fix(web): allow anonymous downloads for global PUBLIC skills (#473)

Use `namespace === 'global'` (without @ prefix) to match the actual
route parameter value. The previous check used '@global' which never
matched, causing anonymous users to be redirected to login even for
global PUBLIC skills.

Co-authored-by: dongmucat <1127093059qq.com>
This commit is contained in:
dongmucat 2026-06-01 17:59:55 +08:00 • committed by GitHub
parent 8bd7a6bc1d
commit 2730d6470e
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -287,6 +287,11 @@ export function SkillDetailPage() {
// Download a single file from the skill version
const handleDownloadFile = () => {
const isAnonymousAllowed = namespace === 'global' && skill?.visibility === 'PUBLIC'
if (!user && !isAnonymousAllowed) {
requireLogin()
return
}
if (!previewNode || !selectedVersion) return
const cleanNamespace = namespace.startsWith('@') ? namespace.slice(1) : namespace
const url = buildApiUrl(
@ -302,7 +307,8 @@ export function SkillDetailPage() {
}
const handleDownload = async () => {
if (!user) {
const isAnonymousAllowed = namespace === 'global' && skill?.visibility === 'PUBLIC'
if (!user && !isAnonymousAllowed) {
requireLogin()
return
}