phase1: RLS simplified to tenant isolation only + canAccess fallback removed + useUserPermissions hook + security kernel docs

This commit is contained in:
Agent Zero
2026-07-29 16:36:51 +02:00
parent 66fd387301
commit 8da803156e
9 changed files with 222 additions and 16 deletions
+4
View File
@@ -1,11 +1,15 @@
import { useEffect } from 'react';
import { useAuthStore } from '@/store/authStore';
import { useCurrentUser } from '@/api/hooks';
import { useUserPermissions } from '@/hooks/useUserPermissions';
export function useAuth() {
const store = useAuthStore();
const { data, isLoading, isError, error } = useCurrentUser();
// Load permissions after authentication
useUserPermissions();
useEffect(() => {
if (isError) {
const status = (error as any)?.status || 0;
+39
View File
@@ -0,0 +1,39 @@
import { useQuery } from '@tanstack/react-query';
import { apiGet } from '@/api/client';
import { useAuthStore } from '@/store/authStore';
import { useEffect } from 'react';
interface PermissionsResponse {
permissions: string[];
denied_permissions: string[];
field_permissions: Record<string, any>;
is_system_admin: boolean;
}
/**
* Fetches the current user's resolved permissions from /api/v1/auth/me/permissions
* and stores them in the authStore.
*/
export function useUserPermissions() {
const { isAuthenticated, setPermissions } = useAuthStore();
const { data, isSuccess } = useQuery<PermissionsResponse>({
queryKey: ['user-permissions'],
queryFn: () => apiGet<PermissionsResponse>('/api/v1/auth/me/permissions'),
enabled: isAuthenticated,
staleTime: 5 * 60 * 1000,
retry: 1,
});
useEffect(() => {
if (isSuccess && data) {
setPermissions(
data.permissions || [],
data.is_system_admin || false,
data.field_permissions || {},
);
}
}, [isSuccess, data, setPermissions]);
return { data, isSuccess };
}