/** HTTP client used by department doors and the admin console. */ export function iamBase() { return (process.env.STAFF_IAM_URL || '').replace(/\/$/, ''); } export async function iamCheck(req, permission) { const base = iamBase(); if (!base) { if (process.env.STAFF_AUTH === '1') { const login = (process.env.STAFF_SESSION_URL || 'http://127.0.0.1:3027').replace(/\/$/, ''); const r = await fetch(`${login}/check`, { headers: { cookie: req.headers.cookie || '' } }).catch(() => null); return { ok: Boolean(r && r.ok), skipped: false, legacy: true }; } return { ok: true, skipped: true }; } const q = permission ? `?permission=${encodeURIComponent(permission)}` : ''; const r = await fetch(`${base}/check${q}`, { headers: { cookie: req.headers.cookie || '', authorization: req.headers.authorization || '', }, }).catch(() => null); if (!r) return { ok: false, status: 502 }; const body = await r.json().catch(() => ({})); return { ok: r.ok, status: r.status, ...body }; } export function iamLoginUrl(next) { const base = iamBase() || (process.env.STAFF_SESSION_URL || 'http://127.0.0.1:3028').replace(/\/$/, ''); return `${base}/login?next=${encodeURIComponent(next)}`; } export async function denyOrRedirect(req, res, { permission, html, json }) { const out = await iamCheck(req, permission); if (out.ok) return out; if (html) { res.writeHead(302, { location: iamLoginUrl(`http://${req.headers.host || '127.0.0.1'}/`) }); res.end(); return out; } json(out.status === 403 ? 403 : 401, { error: out.reason || 'unauthorized', permission: permission || undefined, }); return out; }