feat(perm): frontend session capabilities + can()/canControlBot()

This commit is contained in:
saopig1 committed 2026-05-30 13:51:34 +08:00
1 parent abf60141d9
commit cf76e0f69a
1 file changed
+20
+20
View File
@@ -4,6 +4,8 @@ interface User {
id: string; id: string;
username: string; username: string;
role: 'admin' | 'member'; role: 'admin' | 'member';
capabilities?: string[];
bots?: "all" | string[];
} }
const currentUser = ref<User | null>(null); const currentUser = ref<User | null>(null);
@@ -70,6 +72,8 @@ async function login(username: string, password: string): Promise<void> {
throw new Error(body.error ?? `login failed (${res.status})`); throw new Error(body.error ?? `login failed (${res.status})`);
} }
currentUser.value = (await res.json()) as User; currentUser.value = (await res.json()) as User;
// Login response omits capabilities/bots; fetch the authoritative ones from /me.
await refreshMe();
} }
async function setup(username: string, password: string): Promise<void> { async function setup(username: string, password: string): Promise<void> {
@@ -85,6 +89,8 @@ async function setup(username: string, password: string): Promise<void> {
} }
currentUser.value = (await res.json()) as User; currentUser.value = (await res.json()) as User;
needsSetup.value = false; needsSetup.value = false;
// Setup response omits capabilities/bots; fetch the authoritative ones from /me.
await refreshMe();
} }
async function logout(): Promise<void> { async function logout(): Promise<void> {
@@ -93,6 +99,18 @@ async function logout(): Promise<void> {
currentUser.value = null; currentUser.value = null;
} }
function can(cap: string): boolean {
const u = currentUser.value;
return !!u && (u.role === "admin" || (u.capabilities ?? []).includes(cap));
}
function canControlBot(botId: string): boolean {
const u = currentUser.value;
if (!u) return false;
if (u.role === "admin" || u.bots === "all") return true;
return Array.isArray(u.bots) && u.bots.includes(botId);
}
export function useSession() { export function useSession() {
return { return {
currentUser: readonly(currentUser), currentUser: readonly(currentUser),
@@ -104,5 +122,7 @@ export function useSession() {
login, login,
logout, logout,
setup, setup,
can,
canControlBot,
}; };
} }