fix(03): module guard uses JWT tenantId fallback for deactivation enforcement
ModuleGuard now reads tenantId from req.user?.tenantId as fallback (same pattern as module-registry controller), and throws 403 instead of silently allowing access when no tenant context exists. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -42,11 +42,10 @@ export class ModuleGuard implements CanActivate {
|
||||
}
|
||||
|
||||
const request = context.switchToHttp().getRequest();
|
||||
const tenantId = request.tenantId;
|
||||
const tenantId = request.tenantId ?? request.user?.tenantId;
|
||||
|
||||
// Public routes or routes without tenant context skip module check
|
||||
if (!tenantId) {
|
||||
return true;
|
||||
throw new ForbiddenException('No tenant context');
|
||||
}
|
||||
|
||||
const isActive = await this.moduleRegistryService.isModuleActive(
|
||||
|
||||
Reference in New Issue
Block a user