diff --git a/nae.json b/nae.json index 1a5e6bf93..86408e2c7 100644 --- a/nae.json +++ b/nae.json @@ -293,7 +293,7 @@ }, "access": { "authority": [ - "ADMIN" + "ROLE_ADMIN" ] }, "navigation": { diff --git a/projects/netgrif-components-core/src/lib/user/services/user.service.ts b/projects/netgrif-components-core/src/lib/user/services/user.service.ts index 2ef8a1052..ee890269f 100644 --- a/projects/netgrif-components-core/src/lib/user/services/user.service.ts +++ b/projects/netgrif-components-core/src/lib/user/services/user.service.ts @@ -14,6 +14,7 @@ import {SessionService} from '../../authentication/session/services/session.serv import {UserResource} from '../../resources/interface/user-resource'; import {AnonymousService} from '../../authentication/anonymous/anonymous.service'; +export var SCOPE_SUFFIX = "*"; @Injectable({ providedIn: 'root' @@ -102,9 +103,19 @@ export class UserService implements OnDestroy { return false; } if (authority instanceof Array) { - return authority.some(a => user.authorities.some(u => u === a)); + return authority.some(a => user.authorities.some(u => u === a || this.hasAuthorityFromScope(a, u))); } else { - return user.authorities.some(a => a === authority); + return user.authorities.some(a => a === authority || this.hasAuthorityFromScope(authority, a)); + } + } + + public hasAuthorityFromScope(authorityScope: string, authorityToCheck: string): boolean { + if (authorityScope.includes(SCOPE_SUFFIX) && authorityScope.indexOf(SCOPE_SUFFIX) != authorityScope.length - 1) { + this._log.error('The authority name or scope is not valid.') + return false; + } + else { + return authorityToCheck.startsWith(authorityScope.replace(SCOPE_SUFFIX, '')); } }