- Redesign the Identity module with a richer domain model. - Extend the User entity to support username, Authentik integration, activity tracking, and storage information. - Add Role and Permission domain models with many-to-many relationships. - Implement RBAC foundation using UserRole, RolePermission, and UserPermission mappings. - Add user storage quota and usage fields with default values. - Introduce Authentik identifiers and synchronization metadata. - Refactor user domain logic for role and permission management. - Update Prisma schema to support the new identity architecture. - Improve JWT authentication and permission guard integration. - Update repositories, handlers, controllers, mappers, DTOs, and Swagger configuration. - Refresh environment configuration and project dependencies.
28 lines
883 B
TypeScript
28 lines
883 B
TypeScript
import { Injectable, CanActivate, ExecutionContext, UnauthorizedException } from '@nestjs/common';
|
|
import { SyncIdentityHandler } from '../../application/handlers/user/sync-identity.handler';
|
|
import { IdentityData } from '../../../../core/auth/interfaces/identity-data';
|
|
|
|
@Injectable()
|
|
export class CurrentUserGuard implements CanActivate {
|
|
constructor(
|
|
private readonly syncIdentityHandler: SyncIdentityHandler,
|
|
) {}
|
|
|
|
async canActivate(context: ExecutionContext): Promise<boolean> {
|
|
const request = context.switchToHttp().getRequest() as any;
|
|
|
|
const identity = request.identity as IdentityData | undefined;
|
|
|
|
if (!identity) {
|
|
throw new UnauthorizedException('Identity is missing.');
|
|
}
|
|
|
|
const user = await this.syncIdentityHandler.execute(identity);
|
|
|
|
// attach domain user as currentUser
|
|
request.currentUser = user;
|
|
|
|
return true;
|
|
}
|
|
}
|