Skip to content

feat(frontend): secure admin routes and restore user context - #1420

Merged
mftee merged 2 commits into
CodeGirlsInc:mainfrom
phertyameen:feature/protected-frontend-accessibility-and-pagination
Sep 25, 2026
Merged

mftee merged 2 commits into
CodeGirlsInc:mainfrom
phertyameen:feature/protected-frontend-accessibility-and-pagination

Conversation

@phertyameen

Copy link
Copy Markdown
Contributor

Summary

  • enforce admin authorization in server layouts and middleware with fail-closed handling
  • use the shared dialog primitive for dispute-modal focus containment and restoration
  • add backend-backed document pagination with accessible controls
  • restore the last viewed map parcel from user-scoped session state

Issues

Validation

  • static diff, API contract, authorization, accessibility, import/export, and secret review completed
  • automated tests, lint/typecheck, builds, dependency installation, and CI were not run per maintainer request

Closes #1301
Closes #1302
Closes #1303
Closes #1304

Enforce server-side admin authorization, trap dispute-modal focus, paginate documents, and restore the last viewed map parcel across navigation.

Closes CodeGirlsInc#1301
Closes CodeGirlsInc#1302
Closes CodeGirlsInc#1303
Closes CodeGirlsInc#1304
@vercel

vercel Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

@phertyameen is attempting to deploy a commit to the Mftee's projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Sep 25, 2026

Copy link
Copy Markdown

@phertyameen Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

# Conflicts:
#	backend/.env.example
#	backend/src/auth/auth.controller.spec.ts
#	backend/src/auth/auth.controller.ts
#	backend/src/auth/auth.service.ts
#	backend/src/auth/strategies/github.strategy.ts
#	backend/src/auth/strategies/google.strategy.ts
#	backend/src/auth/strategies/jwt.strategy.spec.ts
#	backend/src/auth/strategies/jwt.strategy.ts
#	backend/src/common/cors.config.ts
#	backend/src/mail/mail.service.ts
#	backend/src/main.ts
#	frontend/app/[locale]/(protected)/admin/providers/page.tsx
#	frontend/app/[locale]/(protected)/admin/users/page.tsx
#	frontend/app/[locale]/(protected)/disputes/[id]/page.tsx
#	frontend/app/[locale]/(protected)/disputes/page.tsx
#	frontend/app/[locale]/(protected)/settings/data/page.tsx
#	frontend/app/[locale]/2fa/setup/page.tsx
#	frontend/app/[locale]/2fa/verify/page.tsx
#	frontend/app/[locale]/forgot-password/page.tsx
#	frontend/app/[locale]/login/LoginForm.tsx
#	frontend/app/[locale]/reset-password/page.tsx
#	frontend/app/[locale]/verify-email/page.tsx
#	frontend/app/layout.tsx
#	frontend/components/LanguageSwitcher.tsx
#	frontend/components/disputes/FileDisputeModal.tsx
#	frontend/components/map/ParcelSidebar.tsx
#	frontend/lib/api-client.ts
#	frontend/lib/auth-session.ts
#	frontend/lib/session-expiry-warning.ts
#	frontend/middleware.ts
#	frontend/test-utils/LoginForm.test.tsx
#	frontend/test-utils/api-client.test.ts
#	frontend/test-utils/language-switcher.test.tsx
#	frontend/test-utils/mocks/handlers.ts

@yusuftomilola yusuftomilola left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed and resolved a large conflict against main: PR #1415 (auth hardening) had independently merged a competing cookie/session scheme right before this landed. Kept main's already-deployed auth-cookie approach and backported this PR's actual contribution — the missing admin-role gate in middleware.ts (main was only checking authentication, not the admin role, on /admin routes), plus the dispute-modal focus containment (now using the shared Dialog primitive), the last-viewed-map-parcel restore/clear wiring, and the FileDisputeModal validation. Dropped the now-dead access-token.ts/session-cookie.config.ts/oauth-exchange-code files and the no-op preferredLanguage backend call (no matching endpoint exists). Good catch on the admin bypass gap.

@mftee
mftee merged commit bcd0a71 into CodeGirlsInc:main Sep 25, 2026
0 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

3 participants