Turn lab IAM on, move portal to access-web, harden sessions and receipts.
Some checks are pending
offline / test (push) Waiting to run
Some checks are pending
offline / test (push) Waiting to run
Fleet and department doors now check STAFF_IAM_URL. Walkthrough: cs can credit (agent is the IAM user) and cannot export; operator can fleet POST; admin /me is owner. Portal is the public web door at :3021/portal/. IAM sessions persist; login is rate-limited per user; receipt PDF is branded. lan-134 stays disabled.
This commit is contained in:
parent
d299d245e8
commit
c32b65038a
20 changed files with 277 additions and 73 deletions
|
|
@ -64,10 +64,12 @@ const server = http.createServer(async (req, res) => {
|
|||
return json(r.status, body);
|
||||
}
|
||||
if (req.method === 'POST' && url.pathname === '/credits') {
|
||||
if (!(await denyOrRedirect(req, res, json, { permission: 'cs.credit' }))) return;
|
||||
const who = await denyOrRedirect(req, res, json, { permission: 'cs.credit' });
|
||||
if (!who) return;
|
||||
const chunks = [];
|
||||
for await (const c of req) chunks.push(c);
|
||||
const body = JSON.parse(Buffer.concat(chunks).toString('utf8') || '{}');
|
||||
if (who.user?.username) body.agent = who.user.username;
|
||||
const gate = await check('verae.billing.balance.adjust', { kind: 'credit', principal: body.agent });
|
||||
if (!gate.allow) return json(403, gate);
|
||||
const r = await fetch(`${BOOKS}/adjust`, {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue