fastify-xauth-nile
requireSuperAdmin()
Returns a preHandler that allows only session users on the superAdmins allowlist.
requireSuperAdmin()
Returns a preHandler that checks the session user id or email against superAdmins. Responds 403 Forbidden when the user is not on the list. Call it after requireAuth() (or a platform protectedPaths guard) so request.auth is set.
This is an allowlist on the same Nile session — not a second auth instance.
Signature
instance.requireSuperAdmin(): (request: FastifyRequest, reply: FastifyReply) => Promise<void>
Params
requireSuperAdmin() takes no arguments. It uses superAdmins from registration.
Returns
A preHandler for the route preHandler option.
Throws
Sends 403 Forbidden when the session user id/email is not in superAdmins.
Examples
const auth = fastify.xAuthNile.default;
fastify.get("/internal/ops", {
preHandler: [auth.requireAuth(), auth.requireSuperAdmin()],
}, async (request) => {
return { isSuperAdmin: request.isSuperAdmin, user: request.user };
});
Prefer { prefix: "/admin", access: "platform" } when every route under /admin should be restricted.
See also
- Protect path surfaces — directory guard for
/admin - requireAuth() — populate the session first
AI Context
package: "@xenterprises/fastify-xauth-nile"
method: fastify.xAuthNile.get(name).requireSuperAdmin()
use-when: Fastify preHandler that 403s unless session user id or email is in superAdmins
usage: { preHandler: [auth.requireAuth(), auth.requireSuperAdmin()] }
