mirror of
https://github.com/siop-spelev/siop2.git
synced 2026-08-08 20:51:53 +00:00
- packages/shared : rôles/catégories, schémas Zod, contrat d'API ; pnpm contract → docs/openapi.json committée (règle d'or ADR-001) - apps/api : NestJS 11 + Prisma 6, migration r0_identity (Role/Permission/User) ; guard JWT global + @Public() ; PermissionsGuard (@RequirePermission, matrice relue en base, cache 60 s) ; FileStorage (seul import MinIO) ; /health - démo-login ADR-002 : module conditionnel DEMO_MODE (404 sinon, testé e2e), double verrou production, refus des comptes isDemo=false - seed idempotent : 7 rôles, matrice complète (70 lignes), 7 comptes démo - 19 tests Jest (unit + e2e) ; smoke test sur build de prod Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
12 lines
496 B
TypeScript
12 lines
496 B
TypeScript
import { z } from 'zod';
|
|
import { AuthUserSchema } from './auth';
|
|
import { PermissionEntrySchema } from '../permissions';
|
|
|
|
/** Profil courant : identité + matrice du rôle (le JWT, lui, ne porte jamais
|
|
* de droits — le web lit cette réponse pour adapter l'UI, l'API re-vérifie
|
|
* chaque requête via PermissionsGuard). */
|
|
export const MeResponseSchema = AuthUserSchema.extend({
|
|
permissions: z.array(PermissionEntrySchema),
|
|
});
|
|
export type MeResponse = z.infer<typeof MeResponseSchema>;
|