This is an automated email from the ASF dual-hosted git repository.

lahirujayathilake pushed a commit to branch auth-endpoints-web
in repository https://gitbox.apache.org/repos/asf/airavata-custos.git

commit 4ac5c53ee30dd56efe5d7c7f87d0e84785c99804
Author: lahiruj <[email protected]>
AuthorDate: Wed Jun 17 16:16:35 2026 -0400

    Gate admin proxy path behind authenticated session and roles:manage
---
 web/src/app/api/v1/[...path]/route.ts | 12 ++++++++----
 web/src/shared/auth/session.ts        |  7 ++++++-
 2 files changed, 14 insertions(+), 5 deletions(-)

diff --git a/web/src/app/api/v1/[...path]/route.ts 
b/web/src/app/api/v1/[...path]/route.ts
index ccdb406a5..f45f2ea30 100644
--- a/web/src/app/api/v1/[...path]/route.ts
+++ b/web/src/app/api/v1/[...path]/route.ts
@@ -32,7 +32,15 @@ async function proxy(request: NextRequest, ctx: Context) {
   const accept = request.headers.get("accept");
   if (accept) headers.set("accept", accept);
 
+  const session = await getPortalSession();
+  if (!session?.accessToken) {
+    return NextResponse.json({ message: "Not authenticated" }, { status: 401 
});
+  }
+
   if (isAdminPath(path)) {
+    if (!session.privileges.includes("roles:manage")) {
+      return NextResponse.json({ message: "Not authorized" }, { status: 403 });
+    }
     if (!serverEnv.CUSTOS_ADMIN_CLIENT_ID || 
!serverEnv.CUSTOS_ADMIN_CLIENT_SECRET) {
       return NextResponse.json(
         { message: "Admin proxy not configured", path: path.join("/") },
@@ -42,10 +50,6 @@ async function proxy(request: NextRequest, ctx: Context) {
     headers.set("X-Client-Id", serverEnv.CUSTOS_ADMIN_CLIENT_ID);
     headers.set("X-Client-Secret", serverEnv.CUSTOS_ADMIN_CLIENT_SECRET);
   } else {
-    const session = await getPortalSession();
-    if (!session?.accessToken) {
-      return NextResponse.json({ message: "Not authenticated" }, { status: 401 
});
-    }
     headers.set("authorization", `Bearer ${session.accessToken}`);
   }
 
diff --git a/web/src/shared/auth/session.ts b/web/src/shared/auth/session.ts
index fbadd50e6..c2a9dd78b 100644
--- a/web/src/shared/auth/session.ts
+++ b/web/src/shared/auth/session.ts
@@ -1,12 +1,17 @@
 import "server-only";
 import { auth } from "./auth";
+import type { Privilege } from "@/features/core/identity/types";
 
-export type PortalSession = { accessToken?: string | null } | null;
+export type PortalSession = {
+  accessToken?: string | null;
+  privileges: Privilege[];
+} | null;
 
 export async function getPortalSession(): Promise<PortalSession> {
   const session = await auth();
   if (!session) return null;
   return {
     accessToken: session.accessToken ?? null,
+    privileges: session.privileges ?? [],
   };
 }

Reply via email to