panels-origin/web-panel/composables/useScope.ts
Cursor Agent aed2f4531b
Implement client IAM v2: roles per tenant, CRUD matrix, scope, and panel UI
- Add IAM v2 auth with role_id, is_owner, status checks, and API key without tenant_admin bypass
- Enforce CRUD permissions and project/warehouse scope across API routes
- Rewrite usuarios.vue with ribbon, tree, user/role management, and permission matrix
- Add dynamic menu, route guards, usePermissions/useScope composables
- Apply role templates on create; filter project docs by category; hide cost tab without permission
- Add iam_test unit tests; update bootstrap and SaaS tenant admin to use role_id

Co-authored-by: alberto.martinez <alberto.martinez@mrdev.mx>
2026-09-08 18:16:59 +00:00

35 lines
933 B
TypeScript

export type UserScopePayload = {
all_projects: boolean;
project_ids: number[];
warehouse_central: boolean;
warehouse_projects: boolean;
};
export function useScope() {
const scope = useState<UserScopePayload | null>("user-scope", () => null);
const loaded = useState("user-scope-loaded", () => false);
const { api } = useApi();
async function load() {
try {
scope.value = await api<UserScopePayload>("/v1/me/scope");
loaded.value = true;
} catch {
scope.value = {
all_projects: false,
project_ids: [],
warehouse_central: false,
warehouse_projects: false,
};
loaded.value = true;
}
}
function canAccessProject(projectId: number): boolean {
if (!scope.value) return true;
if (scope.value.all_projects) return true;
return scope.value.project_ids.includes(projectId);
}
return { scope, loaded, load, canAccessProject };
}