X Enterprises
fastify-xauth-nile

requireSuperAdmin()

Returns a preHandler that allows only session users on the superAdmins allowlist.

requireSuperAdmin()

Returns a preHandler that checks the session user id or email against superAdmins. Responds 403 Forbidden when the user is not on the list. Call it after requireAuth() (or a platform protectedPaths guard) so request.auth is set.

This is an allowlist on the same Nile session — not a second auth instance.

Signature

instance.requireSuperAdmin(): (request: FastifyRequest, reply: FastifyReply) => Promise<void>

Params

requireSuperAdmin() takes no arguments. It uses superAdmins from registration.

Returns

A preHandler for the route preHandler option.

Throws

Sends 403 Forbidden when the session user id/email is not in superAdmins.

Examples

const auth = fastify.xAuthNile.default;

fastify.get("/internal/ops", {
  preHandler: [auth.requireAuth(), auth.requireSuperAdmin()],
}, async (request) => {
  return { isSuperAdmin: request.isSuperAdmin, user: request.user };
});

Prefer { prefix: "/admin", access: "platform" } when every route under /admin should be restricted.

See also

AI Context

package: "@xenterprises/fastify-xauth-nile"
method: fastify.xAuthNile.get(name).requireSuperAdmin()
use-when: Fastify preHandler that 403s unless session user id or email is in superAdmins
usage: { preHandler: [auth.requireAuth(), auth.requireSuperAdmin()] }
Copyright © 2026