feat(auth): check for admin role
CI / Verify (push) Successful in 4m36s
CI / Build immutable images and deploy (push) Successful in 7m37s

This commit is contained in:
2026-09-21 17:58:15 +07:00 Unverified
parent c5af3a63d4
commit 481123eec0
3 changed files with 7 additions and 2 deletions
+4 -1
View File
@@ -8,14 +8,17 @@ const verified = {
id: "admin",
email: "[email protected]",
emailVerified: true,
role: "admin",
};
describe("admin authorization", () => {
it("allows any verified credential user", () => {
it("allows only verified admins", () => {
expect(isAuthorizedAdmin(verified)).toBe(true);
expect(
isAuthorizedAdmin({ ...verified, emailVerified: false }),
).toBe(false);
expect(isAuthorizedAdmin({ ...verified, role: "user" })).toBe(false);
expect(isAuthorizedAdmin({ ...verified, role: null })).toBe(false);
});
it("denies missing users", () => {
+2 -1
View File
@@ -2,6 +2,7 @@ export interface SessionUserLike {
id: string;
email: string;
emailVerified: boolean;
role?: string | null;
name?: string | null;
image?: string | null;
}
@@ -9,5 +10,5 @@ export interface SessionUserLike {
export function isAuthorizedAdmin(
user: SessionUserLike | null | undefined,
): user is SessionUserLike {
return Boolean(user?.email && user.emailVerified === true);
return Boolean(user?.email && user.emailVerified === true && user.role === "admin");
}
+1
View File
@@ -94,6 +94,7 @@ export async function getAdminSession(): Promise<AdminSession | null> {
id: "demo-admin",
email: "[email protected]",
emailVerified: true,
role: "admin",
name: "Demo Admin",
},
session: { id: "demo-session" },