feat(identity): redesign identity module and introduce RBAC foundation
- Redesign the Identity module with a richer domain model. - Extend the User entity to support username, Authentik integration, activity tracking, and storage information. - Add Role and Permission domain models with many-to-many relationships. - Implement RBAC foundation using UserRole, RolePermission, and UserPermission mappings. - Add user storage quota and usage fields with default values. - Introduce Authentik identifiers and synchronization metadata. - Refactor user domain logic for role and permission management. - Update Prisma schema to support the new identity architecture. - Improve JWT authentication and permission guard integration. - Update repositories, handlers, controllers, mappers, DTOs, and Swagger configuration. - Refresh environment configuration and project dependencies.
This commit is contained in:
@@ -0,0 +1,27 @@
|
||||
import { Injectable, CanActivate, ExecutionContext, UnauthorizedException } from '@nestjs/common';
|
||||
import { SyncIdentityHandler } from '../../application/handlers/user/sync-identity.handler';
|
||||
import { IdentityData } from '../../../../core/auth/interfaces/identity-data';
|
||||
|
||||
@Injectable()
|
||||
export class CurrentUserGuard implements CanActivate {
|
||||
constructor(
|
||||
private readonly syncIdentityHandler: SyncIdentityHandler,
|
||||
) {}
|
||||
|
||||
async canActivate(context: ExecutionContext): Promise<boolean> {
|
||||
const request = context.switchToHttp().getRequest() as any;
|
||||
|
||||
const identity = request.identity as IdentityData | undefined;
|
||||
|
||||
if (!identity) {
|
||||
throw new UnauthorizedException('Identity is missing.');
|
||||
}
|
||||
|
||||
const user = await this.syncIdentityHandler.execute(identity);
|
||||
|
||||
// attach domain user as currentUser
|
||||
request.currentUser = user;
|
||||
|
||||
return true;
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user