mirror of
https://github.com/Tria-plc/edr-platform.git
synced 2026-08-26 18:42:49 +00:00
IAM lets an employee hold several positions, but the vendored JwtGuard collapses employee.positions[] down to a single employee.position and drops the rest. Non-delegate secondary positions vanished entirely, so staff on two posts resolved to one post's permissions and every check on the other rejected them. FreightJwtGuard re-attaches the full list from the same session snapshot the parent guard already read, so nothing extra is fetched per request beyond a cached session lookup. employee.position is left untouched, keeping audit logging and delegation unaffected. collectPermissionKeys and collectPositionTypeKeys now union across every position, and /me returns them all. Verified against a real two-position user (djibouti-gl-director + djibouti-gl-chief) on the local dev database: /me positions 1 -> 2 /me permissionKeys 17 -> 28 GET /api/interchange-documents 403 -> 200 GET /api/trains 403 -> 200 11 permissions recovered, none lost. Six single-position users return byte-identical payloads before and after.
24 lines
858 B
TypeScript
24 lines
858 B
TypeScript
import { Controller, Get, UseGuards } from '@nestjs/common';
|
|
import { ApiBearerAuth, ApiOperation, ApiTags } from '@nestjs/swagger';
|
|
import { CurrentUser } from '@tria-plc/api-common/modules/auth/decorators/current-user.decorator';
|
|
import { FreightJwtGuard } from '../../common/freight-jwt.guard';
|
|
import type { TCurrentUser } from '@tria-plc/api-common/modules/auth/types/current-user.type';
|
|
|
|
import { FreightMeService } from './freight-me.service';
|
|
|
|
@ApiTags('auth')
|
|
@Controller('me')
|
|
@ApiBearerAuth()
|
|
export class FreightMeController {
|
|
constructor(private readonly freightMeService: FreightMeService) {}
|
|
|
|
@Get()
|
|
@UseGuards(FreightJwtGuard)
|
|
@ApiOperation({
|
|
summary: 'Current user with flat permissionKeys for backoffice gating',
|
|
})
|
|
getMe(@CurrentUser() user: TCurrentUser) {
|
|
return this.freightMeService.getEnrichedProfile(user);
|
|
}
|
|
}
|