fd38f5659f
Let super admins act as a user from the user detail dashboard for
support/debugging ("full with guardrails", audit-only).
Backend: AuthService.impersonate issues a short-lived token for the
target carrying an `act` claim (acting admin); refresh preserves it and
JwtStrategy surfaces `impersonatedBy`. Guardrails: cannot impersonate an
admin or a deactivated account; new ImpersonationGuard blocks sensitive
self-service (change own password/phone) while impersonating. New
AuditLog entity records impersonation start/stop (admin, target, ip,
time); admin endpoints POST users/:id/impersonate + .../impersonation/
stop and GET users/:id/audit.
Frontend: lib/impersonation swaps admin/impersonation tokens in
localStorage; persistent banner with exit; "Login as user" button and an
"Admin access log" tab on the detail page; logout clears impersonation.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
35 lines
990 B
TypeScript
35 lines
990 B
TypeScript
import { Injectable } from '@nestjs/common';
|
|
import { PassportStrategy } from '@nestjs/passport';
|
|
import { ExtractJwt, Strategy } from 'passport-jwt';
|
|
import { ConfigService } from '@nestjs/config';
|
|
|
|
interface JwtPayload {
|
|
sub: string;
|
|
email: string;
|
|
role: string;
|
|
/** Present on impersonation tokens: the acting admin. */
|
|
act?: { sub: string; role: string };
|
|
}
|
|
|
|
@Injectable()
|
|
export class JwtStrategy extends PassportStrategy(Strategy) {
|
|
constructor(configService: ConfigService) {
|
|
super({
|
|
jwtFromRequest: ExtractJwt.fromAuthHeaderAsBearerToken(),
|
|
ignoreExpiration: false,
|
|
secretOrKey: configService.getOrThrow<string>('jwt.secret'),
|
|
});
|
|
}
|
|
|
|
async validate(payload: JwtPayload) {
|
|
return {
|
|
id: payload.sub,
|
|
email: payload.email,
|
|
role: payload.role,
|
|
// Non-null only while an admin is impersonating this user.
|
|
impersonatedBy: payload.act?.sub ?? null,
|
|
impersonatorRole: payload.act?.role ?? null,
|
|
};
|
|
}
|
|
}
|