Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Billing accounts, terms and enterprises; g1t is no longer free | 1 | import { type RouterContextProvider, createContext } from "react-router"; |
| 2 | ||
| 3 | /** The staff member making the request, as the worker verified them. */ | |
| 4 | export type Staff = { email: string }; | |
| 5 | ||
| 6 | /** Set by the worker (workers/app.ts) once the Access token checks out. */ | |
| 7 | export const staffContext = createContext<Staff | null>(null); | |
| 8 | ||
| 9 | /** | |
| 10 | * The verified staff member, or a 403. The worker refuses anyone else | |
| 11 | * before React Router runs; this is the second lock on the same door. | |
| 12 | */ | |
| 13 | export function requireStaff(context: Readonly<RouterContextProvider>): Staff { | |
| 14 | const staff = context.get(staffContext); | |
| 15 | if (!staff?.email) throw new Response("Forbidden", { status: 403 }); | |
| 16 | return staff; | |
| 17 | } | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 18 | |
| 19 | /** The zone this request's pages say times in, and whether the staff member chose it (lib/time.ts). */ | |
| 20 | export type Zone = { zone: string; chosen: boolean }; | |
| 21 | ||
| 22 | /** Set by the worker from the `sudo_tz` cookie or Cloudflare's guess; UTC otherwise. */ | |
| 23 | export const zoneContext = createContext<Zone>({ zone: "UTC", chosen: false }); |