phase1: RLS simplified to tenant isolation only + canAccess fallback removed + useUserPermissions hook + security kernel docs
This commit is contained in:
@@ -1,11 +1,15 @@
|
||||
import { useEffect } from 'react';
|
||||
import { useAuthStore } from '@/store/authStore';
|
||||
import { useCurrentUser } from '@/api/hooks';
|
||||
import { useUserPermissions } from '@/hooks/useUserPermissions';
|
||||
|
||||
export function useAuth() {
|
||||
const store = useAuthStore();
|
||||
const { data, isLoading, isError, error } = useCurrentUser();
|
||||
|
||||
// Load permissions after authentication
|
||||
useUserPermissions();
|
||||
|
||||
useEffect(() => {
|
||||
if (isError) {
|
||||
const status = (error as any)?.status || 0;
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
import { useQuery } from '@tanstack/react-query';
|
||||
import { apiGet } from '@/api/client';
|
||||
import { useAuthStore } from '@/store/authStore';
|
||||
import { useEffect } from 'react';
|
||||
|
||||
interface PermissionsResponse {
|
||||
permissions: string[];
|
||||
denied_permissions: string[];
|
||||
field_permissions: Record<string, any>;
|
||||
is_system_admin: boolean;
|
||||
}
|
||||
|
||||
/**
|
||||
* Fetches the current user's resolved permissions from /api/v1/auth/me/permissions
|
||||
* and stores them in the authStore.
|
||||
*/
|
||||
export function useUserPermissions() {
|
||||
const { isAuthenticated, setPermissions } = useAuthStore();
|
||||
|
||||
const { data, isSuccess } = useQuery<PermissionsResponse>({
|
||||
queryKey: ['user-permissions'],
|
||||
queryFn: () => apiGet<PermissionsResponse>('/api/v1/auth/me/permissions'),
|
||||
enabled: isAuthenticated,
|
||||
staleTime: 5 * 60 * 1000,
|
||||
retry: 1,
|
||||
});
|
||||
|
||||
useEffect(() => {
|
||||
if (isSuccess && data) {
|
||||
setPermissions(
|
||||
data.permissions || [],
|
||||
data.is_system_admin || false,
|
||||
data.field_permissions || {},
|
||||
);
|
||||
}
|
||||
}, [isSuccess, data, setPermissions]);
|
||||
|
||||
return { data, isSuccess };
|
||||
}
|
||||
Reference in New Issue
Block a user