fix: fixed role check middleware

This commit is contained in:
Sergey Yarkov 2022-02-14 21:58:07 +03:00
parent 046e3a28f3
commit 4056dde970
4 changed files with 48 additions and 10 deletions

View File

@ -1,5 +1,6 @@
import { Exception } from '@adonisjs/core/build/standalone';
import { HttpContextContract } from '@ioc:Adonis/Core/HttpContext';
import User from 'App/Models/User';
export default class Role {
error: {
@ -23,7 +24,7 @@ export default class Role {
* @param {string[]} roles - Array of roles for route
* @param {string[]} userRole - Array of roles of current user
*/
protected checkRoles(roles: string[], userRoles: string[]): void {
protected check(roles: string[], userRoles: string[]): void {
if (!roles.some(role => userRoles.includes(role))) {
/**
* Failed to verify user rights
@ -33,8 +34,20 @@ export default class Role {
}
public async handle({ auth }: HttpContextContract, next: () => Promise<void>, roles: string[]) {
const { userRoles } = auth.use('api').token?.meta;
this.checkRoles(roles, userRoles);
const { userId } = auth.use('api').token?.meta;
const user = await User.query().where('id', userId).preload('roles').first();
if (!user) {
/**
* User not found
*/
throw new Exception('Cannot identify current user.', this.error.status, this.error.code);
}
this.check(
roles,
user.roles.map(role => role.slug)
);
await next();
}
}

View File

@ -66,6 +66,7 @@ export default class AuthService {
*/
const token = await ctx.auth.use(this.authGuard).generate(user, {
expiresIn: '1d',
userId: user.id,
userRoles: user.roles.map(role => role.slug),
userName: user.fullname,
});

View File

@ -12,12 +12,24 @@ export default class UpdateContactsValidator {
}),
rules.unique({ table: 'contacts', column: 'phone_number' }),
]),
vk_id: schema.string.nullableAndOptional({}, [rules.regex(/^([a-zA-Z0-9_]){1,64}$/)]),
twitter_id: schema.string.nullableAndOptional({}, [rules.regex(/(^|[^@\w])@(\w{1,15})\b/)]),
telegram_id: schema.string.nullableAndOptional({}, [rules.regex(/(^|[^@\w])@(\w{1,64})\b/)]),
vk_id: schema.string.nullableAndOptional({}, [
rules.regex(/^([a-zA-Z0-9_]){1,64}$/),
rules.unique({ table: 'contacts', column: 'vk_id' }),
]),
twitter_id: schema.string.nullableAndOptional({}, [
rules.regex(/(^|[^@\w])@(\w{1,15})\b/),
rules.unique({ table: 'contacts', column: 'twitter_id' }),
]),
telegram_id: schema.string.nullableAndOptional({}, [
rules.regex(/(^|[^@\w])@(\w{1,64})\b/),
rules.unique({ table: 'contacts', column: 'telegram_id' }),
]),
});
public messages = {
'phone_number.unique': 'This phone number is not available',
'phone_number.unique': 'This phone number is not available.',
'vk_id.unique': 'This ID is not available.',
'twitter_id.unique': 'Twitter username is not available.',
'telegram_id.unique': 'Telegram username is not available.',
};
}

View File

@ -10,12 +10,24 @@ export default class UpdateUserInfoValidator {
rules.mobile({ locales: ['ru-RU', 'en-US'], strict: true }),
rules.unique({ table: 'contacts', column: 'phone_number' }),
]),
vk_id: schema.string.nullableAndOptional({}, [rules.regex(/^([a-zA-Z0-9_]){1,64}$/)]),
twitter_id: schema.string.nullableAndOptional({}, [rules.regex(/(^|[^@\w])@(\w{1,15})\b/)]),
telegram_id: schema.string.nullableAndOptional({}, [rules.regex(/(^|[^@\w])@(\w{1,64})\b/)]),
vk_id: schema.string.nullableAndOptional({}, [
rules.regex(/^([a-zA-Z0-9_]){1,64}$/),
rules.unique({ table: 'contacts', column: 'vk_id' }),
]),
twitter_id: schema.string.nullableAndOptional({}, [
rules.regex(/(^|[^@\w])@(\w{1,15})\b/),
rules.unique({ table: 'contacts', column: 'twitter_id' }),
]),
telegram_id: schema.string.nullableAndOptional({}, [
rules.regex(/(^|[^@\w])@(\w{1,64})\b/),
rules.unique({ table: 'contacts', column: 'telegram_id' }),
]),
});
public messages = {
'phone_number.unique': 'This phone number is not available.',
'vk_id.unique': 'This ID is not available.',
'twitter_id.unique': 'Twitter username is not available.',
'telegram_id.unique': 'Telegram username is not available.',
};
}