feat: add multi-user RBAC with admin/viewer roles and user management
Add complete multi-user support with role-based access control: Backend: - Add users CRUD endpoints (GET/POST/PUT/DELETE /api/users) with admin-only guards - Add display_name column to users table with ALTER TABLE migration - Fix auth to use session-based user identity (not hardcoded 'admin') - Add POST /api/auth/logout to revoke server-side sessions - Add require_admin() and extract_session() helpers for clean RBAC - Guard all mutating endpoints (clients, providers, models, settings, backup) Frontend: - Add Users management page with create/edit/reset-password/delete modals - Add role gating: hide edit/delete buttons for viewers on clients, providers, models - Settings page hides auth tokens and admin actions for viewers - Logout now revokes server session before clearing localStorage - Sidebar shows real display_name and formatted role (Administrator/Viewer) - Fix sidebar header: single logo with onerror fallback, renamed to 'LLM Proxy' - Add badge and btn-action CSS classes for role pills and action buttons - Bump cache-bust to v=7
This commit is contained in:
@@ -7,6 +7,7 @@ mod providers;
|
||||
pub mod sessions;
|
||||
mod system;
|
||||
mod usage;
|
||||
mod users;
|
||||
mod websocket;
|
||||
|
||||
use axum::{
|
||||
@@ -67,7 +68,16 @@ pub fn router(state: AppState) -> Router {
|
||||
// API endpoints
|
||||
.route("/api/auth/login", post(auth::handle_login))
|
||||
.route("/api/auth/status", get(auth::handle_auth_status))
|
||||
.route("/api/auth/logout", post(auth::handle_logout))
|
||||
.route("/api/auth/change-password", post(auth::handle_change_password))
|
||||
.route(
|
||||
"/api/users",
|
||||
get(users::handle_get_users).post(users::handle_create_user),
|
||||
)
|
||||
.route(
|
||||
"/api/users/{id}",
|
||||
put(users::handle_update_user).delete(users::handle_delete_user),
|
||||
)
|
||||
.route("/api/usage/summary", get(usage::handle_usage_summary))
|
||||
.route("/api/usage/time-series", get(usage::handle_time_series))
|
||||
.route("/api/usage/clients", get(usage::handle_clients_usage))
|
||||
|
||||
Reference in New Issue
Block a user