feat(auth): centralize ThothII permission enforcement

This commit is contained in:
2026-08-16 17:52:03 +02:00
parent 23ac75ce1d
commit 2e0489ce22
20 changed files with 330 additions and 93 deletions
+9 -3
View File
@@ -1,17 +1,23 @@
import type { FastifyRequest, FastifyReply } from "fastify";
import { localPrincipal, type PrincipalContext, upstreamPrincipal } from "./principal.js";
import { rolesToPermissions } from "./config.js";
declare module "fastify" {
interface FastifyRequest { principal?: PrincipalContext }
}
export function authPreHandler(mode: "none" | "mock" | "upstream") {
export function authPreHandler(mode: "none" | "mock" | "upstream", publicExposure = false) {
return async (req: FastifyRequest, reply: FastifyReply) => {
if (mode === "none") {
req.principal = localPrincipal();
req.principal = localPrincipal(publicExposure);
} else if (mode === "mock") {
const subject = typeof req.headers["x-mock-user"] === "string" ? req.headers["x-mock-user"].trim() : "mock";
req.principal = { issuer: "mock", subject: subject || "mock", displayName: subject || "mock", isAdmin: false };
const elevated = req.headers["x-thoth-is-admin"] === "1" || req.headers["x-thoth-is-admin"] === "true";
const roles = elevated ? ["admin"] as const : ["user"] as const;
req.principal = {
issuer: "mock", subject: subject || "mock", displayName: subject || "mock", roles,
permissions: rolesToPermissions(roles), isAdmin: elevated,
};
} else {
const principal = upstreamPrincipal(req.headers);
if (!principal) {