Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 0 additions & 3 deletions .vscode/settings.json

This file was deleted.

Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
import { MiddlewareConsumer, Module, NestModule } from '@nestjs/common';
import { DemoController, FakeAuthMiddleware } from './demo/demo.controller';
import { DemoController, FakeAuthMiddleware } from './demo.controller';

@Module({
controllers: [DemoController],
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
import { Controller, Get, UseGuards, Request } from '@nestjs/common';
import { Roles } from '../auth/roles.decorator';
import { RolesGuard } from '../auth/roles.guard';
import { Role } from '../auth/roles.enum';
import { Roles } from './roles.decorator';
import { RolesGuard } from './roles.guard';
import { Role } from './roles.enum';

/**
* Simulates the object that a real auth guard (e.g. JwtAuthGuard) would attach
Expand All @@ -15,7 +15,11 @@ import { Request as ExpressRequest, Response, NextFunction } from 'express';

@Injectable()
export class FakeAuthMiddleware implements NestMiddleware {
use(req: ExpressRequest & { user?: any }, _res: Response, next: NextFunction) {
use(
req: ExpressRequest & { user?: any },
_res: Response,
next: NextFunction,
) {
const role = (req.query.role as string)?.toUpperCase() ?? Role.USER;
req.user = { id: 1, username: 'testuser', role };
next();
Expand All @@ -24,10 +28,9 @@ export class FakeAuthMiddleware implements NestMiddleware {

// ──────────────────────────────────────────────────────────────────────────────

@UseGuards(RolesGuard) // apply guard to every route in this controller
@UseGuards(RolesGuard) // apply guard to every route in this controller
@Controller('demo')
export class DemoController {

/** Accessible by any authenticated user (no @Roles restriction) */
@Get('public')
publicRoute() {
Expand All @@ -52,6 +55,8 @@ export class DemoController {
@Roles(Role.USER, Role.ADMIN)
@Get('shared')
shared(@Request() req: any) {
return { message: `Hello, ${req.user.username}! Your role is ${req.user.role}.` };
return {
message: `Hello, ${req.user.username}! Your role is ${req.user.role}.`,
};
}
}
Loading