Files
doormile_backend/middlewares/staff_only.go

22 lines
737 B
Go

package middlewares
import "github.com/gofiber/fiber/v2"
// DoormileStaffOnly admits only Doormile's own console staff: a login whose
// token carries tenant 0. A partner-tenant login is refused with 403, not
// handed an empty result — an empty list would read as "nothing configured"
// and hide that the caller is in the wrong place.
//
// Must run after AuthMiddleware, which sets the tenantid local. A missing
// local is treated as not staff: fail closed.
func DoormileStaffOnly(c *fiber.Ctx) error {
tenantID, ok := c.Locals("tenantid").(int)
if !ok || tenantID != 0 {
return c.Status(fiber.StatusForbidden).JSON(fiber.Map{
"success": false,
"message": "available to Doormile staff only",
})
}
return c.Next()
}