feat(auth): check for admin role
CI / Verify (push) Successful in 4m36s
CI / Build immutable images and deploy (push) Successful in 7m37s

This commit is contained in:
2026-09-21 17:58:15 +07:00 Unverified
parent c5af3a63d4
commit 481123eec0
3 changed files with 7 additions and 2 deletions
+4 -1
View File
@@ -8,14 +8,17 @@ const verified = {
id: "admin", id: "admin",
email: "[email protected]", email: "[email protected]",
emailVerified: true, emailVerified: true,
role: "admin",
}; };
describe("admin authorization", () => { describe("admin authorization", () => {
it("allows any verified credential user", () => { it("allows only verified admins", () => {
expect(isAuthorizedAdmin(verified)).toBe(true); expect(isAuthorizedAdmin(verified)).toBe(true);
expect( expect(
isAuthorizedAdmin({ ...verified, emailVerified: false }), isAuthorizedAdmin({ ...verified, emailVerified: false }),
).toBe(false); ).toBe(false);
expect(isAuthorizedAdmin({ ...verified, role: "user" })).toBe(false);
expect(isAuthorizedAdmin({ ...verified, role: null })).toBe(false);
}); });
it("denies missing users", () => { it("denies missing users", () => {
+2 -1
View File
@@ -2,6 +2,7 @@ export interface SessionUserLike {
id: string; id: string;
email: string; email: string;
emailVerified: boolean; emailVerified: boolean;
role?: string | null;
name?: string | null; name?: string | null;
image?: string | null; image?: string | null;
} }
@@ -9,5 +10,5 @@ export interface SessionUserLike {
export function isAuthorizedAdmin( export function isAuthorizedAdmin(
user: SessionUserLike | null | undefined, user: SessionUserLike | null | undefined,
): user is SessionUserLike { ): user is SessionUserLike {
return Boolean(user?.email && user.emailVerified === true); return Boolean(user?.email && user.emailVerified === true && user.role === "admin");
} }
+1
View File
@@ -94,6 +94,7 @@ export async function getAdminSession(): Promise<AdminSession | null> {
id: "demo-admin", id: "demo-admin",
email: "[email protected]", email: "[email protected]",
emailVerified: true, emailVerified: true,
role: "admin",
name: "Demo Admin", name: "Demo Admin",
}, },
session: { id: "demo-session" }, session: { id: "demo-session" },