forked from QuantumNous/new-api
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathadmin-permissions.ts
More file actions
112 lines (95 loc) · 3.4 KB
/
Copy pathadmin-permissions.ts
File metadata and controls
112 lines (95 loc) · 3.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
/*
Copyright (C) 2023-2026 QuantumNous
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as
published by the Free Software Foundation, either version 3 of the
License, or (at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU Affero General Public License for more details.
You should have received a copy of the GNU Affero General Public License
along with this program. If not, see <https://www.gnu.org/licenses/>.
For commercial licensing, please contact support@quantumnous.com
*/
import type { AuthUser } from '@/stores/auth-store'
import { ROLE } from './roles'
export type AdminPermissionMatrix = Record<string, Record<string, boolean>>
export type AdminCapabilities = AdminPermissionMatrix
export const ADMIN_PERMISSION_RESOURCES = {
CHANNEL: 'channel',
} as const
export const ADMIN_PERMISSION_ACTIONS = {
READ: 'read',
OPERATE: 'operate',
WRITE: 'write',
SENSITIVE_WRITE: 'sensitive_write',
SECRET_VIEW: 'secret_view',
} as const
// The role whose baseline grants are used as defaults in the permission editor.
export const ADMIN_ROLE_KEY = 'admin'
// The permission catalog (resources, actions, labels and role baselines) is owned
// by the backend authz package and fetched from GET /api/authz/catalog. It is
// intentionally NOT duplicated here so the schema stays defined in one place.
// These types mirror the backend JSON shape.
export interface PermissionActionDef {
action: string
label_key: string
description_key: string
}
export interface PermissionResourceDef {
resource: string
label_key: string
actions: PermissionActionDef[]
}
export interface PermissionRoleDef {
key: string
name: string
built_in: boolean
superuser: boolean
grants: AdminPermissionMatrix
}
export interface PermissionCatalog {
resources: PermissionResourceDef[]
roles: PermissionRoleDef[]
}
export const EMPTY_PERMISSION_CATALOG: PermissionCatalog = {
resources: [],
roles: [],
}
export function hasPermission(
user: AuthUser | null | undefined,
resource: string,
action: string
): boolean {
if (!user) return false
if (user.role === ROLE.SUPER_ADMIN) return true
return user.permissions?.admin_permissions?.[resource]?.[action] === true
}
// roleGrants returns the baseline grant matrix for the given role key.
export function roleGrants(
catalog: PermissionCatalog,
roleKey: string
): AdminPermissionMatrix {
return catalog.roles.find((role) => role.key === roleKey)?.grants ?? {}
}
// normalizeAdminPermissions produces a full matrix for the catalog, filling any
// value missing from `value` with the admin role's baseline grant.
export function normalizeAdminPermissions(
value: AdminPermissionMatrix | null | undefined,
catalog: PermissionCatalog
): AdminPermissionMatrix {
const baseline = roleGrants(catalog, ADMIN_ROLE_KEY)
const normalized: AdminPermissionMatrix = {}
for (const resource of catalog.resources) {
const actions: Record<string, boolean> = {}
for (const action of resource.actions) {
actions[action.action] =
value?.[resource.resource]?.[action.action] ??
baseline[resource.resource]?.[action.action] ??
false
}
normalized[resource.resource] = actions
}
return normalized
}