fix(07): replace TenantMiddleware with TenantGuard to fix tenant context
Middleware runs before guards in NestJS — req.user was always undefined when TenantMiddleware executed, so req.tenantId was never set. Convert to TenantGuard (APP_GUARD, registered after JwtAuthGuard) so it runs after JWT validation and can read req.user.tenantId correctly. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
import { MiddlewareConsumer, Module, NestModule } from '@nestjs/common';
|
||||
import { Module } from '@nestjs/common';
|
||||
import { ConfigModule } from '@nestjs/config';
|
||||
import { APP_GUARD, APP_INTERCEPTOR } from '@nestjs/core';
|
||||
import { ScheduleModule } from '@nestjs/schedule';
|
||||
@@ -16,7 +16,7 @@ import { DomaincheckModule } from './domaincheck/domaincheck.module';
|
||||
import { ModuleRegistryModule } from './module-registry/module-registry.module';
|
||||
import { PrismaModule } from './prisma/prisma.module';
|
||||
import { SettingsModule } from './settings/settings.module';
|
||||
import { TenantMiddleware } from './tenant/tenant.middleware';
|
||||
import { TenantGuard } from './tenant/tenant.guard';
|
||||
import { TenantModule } from './tenant/tenant.module';
|
||||
import { UserModule } from './user/user.module';
|
||||
|
||||
@@ -44,6 +44,11 @@ import { UserModule } from './user/user.module';
|
||||
provide: APP_GUARD,
|
||||
useClass: JwtAuthGuard,
|
||||
},
|
||||
// Runs after JwtAuthGuard — sets req.tenantId and req.tenantPrisma from req.user
|
||||
{
|
||||
provide: APP_GUARD,
|
||||
useClass: TenantGuard,
|
||||
},
|
||||
// Global roles guard: checks @Roles() decorator
|
||||
{
|
||||
provide: APP_GUARD,
|
||||
@@ -56,9 +61,4 @@ import { UserModule } from './user/user.module';
|
||||
},
|
||||
],
|
||||
})
|
||||
export class AppModule implements NestModule {
|
||||
configure(consumer: MiddlewareConsumer) {
|
||||
// TenantMiddleware runs AFTER AuthGuard (guards run first in NestJS pipeline)
|
||||
consumer.apply(TenantMiddleware).forRoutes('*');
|
||||
}
|
||||
}
|
||||
export class AppModule {}
|
||||
|
||||
Reference in New Issue
Block a user