add platform pages

This commit is contained in:
JCEEE
2026-08-23 15:12:19 +01:00
parent 762fbab4b6
commit bb2b1759dc
11 changed files with 1044 additions and 245 deletions
+26 -1
View File
@@ -1,6 +1,12 @@
import type { Handle } from '@sveltejs/kit';
import { createPbClient } from '$lib/server/pocketbase';
import { SESSION_COOKIE, setSessionCookie, clearSessionCookie } from '$lib/server/session';
import {
SESSION_COOKIE,
setSessionCookie,
clearSessionCookie,
PLATFORM_SESSION_COOKIE,
clearPlatformSession
} from '$lib/server/session';
import type { SessionUser } from '$lib/server/types';
import { handleOf } from '@shared/slugify';
import { migrateOnBoot } from '$lib/server/migrate-boot';
@@ -11,7 +17,26 @@ void migrateOnBoot();
export const handle: Handle = async ({ event, resolve }) => {
event.locals.user = null;
event.locals.pbToken = null;
event.locals.platformAdmin = false;
// Platform-admin routes authenticate via the superuser JWT in
// platform_session, verified against PB (authRefresh) — the cookie value
// is a real signed token, so forging it gains nothing.
if (event.url.pathname.startsWith('/admin')) {
const suToken = event.cookies.get(PLATFORM_SESSION_COOKIE);
if (suToken) {
try {
await createPbClient(suToken).collection('_superusers').authRefresh();
event.locals.platformAdmin = true;
} catch {
// Expired/revoked/forged token — drop it and treat as logged out.
clearPlatformSession(event.cookies);
}
}
return resolve(event);
}
// Fam-user session: pb_token JWT → authRefresh → locals.user.
const token = event.cookies.get(SESSION_COOKIE);
if (token) {