All files / src/authentication auth0.js

100% Statements 20/20
100% Branches 18/18
100% Functions 8/8
100% Lines 18/18

Press n or j to go to the next uncovered block, b, p or k for the previous block.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65                              11x           17x 5x   12x 10x   4x 3x     6x     1x         1x         63x 63x       18x               11x 11x 2x   9x 9x    
/**
 * Auth0 role-claim helpers.
 *
 * BFF (ADR-001 Phase 3): the access token lives in an HttpOnly cookie the SPA
 * cannot read, so the Auth0 token-getter bridge and all `localStorage`
 * access-token plumbing were removed (the C1 cleanup). Identity and role now
 * come from the server session — see `authentication/session.js`
 * (`GET /v1/auth/me`) and `AuthSessionProvider`.
 *
 * What remains here is the roles-claim namespace and a normalizer, still used
 * by the portal-intent logic.
 */
 
import { getStoredRole } from "@/authentication/session";
 
export const ROLES_CLAIM = "https://eruditiontx.com/roles";
 
/**
 * Auth0 may send the roles claim as an array, a single string, or comma/space-separated strings.
 */
export function normalizeAuth0RolesClaim(claimValue) {
    if (claimValue == null || claimValue === "") {
        return [];
    }
    if (Array.isArray(claimValue)) {
        return claimValue.map((r) => String(r).trim()).filter(Boolean);
    }
    if (typeof claimValue === "string") {
        return claimValue
            .trim()
            .split(/[,\s]+/)
            .map((s) => s.trim())
            .filter(Boolean);
    }
    return [String(claimValue)];
}
 
/** @deprecated BFF auth — the access token is httpOnly and not client-readable. */
export function getRolesFromAccessToken() {
    return [];
}
 
/** Teacher/student portal role for UI — from server-verified role cached in session. */
export function getPortalRole() {
    const stored = getStoredRole();
    return stored ? String(stored).toLowerCase() : null;
}
 
export function rolesIncludeAdmin(roleStrings) {
    return roleStrings.some((r) => String(r).toLowerCase() === "admin");
}
 
/**
 * Admin UI gating: combine Auth0 user profile + access token + optional localStorage fallback.
 */
export function userHasAdminRole(user, isAuthenticated) {
    const fromProfile =
        isAuthenticated && user ? normalizeAuth0RolesClaim(user[ROLES_CLAIM]) : [];
    if (rolesIncludeAdmin(fromProfile)) {
        return true;
    }
    const stored = getStoredRole();
    return stored != null && String(stored).toLowerCase() === "admin";
}