This is an automated email from the ASF dual-hosted git repository. lahirujayathilake pushed a commit to branch auth-endpoints-web in repository https://gitbox.apache.org/repos/asf/airavata-custos.git
commit 6a94f351eae6bd6ea7b234306fdd0fb8bea0bb1f Author: lahiruj <[email protected]> AuthorDate: Wed Jun 17 15:23:45 2026 -0400 Fetch privileges from backend during OIDC sign-in --- web/src/shared/auth/auth.ts | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/web/src/shared/auth/auth.ts b/web/src/shared/auth/auth.ts index 8e2ffd0ca..f24c44e0c 100644 --- a/web/src/shared/auth/auth.ts +++ b/web/src/shared/auth/auth.ts @@ -12,6 +12,21 @@ const oidcProvider = { authorization: { params: { scope: serverEnv.OIDC_SCOPES } }, }; +// Privileges aren't an OIDC claim — fetch from the backend so the layout gate sees them. +async function fetchPrivileges(bearer: string): Promise<Privilege[]> { + try { + const res = await fetch(`${serverEnv.CUSTOS_CORE_API_BASE_URL}/user/privileges`, { + headers: { Authorization: `Bearer ${bearer}` }, + cache: "no-store", + }); + if (!res.ok) return []; + const data = (await res.json()) as { privileges?: Privilege[] }; + return data.privileges ?? []; + } catch { + return []; + } +} + export const authConfig: NextAuthConfig = { trustHost: true, secret: serverEnv.NEXTAUTH_SECRET, @@ -25,6 +40,7 @@ export const authConfig: NextAuthConfig = { } if (account?.id_token) { (token as { accessToken?: string }).accessToken = account.id_token; + (token as { privileges?: Privilege[] }).privileges = await fetchPrivileges(account.id_token); } return token; },
