forked from StepFi-app/StepFi-API
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathadmin.guard.ts
More file actions
38 lines (32 loc) · 1.05 KB
/
Copy pathadmin.guard.ts
File metadata and controls
38 lines (32 loc) · 1.05 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
import {
CanActivate,
ExecutionContext,
ForbiddenException,
Injectable,
Logger,
} from '@nestjs/common';
import { ConfigService } from '@nestjs/config';
import { parseAdminWallets } from '../../config/env';
interface AuthenticatedRequest {
user?: { wallet?: string };
}
@Injectable()
export class AdminGuard implements CanActivate {
private readonly logger = new Logger(AdminGuard.name);
private readonly adminWallets: ReadonlySet<string>;
constructor(configService: ConfigService) {
this.adminWallets = new Set(parseAdminWallets(configService.get<string>('ADMIN_WALLETS')));
}
canActivate(context: ExecutionContext): boolean {
const request = context.switchToHttp().getRequest<AuthenticatedRequest>();
const wallet = request.user?.wallet;
if (!wallet || !this.adminWallets.has(wallet)) {
this.logger.warn(`Admin access denied for wallet ${wallet ?? 'unknown'}`);
throw new ForbiddenException({
code: 'AUTH_ADMIN_FORBIDDEN',
message: 'Admin access required.',
});
}
return true;
}
}