feat: add backup recovery, setup wizard and user-view guards
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
// Preview never promotes a user or changes server-side account permissions.
|
||||
export function getEffectiveRole(role: string | null | undefined, preview: boolean) {
|
||||
return preview && role === "admin" ? "user" : role;
|
||||
}
|
||||
|
||||
export function isAdminPage(pathname: string, includeSetup = true): boolean {
|
||||
let path = pathname.split(/[?#]/, 1)[0];
|
||||
try {
|
||||
path = decodeURIComponent(path);
|
||||
} catch {
|
||||
// Let the router handle malformed URLs; never infer a more privileged role.
|
||||
}
|
||||
path = path.replace(/\/{2,}/g, "/");
|
||||
const roots = includeSetup ? ["/admin", "/users", "/setup"] : ["/admin", "/users"];
|
||||
return roots.some((root) => path === root || path.startsWith(`${root}/`));
|
||||
}
|
||||
Reference in New Issue
Block a user