import { createRouter, createWebHistory } from 'vue-router' import { ensureSession } from '@/services/api/auth' import LoginView from '@/views/LoginView.vue' import ReservationView from '@/views/ReservationView.vue' import MyReservationsView from '@/views/MyReservationsView.vue' import CalendarView from '@/views/CalendarView.vue' import AdminView from '@/views/AdminView.vue' import WhiskeyCallbackView from '@/views/WhiskeyCallbackView.vue' declare module 'vue-router' { interface RouteMeta { /** The route needs a session */ requiresAuth?: boolean /** ... and the session must belong to an admin */ requiresAdmin?: boolean } } const router = createRouter({ history: createWebHistory(import.meta.env.BASE_URL), routes: [ { name: 'login', path: '/', component: LoginView }, { name: 'reservations', path: '/reservations', component: ReservationView, meta: { requiresAuth: true }, }, { name: 'my-reservations', path: '/my-reservations', component: MyReservationsView, meta: { requiresAuth: true }, }, { name: 'calendar', path: '/calendar', component: CalendarView }, { name: 'admin', path: '/admin', component: AdminView, meta: { requiresAuth: true, requiresAdmin: true }, }, // Registered as the OIDC redirect uri, see `server.base_url` in config.yml { name: 'whiskey-callback', path: '/whiskey/callback', component: WhiskeyCallbackView }, ], }) /** * Keeps anonymous visitors off the pages that need a session. This is a * convenience, not the security boundary: every protected route answers 401 or * 403 on its own, whatever the frontend does. */ router.beforeEach(async (to) => { if (!to.meta.requiresAuth) return true const user = await ensureSession().catch(() => null) if (!user) return { name: 'login' } if (to.meta.requiresAdmin && !user.admin) return { name: 'reservations' } return true }) export default router