|
|
@ -43,12 +43,8 @@ module.exports = (permType, permLevel = null) => async (ctx, next) => { |
|
|
// don't expose builder endpoints in the cloud
|
|
|
// don't expose builder endpoints in the cloud
|
|
|
if (env.CLOUD && permType === PermissionTypes.BUILDER) return |
|
|
if (env.CLOUD && permType === PermissionTypes.BUILDER) return |
|
|
|
|
|
|
|
|
if (!ctx.auth.authenticated) { |
|
|
|
|
|
ctx.throw(403, "Session not authenticated") |
|
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
|
|
if (!ctx.user) { |
|
|
if (!ctx.user) { |
|
|
ctx.throw(403, "User not found") |
|
|
ctx.throw(403, "No user info found") |
|
|
} |
|
|
} |
|
|
|
|
|
|
|
|
const role = ctx.user.role |
|
|
const role = ctx.user.role |
|
|
@ -56,11 +52,15 @@ module.exports = (permType, permLevel = null) => async (ctx, next) => { |
|
|
ctx.appId, |
|
|
ctx.appId, |
|
|
role._id |
|
|
role._id |
|
|
) |
|
|
) |
|
|
if (ADMIN_ROLES.indexOf(role._id) !== -1) { |
|
|
const isAdmin = ADMIN_ROLES.indexOf(role._id) !== -1 |
|
|
return next() |
|
|
const isAuthed = ctx.auth.authenticated |
|
|
} |
|
|
|
|
|
|
|
|
|
|
|
if (permType === PermissionTypes.BUILDER) { |
|
|
// this may need to change in the future, right now only admins
|
|
|
|
|
|
// can have access to builder features, this is hard coded into
|
|
|
|
|
|
// our rules
|
|
|
|
|
|
if (isAdmin && isAuthed) { |
|
|
|
|
|
return next() |
|
|
|
|
|
} else if (permType === PermissionTypes.BUILDER) { |
|
|
ctx.throw(403, "Not Authorized") |
|
|
ctx.throw(403, "Not Authorized") |
|
|
} |
|
|
} |
|
|
|
|
|
|
|
|
@ -71,6 +71,10 @@ module.exports = (permType, permLevel = null) => async (ctx, next) => { |
|
|
return next() |
|
|
return next() |
|
|
} |
|
|
} |
|
|
|
|
|
|
|
|
|
|
|
if (!isAuthed) { |
|
|
|
|
|
ctx.throw(403, "Session not authenticated") |
|
|
|
|
|
} |
|
|
|
|
|
|
|
|
if (!doesHaveBasePermission(permType, permLevel, basePermissions)) { |
|
|
if (!doesHaveBasePermission(permType, permLevel, basePermissions)) { |
|
|
ctx.throw(403, "User does not have permission") |
|
|
ctx.throw(403, "User does not have permission") |
|
|
} |
|
|
} |
|
|
|