With the MCP plugin enabled, payload.auth() can return a payload-mcp-api-keys doc instead of a User. Add an isPayloadUser type guard and use it in every server action, page, and route that treats the auth result as a real user, so API-key sessions can no longer pass user auth checks. hasRoles now explicitly requires a users-collection doc.
5 lines
210 B
TypeScript
5 lines
210 B
TypeScript
import type { PayloadMcpApiKey, User } from "@/payload-types";
|
|
|
|
export function isPayloadUser(user: User | PayloadMcpApiKey | null | undefined): user is User {
|
|
return !!user && user.collection === "users";
|
|
}
|