feat: bootstrap SuperAdmin from env and lock one-time seeding

Production creates the SuperAdmin from env credentials, and dashboard seeding is authenticated, SuperAdmin-only, and locked after the first run.
This commit is contained in:
2026-08-14 23:23:06 +03:30
parent 3ca098b74d
commit 35704409ec
13 changed files with 251 additions and 34 deletions
+23
View File
@@ -0,0 +1,23 @@
// /utils/superAdmin.js
const config = require('../config/config');
const usernamesMatch = (left, right) => {
if (!left || !right) return false;
return String(left).trim().toLowerCase() === String(right).trim().toLowerCase();
};
const isBootstrapSuperAdmin = (userOrUsername) => {
const username = typeof userOrUsername === 'string'
? userOrUsername
: userOrUsername?.username;
return usernamesMatch(username, config.SUPERADMIN_USERNAME);
};
const isBootstrapSuperAdminDisabled = (userOrUsername) => {
return !config.SUPERADMIN_ENABLED && isBootstrapSuperAdmin(userOrUsername);
};
module.exports = {
isBootstrapSuperAdmin,
isBootstrapSuperAdminDisabled
};