fix: standardize deployment data directory and CI linting
This commit is contained in:
1 parent
c2e138f823
commit
e42d1a5d80
4 files changed
+49
-40
No files matched your search
+35
-27
@@ -90,10 +90,10 @@ pub(crate) const MAX_JSON_EXPORT_ROWS: usize = 50_000;
|
||||
pub(crate) async fn require_auth(
|
||||
state: &AppState,
|
||||
jar: &CookieJar,
|
||||
) -> Result<(User, String), Response> {
|
||||
) -> Result<(User, String), Box<Response>> {
|
||||
let conn = match state.users_db.lock() {
|
||||
Ok(c) => c,
|
||||
Err(_) => return Err(Redirect::to("/admin/login").into_response()),
|
||||
Err(_) => return Err(Box::new(Redirect::to("/admin/login").into_response())),
|
||||
};
|
||||
|
||||
match authenticate_admin_session(&conn, jar) {
|
||||
@@ -102,16 +102,18 @@ pub(crate) async fn require_auth(
|
||||
// Check if user is logged in as a normal tenant user trying to access admin route
|
||||
if let Ok(Some((tenant_user, _))) = authenticate_user_session(&conn, jar) {
|
||||
if tenant_user.account_type != "admin" {
|
||||
return Err((
|
||||
StatusCode::FORBIDDEN,
|
||||
"Forbidden: Standard users cannot access Admin routes",
|
||||
)
|
||||
.into_response());
|
||||
return Err(Box::new(
|
||||
(
|
||||
StatusCode::FORBIDDEN,
|
||||
"Forbidden: Standard users cannot access Admin routes",
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
}
|
||||
Err(Redirect::to("/admin/login").into_response())
|
||||
Err(Box::new(Redirect::to("/admin/login").into_response()))
|
||||
}
|
||||
Err(_) => Err(Redirect::to("/admin/login").into_response()),
|
||||
Err(_) => Err(Box::new(Redirect::to("/admin/login").into_response())),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -119,41 +121,47 @@ pub(crate) async fn require_auth(
|
||||
pub(crate) async fn require_user_auth(
|
||||
state: &AppState,
|
||||
jar: &CookieJar,
|
||||
) -> Result<(crate::models::TenantUser, String), Response> {
|
||||
) -> Result<(crate::models::TenantUser, String), Box<Response>> {
|
||||
let conn = match state.users_db.lock() {
|
||||
Ok(c) => c,
|
||||
Err(_) => return Err(Redirect::to("/login").into_response()),
|
||||
Err(_) => return Err(Box::new(Redirect::to("/login").into_response())),
|
||||
};
|
||||
|
||||
// If an Admin session is present, Core Admin is trying to access /user/* routes -> Reject with 403 Forbidden
|
||||
if let Ok(Some((_admin_user, _))) = authenticate_admin_session(&conn, jar) {
|
||||
return Err((
|
||||
StatusCode::FORBIDDEN,
|
||||
"Forbidden: Core Admin cannot access tenant application routes; use /admin/...",
|
||||
)
|
||||
.into_response());
|
||||
return Err(Box::new(
|
||||
(
|
||||
StatusCode::FORBIDDEN,
|
||||
"Forbidden: Core Admin cannot access tenant application routes; use /admin/...",
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
|
||||
// Now check tenant user session
|
||||
match authenticate_user_session(&conn, jar) {
|
||||
Ok(Some((user, session_id))) => {
|
||||
if user.account_type == "admin" {
|
||||
return Err((
|
||||
StatusCode::FORBIDDEN,
|
||||
"Forbidden: Core Admin cannot access tenant application routes; use /admin/...",
|
||||
)
|
||||
.into_response());
|
||||
return Err(Box::new(
|
||||
(
|
||||
StatusCode::FORBIDDEN,
|
||||
"Forbidden: Core Admin cannot access tenant application routes; use /admin/...",
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
if user.tenant_id.is_none() {
|
||||
return Err((
|
||||
StatusCode::FORBIDDEN,
|
||||
"Forbidden: User has no assigned TenantId",
|
||||
)
|
||||
.into_response());
|
||||
return Err(Box::new(
|
||||
(
|
||||
StatusCode::FORBIDDEN,
|
||||
"Forbidden: User has no assigned TenantId",
|
||||
)
|
||||
.into_response(),
|
||||
));
|
||||
}
|
||||
Ok((user, session_id))
|
||||
}
|
||||
_ => Err(Redirect::to("/login").into_response()),
|
||||
_ => Err(Box::new(Redirect::to("/login").into_response())),
|
||||
}
|
||||
}
|
||||
#[derive(Deserialize)]
|
||||
|
||||
Reference in new issue
Block a user