+18
-14
@@ -114,20 +114,24 @@ func CheckToken(tokenString string) (token models.Token, err error) {
|
||||
return models.Token{}, ErrDeletedUser
|
||||
}
|
||||
|
||||
acceptedPermissions := make([]string, 0, 8)
|
||||
for _, permission := range permissions {
|
||||
found := false
|
||||
acceptedPermissions := make([]string, 0, len(user.Permissions))
|
||||
if len(permissions) > 0 {
|
||||
for _, permission := range permissions {
|
||||
found := false
|
||||
|
||||
for _, userPermission := range user.Permissions {
|
||||
if permission == userPermission {
|
||||
found = true
|
||||
break
|
||||
for _, userPermission := range user.Permissions {
|
||||
if permission == userPermission {
|
||||
found = true
|
||||
break
|
||||
}
|
||||
}
|
||||
|
||||
if found {
|
||||
acceptedPermissions = append(acceptedPermissions, permission)
|
||||
}
|
||||
}
|
||||
|
||||
if found {
|
||||
acceptedPermissions = append(acceptedPermissions, permission)
|
||||
}
|
||||
} else {
|
||||
acceptedPermissions = append(acceptedPermissions, user.Permissions...)
|
||||
}
|
||||
|
||||
return models.Token{UserID: user.ID, Permissions: acceptedPermissions}, nil
|
||||
@@ -153,10 +157,10 @@ func parseClaims(jwtClaims jwt.Claims) (userid string, permissions []string, err
|
||||
permissions = append(permissions, permission)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if len(permissions) == 0 {
|
||||
return "", nil, ErrInvalidClaims
|
||||
if len(permissions) == 0 {
|
||||
return "", nil, ErrInvalidClaims
|
||||
}
|
||||
}
|
||||
|
||||
return
|
||||
|
||||
Reference in New Issue
Block a user