Files
ipal-kit/dist/modules/access/predicates.js
T
2026-07-31 23:21:51 +02:00

32 lines
1.1 KiB
JavaScript

import { ROLE_HIERARCHY } from './types.js';
/** Safely extracts the roles array from a loosely-typed user. */ function getRoles(user) {
if (!user || typeof user !== 'object') {
return [];
}
const roles = user.roles;
if (!Array.isArray(roles)) {
return [];
}
return roles.filter((role)=>ROLE_HIERARCHY.includes(role));
}
/** Highest-privilege role index the user holds, or -1 if none. */ function highestRoleIndex(user) {
const roles = getRoles(user);
if (!roles.length) {
return -1;
}
return Math.max(...roles.map((role)=>ROLE_HIERARCHY.indexOf(role)));
}
/**
* True if the user holds at least the given role in the hierarchy.
* admin satisfies 'editor' and 'user'; editor satisfies 'user'.
*/ export function hasMinimumRole(user, minimum) {
return highestRoleIndex(user) >= ROLE_HIERARCHY.indexOf(minimum);
}
/** True if the user is an admin. */ export function isAdmin(user) {
return hasMinimumRole(user, 'admin');
}
/** True if the user is an editor or higher (editor, admin). */ export function isEditor(user) {
return hasMinimumRole(user, 'editor');
}
//# sourceMappingURL=predicates.js.map