Skip to content

feat(auth): role-based access control with granular permissions - #216

Merged
Akatenvictor merged 1 commit into
AudioBitsStellar:mainfrom
dev-susa:feat/issue-100-rbac
Jul 29, 2026
Merged

feat(auth): role-based access control with granular permissions#216
Akatenvictor merged 1 commit into
AudioBitsStellar:mainfrom
dev-susa:feat/issue-100-rbac

Conversation

@dev-susa

Copy link
Copy Markdown
Contributor

Closes #100

Summary

Adds an RBAC layer that authorizes admin actions against named permissions rather than roles directly. Callers declare the capability they need; the map decides which roles have it.

  • Permission enum + ROLE_PERMISSIONS map — LISTENER/ARTIST have none, MODERATOR moderates content, ADMIN manages users/roles, SUPER_ADMIN holds every permission
  • requirePermission(permission) middleware — 401 when unauthenticated, 403 when the authenticated role lacks the capability
  • New MODERATOR and SUPER_ADMIN roles on UserRole
  • Per-route permission guards on admin routes (content moderation, search rebuild, jobs, role assignment)
  • UserService.assignRole + AdminController.assignRole + AssignRoleDTO for POST /admin/users/:id/role
  • Idempotent migration adding the role column

Testing

16 tests across four suites (permission map, requirePermission middleware, UserService.assignRole, AdminController.assignRole) — all passing.

…loses AudioBitsStellar#100)

Introduce an RBAC layer that authorizes admin actions against named
permissions rather than roles directly:

- Permission enum + ROLE_PERMISSIONS map (LISTENER/ARTIST have none,
  MODERATOR moderates content, ADMIN manages users/roles, SUPER_ADMIN
  holds every permission)
- requirePermission(permission) middleware: 401 unauthenticated,
  403 when the role lacks the capability
- New MODERATOR and SUPER_ADMIN roles on UserRole
- Per-route permission guards on admin routes (content moderation,
  search rebuild, jobs, role assignment)
- UserService.assignRole + AdminController.assignRole + AssignRoleDTO
  for POST /admin/users/:id/role
- Idempotent migration adding the role column
- 16 tests across permission map, middleware, service, and controller

Also removes pre-existing unused imports in User.ts and UserService.ts
surfaced by lint-staged on the touched files.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@drips-wave

drips-wave Bot commented Jul 29, 2026

Copy link
Copy Markdown

@dev-susa Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Akatenvictor
Akatenvictor merged commit f58f0ba into AudioBitsStellar:main Jul 29, 2026
1 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add role-based access control middleware

2 participants