Conversation
buildPageLoginRoutes 的形参是 model.AccessRule(值类型),
但 buildOIDCRoutes 的 providerID==0 分支传了 nil:
cannot use nil as "model.AccessRule" value in argument to
m.buildPageLoginRoutes
改为传 model.AccessRule{}。该分支语义是「未绑定 OIDC provider,
退回页面跳转登录」,AllowedUserIDs 为空恰好表示不限定可登录用户,
与原意图一致(provider 缺失时本就无法按 provider 限定用户)。
这行是 main 分支上的编译错误,go build ./... 整个 backend 失败,
连带 PIKACHUIM#125~PIKACHUIM#129 五个 PR 的 CI 全部 UNSTABLE。
验证:go build ./... 与 go vet ./... 均通过。
This was referenced Sep 30, 2026
Open
Collaborator
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
问题
main分支当前编译不过:go build ./...整个 backend 失败,因此 #125 ~ #129 五个 PR 的 CI 全部处于UNSTABLE,无法通过门禁。根因
buildPageLoginRoutes的形参是值类型model.AccessRule:但
buildOIDCRoutes中providerID == 0的分支传了nil:应是函数签名重构(从
*model.CaddySite改为model.AccessRule)时遗漏了改这一处调用点。仓库中buildPageLoginRoutes有两个调用点,另一个(authMode == "page_login")已正确传authRule。修复
为什么传空值是正确的,不只是「让编译过」
buildPageLoginRoutes的函数体只用rule.AllowedUserIDs一个字段来决定netpanel_session_authhandler 是否附带allowed_user_ids:model.AccessRule{}的AllowedUserIDs为空 → 不附加allowed_user_ids→ 认证中间件接受任意已启用用户。这与该分支的语义一致:provider 缺失时本就无法按 provider 限定可登录用户。若改为传
rule(保留原OidcProviderID == 0的那条规则),反而会把该规则的AllowedUserIDs带入页面登录路径,与「provider 不存在则回退」的设计意图不符。验证
go build ./...通过go vet ./...通过go test ./...:仅service/storage的TestValidateRootPath失败,为上游既有失败,与本 PR 无关(详见下)关于
TestValidateRootPath该测试在 macOS 上失败、在 Linux CI 上通过,原因是 macOS 的
t.TempDir()返回/var/folders/...,而它是指向/private/var/folders/...的符号链接;被测函数ValidateRootPath会调filepath.EvalSymlinks解析软链(这是刻意设计,用于防止用软链绕过目录校验),而测试拿未解析的dir做比较:未在本 PR 处理——与编译错误无关,且建议单独提 PR 修测试断言(应先
EvalSymlinks(dir)再比较)。