import { CanActivate, ExecutionContext, ForbiddenException, Injectable } from "@nestjs/common";
import type { Request } from "express";

/**
 * Bloquea endpoints sensibles (refunds, webhook endpoints, provider configs)
 * cuando la API key tiene scope "restricted".
 *
 * Usar SIEMPRE después del ApiKeyGuard.
 */
@Injectable()
export class RequireFullScopeGuard implements CanActivate {
  canActivate(context: ExecutionContext): boolean {
    const req = context.switchToHttp().getRequest<Request>();
    if (req.auth?.kind !== "api_key") {
      throw new ForbiddenException("Requires merchant API key");
    }
    if (req.auth.scope !== "full") {
      throw new ForbiddenException("API key does not have permission for this action");
    }
    return true;
  }
}
