Log store write failures at the source; share the oper guard
The store's map_err(|_| Internal) discarded the real IO error, so a disk-full or permissions failure was invisible; log it once in the log append path where it happens. Add echo_api::require_oper (parameterised by the required privilege) and route the three copied per-service guards through it, keeping each service's own wording and policy.
This commit is contained in:
parent
081d90ad68
commit
d9c0878b00
5 changed files with 23 additions and 16 deletions
|
|
@ -66,9 +66,5 @@ impl Service for ReportServ {
|
|||
|
||||
// Reviewing the queue is for operators only.
|
||||
fn require_oper(me: &str, from: &Sender, ctx: &mut ServiceCtx) -> bool {
|
||||
if from.privs.any() {
|
||||
return true;
|
||||
}
|
||||
ctx.notice(me, from.uid, "Access denied — reviewing reports is for services operators.");
|
||||
false
|
||||
echo_api::require_oper(me, from, ctx, None, "reviewing reports")
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue