Skip to content
File

Blob: src/worker/auth/scopes.ts

typescript22 lines
1import type { DavScope } from "@/worker/db/types";
2 
3// ADR: DAV write scopes imply read for the same protocol area. A write-only DAV client
4// still needs discovery, ETag, and readback access to perform interoperable writes.
5export function hasDavScope(scopes: readonly DavScope[], required: DavScope): boolean {
6 if (scopes.includes(required)) return true;
7 switch (required) {
8 case "dav:files:read":
9 return scopes.includes("dav:files:write");
10 case "dav:caldav:read":
11 return scopes.includes("dav:caldav:write");
12 case "dav:carddav:read":
13 return scopes.includes("dav:carddav:write");
14 default:
15 return false;
16 }
17}
18 
19export function hasAnyDavScope(scopes: readonly DavScope[], required: readonly DavScope[]): boolean {
20 return required.some((scope) => hasDavScope(scopes, scope));
21}