feat: UI-only permission gate for admin routes (cosmetic pending backend)
adminAuthGuard only checked isAuthenticated() - any signed-in admin could reach any route. The live Telegram/QR auth (Mechanism A) carries no role claim, so a real gate needs a backend change (tracked in BACKEND-API-REFERENCE.md). Added AdminPermissionsService + requireAdminPermission() guard factory that derive a permission set locally by matching the Telegram username against the mock Users domain's roleId - the same local-only stand-in already used for the rest of that domain. Wired onto /backoffice/users requiring 'users.manage'. Explicitly cosmetic: backend must independently authorize every mutation regardless of what this guard decides. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -7,7 +7,7 @@ import { AdminAuthService } from '../../../../core/admin-auth/admin-auth.service
|
||||
|
||||
const BUILT_IN_ROLES: AdminRole[] = [
|
||||
{ id: 'owner', name: 'Owner', permissions: ['*'], builtIn: true },
|
||||
{ id: 'admin', name: 'Admin', permissions: ['products.manage', 'categories.manage', 'orders.manage', 'media.manage'], builtIn: true },
|
||||
{ id: 'admin', name: 'Admin', permissions: ['products.manage', 'categories.manage', 'orders.manage', 'media.manage', 'users.manage'], builtIn: true },
|
||||
{ id: 'editor', name: 'Editor', permissions: ['products.manage', 'categories.manage', 'media.manage'], builtIn: true },
|
||||
{ id: 'viewer', name: 'Viewer', permissions: ['products.view', 'orders.view'], builtIn: true },
|
||||
];
|
||||
|
||||
Reference in New Issue
Block a user