DogStark / DogStark/petChain-Frontend
[Frontend] Replace client-only admin protection with server-enforced authorization
- Dominant language
- TypeScript
- Stars
- 3
- Forks
- 158
- Avg merge
- 3d 6h
- Merged PRs (30d)
- 36
Description
## Problem
Client checks cannot secure admin data or API requests from direct callers.
## Relevant code
`src/pages/admin, src/lib/api/requireAdmin.ts`
## Proposed scope
Enforce roles at server/API boundaries, return consistent 401/403 responses, and test IDOR and forged-client-state attempts.
## Acceptance criteria
- [ ] The reported behavior is reproduced or characterized with a focused automated test before the fix.
- [ ] The implementation satisfies the proposed scope without weakening TypeScript, lint, authorization, privacy, or error handling.
- [ ] Success, empty/loading where applicable, failure, and boundary cases are covered.
- [ ] Existing related tests pass and new regression coverage is included.
- [ ] User-facing behavior remains accessible by keyboard and at mobile viewport sizes where UI is affected.
- [ ] Documentation is updated when the change alters configuration, contracts, security assumptions, or contributor workflow.
## Contributor notes
Base the work on the latest `main` branch. Keep unrelated refactors out of the pull request and include screenshots or recordings for visible changes. Never use real pet, medical, contact, wallet, or credential data in fixtures.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start from src/pages/admin and src/lib/api/requireAdmin.ts on the latest main branch, and reproduce the reported client-only protection problem with a focused automated test. Trace the server/API boundaries involved and cover direct callers, IDOR, forged client state, and consistent 401/403 responses. Done means the proposed authorization scope is implemented with regression and related tests passing.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- api, authorization, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100