diff --git a/web/src/composables/useSession.ts b/web/src/composables/useSession.ts index e8c17ff..725184e 100644 --- a/web/src/composables/useSession.ts +++ b/web/src/composables/useSession.ts @@ -4,6 +4,8 @@ interface User { id: string; username: string; role: 'admin' | 'member'; + capabilities?: string[]; + bots?: "all" | string[]; } const currentUser = ref(null); @@ -70,6 +72,8 @@ async function login(username: string, password: string): Promise { throw new Error(body.error ?? `login failed (${res.status})`); } currentUser.value = (await res.json()) as User; + // Login response omits capabilities/bots; fetch the authoritative ones from /me. + await refreshMe(); } async function setup(username: string, password: string): Promise { @@ -85,6 +89,8 @@ async function setup(username: string, password: string): Promise { } currentUser.value = (await res.json()) as User; needsSetup.value = false; + // Setup response omits capabilities/bots; fetch the authoritative ones from /me. + await refreshMe(); } async function logout(): Promise { @@ -93,6 +99,18 @@ async function logout(): Promise { currentUser.value = null; } +function can(cap: string): boolean { + const u = currentUser.value; + return !!u && (u.role === "admin" || (u.capabilities ?? []).includes(cap)); +} + +function canControlBot(botId: string): boolean { + const u = currentUser.value; + if (!u) return false; + if (u.role === "admin" || u.bots === "all") return true; + return Array.isArray(u.bots) && u.bots.includes(botId); +} + export function useSession() { return { currentUser: readonly(currentUser), @@ -104,5 +122,7 @@ export function useSession() { login, logout, setup, + can, + canControlBot, }; }