fix: anonymous authentication (#3214)

This commit is contained in:
shaohuzhang1 2025-06-09 16:25:18 +08:00 committed by GitHub
parent 3807cf1960
commit 66c868e71f
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -14,7 +14,8 @@ from common.auth.common import ChatUserToken
from common.auth.handle.auth_base_handle import AuthBaseHandle from common.auth.handle.auth_base_handle import AuthBaseHandle
from common.constants.authentication_type import AuthenticationType from common.constants.authentication_type import AuthenticationType
from common.constants.permission_constants import RoleConstants, Permission, Group, Operate, ChatAuth from common.constants.permission_constants import RoleConstants, Permission, Group, Operate, ChatAuth
from common.exception.app_exception import AppAuthenticationFailed, ChatException from common.database_model_manage.database_model_manage import DatabaseModelManage
from common.exception.app_exception import AppAuthenticationFailed
class ChatAnonymousUserToken(AuthBaseHandle): class ChatAnonymousUserToken(AuthBaseHandle):
@ -40,10 +41,11 @@ class ChatAnonymousUserToken(AuthBaseHandle):
raise AppAuthenticationFailed(1002, _('Authentication information is incorrect')) raise AppAuthenticationFailed(1002, _('Authentication information is incorrect'))
if not application_access_token.access_token == access_token: if not application_access_token.access_token == access_token:
raise AppAuthenticationFailed(1002, _('Authentication information is incorrect')) raise AppAuthenticationFailed(1002, _('Authentication information is incorrect'))
# 匿名用户 除了/api/application/profile 都需要校验是否开启了密码认证 application_setting_model = DatabaseModelManage.get_model("application_setting")
if request.path != '/api/application/profile': if application_setting_model is not None:
if chat_user_token.authentication.is_auth and not chat_user_token.authentication.auth_passed: application_setting = QuerySet(application_setting_model).filter(application_id=application_id).first()
raise ChatException(1002, _('Authentication information is incorrect')) if application_setting.authentication:
raise AppAuthenticationFailed(1002, _('Authentication information is incorrect'))
return None, ChatAuth( return None, ChatAuth(
current_role_list=[RoleConstants.CHAT_ANONYMOUS_USER], current_role_list=[RoleConstants.CHAT_ANONYMOUS_USER],
permission_list=[ permission_list=[