Skip to content
This repository was archived by the owner on May 12, 2026. It is now read-only.

Commit 5ca432b

Browse files
committed
Adding SuperAdmin alternative check for creating entitlements
1 parent 918d23e commit 5ca432b

3 files changed

Lines changed: 50 additions & 0 deletions

File tree

‎src/lib/utils/roleChecker.ts‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -123,6 +123,11 @@ export const ROLE_REQUIREMENTS = {
123123
],
124124

125125
createEntitlement: [
126+
{
127+
role: "SuperAdmin",
128+
description: "Super administrator with all permissions",
129+
action: "create entitlements",
130+
},
126131
{
127132
role: "CanCreateEntitlementAtAnyBank",
128133
description: "Create entitlements for users",
@@ -131,6 +136,11 @@ export const ROLE_REQUIREMENTS = {
131136
],
132137

133138
deleteEntitlement: [
139+
{
140+
role: "SuperAdmin",
141+
description: "Super administrator with all permissions",
142+
action: "delete entitlements",
143+
},
134144
{
135145
role: "CanDeleteEntitlementAtAnyBank",
136146
description: "Delete entitlements from users",

‎src/routes/api/rbac/entitlements/+server.ts‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,26 @@ export const POST: RequestHandler = async ({ request, locals }) => {
2222
return json({ error: "No API access token available" }, { status: 401 });
2323
}
2424

25+
// Check if user has required entitlements
26+
const userEntitlements = (session.data.user as any)?.entitlements?.list || [];
27+
const hasPermission = userEntitlements.some(
28+
(ent: any) =>
29+
ent.role_name === "SuperAdmin" ||
30+
ent.role_name === "CanCreateEntitlementAtAnyBank" ||
31+
ent.role_name === "CanCreateEntitlementAtOneBank",
32+
);
33+
34+
if (!hasPermission) {
35+
logger.warn("User does not have permission to create entitlements");
36+
return json(
37+
{
38+
error:
39+
"Insufficient permissions. Required: SuperAdmin, CanCreateEntitlementAtAnyBank, or CanCreateEntitlementAtOneBank",
40+
},
41+
{ status: 403 },
42+
);
43+
}
44+
2545
try {
2646
const body = await request.json();
2747
const { user_id, role_name, bank_id } = body;

‎src/routes/api/rbac/entitlements/[entitlement_id]/+server.ts‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,26 @@ export const DELETE: RequestHandler = async ({ params, locals }) => {
2828
return json({ error: "No API access token available" }, { status: 401 });
2929
}
3030

31+
// Check if user has required entitlements
32+
const userEntitlements = (session.data.user as any)?.entitlements?.list || [];
33+
const hasPermission = userEntitlements.some(
34+
(ent: any) =>
35+
ent.role_name === "SuperAdmin" ||
36+
ent.role_name === "CanDeleteEntitlementAtAnyBank" ||
37+
ent.role_name === "CanDeleteEntitlementAtOneBank",
38+
);
39+
40+
if (!hasPermission) {
41+
logger.warn("User does not have permission to delete entitlements");
42+
return json(
43+
{
44+
error:
45+
"Insufficient permissions. Required: SuperAdmin, CanDeleteEntitlementAtAnyBank, or CanDeleteEntitlementAtOneBank",
46+
},
47+
{ status: 403 },
48+
);
49+
}
50+
3151
try {
3252
logger.info("=== DELETE ENTITLEMENT ===");
3353
logger.info(`Entitlement ID: ${entitlement_id}`);

0 commit comments

Comments
 (0)