From e75863bfd9dcd722fd9c4ae705c80a7402c04450 Mon Sep 17 00:00:00 2001 From: QiuSW <105186638@qq.com> Date: Sat, 12 Sep 2026 10:02:54 +0800 Subject: [PATCH] fix: allow authenticated admin shopee sync --- app/admin/apis/shopee_product.go | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/app/admin/apis/shopee_product.go b/app/admin/apis/shopee_product.go index da9d4a5..450aac8 100644 --- a/app/admin/apis/shopee_product.go +++ b/app/admin/apis/shopee_product.go @@ -6,6 +6,7 @@ import ( "github.com/gin-gonic/gin" "github.com/go-admin-team/go-admin-core/sdk" "github.com/go-admin-team/go-admin-core/sdk/api" + "github.com/go-admin-team/go-admin-core/sdk/pkg/jwtauth/user" "go-admin/app/admin/models" ext "go-admin/config" "go-admin/internal/config" @@ -34,7 +35,10 @@ func (e ShopeeProduct) GetByShopeeID(c *gin.Context) { e.Error(400, fmt.Errorf("shopeeId is required"), "参数错误") return } - if !ValidateAPIKey(c) { + // The admin page runs inside the authenticated GoAdmin session. External + // callers must provide an API key; this keeps the internal workflow usable + // without exposing a key to browser JavaScript. + if user.GetUserId(c) <= 0 && !ValidateAPIKey(c) { e.Error(401, fmt.Errorf("invalid api key"), "未授权") return }