Extend fine-grained ACL to settings, content, shop, and radio.
Local Build and Deploy / deploy (push) Successful in 54s
Local Build and Deploy / deploy (push) Successful in 54s
Gate pages and mutations on module PERMS instead of dashboard-only staff checks, add radio view/edit slugs with migration 0015, and expand the operations contract tests. Co-authored-by: Cursor <[email protected]>
This commit is contained in:
1 parent
f2427b3483
commit
3c8a8ff888
32 files changed
+244
-70
No files matched your search
@@ -19,6 +19,13 @@ const ROUTES: Array<[string, string]> = [
|
||||
["online", "PERMS.USERS_VIEW"],
|
||||
["commandocentrum", "PERMS.RCON_EXECUTE"],
|
||||
["users/edit/[id]", "PERMS.USERS_EDIT"],
|
||||
["settings", "PERMS.SETTINGS_VIEW"],
|
||||
["theme", "PERMS.SETTINGS_VIEW"],
|
||||
["emulator", "PERMS.SETTINGS_VIEW"],
|
||||
["bans", "PERMS.BANS_VIEW"],
|
||||
["wordfilter", "PERMS.WORDFILTER_VIEW"],
|
||||
["articles", "PERMS.NEWS_VIEW"],
|
||||
["shop", "PERMS.SHOP_VIEW"],
|
||||
];
|
||||
|
||||
describe("admin operations route contract", () => {
|
||||
@@ -28,6 +35,12 @@ describe("admin operations route contract", () => {
|
||||
expect(readFileSync(path, "utf8"), path).toContain(permission);
|
||||
});
|
||||
|
||||
it("guards radio section via layout", () => {
|
||||
const path = "src/app/admin/radio/layout.tsx";
|
||||
expect(existsSync(path), path).toBe(true);
|
||||
expect(readFileSync(path, "utf8"), path).toContain("PERMS.RADIO_VIEW");
|
||||
});
|
||||
|
||||
it.each([
|
||||
["analytics/export", "PERMS.ANALYTICS_EXPORT"],
|
||||
["devops/health", "PERMS.DEVOPS_VIEW"],
|
||||
@@ -55,4 +68,19 @@ describe("admin operations route contract", () => {
|
||||
expect(source).toContain("PERMS.RCON_EXECUTE");
|
||||
expect(source).not.toContain("requireStaff()");
|
||||
});
|
||||
|
||||
it.each([
|
||||
["admin-settings.ts", "PERMS.SETTINGS_EDIT"],
|
||||
["admin-theme.ts", "PERMS.SETTINGS_EDIT"],
|
||||
["admin-emulator.ts", "PERMS.SETTINGS_EDIT"],
|
||||
["admin-bans.ts", "PERMS.USERS_BAN"],
|
||||
["admin-wordfilter.ts", "PERMS.WORDFILTER_EDIT"],
|
||||
["admin-articles.ts", "PERMS.NEWS_EDIT"],
|
||||
["admin-shop.ts", "PERMS.SHOP_EDIT"],
|
||||
["admin-radio-autodj.ts", "PERMS.RADIO_EDIT"],
|
||||
])("guards %s mutations with %s", (file, permission) => {
|
||||
const source = readFileSync(`src/actions/${file}`, "utf8");
|
||||
expect(source).toContain(permission);
|
||||
expect(source).not.toMatch(/await requireStaff\(\)/);
|
||||
});
|
||||
});
|
||||
@@ -1,32 +1,34 @@
|
||||
import { readFileSync } from "node:fs";
|
||||
import { readdirSync, readFileSync } from "node:fs";
|
||||
import { resolve } from "node:path";
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { PERMS } from "@/lib/permission-slugs";
|
||||
|
||||
describe("production ACL migration", () => {
|
||||
const migrationPath = resolve(
|
||||
process.cwd(),
|
||||
"prisma/migrations/0012_seed_acl_permissions.sql",
|
||||
);
|
||||
const migrationsDir = resolve(process.cwd(), "prisma/migrations");
|
||||
const allSql = readdirSync(migrationsDir)
|
||||
.filter((name) => name.endsWith(".sql"))
|
||||
.map((name) => readFileSync(resolve(migrationsDir, name), "utf8"))
|
||||
.join("\n");
|
||||
|
||||
it("seeds every permission used by the application", () => {
|
||||
const sql = readFileSync(migrationPath, "utf8");
|
||||
|
||||
for (const slug of Object.values(PERMS)) {
|
||||
expect(sql, `missing ACL seed for ${slug}`).toContain(`'${slug}'`);
|
||||
expect(allSql, `missing ACL seed for ${slug}`).toContain(`'${slug}'`);
|
||||
}
|
||||
});
|
||||
|
||||
it("assigns dashboard access after seeding permissions", () => {
|
||||
const sql = readFileSync(migrationPath, "utf8");
|
||||
const seedPosition = sql.indexOf("INSERT INTO `acl_permissions`");
|
||||
const assignmentPosition = sql.indexOf(
|
||||
const seedSql = readFileSync(
|
||||
resolve(migrationsDir, "0012_seed_acl_permissions.sql"),
|
||||
"utf8",
|
||||
);
|
||||
const seedPosition = seedSql.indexOf("INSERT INTO `acl_permissions`");
|
||||
const assignmentPosition = seedSql.indexOf(
|
||||
"INSERT INTO `acl_model_permissions`",
|
||||
);
|
||||
|
||||
expect(seedPosition).toBeGreaterThanOrEqual(0);
|
||||
expect(assignmentPosition).toBeGreaterThan(seedPosition);
|
||||
expect(sql).toContain("ap.slug = 'admin.dashboard'");
|
||||
expect(sql).toContain("ap.slug = 'mod.dashboard'");
|
||||
expect(seedSql).toContain("ap.slug = 'admin.dashboard'");
|
||||
expect(seedSql).toContain("ap.slug = 'mod.dashboard'");
|
||||
});
|
||||
});
|
||||
@@ -39,6 +39,16 @@ export async function requirePermission(permission: string): Promise<StaffUser>
|
||||
};
|
||||
}
|
||||
|
||||
export async function requirePermissionRateLimited(
|
||||
permission: string,
|
||||
): Promise<StaffUser> {
|
||||
const staff = await requirePermission(permission);
|
||||
const ip = await clientIp();
|
||||
if (!(await rateLimit(`admin:${staff.id}:${ip}`, 30, 60_000)).ok)
|
||||
redirectSafe("/admin?error=ratelimit", "/admin");
|
||||
return staff;
|
||||
}
|
||||
|
||||
export async function requireStaffRateLimited(): Promise<StaffUser> {
|
||||
const staff = await requireStaff();
|
||||
const ip = await clientIp();
|
||||
|
||||
@@ -26,6 +26,9 @@ export const PERMS = {
|
||||
CATALOG_EDIT: "admin.catalog.edit",
|
||||
RCON_EXECUTE: "admin.rcon.execute",
|
||||
EXPORT: "admin.export",
|
||||
// ── Radio Module ──
|
||||
RADIO_VIEW: "admin.radio.view",
|
||||
RADIO_EDIT: "admin.radio.edit",
|
||||
PREFIXES_VIEW: "admin.prefixes.view",
|
||||
PREFIXES_EDIT: "admin.prefixes.edit",
|
||||
TICKETS_VIEW: "admin.tickets.view",
|
||||
|
||||
Reference in new issue
Block a user