81 lines
2.8 KiB
JavaScript
81 lines
2.8 KiB
JavaScript
let pidMePromise = null;
|
|
|
|
/** /api/me/ é chamado uma vez por carregamento de página e cacheado — vários
|
|
* scripts (access.js, account.js, favorites.js, ...) rodam em handlers de
|
|
* DOMContentLoaded independentes e cada um precisa do usuário logado, mas
|
|
* todos podem compartilhar a mesma requisição em vez de disparar uma para
|
|
* cada arquivo. */
|
|
function pidGetMe() {
|
|
if (!pidMePromise) pidMePromise = pidRequireAuth();
|
|
return pidMePromise;
|
|
}
|
|
|
|
function pidCurrentPage() {
|
|
return window.location.pathname.split("/").pop() || "portal.html";
|
|
}
|
|
|
|
function pidApplyAccessVisibility(me) {
|
|
const gerenciaPermissoes = !!me.gerencia_permissoes;
|
|
const isDiretoria = (me.perfis || []).some((p) => p.nome === "Diretoria");
|
|
const efetivas = me.permissoes_efetivas || {};
|
|
|
|
document.querySelectorAll("[data-section]").forEach((el) => {
|
|
const section = el.getAttribute("data-section");
|
|
if (section === "perfis-acesso" || section === "usuarios") {
|
|
el.hidden = !gerenciaPermissoes;
|
|
return;
|
|
}
|
|
const perm = efetivas[section];
|
|
el.hidden = !(perm && perm.enabled);
|
|
});
|
|
|
|
document.querySelectorAll("[data-app]").forEach((el) => {
|
|
const moduleLi = el.closest("[data-section]");
|
|
const moduleKey = moduleLi ? moduleLi.getAttribute("data-section") : null;
|
|
const appKey = el.getAttribute("data-app");
|
|
const perm = moduleKey && efetivas[moduleKey];
|
|
el.hidden = !(perm && perm.enabled && perm.apps && perm.apps[appKey]);
|
|
});
|
|
|
|
document.querySelectorAll(".nav-subgroup").forEach((subgroup) => {
|
|
const hasVisibleTool = Array.from(subgroup.querySelectorAll("[data-app]")).some((el) => !el.hidden);
|
|
subgroup.hidden = !hasVisibleTool;
|
|
});
|
|
|
|
document.querySelectorAll("[data-restricted-badge]").forEach((el) => {
|
|
el.hidden = !isDiretoria;
|
|
});
|
|
|
|
// Só revela o menu (ver regra `.sidebar:not(.is-ready)` em layout.css) depois
|
|
// que todo item já teve sua visibilidade real decidida acima — evita mostrar
|
|
// seções/aplicações que o usuário não deveria ver, ainda que por um instante.
|
|
const sidebarEl = document.querySelector(".sidebar");
|
|
if (sidebarEl) sidebarEl.classList.add("is-ready");
|
|
}
|
|
|
|
async function pidInitAccess() {
|
|
const me = await pidGetMe();
|
|
if (!me) return null;
|
|
|
|
const perfis = me.perfis || [];
|
|
const hasAccess = perfis.length > 0;
|
|
|
|
if (!hasAccess && pidCurrentPage() !== "portal.html") {
|
|
window.location.href = "portal.html";
|
|
return null;
|
|
}
|
|
|
|
pidApplyAccessVisibility(me);
|
|
|
|
const dashboardContent = document.getElementById("dashboard-content");
|
|
const noAccessMessage = document.getElementById("no-access-message");
|
|
if (dashboardContent && noAccessMessage) {
|
|
dashboardContent.hidden = !hasAccess;
|
|
noAccessMessage.hidden = hasAccess;
|
|
}
|
|
|
|
return me;
|
|
}
|
|
|
|
document.addEventListener("DOMContentLoaded", pidInitAccess);
|