Skip to content

Commit

Permalink
feat: add segment query checking
Browse files Browse the repository at this point in the history
  • Loading branch information
Thenkei committed Jun 16, 2021
1 parent fcb7c02 commit 0a72503
Showing 1 changed file with 15 additions and 3 deletions.
18 changes: 15 additions & 3 deletions src/services/permissions-checker.js
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,20 @@ class PermissionsChecker {
});
}

static async _isCollectionBrowseAllowed(collectionPermissions, permissionInfos) {
static async _isCollectionBrowseAllowed(permissions, permissionInfos) {
const { collection: collectionPermissions, segments } = permissions;

// NOTICE: Security - Segment Query check additional permission
if (permissionInfos.segmentQuery) {
// NOTICE: The segmentQuery should be in the segments
if (!segments) {
return false;
}
if (!segments.includes(permissionInfos.segmentQuery)) {
return false;
}
}

return collectionPermissions
&& permissionInfos
&& PermissionsChecker
Expand All @@ -52,9 +65,8 @@ class PermissionsChecker {
case 'actions':
return PermissionsChecker._isSmartActionAllowed(permissions.actions, permissionInfos);
case 'browseEnabled':
console.log('browseEnabled CHECKING', JSON.stringify(permissions));
return PermissionsChecker
._isCollectionBrowseAllowed(permissions.collection, permissionInfos);
._isCollectionBrowseAllowed(permissions, permissionInfos);
case 'liveQueries':
return PermissionsChecker._isLiveQueryAllowed(permissions.stats.queries, permissionInfos);
case 'statWithParameters':
Expand Down

0 comments on commit 0a72503

Please sign in to comment.