From 2730d6470e6e086b5f381e2f07fb2ae53e94d920 Mon Sep 17 00:00:00 2001 From: dongmucat <70678707+dongmucat@users.noreply.github.com> Date: Mon, 1 Jun 2026 17:59:55 +0800 Subject: [PATCH] fix(web): allow anonymous downloads for global PUBLIC skills (#473) Use `namespace === 'global'` (without @ prefix) to match the actual route parameter value. The previous check used '@global' which never matched, causing anonymous users to be redirected to login even for global PUBLIC skills. Co-authored-by: dongmucat <1127093059qq.com> --- web/src/pages/skill-detail.tsx | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/web/src/pages/skill-detail.tsx b/web/src/pages/skill-detail.tsx index 5687eaa1..086f85a0 100644 --- a/web/src/pages/skill-detail.tsx +++ b/web/src/pages/skill-detail.tsx @@ -287,6 +287,11 @@ export function SkillDetailPage() { // Download a single file from the skill version const handleDownloadFile = () => { + const isAnonymousAllowed = namespace === 'global' && skill?.visibility === 'PUBLIC' + if (!user && !isAnonymousAllowed) { + requireLogin() + return + } if (!previewNode || !selectedVersion) return const cleanNamespace = namespace.startsWith('@') ? namespace.slice(1) : namespace const url = buildApiUrl( @@ -302,7 +307,8 @@ export function SkillDetailPage() { } const handleDownload = async () => { - if (!user) { + const isAnonymousAllowed = namespace === 'global' && skill?.visibility === 'PUBLIC' + if (!user && !isAnonymousAllowed) { requireLogin() return }