From 1491a9677af0a3a3ad4993a8fd7ffbfeb7eea200 Mon Sep 17 00:00:00 2001 From: QiuSW <105186638@qq.com> Date: Sun, 27 Sep 2026 11:59:31 +0800 Subject: [PATCH] fix(access): allow after-sales purchase readiness (#341) --- server/app/goauto/purchase/handler.go | 4 +-- .../goauto/purchase/handler_access_test.go | 26 +++++++++++++++++++ 2 files changed, 28 insertions(+), 2 deletions(-) create mode 100644 server/app/goauto/purchase/handler_access_test.go diff --git a/server/app/goauto/purchase/handler.go b/server/app/goauto/purchase/handler.go index 52d2935..51aa077 100644 --- a/server/app/goauto/purchase/handler.go +++ b/server/app/goauto/purchase/handler.go @@ -475,10 +475,10 @@ func allowedOperator(c *gin.Context) bool { return true } role, _ := jwt.ExtractClaims(c)["rolekey"].(string) - if role == "admin" || role == "purchaser" { + if role == "admin" || role == "purchaser" || role == "after_sales" { return true } - c.JSON(http.StatusForbidden, gin.H{"code": "FORBIDDEN", "message": "只有管理员或采购员可以操作采购任务"}) + c.JSON(http.StatusForbidden, gin.H{"code": "FORBIDDEN", "message": "只有管理员、采购员或售后可以操作采购任务"}) c.Abort() return false } diff --git a/server/app/goauto/purchase/handler_access_test.go b/server/app/goauto/purchase/handler_access_test.go new file mode 100644 index 0000000..651d171 --- /dev/null +++ b/server/app/goauto/purchase/handler_access_test.go @@ -0,0 +1,26 @@ +package purchase + +import ( + "net/http/httptest" + "testing" + + "github.com/gin-gonic/gin" + jwt "github.com/go-admin-team/go-admin-core/sdk/pkg/jwtauth" +) + +func TestAllowedOperatorIncludesAfterSales(t *testing.T) { + for _, role := range []string{"admin", "purchaser", "after_sales", "other", ""} { + t.Run(role, func(t *testing.T) { + w := httptest.NewRecorder() + c, _ := gin.CreateTestContext(w) + c.Set("JWT_PAYLOAD", jwt.MapClaims{"rolekey": role}) + want := role == "admin" || role == "purchaser" || role == "after_sales" + if got := allowedOperator(c); got != want { + t.Fatalf("role %q allowed=%v want %v", role, got, want) + } + if !want && w.Code != 403 { + t.Fatalf("denied role status=%d", w.Code) + } + }) + } +}