mirror of
https://github.com/Tria-plc/edr-platform.git
synced 2026-08-26 18:42:49 +00:00
fix(freight:backoffice): remove coarse fleet.view/fleet.manage/admin fallbacks
Now that every fleet-resource page and settings page has its own dedicated permission key (previous commit), the broad fallbacks are redundant and over-grant: anyone holding only fleet:view/fleet:manage or admin could reach every page in that whole section, not just one. Removed fleet.view fallback from: Routes, Locomotives, Train Builder, Wagons, Containers, Cargoes, Compliance & Alerts, Procurement, and the Overview dashboard's Fleet KPI tab. Removed fleet.manage fallback from: canFleetAction() (per-resource fleet CRUD, lib/permissions.ts) and TrainBuilderDetailPage's wagon- assignment check. Hard-delete already had no such fallback. Removed admin fallback from: File settings, Dropdown settings, Contract templates, Portal content, Trade access, Exchange rate. Left untouched: Incidents (sole gate is fleet.view — no dedicated edr_freight_app:incidents:* key exists on the backend yet, so there's nothing to fall back FROM; removing it would make the page super-admin-only). Access-narrowing change: anyone currently relying on the coarse grant without also holding the specific resource/settings key will lose access to these pages until roles are updated to grant the specific keys directly. Audit role assignments before this deploys. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -658,19 +658,13 @@ export type FleetCrudResource =
|
||||
| "vehicles"
|
||||
| "drivers";
|
||||
|
||||
/**
|
||||
* Per-resource fleet CRUD check. The legacy coarse fleet:manage key still
|
||||
* grants every action (mirrors the API's one-of guard fallback).
|
||||
*/
|
||||
/** Per-resource fleet CRUD check — each resource needs its own grant. */
|
||||
export function canFleetAction(
|
||||
user: AuthUser | null | undefined,
|
||||
resource: FleetCrudResource,
|
||||
action: "create" | "update" | "delete",
|
||||
): boolean {
|
||||
return (
|
||||
hasPermission(user, FREIGHT_PERMS[resource][action]) ||
|
||||
hasPermission(user, FREIGHT_PERMS.fleet.manage)
|
||||
);
|
||||
return hasPermission(user, FREIGHT_PERMS[resource][action]);
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user