-
Notifications
You must be signed in to change notification settings - Fork 9
Restrict non-idir user features #307
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
Release 991d72b deployed at https://coms-dev-pr-307.apps.silver.devops.gov.bc.ca |
app/src/middleware/authorization.js
Outdated
req.currentUser.tokenPayload.identity_provider !== 'idir' && | ||
!hasOnlyPermittedKeys(req.query, ['email', 'userId', 'identityId']) | ||
) { | ||
throw new Error('User lacks permission to complete this actionnn'); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
just an extra 'n'
@@ -72,6 +72,11 @@ const utils = { | |||
return key || '/'; // set empty key to '/' to match convention in COMS db | |||
}, | |||
|
|||
hasOnlyPermittedKeys(obj, permittedKeys) { | |||
const objKeys = Object.keys(obj); | |||
return objKeys.every(key => permittedKeys.includes(key)); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
will this allow empty object? may be adding 'objKeys.length > 0 &&' will help?
Description
Types of changes
Checklist
Further comments