feat: bootstrap SuperAdmin from env and lock one-time seeding
Production creates the SuperAdmin from env credentials, and dashboard seeding is authenticated, SuperAdmin-only, and locked after the first run.
This commit is contained in:
@@ -0,0 +1,18 @@
|
||||
// /middlewares/requireSuperAdmin.js
|
||||
'use strict';
|
||||
|
||||
const AppError = require('../utils/AppError');
|
||||
|
||||
const requireSuperAdmin = (req, res, next) => {
|
||||
if (!req.user) {
|
||||
return next(new AppError('UNAUTHORIZED'));
|
||||
}
|
||||
|
||||
if (req.user.role?.name !== 'SuperAdmin') {
|
||||
return next(new AppError('FORBIDDEN'));
|
||||
}
|
||||
|
||||
return next();
|
||||
};
|
||||
|
||||
module.exports = requireSuperAdmin;
|
||||
Reference in New Issue
Block a user