Files
ipal-kit/dist/modules/access/rolesField.js
T
2026-07-31 23:21:51 +02:00

32 lines
1016 B
JavaScript

import { isAdmin } from './predicates.js';
import { ROLE_HIERARCHY } from './types.js';
/**
* Builds the fixed `roles` field the plugin injects into the auth collection.
*
* Saved to the JWT so role checks avoid a database lookup. Only admins can
* change roles, preventing privilege escalation by lower-privilege users.
*/ export function buildRolesField(defaultRole = 'user') {
return {
name: 'roles',
type: 'select',
access: {
// Only admins may assign or change roles
update: ({ req: { user } })=>isAdmin(user)
},
admin: {
description: 'Role hierarchy: admin > editor > user.'
},
defaultValue: [
defaultRole
],
hasMany: true,
options: ROLE_HIERARCHY.map((role)=>({
label: role.charAt(0).toUpperCase() + role.slice(1),
value: role
})),
required: true,
saveToJWT: true
};
}
//# sourceMappingURL=rolesField.js.map