mirror of
https://origin.cursor.com/mrdevmx/panels.git
synced 2026-10-09 13:23:17 +00:00
- Add IAM v2 auth with role_id, is_owner, status checks, and API key without tenant_admin bypass - Enforce CRUD permissions and project/warehouse scope across API routes - Rewrite usuarios.vue with ribbon, tree, user/role management, and permission matrix - Add dynamic menu, route guards, usePermissions/useScope composables - Apply role templates on create; filter project docs by category; hide cost tab without permission - Add iam_test unit tests; update bootstrap and SaaS tenant admin to use role_id Co-authored-by: alberto.martinez <alberto.martinez@mrdev.mx>
35 lines
933 B
TypeScript
35 lines
933 B
TypeScript
export type UserScopePayload = {
|
|
all_projects: boolean;
|
|
project_ids: number[];
|
|
warehouse_central: boolean;
|
|
warehouse_projects: boolean;
|
|
};
|
|
|
|
export function useScope() {
|
|
const scope = useState<UserScopePayload | null>("user-scope", () => null);
|
|
const loaded = useState("user-scope-loaded", () => false);
|
|
const { api } = useApi();
|
|
|
|
async function load() {
|
|
try {
|
|
scope.value = await api<UserScopePayload>("/v1/me/scope");
|
|
loaded.value = true;
|
|
} catch {
|
|
scope.value = {
|
|
all_projects: false,
|
|
project_ids: [],
|
|
warehouse_central: false,
|
|
warehouse_projects: false,
|
|
};
|
|
loaded.value = true;
|
|
}
|
|
}
|
|
|
|
function canAccessProject(projectId: number): boolean {
|
|
if (!scope.value) return true;
|
|
if (scope.value.all_projects) return true;
|
|
return scope.value.project_ids.includes(projectId);
|
|
}
|
|
|
|
return { scope, loaded, load, canAccessProject };
|
|
}
|