feat(auth): check for admin role
This commit is contained in:
@@ -8,14 +8,17 @@ const verified = {
|
|||||||
id: "admin",
|
id: "admin",
|
||||||
email: "[email protected]",
|
email: "[email protected]",
|
||||||
emailVerified: true,
|
emailVerified: true,
|
||||||
|
role: "admin",
|
||||||
};
|
};
|
||||||
|
|
||||||
describe("admin authorization", () => {
|
describe("admin authorization", () => {
|
||||||
it("allows any verified credential user", () => {
|
it("allows only verified admins", () => {
|
||||||
expect(isAuthorizedAdmin(verified)).toBe(true);
|
expect(isAuthorizedAdmin(verified)).toBe(true);
|
||||||
expect(
|
expect(
|
||||||
isAuthorizedAdmin({ ...verified, emailVerified: false }),
|
isAuthorizedAdmin({ ...verified, emailVerified: false }),
|
||||||
).toBe(false);
|
).toBe(false);
|
||||||
|
expect(isAuthorizedAdmin({ ...verified, role: "user" })).toBe(false);
|
||||||
|
expect(isAuthorizedAdmin({ ...verified, role: null })).toBe(false);
|
||||||
});
|
});
|
||||||
|
|
||||||
it("denies missing users", () => {
|
it("denies missing users", () => {
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ export interface SessionUserLike {
|
|||||||
id: string;
|
id: string;
|
||||||
email: string;
|
email: string;
|
||||||
emailVerified: boolean;
|
emailVerified: boolean;
|
||||||
|
role?: string | null;
|
||||||
name?: string | null;
|
name?: string | null;
|
||||||
image?: string | null;
|
image?: string | null;
|
||||||
}
|
}
|
||||||
@@ -9,5 +10,5 @@ export interface SessionUserLike {
|
|||||||
export function isAuthorizedAdmin(
|
export function isAuthorizedAdmin(
|
||||||
user: SessionUserLike | null | undefined,
|
user: SessionUserLike | null | undefined,
|
||||||
): user is SessionUserLike {
|
): user is SessionUserLike {
|
||||||
return Boolean(user?.email && user.emailVerified === true);
|
return Boolean(user?.email && user.emailVerified === true && user.role === "admin");
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -94,6 +94,7 @@ export async function getAdminSession(): Promise<AdminSession | null> {
|
|||||||
id: "demo-admin",
|
id: "demo-admin",
|
||||||
email: "[email protected]",
|
email: "[email protected]",
|
||||||
emailVerified: true,
|
emailVerified: true,
|
||||||
|
role: "admin",
|
||||||
name: "Demo Admin",
|
name: "Demo Admin",
|
||||||
},
|
},
|
||||||
session: { id: "demo-session" },
|
session: { id: "demo-session" },
|
||||||
|
|||||||
Reference in New Issue
Block a user