From 4eb8c29b08d9893dc0ca3a39675ceb6b67271177 Mon Sep 17 00:00:00 2001 From: Stefan Renczes Date: Fri, 13 Jan 2023 07:03:36 +0100 Subject: [PATCH] [NAE-1617] Refactor authority - implemented required changes for frontend too --- nae.json | 12 ++++++++---- .../src/lib/user/services/user.service.ts | 16 ++++++++++++++-- 2 files changed, 22 insertions(+), 6 deletions(-) diff --git a/nae.json b/nae.json index f8e92209eb..a4c5584be8 100644 --- a/nae.json +++ b/nae.json @@ -233,7 +233,7 @@ }, "access": { "authority": [ - "ROLE_ADMIN" + "PROCESS_*" ] }, "navigation": { @@ -412,7 +412,11 @@ "class": "WorkflowViewExampleComponent", "from": "./doc/workflow-view-example/workflow-view-example.component" }, - "access": "private", + "access": { + "authority": [ + "PROCESS_*" + ] + }, "navigation": true, "routing": { "path": "workflow-view" @@ -528,7 +532,7 @@ ], "group": [], "authority": [ - "ROLE_ADMIN" + "USER_*" ] }, "navigation": false, @@ -769,7 +773,7 @@ "from": "./doc/navigation-example/buttons-nav/buttons-nav.component" }, "access": { - "authority": "ROLE_ADMIN" + "authority": "AUTHORITY_VIEW" }, "navigation": { "title": "authority check", diff --git a/projects/netgrif-components-core/src/lib/user/services/user.service.ts b/projects/netgrif-components-core/src/lib/user/services/user.service.ts index 84c3783470..19519994e5 100644 --- a/projects/netgrif-components-core/src/lib/user/services/user.service.ts +++ b/projects/netgrif-components-core/src/lib/user/services/user.service.ts @@ -13,6 +13,8 @@ import {SessionService} from '../../authentication/session/services/session.serv import {UserResource} from '../../resources/interface/user-resource'; import {AnonymousService} from '../../authentication/anonymous/anonymous.service'; +export var SCOPE_SUFFIX = "*"; + @Injectable({ providedIn: 'root' }) @@ -87,9 +89,19 @@ export class UserService implements OnDestroy { return false; } if (authority instanceof Array) { - return authority.some(a => user.authorities.some(u => u === a)); + return authority.some(a => user.authorities.some(u => u === a || this.hasAuthorityFromScope(a, u))); } else { - return user.authorities.some(a => a === authority); + return user.authorities.some(a => a === authority || this.hasAuthorityFromScope(authority, a)); + } + } + + public hasAuthorityFromScope(authorityScope: string, authorityToCheck: string): boolean { + if (authorityScope.includes(SCOPE_SUFFIX) && authorityScope.indexOf(SCOPE_SUFFIX) != authorityScope.length - 1) { + this._log.error('The authority name or scope is not valid.') + return false; + } + else { + return authorityToCheck.startsWith(authorityScope.replace(SCOPE_SUFFIX, '')); } }