Renames every .js module under src/ to .ts (api, useResource, adminSchema, navConfig, adminNav and src/data/*) and points imports, comments and the seed script's module paths at the new names. Their types now come from inference; no .d.ts files and no shape interfaces. tsc stays strict (noImplicitAny off). The errors inference leaves behind get the lightest fix that clears them: `any` on empty state, contexts and list defaults, `: any` on components with optional or spread props, class fields on ApiError, and option shapes on get/useResource. Kept as real types, since they belong to modules that were already TypeScript and later features import them: PageShell's ShellSection and props, useContent's corrected record types (website/email/ instagram are bare strings) and EventListItem, and TimelineRef's orgKind. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
34 lines
1.6 KiB
TypeScript
34 lines
1.6 KiB
TypeScript
/* ═══════════════════════════════════════════════════════════════
|
|
ROLE GUARD — src/pages/admin/RequireRole.tsx
|
|
|
|
Sits inside RequireAuth, never instead of it: by the time this
|
|
renders, the session question has already been answered. All
|
|
this decides is whether the answer was good enough.
|
|
|
|
Same caveat as RequireAuth — this hides the interface, not the
|
|
data. /api/admin/panel/* is superadmin-only on the server, and
|
|
that's the part that matters. Without it, a bookmarked URL and
|
|
a disabled select would be the only thing between a viewer and
|
|
the account list.
|
|
|
|
Bounces to Home rather than showing a "denied" page. Someone
|
|
who lands here has almost always followed a stale link, and a
|
|
working page beats an explanation of one.
|
|
═══════════════════════════════════════════════════════════════ */
|
|
|
|
import { Navigate, Outlet } from "react-router-dom";
|
|
import { useAuth } from "../../lib/auth.tsx";
|
|
import { atLeast, type Role } from "../../lib/roles.ts";
|
|
import { ADMIN_HOME } from "./adminNav.ts";
|
|
|
|
export default function RequireRole({ role = "superadmin" }: { role?: Role }) {
|
|
const { user, loading } = useAuth();
|
|
|
|
// RequireAuth is already showing its own placeholder above this.
|
|
if (loading) return null;
|
|
|
|
if (!user) return <Navigate to="/admin/login" replace />;
|
|
if (!atLeast(user, role)) return <Navigate to={ADMIN_HOME} replace />;
|
|
|
|
return <Outlet />;
|
|
}
|