Bernt Christian Egeland 7 месяцев назад
Родитель
Сommit
e882e7c893

+ 2 - 2
src/features/team/Actions/assignRole.ts

@@ -7,8 +7,8 @@ import { revalidatePath } from "next/cache";
 import { PermissionAction, PermissionSubject } from "@/lib/permissions";
 
 export async function assignRole(input: unknown) {
-  return withAuth(async ({ organizationId, role }) => {
-    if (role !== "owner" && role !== "admin") {
+  return withAuth(async ({ organizationId, role, isSuperAdmin }) => {
+    if (!isSuperAdmin && role !== "owner" && role !== "admin") {
       throw new Error("Only owners and admins can assign roles");
     }
 

+ 2 - 2
src/features/team/Actions/createRole.ts

@@ -7,8 +7,8 @@ import { revalidatePath } from "next/cache";
 import { PermissionAction, PermissionSubject } from "@/lib/permissions";
 
 export async function createRole(input: unknown) {
-  return withAuth(async ({ organizationId, role }) => {
-    if (role !== "owner" && role !== "admin") {
+  return withAuth(async ({ organizationId, role, isSuperAdmin }) => {
+    if (!isSuperAdmin && role !== "owner" && role !== "admin") {
       throw new Error("Only owners and admins can create roles");
     }
 

+ 2 - 2
src/features/team/Actions/deleteRole.ts

@@ -6,8 +6,8 @@ import { revalidatePath } from "next/cache";
 import { PermissionAction, PermissionSubject } from "@/lib/permissions";
 
 export async function deleteRole(roleId: string) {
-  return withAuth(async ({ organizationId, role }) => {
-    if (role !== "owner" && role !== "admin") {
+  return withAuth(async ({ organizationId, role, isSuperAdmin }) => {
+    if (!isSuperAdmin && role !== "owner" && role !== "admin") {
       throw new Error("Only owners and admins can delete roles");
     }
 

+ 2 - 2
src/features/team/Actions/updateRole.ts

@@ -7,8 +7,8 @@ import { revalidatePath } from "next/cache";
 import { PermissionAction, PermissionSubject } from "@/lib/permissions";
 
 export async function updateRole(input: unknown) {
-  return withAuth(async ({ organizationId, role }) => {
-    if (role !== "owner" && role !== "admin") {
+  return withAuth(async ({ organizationId, role, isSuperAdmin }) => {
+    if (!isSuperAdmin && role !== "owner" && role !== "admin") {
       throw new Error("Only owners and admins can update roles");
     }