Compare commits

...

4 Commits

Author SHA1 Message Date
anys dc0af96470 Refactor AuthenticatedState to store displayName and uid
The AuthenticatedState interface was updated to directly store the
`displayName` and `uid` properties. Previously, it stored the entire
`CasContent` object, which contained these properties along with others
that were not consistently used. This change simplifies the interface
and reduces redundancy.
2026-01-08 20:04:17 +01:00
anys bda47fd88b Update role enum and access control Remove isRouteAnAPI(route: string):
boolean

Refactor role determination logic to use `eduPersonPrimaryAffiliation`
and `amuComposante`. This simplifies checking for Polytech affiliation
and identifies roles like professor, administration, and student more
accurately. The API access control is updated to reflect the new role
names.
2026-01-08 19:34:29 +01:00
anys c0a335d33f - Add role detection
- Restrict APIs to personnels
- Show 403 for unauthorized access"
2026-01-08 19:33:20 +01:00
anys e818051621 Add 403 error page and Polytech access control. 2026-01-08 19:33:03 +01:00
11 changed files with 68 additions and 25 deletions
+5 -1
View File
@@ -3,12 +3,16 @@ import { AsyncRoute } from "$fresh/src/server/types.ts";
export interface AuthenticatedState { export interface AuthenticatedState {
isAuthenticated: true; isAuthenticated: true;
session: CasContent; isFromPolytech: boolean;
role: "etudiant" | "professeur" | "administration" | "autre";
displayName: string;
uid: string;
availablePages: Record<string, string>; availablePages: Record<string, string>;
} }
interface UnauthenticatedState { interface UnauthenticatedState {
isAuthenticated: false; isAuthenticated: false;
isFromPolytech: false;
session: undefined; session: undefined;
} }
+2
View File
@@ -19,6 +19,7 @@ import * as $_apps_students_partials_admin_consult from "./routes/(apps)/student
import * as $_apps_students_partials_admin_upload from "./routes/(apps)/students/partials/(admin)/upload.tsx"; import * as $_apps_students_partials_admin_upload from "./routes/(apps)/students/partials/(admin)/upload.tsx";
import * as $_apps_students_partials_index from "./routes/(apps)/students/partials/index.tsx"; import * as $_apps_students_partials_index from "./routes/(apps)/students/partials/index.tsx";
import * as $_apps_students_types_d from "./routes/(apps)/students/types.d.ts"; import * as $_apps_students_types_d from "./routes/(apps)/students/types.d.ts";
import * as $_403 from "./routes/_403.tsx";
import * as $_404 from "./routes/_404.tsx"; import * as $_404 from "./routes/_404.tsx";
import * as $_app from "./routes/_app.tsx"; import * as $_app from "./routes/_app.tsx";
import * as $_middleware from "./routes/_middleware.ts"; import * as $_middleware from "./routes/_middleware.ts";
@@ -64,6 +65,7 @@ const manifest = {
"./routes/(apps)/students/partials/index.tsx": "./routes/(apps)/students/partials/index.tsx":
$_apps_students_partials_index, $_apps_students_partials_index,
"./routes/(apps)/students/types.d.ts": $_apps_students_types_d, "./routes/(apps)/students/types.d.ts": $_apps_students_types_d,
"./routes/_403.tsx": $_403,
"./routes/_404.tsx": $_404, "./routes/_404.tsx": $_404,
"./routes/_app.tsx": $_app, "./routes/_app.tsx": $_app,
"./routes/_middleware.ts": $_middleware, "./routes/_middleware.ts": $_middleware,
+1 -1
View File
@@ -23,7 +23,7 @@ export const handler: MiddlewareHandler<AuthenticatedState>[] = [
context.state.availablePages = properties.pages; context.state.availablePages = properties.pages;
if ( if (
context.state.session.eduPersonPrimaryAffiliation == "student" && context.state.role == "etudiant" &&
Deno.env.get("LOCAL") != "true" Deno.env.get("LOCAL") != "true"
) { ) {
properties.adminOnly.forEach((page) => properties.adminOnly.forEach((page) =>
+1 -1
View File
@@ -7,7 +7,7 @@ import { State } from "$root/routes/_middleware.ts";
// deno-lint-ignore require-await // deno-lint-ignore require-await
export async function Index(_request: Request, context: FreshContext<State>) { export async function Index(_request: Request, context: FreshContext<State>) {
return <h2>Welcome to {context.state.session?.displayName}.</h2>; return <h2>Welcome to {context.state.displayName || 'Guest'}.</h2>;
} }
export const config = getPartialsConfig(); export const config = getPartialsConfig();
@@ -7,7 +7,7 @@ import { State } from "$root/routes/_middleware.ts";
// deno-lint-ignore require-await // deno-lint-ignore require-await
async function Courses(_request: Request, context: FreshContext<State>) { async function Courses(_request: Request, context: FreshContext<State>) {
return <h2>Welcome to {context.state.session?.displayName}.</h2>; return <h2>Welcome to {context.state.displayName || 'Guest'}.</h2>;
} }
export const config = getPartialsConfig(); export const config = getPartialsConfig();
+1 -1
View File
@@ -7,7 +7,7 @@ import { State } from "$root/routes/_middleware.ts";
// deno-lint-ignore require-await // deno-lint-ignore require-await
export async function Index(_request: Request, context: FreshContext<State>) { export async function Index(_request: Request, context: FreshContext<State>) {
return <h2>Welcome to {context.state.session?.displayName}.</h2>; return <h2>Welcome to {context.state.displayName || 'Guest'}.</h2>;
} }
export const config = getPartialsConfig(); export const config = getPartialsConfig();
+1 -1
View File
@@ -7,7 +7,7 @@ import { State } from "$root/routes/_middleware.ts";
// deno-lint-ignore require-await // deno-lint-ignore require-await
async function Notes(_request: Request, context: FreshContext<State>) { async function Notes(_request: Request, context: FreshContext<State>) {
return <h2>Welcome to {context.state.session?.displayName}.</h2>; return <h2>Welcome to {context.state.displayName || 'Guest'}.</h2>;
} }
export const config = getPartialsConfig(); export const config = getPartialsConfig();
+2 -2
View File
@@ -92,9 +92,9 @@ export const handler: Handlers<null, AuthenticatedState> = {
using connection = connect("students"); using connection = connect("students");
const database = connection.database; const database = connection.database;
if (context.state.session.eduPersonPrimaryAffiliation == "student") { if (context.state.role == "etudiant") {
return new Response( return new Response(
JSON.stringify(getItself(database, context.state.session.uid)), JSON.stringify(getItself(database, context.state.uid)),
{ {
headers: { headers: {
"content-type": "application/json", "content-type": "application/json",
+1 -7
View File
@@ -8,13 +8,7 @@ import SelfPortrait from "$root/routes/(apps)/students/(_components)/SelfPortrai
// deno-lint-ignore require-await // deno-lint-ignore require-await
export async function Index(_request: Request, context: FreshContext<State>) { export async function Index(_request: Request, context: FreshContext<State>) {
return ( return <h2>Welcome {context.state.displayName || 'Guest'}!</h2>;
<>
<h2>Welcome {context.state.session?.givenName}!</h2>
<h3>Your amU identity</h3>
<SelfPortrait self={context.state.session!} />
</>
);
} }
export const config = getPartialsConfig(); export const config = getPartialsConfig();
+12
View File
@@ -0,0 +1,12 @@
import { Head } from "$fresh/runtime.ts";
export default function Error403() {
return (
<>
<Head>
<title>403 - Forbidden</title>
</Head>
<p>403</p>
</>
);
}
+33 -2
View File
@@ -44,6 +44,7 @@ export function getKey(user: string): string {
export const handler: MiddlewareHandler<State>[] = [ export const handler: MiddlewareHandler<State>[] = [
/** /**
* Check if user is authenticated and add session to context accordingly. * Check if user is authenticated and add session to context accordingly.
* Only authenticated users who are members of Polytech are allowed.
* @param request The HTTP incomming request. * @param request The HTTP incomming request.
* @param context The Fresh context object with custom `State`. * @param context The Fresh context object with custom `State`.
* @returns The response from the next middleware. * @returns The response from the next middleware.
@@ -55,6 +56,7 @@ export const handler: MiddlewareHandler<State>[] = [
const cookies = getCookies(request.headers); const cookies = getCookies(request.headers);
if (!cookies["sessionToken"]) { if (!cookies["sessionToken"]) {
context.state.isAuthenticated = false; context.state.isAuthenticated = false;
context.state.isFromPolytech = false;
return await context.next(); return await context.next();
} }
@@ -67,9 +69,27 @@ export const handler: MiddlewareHandler<State>[] = [
); );
if (context.state.isAuthenticated) { if (context.state.isAuthenticated) {
const session: CasContent = const session: CasContent =
(getJwtPayload(cookies["sessionToken"]) as LoginJWT).user; (getJwtPayload(cookies["sessionToken"]) as LoginJWT).user;
context.state.session = session;
const isFromPolytech = session.amuComposante.includes("polytech");
context.state.isFromPolytech = isFromPolytech;
if (isFromPolytech) {
context.state.displayName = session.displayName;
context.state.uid = session.uid;
if (session.eduPersonPrimaryAffiliation == "faculty") {
context.state.role = "professeur"
} else if (session.eduPersonPrimaryAffiliation == "employee") {
context.state.role = "administration"
} else if (session.eduPersonPrimaryAffiliation == "student") {
context.state.role = "etudiant";
} else {
context.state.role = "autre";
}
}
} }
return await context.next(); return await context.next();
@@ -87,7 +107,8 @@ export const handler: MiddlewareHandler<State>[] = [
): Promise<Response> { ): Promise<Response> {
const url = new URL(request.url); const url = new URL(request.url);
if (!isRoutePublic(url.pathname) && !context.state.isAuthenticated) { if (!isRoutePublic(url.pathname)) {
if (!context.state.isAuthenticated) {
return new Response(null, { return new Response(null, {
status: 302, status: 302,
headers: { headers: {
@@ -96,6 +117,16 @@ export const handler: MiddlewareHandler<State>[] = [
}); });
} }
if (!context.state.isFromPolytech) {
return new Response(null, {
status: 403,
headers: {
Location: "/403",
},
});
}
}
return await context.next(); return await context.next();
}, },
]; ];