mirror of
https://github.com/sergeyyarkov/educt-server.git
synced 2026-10-11 18:29:15 +03:00
fix: fixed role check middleware
This commit is contained in:
parent
046e3a28f3
commit
4056dde970
@ -1,5 +1,6 @@
|
||||
import { Exception } from '@adonisjs/core/build/standalone';
|
||||
import { HttpContextContract } from '@ioc:Adonis/Core/HttpContext';
|
||||
import User from 'App/Models/User';
|
||||
|
||||
export default class Role {
|
||||
error: {
|
||||
@ -23,7 +24,7 @@ export default class Role {
|
||||
* @param {string[]} roles - Array of roles for route
|
||||
* @param {string[]} userRole - Array of roles of current user
|
||||
*/
|
||||
protected checkRoles(roles: string[], userRoles: string[]): void {
|
||||
protected check(roles: string[], userRoles: string[]): void {
|
||||
if (!roles.some(role => userRoles.includes(role))) {
|
||||
/**
|
||||
* Failed to verify user rights
|
||||
@ -33,8 +34,20 @@ export default class Role {
|
||||
}
|
||||
|
||||
public async handle({ auth }: HttpContextContract, next: () => Promise<void>, roles: string[]) {
|
||||
const { userRoles } = auth.use('api').token?.meta;
|
||||
this.checkRoles(roles, userRoles);
|
||||
const { userId } = auth.use('api').token?.meta;
|
||||
const user = await User.query().where('id', userId).preload('roles').first();
|
||||
|
||||
if (!user) {
|
||||
/**
|
||||
* User not found
|
||||
*/
|
||||
throw new Exception('Cannot identify current user.', this.error.status, this.error.code);
|
||||
}
|
||||
|
||||
this.check(
|
||||
roles,
|
||||
user.roles.map(role => role.slug)
|
||||
);
|
||||
await next();
|
||||
}
|
||||
}
|
||||
|
||||
@ -66,6 +66,7 @@ export default class AuthService {
|
||||
*/
|
||||
const token = await ctx.auth.use(this.authGuard).generate(user, {
|
||||
expiresIn: '1d',
|
||||
userId: user.id,
|
||||
userRoles: user.roles.map(role => role.slug),
|
||||
userName: user.fullname,
|
||||
});
|
||||
|
||||
@ -12,12 +12,24 @@ export default class UpdateContactsValidator {
|
||||
}),
|
||||
rules.unique({ table: 'contacts', column: 'phone_number' }),
|
||||
]),
|
||||
vk_id: schema.string.nullableAndOptional({}, [rules.regex(/^([a-zA-Z0-9_]){1,64}$/)]),
|
||||
twitter_id: schema.string.nullableAndOptional({}, [rules.regex(/(^|[^@\w])@(\w{1,15})\b/)]),
|
||||
telegram_id: schema.string.nullableAndOptional({}, [rules.regex(/(^|[^@\w])@(\w{1,64})\b/)]),
|
||||
vk_id: schema.string.nullableAndOptional({}, [
|
||||
rules.regex(/^([a-zA-Z0-9_]){1,64}$/),
|
||||
rules.unique({ table: 'contacts', column: 'vk_id' }),
|
||||
]),
|
||||
twitter_id: schema.string.nullableAndOptional({}, [
|
||||
rules.regex(/(^|[^@\w])@(\w{1,15})\b/),
|
||||
rules.unique({ table: 'contacts', column: 'twitter_id' }),
|
||||
]),
|
||||
telegram_id: schema.string.nullableAndOptional({}, [
|
||||
rules.regex(/(^|[^@\w])@(\w{1,64})\b/),
|
||||
rules.unique({ table: 'contacts', column: 'telegram_id' }),
|
||||
]),
|
||||
});
|
||||
|
||||
public messages = {
|
||||
'phone_number.unique': 'This phone number is not available',
|
||||
'phone_number.unique': 'This phone number is not available.',
|
||||
'vk_id.unique': 'This ID is not available.',
|
||||
'twitter_id.unique': 'Twitter username is not available.',
|
||||
'telegram_id.unique': 'Telegram username is not available.',
|
||||
};
|
||||
}
|
||||
|
||||
@ -10,12 +10,24 @@ export default class UpdateUserInfoValidator {
|
||||
rules.mobile({ locales: ['ru-RU', 'en-US'], strict: true }),
|
||||
rules.unique({ table: 'contacts', column: 'phone_number' }),
|
||||
]),
|
||||
vk_id: schema.string.nullableAndOptional({}, [rules.regex(/^([a-zA-Z0-9_]){1,64}$/)]),
|
||||
twitter_id: schema.string.nullableAndOptional({}, [rules.regex(/(^|[^@\w])@(\w{1,15})\b/)]),
|
||||
telegram_id: schema.string.nullableAndOptional({}, [rules.regex(/(^|[^@\w])@(\w{1,64})\b/)]),
|
||||
vk_id: schema.string.nullableAndOptional({}, [
|
||||
rules.regex(/^([a-zA-Z0-9_]){1,64}$/),
|
||||
rules.unique({ table: 'contacts', column: 'vk_id' }),
|
||||
]),
|
||||
twitter_id: schema.string.nullableAndOptional({}, [
|
||||
rules.regex(/(^|[^@\w])@(\w{1,15})\b/),
|
||||
rules.unique({ table: 'contacts', column: 'twitter_id' }),
|
||||
]),
|
||||
telegram_id: schema.string.nullableAndOptional({}, [
|
||||
rules.regex(/(^|[^@\w])@(\w{1,64})\b/),
|
||||
rules.unique({ table: 'contacts', column: 'telegram_id' }),
|
||||
]),
|
||||
});
|
||||
|
||||
public messages = {
|
||||
'phone_number.unique': 'This phone number is not available.',
|
||||
'vk_id.unique': 'This ID is not available.',
|
||||
'twitter_id.unique': 'Twitter username is not available.',
|
||||
'telegram_id.unique': 'Telegram username is not available.',
|
||||
};
|
||||
}
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user