import { gpsStorage } from "./storage"; /** * Контроль доступа к GPS-вкладке. * * Правило: * - admin приложения (users.app_role = 'admin') — доступ всегда; * - если allowed_user_ids и allowed_role_ids оба пустые/NULL — доступ у всех; * - иначе — если user.id ∈ allowedUserIds ИЛИ пользователь состоит * в организационной роли из allowedRoleIds (таблицы roles/role_members). */ export async function hasGpsAccess( user: { id: number; organizationId: number; appRole?: string }, settings?: Awaited> ): Promise { if (user.appRole === "admin") return true; const s = settings ?? (await gpsStorage.getSettings(user.organizationId)); const userIds = s.allowedUserIds ?? []; const roleIds = s.allowedRoleIds ?? []; // Оба списка пустые — модуль открыт всем if (userIds.length === 0 && roleIds.length === 0) return true; if (userIds.includes(user.id)) return true; if (roleIds.length > 0) { const userRoleIds = await gpsStorage.getUserRoleIds(user.id, user.organizationId); if (userRoleIds.some((id) => roleIds.includes(id))) return true; } return false; }