Restructures into apps/ssp + apps/behandelportal (two Angular projects) plus libs/shared + libs/beheer (cross-app libraries), replacing WP-61's separate sibling repo. That split had already produced real drift: a hand-vendored copy of the backend's OpenAPI doc, a shared/ui+layout tree forked and silently diverging (7 files), and beheer + the styles.scss token bridge duplicated byte-for-byte across both repos. - git mv the SSP's src/app/* into apps/ssp/; fold shared/, beheer/, environments/, the Storybook docs/*.mdx, and styles.scss into libs/shared + libs/beheer (all confirmed identical between the two repos before merging). auth stays deliberately duplicated per ADR-0002 (actor-specific, expected to diverge) - amended there. - One generated API client (libs/shared), no more vendored swagger.json. - .dependency-cruiser split into a base factory + one config per app, and Storybook into .storybook-ssp/.storybook-behandelportal - both forced by the @auth/* alias resolving to different directories per app. - SiteHeaderComponent/ShellComponent gained HEADER_NAV_ITEMS/ HEADER_ADMIN_LINKS/DEBUG_PANEL injection tokens so each app supplies its own nav/admin-links/dev-panel instead of one being hardcoded. - CLAUDE.md, ARCHITECTURE.md, dependencies.md, and ADR-0002 updated; WP-67 backlog entry documents the full decision trail. npm run ci green (lint, dep:check x2, 360 tests across ssp/ behandelportal/shared/beheer, both localized builds, backend tests, snippet + api-client drift); both dev servers, both Storybook instances, and docker compose verified working. The old sibling repo (/home/eho/repos/behandelportal) is left untouched, not deleted. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
35 lines
1.6 KiB
TypeScript
35 lines
1.6 KiB
TypeScript
import { inject } from '@angular/core';
|
|
import { CanActivateFn, Router } from '@angular/router';
|
|
import { AccessStore } from '@shared/application/access.store';
|
|
import { Capability } from '@shared/domain/capability';
|
|
import { SessionStore } from './application/session.store';
|
|
|
|
/** Route guard: only let authenticated users in; otherwise redirect to /login. */
|
|
export const authGuard: CanActivateFn = () => {
|
|
const store = inject(SessionStore);
|
|
const router = inject(Router);
|
|
return store.isAuthenticated() ? true : router.createUrlTree(['/login']);
|
|
};
|
|
|
|
/**
|
|
* Route guard factory (PRD-0002 §6): authenticated AND holding `capability`, else
|
|
* redirect. Used by the admin pages (`/brief/huisstijl`, `/beheer/stamdata`).
|
|
*
|
|
* **Async on purpose:** `can()` is deny-by-default, so it must not be read while `/me`
|
|
* is still loading — it would deny an entitled admin and bounce them. We await
|
|
* `AccessStore.whenReady()` (caps resolved) before deciding. An unauthenticated user
|
|
* goes to `/login`; an authenticated-but-unentitled user goes to `/dashboard` (they're
|
|
* logged in, just not allowed here — no re-login loop). The backend re-enforces
|
|
* regardless (403); this guard is the UX pre-gate.
|
|
*/
|
|
export function capabilityGuard(capability: Capability): CanActivateFn {
|
|
return async () => {
|
|
const session = inject(SessionStore);
|
|
const access = inject(AccessStore);
|
|
const router = inject(Router);
|
|
if (!session.isAuthenticated()) return router.createUrlTree(['/login']);
|
|
await access.whenReady();
|
|
return access.can(capability) ? true : router.createUrlTree(['/dashboard']);
|
|
};
|
|
}
|