fix: enforce public contrast and audit rank errors
This commit is contained in:
1 parent
e1381c0f40
commit
b695a33ead
12 files changed
+184
-29
No files matched your search
@@ -2,6 +2,7 @@ import type { z } from 'zod'
|
||||
import { auth } from '@/lib/auth'
|
||||
import { canAccess, getApiAdminContext } from '@/lib/permissions'
|
||||
import { type ActionResult, actionError, handleActionError } from '@/lib/safe-action-shared'
|
||||
import { logAuthorizationEvent } from '@/lib/admin/authorization-events'
|
||||
|
||||
export type { ActionResult }
|
||||
|
||||
@@ -42,6 +43,11 @@ export function adminAction<TSchema extends z.ZodType | undefined = undefined>(
|
||||
|
||||
if (options.permission) {
|
||||
if (!canAccess(apiCtx.permissions, options.permission, apiCtx.session.user.rank)) {
|
||||
await logAuthorizationEvent({
|
||||
kind: 'permission.denied', userId: apiCtx.session.user.id,
|
||||
username: apiCtx.session.user.name ?? undefined, rank: apiCtx.session.user.rank,
|
||||
permission: options.permission, source: 'adminAction', reason: 'Permission check denied',
|
||||
})
|
||||
return actionError('Unauthorized')
|
||||
}
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user