Initial commit: teaching institution management API.
Express/MongoDB backend with JWT auth, RBAC, S3 uploads, notifications, and scheduled jobs.
This commit is contained in:
@@ -0,0 +1,35 @@
|
||||
// /middlewares/permissionMiddleware.js
|
||||
|
||||
const AppError = require('../utils/AppError');
|
||||
|
||||
const requirePermission = (requiredPermission) => {
|
||||
return (req, res, next) => {
|
||||
try {
|
||||
if (!req.user) {
|
||||
return next(new AppError('UNAUTHORIZED'));
|
||||
}
|
||||
|
||||
const role = req.user.role;
|
||||
if (!role) {
|
||||
return next(new AppError('FORBIDDEN'));
|
||||
}
|
||||
|
||||
// Check if user is superAdmin (by role name or system status)
|
||||
if (role.name === 'superAdmin' || (role.isSystem && role.permissions.includes('*'))) {
|
||||
return next();
|
||||
}
|
||||
|
||||
// Check if required permission is held by role
|
||||
if (Array.isArray(role.permissions) && role.permissions.includes(requiredPermission)) {
|
||||
return next();
|
||||
}
|
||||
|
||||
return next(new AppError('FORBIDDEN'));
|
||||
} catch (error) {
|
||||
next(error);
|
||||
}
|
||||
};
|
||||
};
|
||||
|
||||
module.exports = requirePermission;
|
||||
module.exports.requires = requirePermission;
|
||||
Reference in New Issue
Block a user