fix(03): module guard uses JWT tenantId fallback for deactivation enforcement
ModuleGuard now reads tenantId from req.user?.tenantId as fallback (same pattern as module-registry controller), and throws 403 instead of silently allowing access when no tenant context exists. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -42,11 +42,10 @@ export class ModuleGuard implements CanActivate {
|
|||||||
}
|
}
|
||||||
|
|
||||||
const request = context.switchToHttp().getRequest();
|
const request = context.switchToHttp().getRequest();
|
||||||
const tenantId = request.tenantId;
|
const tenantId = request.tenantId ?? request.user?.tenantId;
|
||||||
|
|
||||||
// Public routes or routes without tenant context skip module check
|
|
||||||
if (!tenantId) {
|
if (!tenantId) {
|
||||||
return true;
|
throw new ForbiddenException('No tenant context');
|
||||||
}
|
}
|
||||||
|
|
||||||
const isActive = await this.moduleRegistryService.isModuleActive(
|
const isActive = await this.moduleRegistryService.isModuleActive(
|
||||||
|
|||||||
Reference in New Issue
Block a user