40 lines
1.4 KiB
Go
40 lines
1.4 KiB
Go
package middlewares
|
|
|
|
import (
|
|
"strings"
|
|
|
|
"github.com/gofiber/fiber/v2"
|
|
)
|
|
|
|
// ClientOnboardingOwnerOnly admits only the console logins named in
|
|
// CLIENT_ONBOARDING_OWNERS (default admin@doormile.com): the token's email must
|
|
// be on that list, AND it must be Doormile staff (tenant 0) with roleid 1.
|
|
//
|
|
// Onboarding mints a client's console credentials, so it is narrower than
|
|
// "any admin". Everything else refuses with the same 403 — a partner login,
|
|
// another Doormile admin, a manager — and the refusal names no allowed email.
|
|
//
|
|
// Must run after AuthMiddleware. Missing locals fail closed. The handler also
|
|
// re-reads the owner's doormile_auth row, so a token that outlives a removed
|
|
// or demoted account stops working at once.
|
|
func ClientOnboardingOwnerOnly(owners []string) fiber.Handler {
|
|
allowed := make(map[string]bool, len(owners))
|
|
for _, e := range owners {
|
|
if e = strings.ToLower(strings.TrimSpace(e)); e != "" {
|
|
allowed[e] = true
|
|
}
|
|
}
|
|
return func(c *fiber.Ctx) error {
|
|
email, _ := c.Locals("email").(string)
|
|
tenantID, tenantOK := c.Locals("tenantid").(int)
|
|
roleID, roleOK := c.Locals("roleid").(int)
|
|
if !tenantOK || !roleOK || tenantID != 0 || roleID != 1 || !allowed[strings.ToLower(strings.TrimSpace(email))] {
|
|
return c.Status(fiber.StatusForbidden).JSON(fiber.Map{
|
|
"success": false,
|
|
"message": "client onboarding is restricted to the designated onboarding account",
|
|
})
|
|
}
|
|
return c.Next()
|
|
}
|
|
}
|