fix: protect admin routes and ignore local docs
This commit is contained in:
1 parent
6a08db8dd0
commit
17264dfc06
6 files changed
+37
-413
No files matched your search
@@ -0,0 +1,14 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { shouldRedirectAdminRequest } from "./proxy-access";
|
||||
|
||||
describe("shouldRedirectAdminRequest", () => {
|
||||
it("redirects anonymous and non-staff admin requests before rendering", () => {
|
||||
expect(shouldRedirectAdminRequest("/admin", null)).toBe(true);
|
||||
expect(shouldRedirectAdminRequest("/admin/tickets", { rank: 1 })).toBe(true);
|
||||
});
|
||||
|
||||
it("allows staff admin requests and never affects public routes", () => {
|
||||
expect(shouldRedirectAdminRequest("/admin/permissions", { rank: 7 })).toBe(false);
|
||||
expect(shouldRedirectAdminRequest("/news", null)).toBe(false);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,9 @@
|
||||
export interface ProxyToken {
|
||||
rank?: unknown;
|
||||
}
|
||||
|
||||
export function shouldRedirectAdminRequest(pathname: string, token: ProxyToken | null): boolean {
|
||||
if (pathname !== "/admin" && !pathname.startsWith("/admin/")) return false;
|
||||
const rank = typeof token?.rank === "number" ? token.rank : Number(token?.rank);
|
||||
return !Number.isInteger(rank) || rank < 7;
|
||||
}
|
||||
Reference in new issue
Block a user