This is an automated email from the ASF dual-hosted git repository.

lahirujayathilake pushed a commit to branch auth-endpoints-web
in repository https://gitbox.apache.org/repos/asf/airavata-custos.git

commit 6a94f351eae6bd6ea7b234306fdd0fb8bea0bb1f
Author: lahiruj <[email protected]>
AuthorDate: Wed Jun 17 15:23:45 2026 -0400

    Fetch privileges from backend during OIDC sign-in
---
 web/src/shared/auth/auth.ts | 16 ++++++++++++++++
 1 file changed, 16 insertions(+)

diff --git a/web/src/shared/auth/auth.ts b/web/src/shared/auth/auth.ts
index 8e2ffd0ca..f24c44e0c 100644
--- a/web/src/shared/auth/auth.ts
+++ b/web/src/shared/auth/auth.ts
@@ -12,6 +12,21 @@ const oidcProvider = {
   authorization: { params: { scope: serverEnv.OIDC_SCOPES } },
 };
 
+// Privileges aren't an OIDC claim — fetch from the backend so the layout gate 
sees them.
+async function fetchPrivileges(bearer: string): Promise<Privilege[]> {
+  try {
+    const res = await 
fetch(`${serverEnv.CUSTOS_CORE_API_BASE_URL}/user/privileges`, {
+      headers: { Authorization: `Bearer ${bearer}` },
+      cache: "no-store",
+    });
+    if (!res.ok) return [];
+    const data = (await res.json()) as { privileges?: Privilege[] };
+    return data.privileges ?? [];
+  } catch {
+    return [];
+  }
+}
+
 export const authConfig: NextAuthConfig = {
   trustHost: true,
   secret: serverEnv.NEXTAUTH_SECRET,
@@ -25,6 +40,7 @@ export const authConfig: NextAuthConfig = {
       }
       if (account?.id_token) {
         (token as { accessToken?: string }).accessToken = account.id_token;
+        (token as { privileges?: Privilege[] }).privileges = await 
fetchPrivileges(account.id_token);
       }
       return token;
     },

Reply via email to