fix: authorize super admins by dynamic highest rank
Remote Build and Deploy / deploy (push) Successful in 42s
Remote Build and Deploy / deploy (push) Successful in 42s
This commit is contained in:
1 parent
bb847176ad
commit
f08e56cf53
10 files changed
+173
-65
No files matched your search
+4
-20
@@ -1,18 +1,10 @@
|
||||
import { redirect } from "next/navigation";
|
||||
import { isStaff } from "@/lib/admin/is-staff";
|
||||
import { resolveStaffUser } from "@/lib/admin/staff-user";
|
||||
import { auth } from "@/lib/auth";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { siteSettings } from "@/lib/services/site-settings";
|
||||
import { canAccess, getAdminContext, PERMS } from "@/lib/permissions";
|
||||
import { clientIp, rateLimit } from "@/lib/rate-limit";
|
||||
|
||||
export { isStaff };
|
||||
|
||||
export async function getMinStaffRank(): Promise<number> {
|
||||
const n = Number(await siteSettings.get("min_staff_rank", "7"));
|
||||
return Number.isFinite(n) ? n : 7;
|
||||
}
|
||||
|
||||
export interface StaffUser {
|
||||
id: number;
|
||||
rank: number;
|
||||
@@ -24,17 +16,9 @@ export interface StaffUser {
|
||||
* and to / when authenticated but not staff. Returns the staff user otherwise.
|
||||
*/
|
||||
export async function requireStaff(): Promise<StaffUser> {
|
||||
const session = await auth();
|
||||
if (!session?.user?.id) redirect("/login");
|
||||
const minRank = await getMinStaffRank();
|
||||
const staff = await resolveStaffUser(session.user.id, minRank, (id) =>
|
||||
prisma.user.findUnique({
|
||||
where: { id },
|
||||
select: { id: true, rank: true, username: true },
|
||||
}),
|
||||
);
|
||||
if (!staff) redirect("/");
|
||||
return staff;
|
||||
const { session, permissions } = await getAdminContext();
|
||||
if (!canAccess(permissions, PERMS.ADMIN_DASHBOARD, session.user.rank)) redirect("/");
|
||||
return { id: session.user.id, rank: session.user.rank, username: session.user.username };
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
Reference in new issue
Block a user