/** * Contract source: https://git.io/Jte3T * * Feel free to let us know via PR, if you find something broken in this config * file. */ import Bouncer from '@ioc:Adonis/Addons/Bouncer'; import RoleEnum from 'App/Datatypes/Enums/RoleEnum'; import RoleHelper from 'App/Helpers/RoleHelper'; import Lesson from 'App/Models/Lesson'; import Role from 'App/Models/Role'; import User from 'App/Models/User'; /* |-------------------------------------------------------------------------- | Bouncer Actions |-------------------------------------------------------------------------- | | Actions allows you to separate your application business logic from the | authorization logic. Feel free to make use of policies when you find | yourself creating too many actions | | You can define an action using the `.define` method on the Bouncer object | as shown in the following example | | ``` | Bouncer.define('deletePost', (user: User, post: Post) => { | return post.user_id === user.id | }) | ``` | |**************************************************************** | NOTE: Always export the "actions" const from this file |**************************************************************** */ export const { actions } = Bouncer.define('manageUserRole', async (user: User, role: Role) => { await user.load('roles'); return !( (role.slug === RoleEnum.ADMIN || role.slug === RoleEnum.TEACHER) && !RoleHelper.userContainRoles(user.roles, [RoleEnum.ADMIN]) ); }).define('viewLessonContent', async (user: User, lesson: Lesson) => { await user.load(loader => loader.load('roles').load('courses')); await lesson.load('course'); if (!RoleHelper.userContainRoles(user.roles, [RoleEnum.ADMIN, RoleEnum.TEACHER])) { return !!user.courses.find(course => course.id === lesson.course.id); } return true; }); /* |-------------------------------------------------------------------------- | Bouncer Policies |-------------------------------------------------------------------------- | | Policies are self contained actions for a given resource. For example: You | can create a policy for a "User" resource, one policy for a "Post" resource | and so on. | | The "registerPolicies" accepts a unique policy name and a function to lazy | import the policy | | ``` | Bouncer.registerPolicies({ | UserPolicy: () => import('App/Policies/User'), | PostPolicy: () => import('App/Policies/Post') | }) | ``` | |**************************************************************** | NOTE: Always export the "policies" const from this file |**************************************************************** */ export const { policies } = Bouncer.registerPolicies({});