feat(09-11): add permissioned admin metadata and settings
This commit is contained in:
@@ -30,7 +30,8 @@ const (
|
||||
|
||||
// BackendUsers loads activated backend principals. It never reads frontend users.
|
||||
type BackendUsers struct {
|
||||
DB *gorm.DB
|
||||
DB *gorm.DB
|
||||
Registry *Registry
|
||||
}
|
||||
|
||||
func (p BackendUsers) FindByID(ctx context.Context, id uint) (*bouncer.Principal, error) {
|
||||
@@ -48,12 +49,23 @@ func (p BackendUsers) FindByID(ctx context.Context, id uint) (*bouncer.Principal
|
||||
if !user.IsActivated {
|
||||
return nil, nil
|
||||
}
|
||||
return principalFrom(user), nil
|
||||
principal := principalFrom(user)
|
||||
for code, allowed := range p.Registry.rolePermissions(user.Role.Code) {
|
||||
if !allowed {
|
||||
continue
|
||||
}
|
||||
if principal.PermissionGrants == nil {
|
||||
principal.PermissionGrants = map[string]bool{}
|
||||
}
|
||||
principal.PermissionGrants[code] = true
|
||||
}
|
||||
return principal, nil
|
||||
}
|
||||
|
||||
func principalFrom(user BackendUser) *bouncer.Principal {
|
||||
principal := &bouncer.Principal{
|
||||
ID: user.ID,
|
||||
Backend: true,
|
||||
IsSuperuser: user.IsSuperuser,
|
||||
PermissionGrants: parseGrants(user.Role.Permissions),
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user