fix: complete acl management
This commit is contained in:
1 parent
667ec9af4c
commit
4b596226e0
6 files changed
+187
-75
No files matched your search
@@ -0,0 +1,23 @@
|
||||
import { revalidateTag } from 'next/cache'
|
||||
import { NextResponse } from 'next/server'
|
||||
import { withAdmin } from '@/lib/api-handler'
|
||||
import { apiError } from '@/lib/api-response'
|
||||
import { PERMS } from '@/lib/permissions'
|
||||
import { prisma } from '@/lib/prisma'
|
||||
|
||||
export const POST = withAdmin({ permission: PERMS.PERMISSIONS_MANAGE }, async (request) => {
|
||||
const body = await request.json()
|
||||
const userId = Number(body.userId)
|
||||
const roleId = Number(body.roleId)
|
||||
if (!Number.isInteger(userId) || userId <= 0 || !Number.isInteger(roleId) || roleId <= 0) {
|
||||
return apiError('Valid userId and roleId required', 400)
|
||||
}
|
||||
if (body.action === 'remove') {
|
||||
await prisma.aclModelRole.deleteMany({ where: { modelType: 'User', modelId: userId, roleId } })
|
||||
} else {
|
||||
const existing = await prisma.aclModelRole.findFirst({ where: { modelType: 'User', modelId: userId, roleId } })
|
||||
if (!existing) await prisma.aclModelRole.create({ data: { modelType: 'User', modelId: userId, roleId } })
|
||||
}
|
||||
revalidateTag('permissions', { expire: 0 })
|
||||
return NextResponse.json({ success: true })
|
||||
})
|
||||
@@ -0,0 +1,31 @@
|
||||
import { revalidateTag } from 'next/cache'
|
||||
import { NextResponse } from 'next/server'
|
||||
import { withAdmin } from '@/lib/api-handler'
|
||||
import { apiError } from '@/lib/api-response'
|
||||
import { PERMS } from '@/lib/permissions'
|
||||
import { prisma } from '@/lib/prisma'
|
||||
|
||||
export const POST = withAdmin({ permission: PERMS.PERMISSIONS_MANAGE }, async (request) => {
|
||||
const body = await request.json()
|
||||
const slug = String(body.slug ?? '').trim().toLowerCase()
|
||||
const title = String(body.title ?? '').trim()
|
||||
if (!/^[a-z0-9._-]{2,64}$/.test(slug) || !title) return apiError('Valid slug and title required', 400)
|
||||
const role = await prisma.aclRole.create({ data: { slug, title } })
|
||||
revalidateTag('permissions', { expire: 0 })
|
||||
return NextResponse.json({ role })
|
||||
})
|
||||
|
||||
export const DELETE = withAdmin({ permission: PERMS.PERMISSIONS_MANAGE }, async (request) => {
|
||||
const id = Number(request.nextUrl.searchParams.get('id'))
|
||||
if (!Number.isInteger(id) || id <= 0) return apiError('Valid ID required', 400)
|
||||
const role = await prisma.aclRole.findUnique({ where: { id }, select: { slug: true } })
|
||||
if (!role) return apiError('Role not found', 404)
|
||||
if (role.slug.startsWith('rank_')) return apiError('Rank roles must be managed through emulator ranks', 409)
|
||||
await prisma.$transaction([
|
||||
prisma.aclModelPermission.deleteMany({ where: { modelType: 'Role', modelId: id } }),
|
||||
prisma.aclModelRole.deleteMany({ where: { roleId: id } }),
|
||||
prisma.aclRole.delete({ where: { id } }),
|
||||
])
|
||||
revalidateTag('permissions', { expire: 0 })
|
||||
return NextResponse.json({ success: true })
|
||||
})
|
||||
Reference in new issue
Block a user