feat: add Discord role-based access control for forms with custom dropdown UI
This commit is contained in:
@@ -3,6 +3,7 @@ import { FormFillerClient } from "../client";
|
||||
import { getServerSession } from "next-auth";
|
||||
import { authOptions } from "@/app/api/auth/[...nextauth]/route";
|
||||
import { notFound } from "next/navigation";
|
||||
import { getGuildMemberRoles } from "@/app/actions/discord";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
@@ -23,6 +24,29 @@ export default async function FormsSubmitPage(
|
||||
return notFound();
|
||||
}
|
||||
|
||||
if (discordId) {
|
||||
const allowedRoles = form.allowedRoles || [];
|
||||
const deniedRoles = form.deniedRoles || [];
|
||||
|
||||
if (allowedRoles.length > 0 || deniedRoles.length > 0) {
|
||||
const userRoles = await getGuildMemberRoles(discordId);
|
||||
|
||||
let isAllowed = allowedRoles.length === 0;
|
||||
if (allowedRoles.length > 0) {
|
||||
isAllowed = userRoles.some(r => allowedRoles.includes(r));
|
||||
}
|
||||
|
||||
let isDenied = false;
|
||||
if (deniedRoles.length > 0) {
|
||||
isDenied = userRoles.some(r => deniedRoles.includes(r));
|
||||
}
|
||||
|
||||
if (!isAllowed || isDenied) {
|
||||
return notFound();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
const questionsList = await db.query.questions.findMany({
|
||||
where: (q, { eq }) => eq(q.formId, form.id),
|
||||
orderBy: (q, { asc }) => [asc(q.displayOrder)],
|
||||
|
||||
Reference in New Issue
Block a user