diff --git a/lib/auth/authorization.test.ts b/lib/auth/authorization.test.ts index 7ed3166..7301975 100644 --- a/lib/auth/authorization.test.ts +++ b/lib/auth/authorization.test.ts @@ -8,14 +8,17 @@ const verified = { id: "admin", email: "admin@example.com", emailVerified: true, + role: "admin", }; describe("admin authorization", () => { - it("allows any verified credential user", () => { + it("allows only verified admins", () => { expect(isAuthorizedAdmin(verified)).toBe(true); expect( isAuthorizedAdmin({ ...verified, emailVerified: false }), ).toBe(false); + expect(isAuthorizedAdmin({ ...verified, role: "user" })).toBe(false); + expect(isAuthorizedAdmin({ ...verified, role: null })).toBe(false); }); it("denies missing users", () => { diff --git a/lib/auth/authorization.ts b/lib/auth/authorization.ts index 98766bf..da72892 100644 --- a/lib/auth/authorization.ts +++ b/lib/auth/authorization.ts @@ -2,6 +2,7 @@ export interface SessionUserLike { id: string; email: string; emailVerified: boolean; + role?: string | null; name?: string | null; image?: string | null; } @@ -9,5 +10,5 @@ export interface SessionUserLike { export function isAuthorizedAdmin( user: SessionUserLike | null | undefined, ): user is SessionUserLike { - return Boolean(user?.email && user.emailVerified === true); + return Boolean(user?.email && user.emailVerified === true && user.role === "admin"); } diff --git a/lib/auth/server.ts b/lib/auth/server.ts index 92abd4e..ebc24a7 100644 --- a/lib/auth/server.ts +++ b/lib/auth/server.ts @@ -94,6 +94,7 @@ export async function getAdminSession(): Promise { id: "demo-admin", email: "demo@buzz-sheet.local", emailVerified: true, + role: "admin", name: "Demo Admin", }, session: { id: "demo-session" },