feat(portal): add SSR operations and exclusive groups
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { enabledAccessGroup, isRequestTimestampFresh, verifyHashedToken } from "@minecraft-account-manager/auth";
|
||||
import { isRequestTimestampFresh, resolveEffectiveGroup, verifyHashedToken } from "@minecraft-account-manager/auth";
|
||||
import { problemDetails, velocityAccessRequestSchema } from "@minecraft-account-manager/contracts";
|
||||
import {
|
||||
appSettings,
|
||||
@@ -11,7 +11,7 @@ import {
|
||||
pluginRequests,
|
||||
userGroupMemberships,
|
||||
} from "@minecraft-account-manager/database";
|
||||
import { and, eq, isNull, lt, or, sql } from "drizzle-orm";
|
||||
import { and, eq, isNull, lt, sql } from "drizzle-orm";
|
||||
import { NextResponse } from "next/server";
|
||||
import { db } from "@/lib/database";
|
||||
import { isUniqueConstraintViolation } from "@/lib/database-errors";
|
||||
@@ -212,14 +212,20 @@ async function handleVelocityAccess(request: Request) {
|
||||
return { allowed: false as const, message: denialMessage };
|
||||
}
|
||||
|
||||
const assignedGroups = await tx
|
||||
const [explicitGroup] = await tx
|
||||
.select({ id: groups.id, name: groups.name, accessEnabled: groups.accessEnabled })
|
||||
.from(userGroupMemberships)
|
||||
.innerJoin(groups, eq(groups.id, userGroupMemberships.groupId))
|
||||
.where(eq(userGroupMemberships.userId, account.userId))
|
||||
.limit(1);
|
||||
const [defaultGroup] = await tx
|
||||
.select({ id: groups.id, name: groups.name, accessEnabled: groups.accessEnabled })
|
||||
.from(groups)
|
||||
.leftJoin(userGroupMemberships, eq(userGroupMemberships.groupId, groups.id))
|
||||
.where(or(eq(groups.isDefault, true), eq(userGroupMemberships.userId, account.userId)));
|
||||
const enabledGroup = enabledAccessGroup(assignedGroups);
|
||||
.where(eq(groups.isDefault, true))
|
||||
.limit(1);
|
||||
const effectiveGroup = resolveEffectiveGroup(explicitGroup ?? null, defaultGroup ?? null);
|
||||
|
||||
if (!enabledGroup) {
|
||||
if (!effectiveGroup?.accessEnabled) {
|
||||
await tx.insert(events).values({
|
||||
id: randomUUID(),
|
||||
source: `/velocity/${input.serverId}`,
|
||||
@@ -297,7 +303,7 @@ async function handleVelocityAccess(request: Request) {
|
||||
previousUsername: account.username === input.username ? null : account.username,
|
||||
uuidBackfilled: account.minecraftUuid === null,
|
||||
ipIntelligence: auditIpData,
|
||||
accessGroup: enabledGroup.name,
|
||||
accessGroup: effectiveGroup.name,
|
||||
},
|
||||
ipAddress: input.ipAddress,
|
||||
correlationId: input.requestId,
|
||||
|
||||
Reference in New Issue
Block a user