iven
90340725a4
fix(saas): admin_guard_middleware — 非 admin 用户统一返回 403
BUG-M4 修复: 之前非 admin 用户发送 malformed body 到 admin 端点时,
Axum 先反序列化 body 返回 422,绕过了权限检查。
- 新增 admin_guard_middleware (auth/mod.rs) 在中间件层拦截
- account::admin_routes() 拆分 (dashboard 独立)
- billing::admin_routes() + account::admin_routes() 加 guard layer
- 非 admin 用户无论 body 是否合法,统一返回 403
2026-04-17 11:45:55 +08:00
..
2026-04-17 11:45:55 +08:00
2026-04-07 14:25:34 +08:00
2026-04-17 11:45:55 +08:00
2026-04-17 03:31:06 +08:00
2026-04-14 19:06:58 +08:00
2026-04-14 00:17:08 +08:00
2026-04-14 18:35:24 +08:00
2026-04-14 22:02:02 +08:00
2026-04-12 08:10:50 +08:00
2026-04-17 03:31:06 +08:00
2026-04-16 09:21:46 +08:00
2026-04-07 14:25:34 +08:00
2026-04-07 14:25:34 +08:00
2026-04-07 14:25:34 +08:00
2026-04-09 23:45:19 +08:00
2026-04-12 18:36:05 +08:00
2026-04-14 00:17:08 +08:00
2026-03-29 10:46:41 +08:00
2026-04-14 00:17:08 +08:00
2026-04-01 08:38:37 +08:00
2026-04-14 18:35:24 +08:00
2026-04-09 22:23:05 +08:00
2026-04-12 15:42:35 +08:00
2026-04-17 11:45:55 +08:00
2026-04-14 17:48:22 +08:00
2026-04-15 01:41:50 +08:00
2026-04-02 19:24:44 +08:00