This is an automated email from the ASF dual-hosted git repository. lahirujayathilake pushed a commit to branch auth-endpoints-web in repository https://gitbox.apache.org/repos/asf/airavata-custos.git
commit 4ac5c53ee30dd56efe5d7c7f87d0e84785c99804 Author: lahiruj <[email protected]> AuthorDate: Wed Jun 17 16:16:35 2026 -0400 Gate admin proxy path behind authenticated session and roles:manage --- web/src/app/api/v1/[...path]/route.ts | 12 ++++++++---- web/src/shared/auth/session.ts | 7 ++++++- 2 files changed, 14 insertions(+), 5 deletions(-) diff --git a/web/src/app/api/v1/[...path]/route.ts b/web/src/app/api/v1/[...path]/route.ts index ccdb406a5..f45f2ea30 100644 --- a/web/src/app/api/v1/[...path]/route.ts +++ b/web/src/app/api/v1/[...path]/route.ts @@ -32,7 +32,15 @@ async function proxy(request: NextRequest, ctx: Context) { const accept = request.headers.get("accept"); if (accept) headers.set("accept", accept); + const session = await getPortalSession(); + if (!session?.accessToken) { + return NextResponse.json({ message: "Not authenticated" }, { status: 401 }); + } + if (isAdminPath(path)) { + if (!session.privileges.includes("roles:manage")) { + return NextResponse.json({ message: "Not authorized" }, { status: 403 }); + } if (!serverEnv.CUSTOS_ADMIN_CLIENT_ID || !serverEnv.CUSTOS_ADMIN_CLIENT_SECRET) { return NextResponse.json( { message: "Admin proxy not configured", path: path.join("/") }, @@ -42,10 +50,6 @@ async function proxy(request: NextRequest, ctx: Context) { headers.set("X-Client-Id", serverEnv.CUSTOS_ADMIN_CLIENT_ID); headers.set("X-Client-Secret", serverEnv.CUSTOS_ADMIN_CLIENT_SECRET); } else { - const session = await getPortalSession(); - if (!session?.accessToken) { - return NextResponse.json({ message: "Not authenticated" }, { status: 401 }); - } headers.set("authorization", `Bearer ${session.accessToken}`); } diff --git a/web/src/shared/auth/session.ts b/web/src/shared/auth/session.ts index fbadd50e6..c2a9dd78b 100644 --- a/web/src/shared/auth/session.ts +++ b/web/src/shared/auth/session.ts @@ -1,12 +1,17 @@ import "server-only"; import { auth } from "./auth"; +import type { Privilege } from "@/features/core/identity/types"; -export type PortalSession = { accessToken?: string | null } | null; +export type PortalSession = { + accessToken?: string | null; + privileges: Privilege[]; +} | null; export async function getPortalSession(): Promise<PortalSession> { const session = await auth(); if (!session) return null; return { accessToken: session.accessToken ?? null, + privileges: session.privileges ?? [], }; }
