import type { Response, NextFunction } from 'express'; import type { AuthenticatedRequest } from './auth.middleware'; import { _tenantCtx } from '../db'; // Validates that the authenticated user belongs to an organization. // If authenticateToken already opened a per-request tenant context (the common // case), this middleware just sets req.organizationId and calls next(). // It never opens a second connection — the context from authenticateToken is reused. export const tenantIsolation = ( req: AuthenticatedRequest, res: Response, next: NextFunction ): void => { if (!req.user?.organizationId) { res.status(400).json({ success: false, error: 'Ошибка идентификации организации' }); return; } req.organizationId = req.user.organizationId; next(); }; export const validateTenantAccess = ( req: AuthenticatedRequest, res: Response, next: NextFunction ) => { const requestedOrgId = req.params.organizationId || req.body.organizationId; if (requestedOrgId && parseInt(requestedOrgId) !== req.organizationId) { return res.status(403).json({ error: 'Доступ запрещен: нет прав на данные другой организации', }); } next(); };