File
Blob: src/shared/role.ts
| 1 | // Better Auth's admin plugin stores `role` as a comma-joined string when |
| 2 | // `setRole` receives an array (parseRoles in node_modules/better-auth/ |
| 3 | // dist/plugins/admin/routes.mjs). tessera reads `role` from D1 in that |
| 4 | // joined form, so a user with `role = "admin,user"` is still an admin |
| 5 | // everywhere admin gating happens. Single source of truth for that |
| 6 | // interpretation lives here so client and worker cannot drift. |
| 7 | // |
| 8 | // Accepts `unknown` because the upstream oauth-provider plugin types |
| 9 | // `clientPrivileges` user.role as `unknown`; defensive handling here |
| 10 | // keeps the surface tidy at every call site. |
| 11 | export const hasAdminRole = (role: unknown): boolean => { |
| 12 | if (role == null) return false; |
| 13 | if (typeof role === "string") return role.split(",").some((r) => r.trim() === "admin"); |
| 14 | if (Array.isArray(role)) return role.some((r) => typeof r === "string" && r.trim() === "admin"); |
| 15 | return false; |
| 16 | }; |