fix: add missing @RequirePermission decorators

Adds @RequirePermission to 19 TS GraphQL resolvers across 5
subgraphs (iam, config-service, core-edu, content, msg) per
audit report §6.1. Maps: iam user/role -> IAM_USER_READ;
config-service 5 queries -> CONFIG_USER; core-edu classInfo ->
CLASS_READ, exam -> EXAM_READ, grade -> GRADE_READ, homework
-> HOMEWORK_READ, datascope visibleGrades/visibleExams ->
GRADE_READ/EXAM_READ; content chapter/knowledgePoint/question/
textbook -> CONTENT_*_READ; msg notifications ->
MSG_NOTIFICATION_READ, template -> MSG_NOTIFICATION_MANAGE.
Federation resolveReference left unguarded. Python subgraphs
(data-ana, ai) deferred to follow-up infrastructure work.
This commit is contained in:
SpecialX
2026-07-17 13:26:58 +08:00
parent 315b954998
commit 1b5781bf42
17 changed files with 117 additions and 30 deletions

View File

@@ -16,6 +16,10 @@ import {
Directive,
} from "@nestjs/graphql";
import { DataLoaderService, type RoleEntity } from "../dataloader.service.js";
import {
Permissions,
RequirePermission,
} from "../../middleware/permission.guard.js";
@ObjectType()
@Directive(`@key(fields: "roleId")`)
@@ -26,7 +30,7 @@ export class Role {
@Field()
name!: string;
@Field({ nullable: true })
@Field(() => String, { nullable: true })
description: string | null = null;
@Field()
@@ -46,6 +50,7 @@ export class RoleResolver {
}
@Query(() => Role, { nullable: true })
@RequirePermission(Permissions.IAM_USER_READ)
async role(
@Args("roleId", { type: () => ID }) roleId: string,
): Promise<RoleEntity | null> {