in dev, allow dev FE
[akkoma] / lib / pleroma / web / plugs / ensure_staff_privileged_plug.ex
1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2021 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
4
5 defmodule Pleroma.Web.Plugs.EnsureStaffPrivilegedPlug do
6 @moduledoc """
7 Ensures staff are privileged enough to do certain tasks.
8 """
9 import Pleroma.Web.TranslationHelpers
10 import Plug.Conn
11
12 alias Pleroma.Config
13 alias Pleroma.User
14
15 def init(options) do
16 options
17 end
18
19 def call(%{assigns: %{user: %User{is_admin: true}}} = conn, _), do: conn
20
21 def call(%{assigns: %{user: %User{is_moderator: true}}} = conn, _) do
22 if Config.get!([:instance, :privileged_staff]) do
23 conn
24 else
25 conn
26 |> render_error(:forbidden, "User is not an admin.")
27 |> halt()
28 end
29 end
30
31 def call(conn, _) do
32 conn
33 |> render_error(:forbidden, "User is not a staff member.")
34 |> halt()
35 end
36 end