up
This commit is contained in:
@@ -36,21 +36,21 @@ export class AdminAuthGuard implements CanActivate {
|
|||||||
async canActivate(context: ExecutionContext) {
|
async canActivate(context: ExecutionContext) {
|
||||||
const request = context.switchToHttp().getRequest<AdminAuthRequest>();
|
const request = context.switchToHttp().getRequest<AdminAuthRequest>();
|
||||||
|
|
||||||
|
const token = this.extractTokenFromHeader(request);
|
||||||
|
if (!token) {
|
||||||
|
this.logger.warn('No token provided');
|
||||||
|
throw new UnauthorizedException('No token provided');
|
||||||
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const secret = this.configService.get<string>('JWT_SECRET');
|
// Verify token - JWT module is global, so it uses the configured secret automatically
|
||||||
const token = this.extractTokenFromHeader(request);
|
const payload = await this.jwtService.verifyAsync<IAdminTokenPayload>(token);
|
||||||
if (!token) {
|
|
||||||
throw new UnauthorizedException();
|
if (!payload.adminId || !payload.restId) {
|
||||||
|
this.logger.error('Invalid token payload structure', payload);
|
||||||
|
throw new UnauthorizedException('Invalid token payload');
|
||||||
}
|
}
|
||||||
|
|
||||||
const payload = await this.jwtService
|
|
||||||
.verifyAsync<IAdminTokenPayload>(token, {
|
|
||||||
secret,
|
|
||||||
})
|
|
||||||
.catch(err => {
|
|
||||||
this.logger.error('error in AdminAuthGuard', err);
|
|
||||||
throw new UnauthorizedException('Invalid or expired token');
|
|
||||||
});
|
|
||||||
request['adminId'] = payload.adminId;
|
request['adminId'] = payload.adminId;
|
||||||
request['restId'] = payload.restId;
|
request['restId'] = payload.restId;
|
||||||
|
|
||||||
@@ -58,20 +58,37 @@ export class AdminAuthGuard implements CanActivate {
|
|||||||
const requiredPermissions =
|
const requiredPermissions =
|
||||||
this.reflector.getAllAndOverride<string[]>(PERMISSIONS_KEY, [context.getHandler(), context.getClass()]) ?? [];
|
this.reflector.getAllAndOverride<string[]>(PERMISSIONS_KEY, [context.getHandler(), context.getClass()]) ?? [];
|
||||||
|
|
||||||
if (!requiredPermissions || requiredPermissions.length === 0) return true;
|
if (!requiredPermissions || requiredPermissions.length === 0) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
const adminPermission = await this.permissionsService.getAdminPermissions(payload.adminId, payload.restId);
|
const adminPermission = await this.permissionsService.getAdminPermissions(payload.adminId, payload.restId);
|
||||||
if (!adminPermission || !Array.isArray(adminPermission)) {
|
if (!adminPermission || !Array.isArray(adminPermission)) {
|
||||||
this.logger.error('No permissions found');
|
this.logger.error('No permissions found', { adminId: payload.adminId, restId: payload.restId });
|
||||||
throw new ForbiddenException('No permissions found');
|
throw new ForbiddenException('No permissions found');
|
||||||
}
|
}
|
||||||
|
|
||||||
const hasPermission = requiredPermissions.every(p => adminPermission.includes(p));
|
const hasPermission = requiredPermissions.every(p => adminPermission.includes(p));
|
||||||
|
|
||||||
if (!hasPermission) throw new ForbiddenException('You are not authorized to access this resource');
|
if (!hasPermission) {
|
||||||
|
this.logger.warn('Insufficient permissions', {
|
||||||
|
adminId: payload.adminId,
|
||||||
|
restId: payload.restId,
|
||||||
|
required: requiredPermissions,
|
||||||
|
has: adminPermission,
|
||||||
|
});
|
||||||
|
throw new ForbiddenException('You are not authorized to access this resource');
|
||||||
|
}
|
||||||
|
|
||||||
return true;
|
return true;
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
this.logger.error('error in AdminAuthGuard', err);
|
if (err instanceof ForbiddenException || err instanceof UnauthorizedException) {
|
||||||
|
throw err;
|
||||||
|
}
|
||||||
|
this.logger.error('Token verification error in AdminAuthGuard', {
|
||||||
|
error: err.message,
|
||||||
|
stack: err.stack,
|
||||||
|
});
|
||||||
throw new UnauthorizedException('Invalid or expired token');
|
throw new UnauthorizedException('Invalid or expired token');
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user