feat(gps): фокус геозоны на карте, город по умолчанию для всех карт, доступ к GPS по пользователям/ролям (админ)
This commit is contained in:
33
server/gps/access.ts
Normal file
33
server/gps/access.ts
Normal file
@@ -0,0 +1,33 @@
|
||||
import { gpsStorage } from "./storage";
|
||||
|
||||
/**
|
||||
* Контроль доступа к GPS-вкладке.
|
||||
*
|
||||
* Правило:
|
||||
* - admin приложения (users.app_role = 'admin') — доступ всегда;
|
||||
* - если allowed_user_ids и allowed_role_ids оба пустые/NULL — доступ у всех;
|
||||
* - иначе — если user.id ∈ allowedUserIds ИЛИ пользователь состоит
|
||||
* в организационной роли из allowedRoleIds (таблицы roles/role_members).
|
||||
*/
|
||||
export async function hasGpsAccess(
|
||||
user: { id: number; organizationId: number; appRole?: string },
|
||||
settings?: Awaited<ReturnType<typeof gpsStorage.getSettings>>
|
||||
): Promise<boolean> {
|
||||
if (user.appRole === "admin") return true;
|
||||
|
||||
const s = settings ?? (await gpsStorage.getSettings(user.organizationId));
|
||||
const userIds = s.allowedUserIds ?? [];
|
||||
const roleIds = s.allowedRoleIds ?? [];
|
||||
|
||||
// Оба списка пустые — модуль открыт всем
|
||||
if (userIds.length === 0 && roleIds.length === 0) return true;
|
||||
|
||||
if (userIds.includes(user.id)) return true;
|
||||
|
||||
if (roleIds.length > 0) {
|
||||
const userRoleIds = await gpsStorage.getUserRoleIds(user.id, user.organizationId);
|
||||
if (userRoleIds.some((id) => roleIds.includes(id))) return true;
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
Reference in New Issue
Block a user