32 lines
1016 B
JavaScript
32 lines
1016 B
JavaScript
import { isAdmin } from './predicates.js';
|
|
import { ROLE_HIERARCHY } from './types.js';
|
|
/**
|
|
* Builds the fixed `roles` field the plugin injects into the auth collection.
|
|
*
|
|
* Saved to the JWT so role checks avoid a database lookup. Only admins can
|
|
* change roles, preventing privilege escalation by lower-privilege users.
|
|
*/ export function buildRolesField(defaultRole = 'user') {
|
|
return {
|
|
name: 'roles',
|
|
type: 'select',
|
|
access: {
|
|
// Only admins may assign or change roles
|
|
update: ({ req: { user } })=>isAdmin(user)
|
|
},
|
|
admin: {
|
|
description: 'Role hierarchy: admin > editor > user.'
|
|
},
|
|
defaultValue: [
|
|
defaultRole
|
|
],
|
|
hasMany: true,
|
|
options: ROLE_HIERARCHY.map((role)=>({
|
|
label: role.charAt(0).toUpperCase() + role.slice(1),
|
|
value: role
|
|
})),
|
|
required: true,
|
|
saveToJWT: true
|
|
};
|
|
}
|
|
|
|
//# sourceMappingURL=rolesField.js.map
|