All files / src/router ProtectedRoute.jsx

100% Statements 14/14
100% Branches 12/12
100% Functions 2/2
100% Lines 14/14

Press n or j to go to the next uncovered block, b, p or k for the previous block.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44                          2x 8x 8x 9x     8x 1x             7x 4x 4x 2x   4x     3x 1x     2x        
import { Navigate, Outlet } from "react-router-dom";
import CircularProgress from "@mui/material/CircularProgress";
import Box from "@mui/material/Box";
import { useAuthSession } from "@/authentication/AuthSessionProvider";
import { computeStrictPortalIntent, setAuthPortalIntent } from "@/authentication/authPortalIntent";
 
/**
 * Route guard — ADR-001 Phase 2 (BFF httpOnly-cookie auth).
 *
 * Authentication is established server-side: AuthSessionProvider probes
 * `GET /v1/auth/me` (the httpOnly cookie rides along) and exposes
 * { loading, isAuthenticated, role }. The SPA no longer reads any token.
 */
const ProtectedRoute = ({ allowedRole }) => {
    const { loading, isAuthenticated, role } = useAuthSession();
    const allowedRoles = (Array.isArray(allowedRole) ? allowedRole : [allowedRole]).map((r) =>
        String(r).toLowerCase()
    );
 
    if (loading) {
        return (
            <Box display="flex" justifyContent="center" alignItems="center" minHeight="100vh">
                <CircularProgress />
            </Box>
        );
    }
 
    if (!isAuthenticated) {
        const portal = computeStrictPortalIntent(allowedRole);
        if (portal) {
            setAuthPortalIntent(portal);
        }
        return <Navigate to="/login" replace />;
    }
 
    if (role && !allowedRoles.includes(String(role).toLowerCase())) {
        return <Navigate to={`/${role}`} replace />;
    }
 
    return <Outlet />;
};
 
export default ProtectedRoute;