ACL is enabled, otherwise false
func (acl *ACL) Enabled() bool {
return acl.Config.Enabled
}