pr_01m47d24b0e6n91zwymwxg0vpx/apps/sudo/app/lib/staff.ts
| 1 | import { type RouterContextProvider, createContext } from "react-router"; |
| 2 | |
| 3 | /** The staff member making the request, as the worker verified them. */ |
| 4 | export type Staff = { email: string }; |
| 5 | |
| 6 | /** Set by the worker (workers/app.ts) once the Access token checks out. */ |
| 7 | export const staffContext = createContext<Staff | null>(null); |
| 8 | |
| 9 | /** |
| 10 | * The verified staff member, or a 403. The worker refuses anyone else |
| 11 | * before React Router runs; this is the second lock on the same door. |
| 12 | */ |
| 13 | export function requireStaff(context: Readonly<RouterContextProvider>): Staff { |
| 14 | const staff = context.get(staffContext); |
| 15 | if (!staff?.email) throw new Response("Forbidden", { status: 403 }); |
| 16 | return staff; |
| 17 | } |