add dist
This commit is contained in:
Vendored
+32
@@ -0,0 +1,32 @@
|
||||
import { isAdmin } from './predicates.js';
|
||||
import { ROLE_HIERARCHY } from './types.js';
|
||||
/**
|
||||
* Builds the fixed `roles` field the plugin injects into the auth collection.
|
||||
*
|
||||
* Saved to the JWT so role checks avoid a database lookup. Only admins can
|
||||
* change roles, preventing privilege escalation by lower-privilege users.
|
||||
*/ export function buildRolesField(defaultRole = 'user') {
|
||||
return {
|
||||
name: 'roles',
|
||||
type: 'select',
|
||||
access: {
|
||||
// Only admins may assign or change roles
|
||||
update: ({ req: { user } })=>isAdmin(user)
|
||||
},
|
||||
admin: {
|
||||
description: 'Role hierarchy: admin > editor > user.'
|
||||
},
|
||||
defaultValue: [
|
||||
defaultRole
|
||||
],
|
||||
hasMany: true,
|
||||
options: ROLE_HIERARCHY.map((role)=>({
|
||||
label: role.charAt(0).toUpperCase() + role.slice(1),
|
||||
value: role
|
||||
})),
|
||||
required: true,
|
||||
saveToJWT: true
|
||||
};
|
||||
}
|
||||
|
||||
//# sourceMappingURL=rolesField.js.map
|
||||
Reference in New Issue
Block a user