修复后台评论加载问题,非admin也可加载对自己文章的未审核评论。

This commit is contained in:
2026-08-26 17:59:03 +08:00
parent 20395a79a2
commit cfe5cf53aa
6 changed files with 24 additions and 24 deletions
+8 -8
View File
@@ -35,9 +35,13 @@ func GetComments(c *gin.Context) {
})
// 非管理员只能查看自己文章上的评论(后台)或已审核的评论(前台)
if !isAdmin(c) {
// 前台访问:只显示已审核的评论
db = db.Where("status = ?", "approved")
if isAdmin(c) {
// 管理员可以查看所有评论
if status != "" {
db = db.Where("status = ?", status)
}
} else {
if userID, exists := c.Get("userID"); exists {
// 如果是后台接口调用,限制为自己的文章
if postID == "" && postSlug == "" {
@@ -45,11 +49,7 @@ func GetComments(c *gin.Context) {
database.DB.Model(&models.Post{}).Select("id").Where("author_id = ?", userID))
}
}
} else {
// 管理员可以查看所有状态的评论(通过 status 参数过滤)
if status != "" {
db = db.Where("status = ?", status)
}
}
// 按文章 ID 或 slug 过滤
+1
View File
@@ -59,6 +59,7 @@ func main() {
r := gin.New()
r.Use(gin.Recovery())
r.Use(slogMiddleware(logger))
r.Use(gin.Logger())
// 配置模板渲染器(现在 LoadTemplates 返回 error)
htmlRenderer, err := utils.LoadTemplates(theme)
+1 -1
View File
@@ -110,12 +110,12 @@ func setupAdminAPIRoutes(api *gin.RouterGroup) {
admin.DELETE("/categories/:id", backend.DeleteCategory)
// 标签管理(写入)
admin.POST("/tags", backend.CreateTag)
admin.GET("/tags/:id", backend.GetTag)
admin.PUT("/tags/:id", backend.UpdateTag)
admin.DELETE("/tags/:id", backend.DeleteTag)
// 页面管理(写入)
admin.GET("/pages", backend.GetPages)
admin.POST("/pages", backend.CreatePage)
admin.PUT("/pages/:id", backend.UpdatePage)
admin.DELETE("/pages/:id", backend.DeletePage)
+13 -13
View File
@@ -725,7 +725,7 @@ async function loadTags() {
// 加载页面
async function loadPages() {
try {
const res = await fetch(`${API_BASE}/pages`);
const res = await fetch(`${API_BASE}/admin/pages`);
const data = await res.json();
const tbody = document.getElementById('pages-list');
@@ -900,7 +900,7 @@ function editTag(id, name, slug) {
// 编辑页面
async function editPage(id) {
try {
const res = await fetch(`${API_BASE}/pages/${id}`, { headers: getHeaders() });
const res = await fetch(`${API_BASE}/admin/pages/${id}`, { headers: getHeaders() });
const data = await res.json();
const page = data.data;
@@ -1266,14 +1266,14 @@ let currentTheme = null;
async function loadThemes() {
try {
// 获取当前主题
const currentRes = await fetch(`${API_BASE}/theme`, {
const currentRes = await fetch(`${API_BASE}/admin/theme`, {
headers: getHeaders()
});
const currentData = await currentRes.json();
currentTheme = currentData.theme;
// 获取所有可用主题
const themesRes = await fetch(`${API_BASE}/themes`, {
const themesRes = await fetch(`${API_BASE}/admin/themes`, {
headers: getHeaders()
});
const themesData = await themesRes.json();
@@ -1345,7 +1345,7 @@ async function switchTheme() {
}
try {
const response = await fetch(`${API_BASE}/theme`, {
const response = await fetch(`${API_BASE}/admin/theme`, {
method: 'POST',
headers: {
...getHeaders(),
@@ -1392,7 +1392,7 @@ async function showCreateThemeModal() {
const themeSelect = document.getElementById('theme-template');
try {
// 获取所有可用主题
const res = await fetch(`${API_BASE}/themes`, {
const res = await fetch(`${API_BASE}/admin/themes`, {
headers: getHeaders()
});
const themesData = await res.json();
@@ -1443,7 +1443,7 @@ async function handleCreateTheme(e) {
}
try {
const response = await fetch(`${API_BASE}/themes/create`, {
const response = await fetch(`${API_BASE}/admin/themes/create`, {
method: 'POST',
headers: {
...getHeaders(),
@@ -1477,7 +1477,7 @@ async function handleCreateTheme(e) {
// 快速切换主题
async function quickSwitch(theme) {
try {
const response = await fetch(`${API_BASE}/theme`, {
const response = await fetch(`${API_BASE}/admin/theme`, {
method: 'POST',
headers: {
...getHeaders(),
@@ -1525,7 +1525,7 @@ async function editTheme(themeName) {
// 加载主题文件列表
async function loadThemeFiles(themeName) {
try {
const response = await fetch(`${API_BASE}/themes/${themeName}/files`, {
const response = await fetch(`${API_BASE}/admin/themes/${themeName}/files`, {
headers: getHeaders()
});
const data = await response.json();
@@ -1577,7 +1577,7 @@ async function loadFileContent(filename) {
try {
currentEditingFile = filename;
const response = await fetch(`${API_BASE}/themes/${currentEditingTheme}/files/${filename}`, {
const response = await fetch(`${API_BASE}/admin/themes/${currentEditingTheme}/files/${filename}`, {
headers: getHeaders()
});
const data = await response.json();
@@ -1610,7 +1610,7 @@ async function saveCurrentFile() {
const content = document.getElementById('theme-file-editor').value;
try {
const response = await fetch(`${API_BASE}/themes/${currentEditingTheme}/files/${currentEditingFile}`, {
const response = await fetch(`${API_BASE}/admin/themes/${currentEditingTheme}/files/${currentEditingFile}`, {
method: 'PUT',
headers: {
...getHeaders(),
@@ -1626,11 +1626,11 @@ async function saveCurrentFile() {
// 如果是模板文件,重新加载主题
if (currentEditingFile.endsWith('.html')) {
const renderer = await fetch(`${API_BASE}/theme`, { headers: getHeaders() });
const renderer = await fetch(`${API_BASE}/admin/theme`, { headers: getHeaders() });
const rendererData = await renderer.json();
if (rendererData.theme === currentEditingTheme) {
// 重新加载当前主题以应用更改
await fetch(`${API_BASE}/theme`, {
await fetch(`${API_BASE}/admin/theme`, {
method: 'POST',
headers: {
...getHeaders(),
-1
View File
@@ -304,7 +304,6 @@
<div id="tags-page" class="page hidden">
<div class="page-header">
<h1>标签管理</h1>
<button class="btn-primary" onclick="showTagForm()">新建标签</button>
</div>
<table class="data-table">
<thead>
+1 -1
View File
@@ -67,7 +67,7 @@
<ul class="system-menu">
{{if .IsLoggedIn}}
<li class="system-menu-item">
<a href="/admin" class="system-menu-link">🔐 进入后台</a>
<a href="/admin" class="system-menu-link">🔐 进入后台^_^</a>
</li>
<li class="system-menu-item">
<a href="/logout" class="system-menu-link">🚪 退出登录{{if .LoginName}}({{.LoginName}}){{end}}</a>