feat(auth): centralize ThothII permission enforcement
This commit is contained in:
@@ -1,9 +1,9 @@
|
||||
import type { FastifyInstance } from "fastify";
|
||||
import type { ThtRunner } from "../tht/tht-runner.js";
|
||||
import { getPrincipal } from "../auth/auth.js";
|
||||
import type { PrincipalContext } from "../auth/principal.js";
|
||||
import type { Settings } from "../settings/settings-store.js";
|
||||
import type { WorkspaceRegistry } from "../workspaces/registry.js";
|
||||
import { isPrincipalContext, requirePermission } from "../auth/authorization.js";
|
||||
|
||||
export function sqlRoutes(app: FastifyInstance, deps: {
|
||||
tht: ThtRunner; getSettings: (principal: PrincipalContext) => Promise<Settings>;
|
||||
@@ -54,7 +54,9 @@ export function sqlRoutes(app: FastifyInstance, deps: {
|
||||
let principal: PrincipalContext;
|
||||
let workspace: string | undefined;
|
||||
try {
|
||||
principal = getPrincipal(req);
|
||||
const authorized = requirePermission(req, reply, "session.use");
|
||||
if (!isPrincipalContext(authorized)) return authorized;
|
||||
principal = authorized;
|
||||
const settings = await deps.getSettings(principal);
|
||||
const located = await locate(principal, id, settings.workspace);
|
||||
if (!located) return reply.code(404).send({ error: "session not found" });
|
||||
@@ -74,7 +76,9 @@ export function sqlRoutes(app: FastifyInstance, deps: {
|
||||
let principal: PrincipalContext;
|
||||
let workspace: string | undefined;
|
||||
try {
|
||||
principal = getPrincipal(req);
|
||||
const authorized = requirePermission(req, reply, "session.use");
|
||||
if (!isPrincipalContext(authorized)) return authorized;
|
||||
principal = authorized;
|
||||
const settings = await deps.getSettings(principal);
|
||||
const located = await locate(principal, id, settings.workspace);
|
||||
if (!located) return reply.code(404).send({ error: "session not found" });
|
||||
|
||||
Reference in New Issue
Block a user