Skip to content

认证 API ​

1. "用户登录" ​

  1. route definition
  • Url: /api/v1/auth/login
  • Method: POST
  • Request: LoginRequest
  • Response: LoginResponse
  1. request definition
go
type LoginRequest struct {
	Username string `json:"username"` // 用户名
	Password string `json:"password"` // 密码
}
  1. response definition
go
type LoginResponse struct {
	Token string `json:"token"`
	User UserInfo `json:"user"`
}

type UserInfo struct {
	Username string `json:"username"`
	Roles []string `json:"roles"`
	Nickname string `json:"nickname,omitempty"`
	Email string `json:"email,omitempty"`
	Phone string `json:"phone,omitempty"`
}

2. "用户登出" ​

  1. route definition
  • Url: /api/v1/auth/logout
  • Method: POST
  • Request: LogoutRequest
  • Response: LogoutResponse
  1. request definition
go
type LogoutRequest struct {
}
  1. response definition
go
type LogoutResponse struct {
}

3. "权限校验" ​

  1. route definition
  • Url: /api/v1/auth/check
  • Method: POST
  • Auth: Bearer Token
  • Request: CheckRequest
  • Response: CheckResponse
  1. request definition
go
type CheckRequest struct {
	Resource string `json:"resource"` // 例如 roles、games、functions
	Action   string `json:"action"`   // 例如 read、write、manage
	GameID   string `json:"gameId,omitempty"`
	Env      string `json:"env,omitempty"`
}
  1. response definition
go
type CheckResponse struct {
	Allowed bool   `json:"allowed"`
	Reason  string `json:"reason,omitempty"`
}

4. "批量权限校验" ​

  1. route definition
  • Url: /api/v1/auth/check/batch
  • Method: POST
  • Auth: Bearer Token
  • Request: BatchCheckRequest
  • Response: BatchCheckResponse
  1. request definition
go
type BatchCheckRequest struct {
	Checks []CheckRequest `json:"checks"`
}
  1. response definition
go
type BatchCheckResponse struct {
	Results []CheckResponse `json:"results"`
}

说明 ​

  • 校验基于当前登录用户在数据库中的角色和权限,不依赖前端缓存。
  • gameId 与 env 字段当前保留用于兼容前端请求结构,现阶段权限判断主要按资源和动作执行。

外部身份源端点 ​

以下端点在启用 auth.providers 后可用,未启用时 providers 返回全 local,OIDC 端点返回 400。

查询已启用登录方式 ​

  • Url: /api/v1/auth/providers
  • Method: GET
  • Auth: 无
json
{
  "local": true,
  "ldap": true,
  "oidc": false
}

发起 OIDC 登录 ​

  • Url: /api/v1/auth/oidc/login
  • Method: GET
  • Auth: 无
  • 行为: 302 重定向到身份源授权页,state 含 HMAC 签名与 10 分钟有效期

OIDC 回调 ​

  • Url: /api/v1/auth/oidc/callback?code=xxx&state=xxx
  • Method: GET
  • Auth: 无
  • Response: LoginResponse(与密码登录一致);配置 loginSuccessUrl 时改为 302 携带 ?token=xxx 跳转前端