mirror of
https://github.com/Drop-OSS/drop.git
synced 2026-07-24 17:03:00 +10:00
Depot API & v4 (#298)
* feat: nginx + torrential basics & services system * fix: lint + i18n * fix: update torrential to remove openssl * feat: add torrential to Docker build * feat: move to self hosted runner * fix: move off self-hosted runner * fix: update nginx.conf * feat: torrential cache invalidation * fix: update torrential for cache invalidation * feat: integrity check task * fix: lint * feat: move to version ids * fix: client fixes and client-side checks * feat: new depot apis and version id fixes * feat: update torrential * feat: droplet bump and remove unsafe update functions * fix: lint * feat: v4 featureset: emulators, multi-launch commands * fix: lint * fix: mobile ui for game editor * feat: launch options * fix: lint * fix: remove axios, use $fetch * feat: metadata and task api improvements * feat: task actions * fix: slight styling issue * feat: fix style and lints * feat: totp backend routes * feat: oidc groups * fix: update drop-base * feat: creation of passkeys & totp * feat: totp signin * feat: webauthn mfa/signin * feat: launch selecting ui * fix: manually running tasks * feat: update add company game modal to use new SelectorGame * feat: executor selector * fix(docker): update rust to rust nightly for torrential build (#305) * feat: new version ui * feat: move package lookup to build time to allow for deno dev * fix: lint * feat: localisation cleanup * feat: apply localisation cleanup * feat: potential i18n refactor logic * feat: remove args from commands * fix: lint * fix: lockfile --------- Co-authored-by: Aden Lindsay <140392385+AdenMGB@users.noreply.github.com>
This commit is contained in:
@@ -103,4 +103,7 @@ export const systemACLDescriptions: ObjectFromList<typeof systemACLs> = {
|
||||
"Read tasks and maintenance information, like updates available and cleanup.",
|
||||
|
||||
"settings:update": "Update system settings.",
|
||||
|
||||
"depot:new": "Create a new download depot",
|
||||
"depot:delete": "Remove a download depot",
|
||||
};
|
||||
|
||||
@@ -43,6 +43,9 @@ export type UserACL = Array<(typeof userACLs)[number]>;
|
||||
export const systemACLs = [
|
||||
"setup",
|
||||
|
||||
"depot:new",
|
||||
"depot:delete",
|
||||
|
||||
"auth:read",
|
||||
"auth:simple:invitation:read",
|
||||
"auth:simple:invitation:new",
|
||||
@@ -123,8 +126,12 @@ class ACLManager {
|
||||
if (!request)
|
||||
throw new Error("Native web requests not available - weird deployment?");
|
||||
// Sessions automatically have all ACLs
|
||||
const user = await sessionHandler.getSession(request);
|
||||
if (user) return user.userId;
|
||||
const session = await sessionHandler.getSession(request);
|
||||
if (session && session.authenticated) {
|
||||
if (session.authenticated.level >= session.authenticated.requiredLevel)
|
||||
return session.authenticated.userId;
|
||||
return undefined;
|
||||
}
|
||||
|
||||
const authorizationToken = this.getAuthorizationToken(request);
|
||||
if (!authorizationToken) return undefined;
|
||||
@@ -158,6 +165,19 @@ class ACLManager {
|
||||
return undefined;
|
||||
}
|
||||
|
||||
async allowUserSuperlevel(request: MinimumRequestObject | undefined) {
|
||||
if (!request)
|
||||
throw new Error("Native web requests not available - weird deployment?");
|
||||
const session = await sessionHandler.getSession(request);
|
||||
if (!session || !session.authenticated) return undefined;
|
||||
if (session.authenticated.level < session.authenticated.requiredLevel)
|
||||
return undefined;
|
||||
if (session.authenticated.superleveledExpiry === undefined)
|
||||
return undefined;
|
||||
if (session.authenticated.superleveledExpiry < Date.now()) return undefined;
|
||||
return session.authenticated.userId;
|
||||
}
|
||||
|
||||
async allowSystemACL(
|
||||
request: MinimumRequestObject | undefined,
|
||||
acls: SystemACL,
|
||||
@@ -165,14 +185,19 @@ class ACLManager {
|
||||
if (!request)
|
||||
throw new Error("Native web requests not available - weird deployment?");
|
||||
const userSession = await sessionHandler.getSession(request);
|
||||
if (userSession) {
|
||||
if (userSession && userSession.authenticated) {
|
||||
const user = await prisma.user.findUnique({
|
||||
where: { id: userSession.userId },
|
||||
where: { id: userSession.authenticated.userId },
|
||||
});
|
||||
if (user) {
|
||||
if (!user) return false;
|
||||
if (user.admin) return true;
|
||||
return false;
|
||||
if (!user.admin) return false;
|
||||
if (
|
||||
userSession.authenticated.level <
|
||||
userSession.authenticated.requiredLevel
|
||||
)
|
||||
return false;
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -221,7 +246,7 @@ class ACLManager {
|
||||
request: MinimumRequestObject,
|
||||
): Promise<GlobalACL[] | undefined> {
|
||||
const userSession = await sessionHandler.getSession(request);
|
||||
if (!userSession) {
|
||||
if (!userSession || !userSession.authenticated) {
|
||||
const authorizationToken = this.getAuthorizationToken(request);
|
||||
if (!authorizationToken) return undefined;
|
||||
const token = await prisma.aPIToken.findUnique({
|
||||
@@ -232,7 +257,7 @@ class ACLManager {
|
||||
}
|
||||
|
||||
const user = await prisma.user.findUnique({
|
||||
where: { id: userSession.userId },
|
||||
where: { id: userSession.authenticated.userId },
|
||||
select: {
|
||||
admin: true,
|
||||
},
|
||||
|
||||
Reference in New Issue
Block a user