mirror of
https://github.com/Drop-OSS/drop.git
synced 2026-01-31 15:37:09 +01:00
* feat: nginx + torrential basics & services system * fix: lint + i18n * fix: update torrential to remove openssl * feat: add torrential to Docker build * feat: move to self hosted runner * fix: move off self-hosted runner * fix: update nginx.conf * feat: torrential cache invalidation * fix: update torrential for cache invalidation * feat: integrity check task * fix: lint * feat: move to version ids * fix: client fixes and client-side checks * feat: new depot apis and version id fixes * feat: update torrential * feat: droplet bump and remove unsafe update functions * fix: lint * feat: v4 featureset: emulators, multi-launch commands * fix: lint * fix: mobile ui for game editor * feat: launch options * fix: lint * fix: remove axios, use $fetch * feat: metadata and task api improvements * feat: task actions * fix: slight styling issue * feat: fix style and lints * feat: totp backend routes * feat: oidc groups * fix: update drop-base * feat: creation of passkeys & totp * feat: totp signin * feat: webauthn mfa/signin * feat: launch selecting ui * fix: manually running tasks * feat: update add company game modal to use new SelectorGame * feat: executor selector * fix(docker): update rust to rust nightly for torrential build (#305) * feat: new version ui * feat: move package lookup to build time to allow for deno dev * fix: lint * feat: localisation cleanup * feat: apply localisation cleanup * feat: potential i18n refactor logic * feat: remove args from commands * fix: lint * fix: lockfile --------- Co-authored-by: Aden Lindsay <140392385+AdenMGB@users.noreply.github.com>
65 lines
1.9 KiB
TypeScript
65 lines
1.9 KiB
TypeScript
import capabilityManager, {
|
|
validCapabilities,
|
|
} from "~/server/internal/clients/capabilities";
|
|
import { defineClientEventHandler } from "~/server/internal/clients/event-handler";
|
|
import notificationSystem from "~/server/internal/notifications";
|
|
|
|
export default defineClientEventHandler(
|
|
async (h3, { clientId, fetchClient, fetchUser }) => {
|
|
const body = await readBody(h3);
|
|
const rawCapability = body.capability;
|
|
const configuration = body.configuration;
|
|
|
|
if (!rawCapability || typeof rawCapability !== "string")
|
|
throw createError({
|
|
statusCode: 400,
|
|
statusMessage: "capability must be a string",
|
|
});
|
|
|
|
if (!configuration || typeof configuration !== "object")
|
|
throw createError({
|
|
statusCode: 400,
|
|
statusMessage: "configuration must be an object",
|
|
});
|
|
|
|
const capability = validCapabilities.find(
|
|
(v) => v.toLowerCase() === rawCapability.toLowerCase(),
|
|
);
|
|
|
|
if (!capability)
|
|
throw createError({
|
|
statusCode: 400,
|
|
statusMessage: "Invalid capability.",
|
|
});
|
|
|
|
const isValid = await capabilityManager.validateCapabilityConfiguration(
|
|
capability,
|
|
configuration,
|
|
);
|
|
if (!isValid)
|
|
throw createError({
|
|
statusCode: 400,
|
|
statusMessage: "Invalid capability configuration.",
|
|
});
|
|
|
|
await capabilityManager.upsertClientCapability(
|
|
capability,
|
|
configuration,
|
|
clientId,
|
|
);
|
|
|
|
const client = await fetchClient();
|
|
const user = await fetchUser();
|
|
|
|
await notificationSystem.push(user.id, {
|
|
nonce: `capability-${clientId}-${capability}`,
|
|
title: `"${client.name}" can now access ${capability}`,
|
|
description: `A device called "${client.name}" now has access to your ${capability}.`,
|
|
actions: ["Review|/account/devices"],
|
|
acls: ["user:clients:read"],
|
|
});
|
|
|
|
return {};
|
|
},
|
|
);
|