wulf-pulse/lib/auth-utils.ts
lorentz 9bfb57553d feat(design): nav/visual overhaul — brand layer, /status route, KPI dashboard, TanStack DataTable
Major UI refresh on the nav-design-improvements branch.  Drops 2013-era
inline styles and consolidates patterns behind shared primitives.

Foundation
- New Wulf brand layer in app/styles/brand.css repointing --primary to
  the standards-guide blue (#0075AD) with utility classes for numerics
  (.num / .num-lg / .num-xl), metric labels, surface tints, and the
  wolf-mark watermark
- Switch primary face to IBM Plex Sans + IBM Plex Mono via next/font;
  Helvetica/Arial stays in the fallback chain for brand fidelity
- Wordmark subtitle changed from "PSA Management System" to
  "Operations console" everywhere it appeared
- Tagline footer ("Don't be afraid to cry") on every non-mobile page

Status moved out of /dashboard
- New /status route with integration tiles grouped by category, sync
  health table, worker pulse cards (analyzer / RMM / sync scheduler),
  token-expiry section, conditional alert banner
- Top-bar StatusIndicator polls integration health every 60s and links
  to /status
- INTEGRATIONS_DISABLED env var suppresses operator-disabled
  integrations (e.g. SentinelOne) — no failure noise from broken-on-
  purpose entries.  Aliases supported (sentinelone → s1, etc.)

Dashboard rebuilt around KPIs
- /api/dashboard/overview adds today snapshot (opened, resolved, open
  total, SLA breaches) with delta math
- /api/dashboard/trends backs queue × priority heatmap, 30-day volume
  area chart, 30-day mean resolution time line chart, today's active
  engineers leaderboard

Components
- StatusBadge driven by lib/status-registry.ts (priority, ticket
  status, classification, source, company type, publish, active /
  yes-no / billable / approved registries)
- StatusLight (8px geometric square, five states, three sizes)
- EmptyState (shared dashed panel with icon + headline + optional CTA)
- KpiCard with delta indicator and tonal left border
- WulfMark (mark / wordmark variants from /public/branding)
- Skeleton helpers (SkeletonRow / Rows / Card / Chart / Header / Table)

Navigation
- Admin flat link → dropdown with seven shortcuts
- New UserMenu (initials avatar, role badge, settings + sign-out)
- Active-route highlight is now a 2px Wulf-blue underline echoing the
  PageHeader rule (consistent across flat links and submenu triggers);
  active children inside dropdowns use bg-primary/10
- Submenu width is content-driven (min-w 320 / max-w 440, single col)
- Mobile hamburger via Sheet, reuses the same nav config

Pages migrated
- 16 admin sub-pages adopt PageHeader (with accent prop)
- /addigy-devices: shadcn Table + Checkbox; PageHeader; status badges
- 10 raw <table> blocks across admin/sync/* migrated to shadcn Table
- /veeam-analysis migrated to shadcn Table (kept its expansion logic)
- Detail routes (analyzer ticket, analyzer analysis) get breadcrumbs

DataTable
- Rewritten on @tanstack/react-table v8 in manual mode; external API
  unchanged so all 10+ data-browser pages keep working
- New optional props for drill-down rows: getRowCanExpand + renderSubRow

Mobile
- Multi-select Popover gets max-w-[calc(100vw-1rem)] and
  collisionPadding so dropdowns can't overflow narrow viewports
- CI filter bar wraps and shrinks; stat pill flows below

Docs
- New ARCHITECTURE.md (load-bearing reference for runtime, data flow,
  workers, analyzer pipeline, auth, deployment, gotchas)
- New DESIGN.md (tokens, layout, navigation IA, component vocabulary,
  rolling backlog of remaining cleanup)
- CLAUDE.md refreshed with pointers to the two new docs and the
  INTEGRATIONS_DISABLED operator config note
- shadcn registry registered as project-level MCP server (.mcp.json)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-03 09:33:13 -04:00

169 lines
3.6 KiB
TypeScript

import { headers } from "next/headers";
import { NextResponse } from "next/server";
import { auth } from "./auth";
import { hasPermission, type Permission } from "./permissions";
// Extended user type with custom fields
type UserWithRole = {
id: string;
email: string;
name: string;
role?: string;
requires_setup?: boolean;
[key: string]: unknown;
};
/**
* Get the current session from the request headers
* Use this in API routes and server components
*/
export async function getSession() {
const session = await auth.api.getSession({
headers: await headers(),
});
return session;
}
/**
* Require authentication for an API route
* Returns the session if authenticated, or a 401 response if not
*/
export async function requireAuth() {
const session = await getSession();
if (!session) {
return {
session: null,
error: NextResponse.json(
{ error: "Unauthorized" },
{ status: 401 }
),
};
}
return { session, error: null };
}
/**
* Require specific permissions for an API route
* Returns the session if authorized, or a 403 response if not
*/
export async function requirePermission(
resource: Permission["resource"],
action: string
) {
const { session, error } = await requireAuth();
if (error) {
return { session: null, error };
}
const userRole = (session!.user as UserWithRole).role || "user";
if (!hasPermission(userRole, resource, action)) {
return {
session: null,
error: NextResponse.json(
{ error: "Forbidden" },
{ status: 403 }
),
};
}
return { session, error: null };
}
/**
* Require admin or super-admin role
*/
export async function requireAdmin() {
const { session, error } = await requireAuth();
if (error) {
return { session: null, error };
}
const userRole = (session!.user as UserWithRole).role || "user";
if (userRole !== "admin" && userRole !== "super-admin") {
return {
session: null,
error: NextResponse.json(
{ error: "Forbidden - Admin access required" },
{ status: 403 }
),
};
}
return { session, error: null };
}
/**
* Require super-admin role
*/
export async function requireSuperAdmin() {
const { session, error } = await requireAuth();
if (error) {
return { session: null, error };
}
const userRole = (session!.user as UserWithRole).role || "user";
if (userRole !== "super-admin") {
return {
session: null,
error: NextResponse.json(
{ error: "Forbidden - Super admin access required" },
{ status: 403 }
),
};
}
return { session, error: null };
}
/**
* Check if the current user has a specific permission
* Use this in server components for conditional rendering
*/
export async function checkPermission(
resource: Permission["resource"],
action: string
): Promise<boolean> {
const session = await getSession();
if (!session) {
return false;
}
const userRole = (session.user as UserWithRole).role || "user";
return hasPermission(userRole, resource, action);
}
/**
* Check if the current user is an admin or super-admin
*/
export async function isAdmin(): Promise<boolean> {
const session = await getSession();
if (!session) {
return false;
}
const userRole = (session.user as UserWithRole).role || "user";
return userRole === "admin" || userRole === "super-admin";
}
/**
* Check if the current user is a super-admin
*/
export async function isSuperAdmin(): Promise<boolean> {
const session = await getSession();
if (!session) {
return false;
}
return (session.user as UserWithRole).role === "super-admin";
}