g1t/apps/sudo/app/lib/staff.ts

23 lines1,019 bytesCodeBlame
1import { type RouterContextProvider, createContext } from "react-router";
2
3/** The staff member making the request, as the worker verified them. */
4export type Staff = { email: string };
5
6/** Set by the worker (workers/app.ts) once the Access token checks out. */
7export const staffContext = createContext<Staff | null>(null);
8
9/**
10 * The verified staff member, or a 403. The worker refuses anyone else
11 * before React Router runs; this is the second lock on the same door.
12 */
13export function requireStaff(context: Readonly<RouterContextProvider>): Staff {
14 const staff = context.get(staffContext);
15 if (!staff?.email) throw new Response("Forbidden", { status: 403 });
16 return staff;
17}
18
19/** The zone this request's pages say times in, and whether the staff member chose it (lib/time.ts). */
20export type Zone = { zone: string; chosen: boolean };
21
22/** Set by the worker from the `sudo_tz` cookie or Cloudflare's guess; UTC otherwise. */
23export const zoneContext = createContext<Zone>({ zone: "UTC", chosen: false });