Catalog declared in code (Domain/Features/FeatureFlags.cs, build-validated), on/off state
persisted in SQLite (FeatureFlagStore + migration). GET /flags (drives FE gating) + admin
PUT /admin/flags/{key} (new flags:manage capability + FlagsAdmin gate). Enforced end-to-end:
the `inschrijving-open` flag hides the Inschrijven nav item + dashboard action (FE) AND makes
POST /applications for a registratie 403 when off (backend). FE FeatureFlagStore mirrors
AccessStore (enabled() deny-by-default); admin toggle page at /beheer/functies in ADMIN_LINKS.
+4 backend tests, /me cap-list updated, client regenerated.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
109 lines
4.5 KiB
TypeScript
109 lines
4.5 KiB
TypeScript
import { Routes } from '@angular/router';
|
|
import { ShellComponent } from '@shared/layout/shell/shell.component';
|
|
import { authGuard, capabilityGuard } from '@auth/auth.guard';
|
|
import { flushPendingGuard } from '@shared/application/pending-saves';
|
|
|
|
export const routes: Routes = [
|
|
{
|
|
path: '',
|
|
component: ShellComponent, // persistent header/footer; only children swap
|
|
children: [
|
|
{ path: '', pathMatch: 'full', redirectTo: 'login' },
|
|
{
|
|
path: 'login',
|
|
loadComponent: () => import('@auth/ui/login.page').then((m) => m.LoginPage),
|
|
},
|
|
{
|
|
path: 'dashboard',
|
|
canActivate: [authGuard],
|
|
loadComponent: () => import('@registratie/ui/dashboard.page').then((m) => m.DashboardPage),
|
|
},
|
|
{
|
|
path: 'registratie',
|
|
canActivate: [authGuard],
|
|
loadComponent: () =>
|
|
import('@registratie/ui/registration-detail.page').then((m) => m.RegistrationDetailPage),
|
|
},
|
|
{
|
|
path: 'aanvraag/:id',
|
|
canActivate: [authGuard],
|
|
loadComponent: () =>
|
|
import('@registratie/ui/aanvraag-detail.page').then((m) => m.AanvraagDetailPage),
|
|
},
|
|
{
|
|
path: 'registreren',
|
|
canActivate: [authGuard],
|
|
// Autosave wizard: flush the pending debounced draft before leaving (pending-saves.ts).
|
|
canDeactivate: [flushPendingGuard],
|
|
loadComponent: () =>
|
|
import('@registratie/ui/registratie.page').then((m) => m.RegistratiePage),
|
|
},
|
|
{
|
|
path: 'herregistratie',
|
|
canActivate: [authGuard],
|
|
canDeactivate: [flushPendingGuard],
|
|
loadComponent: () =>
|
|
import('@herregistratie/ui/herregistratie.page').then((m) => m.HerregistratiePage),
|
|
},
|
|
{
|
|
path: 'intake',
|
|
canActivate: [authGuard],
|
|
canDeactivate: [flushPendingGuard],
|
|
loadComponent: () => import('@herregistratie/ui/intake.page').then((m) => m.IntakePage),
|
|
},
|
|
{
|
|
path: 'brief',
|
|
canActivate: [authGuard],
|
|
canDeactivate: [flushPendingGuard],
|
|
loadComponent: () => import('@brief/ui/brief.page').then((m) => m.BriefPage),
|
|
},
|
|
{
|
|
path: 'brief/huisstijl',
|
|
// Admin-only org-template editor (WP-26): capabilityGuard denies-by-default
|
|
// unless GET /me resolved `orgtemplate:edit` (Admin role). Backend re-enforces
|
|
// via the OrgAdmin gate — the guard just avoids loading a page that would 403.
|
|
canActivate: [capabilityGuard('orgtemplate:edit')],
|
|
canDeactivate: [flushPendingGuard],
|
|
loadComponent: () => import('@brief/ui/org-template.page').then((m) => m.OrgTemplatePage),
|
|
},
|
|
{
|
|
path: 'beheer/stamdata',
|
|
// Admin-only stamdata maintenance editor (ADR-0004): capabilityGuard denies-by-default
|
|
// unless GET /me resolved `stamdata:edit` (Admin role). Backend re-enforces via the
|
|
// StamdataAdmin gate — the guard just avoids loading a page that would 403.
|
|
canActivate: [capabilityGuard('stamdata:edit')],
|
|
loadComponent: () => import('@beheer/ui/stamdata.page').then((m) => m.StamdataPage),
|
|
},
|
|
{
|
|
path: 'beheer/zaken',
|
|
// Admin-only cases overview + delete (WP-36): capabilityGuard denies-by-default
|
|
// unless GET /me resolved `cases:manage` (Admin role). Backend re-enforces via the
|
|
// CasesAdmin gate — the guard just avoids loading a page that would 403. The page
|
|
// lives in registratie/ui (which owns the Aanvraag aggregate); routed under /beheer.
|
|
canActivate: [capabilityGuard('cases:manage')],
|
|
loadComponent: () =>
|
|
import('@registratie/ui/admin-cases.page').then((m) => m.AdminCasesPage),
|
|
},
|
|
{
|
|
path: 'beheer/audit',
|
|
// Admin-only authz/PII-reveal audit trail (WP-41/42). capabilityGuard denies-by-default
|
|
// unless GET /me resolved `cases:manage` (reused for audit read). Backend re-enforces.
|
|
canActivate: [capabilityGuard('cases:manage')],
|
|
loadComponent: () => import('@beheer/ui/audit.page').then((m) => m.AuditPage),
|
|
},
|
|
{
|
|
path: 'beheer/functies',
|
|
// Admin-only feature-flag toggles (WP-47), gated by `flags:manage`.
|
|
canActivate: [capabilityGuard('flags:manage')],
|
|
loadComponent: () =>
|
|
import('@beheer/ui/feature-flags.page').then((m) => m.FeatureFlagsPage),
|
|
},
|
|
{
|
|
path: 'concepts',
|
|
loadComponent: () => import('./showcase/concepts.page').then((m) => m.ConceptsPage),
|
|
},
|
|
{ path: '**', redirectTo: 'login' },
|
|
],
|
|
},
|
|
];
|