feat(auth): centralize ThothII permission enforcement
This commit is contained in:
+4
-4
@@ -7,7 +7,7 @@ import { ThtRunner } from "./tht/tht-runner.js";
|
||||
import { PiProcessManager } from "./pi/pi-process-manager.js";
|
||||
import { SseHub } from "./sse/sse-hub.js";
|
||||
import { authPreHandler } from "./auth/auth.js";
|
||||
import { getPrincipal } from "./auth/auth.js";
|
||||
import { requirePermission } from "./auth/authorization.js";
|
||||
import type { PrincipalContext } from "./auth/principal.js";
|
||||
import { sessionRoutes } from "./routes/sessions.js";
|
||||
import { sqlRoutes } from "./routes/sql.js";
|
||||
@@ -140,7 +140,7 @@ export function buildApp(config: AppConfig, deps?: BuildAppDeps): FastifyInstanc
|
||||
if (config.authMode === "local" || config.authMode === "oidc") {
|
||||
throw new Error("configured authentication mode is not implemented");
|
||||
}
|
||||
const authenticate = authPreHandler(config.authMode);
|
||||
const authenticate = authPreHandler(config.authMode, config.publicExposure);
|
||||
app.addHook("preHandler", async (req, reply) => {
|
||||
// Process readiness is intentionally unauthenticated for local container/proxy probes.
|
||||
if (req.url === "/health" || req.url === "/health/dwh") return;
|
||||
@@ -167,7 +167,7 @@ export function buildApp(config: AppConfig, deps?: BuildAppDeps): FastifyInstanc
|
||||
}
|
||||
return { ok: true, detail: "workspace diagnostics own DWH reachability" };
|
||||
});
|
||||
app.get("/me", async (req) => getPrincipal(req));
|
||||
app.get("/me", async (req, reply) => requirePermission(req, reply, "session.use"));
|
||||
sessionRoutes(app, {
|
||||
mgr, tht: tht as ThtRunner, hub, getSettings, readiness, listModels, workspaceRegistry,
|
||||
dwhPrecheck: config.dwhPrecheck,
|
||||
@@ -211,7 +211,7 @@ export function buildApp(config: AppConfig, deps?: BuildAppDeps): FastifyInstanc
|
||||
secretStore: workspaceSecretStore,
|
||||
});
|
||||
settingsRoutes(app, { cfg: config, listModels, getSettings });
|
||||
piManagementRoutes(app, { config, service: piManagement });
|
||||
piManagementRoutes(app, { service: piManagement });
|
||||
|
||||
return app;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user