Extend fine-grained ACL to settings, content, shop, and radio.
Local Build and Deploy / deploy (push) Successful in 54s
Local Build and Deploy / deploy (push) Successful in 54s
Gate pages and mutations on module PERMS instead of dashboard-only staff checks, add radio view/edit slugs with migration 0015, and expand the operations contract tests. Co-authored-by: Cursor <[email protected]>
This commit is contained in:
1 parent
f2427b3483
commit
3c8a8ff888
32 files changed
+244
-70
No files matched your search
@@ -1,32 +1,34 @@
|
||||
import { readFileSync } from "node:fs";
|
||||
import { readdirSync, readFileSync } from "node:fs";
|
||||
import { resolve } from "node:path";
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { PERMS } from "@/lib/permission-slugs";
|
||||
|
||||
describe("production ACL migration", () => {
|
||||
const migrationPath = resolve(
|
||||
process.cwd(),
|
||||
"prisma/migrations/0012_seed_acl_permissions.sql",
|
||||
);
|
||||
const migrationsDir = resolve(process.cwd(), "prisma/migrations");
|
||||
const allSql = readdirSync(migrationsDir)
|
||||
.filter((name) => name.endsWith(".sql"))
|
||||
.map((name) => readFileSync(resolve(migrationsDir, name), "utf8"))
|
||||
.join("\n");
|
||||
|
||||
it("seeds every permission used by the application", () => {
|
||||
const sql = readFileSync(migrationPath, "utf8");
|
||||
|
||||
for (const slug of Object.values(PERMS)) {
|
||||
expect(sql, `missing ACL seed for ${slug}`).toContain(`'${slug}'`);
|
||||
expect(allSql, `missing ACL seed for ${slug}`).toContain(`'${slug}'`);
|
||||
}
|
||||
});
|
||||
|
||||
it("assigns dashboard access after seeding permissions", () => {
|
||||
const sql = readFileSync(migrationPath, "utf8");
|
||||
const seedPosition = sql.indexOf("INSERT INTO `acl_permissions`");
|
||||
const assignmentPosition = sql.indexOf(
|
||||
const seedSql = readFileSync(
|
||||
resolve(migrationsDir, "0012_seed_acl_permissions.sql"),
|
||||
"utf8",
|
||||
);
|
||||
const seedPosition = seedSql.indexOf("INSERT INTO `acl_permissions`");
|
||||
const assignmentPosition = seedSql.indexOf(
|
||||
"INSERT INTO `acl_model_permissions`",
|
||||
);
|
||||
|
||||
expect(seedPosition).toBeGreaterThanOrEqual(0);
|
||||
expect(assignmentPosition).toBeGreaterThan(seedPosition);
|
||||
expect(sql).toContain("ap.slug = 'admin.dashboard'");
|
||||
expect(sql).toContain("ap.slug = 'mod.dashboard'");
|
||||
expect(seedSql).toContain("ap.slug = 'admin.dashboard'");
|
||||
expect(seedSql).toContain("ap.slug = 'mod.dashboard'");
|
||||
});
|
||||
});
|
||||
@@ -39,6 +39,16 @@ export async function requirePermission(permission: string): Promise<StaffUser>
|
||||
};
|
||||
}
|
||||
|
||||
export async function requirePermissionRateLimited(
|
||||
permission: string,
|
||||
): Promise<StaffUser> {
|
||||
const staff = await requirePermission(permission);
|
||||
const ip = await clientIp();
|
||||
if (!(await rateLimit(`admin:${staff.id}:${ip}`, 30, 60_000)).ok)
|
||||
redirectSafe("/admin?error=ratelimit", "/admin");
|
||||
return staff;
|
||||
}
|
||||
|
||||
export async function requireStaffRateLimited(): Promise<StaffUser> {
|
||||
const staff = await requireStaff();
|
||||
const ip = await clientIp();
|
||||
|
||||
Reference in new issue
Block a user