package middlewares import "github.com/gofiber/fiber/v2" // DoormileStaffOnly admits only Doormile's own console staff: a login whose // token carries tenant 0. A partner-tenant login is refused with 403, not // handed an empty result — an empty list would read as "nothing configured" // and hide that the caller is in the wrong place. // // Must run after AuthMiddleware, which sets the tenantid local. A missing // local is treated as not staff: fail closed. func DoormileStaffOnly(c *fiber.Ctx) error { tenantID, ok := c.Locals("tenantid").(int) if !ok || tenantID != 0 { return c.Status(fiber.StatusForbidden).JSON(fiber.Map{ "success": false, "message": "available to Doormile staff only", }) } return c.Next() }