import { isAdmin } from './predicates.js'; import { ROLE_HIERARCHY } from './types.js'; /** * Builds the fixed `roles` field the plugin injects into the auth collection. * * Saved to the JWT so role checks avoid a database lookup. Only admins can * change roles, preventing privilege escalation by lower-privilege users. */ export function buildRolesField(defaultRole = 'user') { return { name: 'roles', type: 'select', access: { // Only admins may assign or change roles update: ({ req: { user } })=>isAdmin(user) }, admin: { description: 'Role hierarchy: admin > editor > user.' }, defaultValue: [ defaultRole ], hasMany: true, options: ROLE_HIERARCHY.map((role)=>({ label: role.charAt(0).toUpperCase() + role.slice(1), value: role })), required: true, saveToJWT: true }; } //# sourceMappingURL=rolesField.js.map