mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-02 04:52:50 +08:00
feat(perm): enforce capabilities + bot access on action routes
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
696b224f8d
commit
cd6f2c6078
6 files changed
+287
-39
No files matched your search
@@ -1,18 +1,23 @@
|
||||
import type { Request, Response, NextFunction, RequestHandler } from "express";
|
||||
|
||||
export function requirePermission(capability: string): RequestHandler {
|
||||
return (req: Request, res: Response, next: NextFunction) => {
|
||||
// Generic over the route-param shape (`P`) so Express can keep inferring
|
||||
// `req.params` from the route string (e.g. `/:id` → `{ id: string }`) when
|
||||
// these are passed as a per-route middleware argument. Pinning the default
|
||||
// `ParamsDictionary` here would otherwise force the broad
|
||||
// `string | string[]` param overload on every route they guard.
|
||||
export function requirePermission<P = Record<string, string>>(capability: string): RequestHandler<P> {
|
||||
return (req: Request<P>, res: Response, next: NextFunction) => {
|
||||
if (!req.user) { res.status(401).json({ error: "unauthenticated" }); return; }
|
||||
if (req.user.role === "admin" || req.user.capabilities?.has(capability)) { next(); return; }
|
||||
res.status(403).json({ error: "forbidden" });
|
||||
};
|
||||
}
|
||||
|
||||
export function requireBotAccess(paramName = "botId"): RequestHandler {
|
||||
return (req: Request, res: Response, next: NextFunction) => {
|
||||
export function requireBotAccess<P = Record<string, string>>(paramName = "botId"): RequestHandler<P> {
|
||||
return (req: Request<P>, res: Response, next: NextFunction) => {
|
||||
if (!req.user) { res.status(401).json({ error: "unauthenticated" }); return; }
|
||||
if (req.user.role === "admin" || req.user.bots === "all") { next(); return; }
|
||||
const botId = req.params[paramName];
|
||||
const botId = (req.params as Record<string, string | undefined>)[paramName];
|
||||
if (typeof botId === "string" && req.user.bots instanceof Set && req.user.bots.has(botId)) { next(); return; }
|
||||
res.status(403).json({ error: "forbidden" });
|
||||
};
|
||||
|
||||
Reference in new issue
Block a user