{"version":3,"file":"catalog.mjs","names":[],"sources":["../../../../../../src/astro/routes/api/admin/authz/catalog.ts"],"sourcesContent":["/**\n * GET /_emdash/api/admin/authz/catalog\n *\n * Everything the policy editor and the Routes tab need in one call: the\n * generated route catalogue, the admin page catalogue, and the permission\n * table with each key's legacy minimum level.\n */\n\nimport { ADMIN_PAGES, Permissions } from \"@premium-cms/auth\";\nimport type { APIRoute } from \"astro\";\n\nimport { requirePerm } from \"#api/authorize.js\";\nimport { apiSuccess } from \"#api/error.js\";\nimport { catalogGroups, patternToGrantPath, pluginCatalogEntries, ROUTE_CATALOG } from \"#auth/route-catalog.js\";\n\nexport const prerender = false;\n\nexport const GET: APIRoute = async ({ locals }) => {\n\tconst { user, emdash } = locals;\n\tconst denied = requirePerm(user, \"routes:read\");\n\tif (denied) return denied;\n\n\tconst pluginEntries = pluginCatalogEntries(emdash?.listPluginRoutes?.() ?? []);\n\treturn apiSuccess({\n\t\troutes: [...ROUTE_CATALOG, ...pluginEntries].map((e) => ({\n\t\t\t...e,\n\t\t\tgrantPath: patternToGrantPath(e.pattern),\n\t\t})),\n\t\tgroups: catalogGroups(pluginEntries),\n\t\tadminPages: ADMIN_PAGES,\n\t\tpermissions: Object.entries(Permissions).map(([key, minLevel]) => ({ key, minLevel })),\n\t});\n};\n\n// Static data; a long private cache is fine, and the auth middleware already\n// marks every /_emdash response no-store for shared caches.\n"],"mappings":";;;;;;;;;;;;;;;AAeA,MAAa,YAAY;AAEzB,MAAa,MAAgB,OAAO,EAAE,aAAa;CAClD,MAAM,EAAE,MAAM,WAAW;CACzB,MAAM,SAAS,YAAY,MAAM,cAAc;AAC/C,KAAI,OAAQ,QAAO;CAEnB,MAAM,gBAAgB,qBAAqB,QAAQ,oBAAoB,IAAI,EAAE,CAAC;AAC9E,QAAO,WAAW;EACjB,QAAQ,CAAC,GAAG,eAAe,GAAG,cAAc,CAAC,KAAK,OAAO;GACxD,GAAG;GACH,WAAW,mBAAmB,EAAE,QAAQ;GACxC,EAAE;EACH,QAAQ,cAAc,cAAc;EACpC,YAAY;EACZ,aAAa,OAAO,QAAQ,YAAY,CAAC,KAAK,CAAC,KAAK,eAAe;GAAE;GAAK;GAAU,EAAE;EACtF,CAAC"}