diff --git a/src/messages/messages.service.ts b/src/messages/messages.service.ts index e73bc70..dcb35bb 100644 --- a/src/messages/messages.service.ts +++ b/src/messages/messages.service.ts @@ -191,6 +191,17 @@ export class MessagesService { throw new ForbiddenException('You are not part of this conversation'); } + // Verify connection is still active before allowing message + const canMessage = await this.validateCanMessage( + conversation.userId, + conversation.agentProfileId, + ); + if (!canMessage) { + throw new ForbiddenException( + 'You can only message users with accepted connection requests', + ); + } + // Create the message const message = await this.prisma.message.create({ data: { diff --git a/src/support-chat/support-chat.controller.ts b/src/support-chat/support-chat.controller.ts index 9a888ad..58ddf4e 100644 --- a/src/support-chat/support-chat.controller.ts +++ b/src/support-chat/support-chat.controller.ts @@ -74,7 +74,7 @@ export class SupportChatController { @Query('limit') limit?: string, ) { // Validate access - const isAdmin = role === UserRole.ADMIN; + const isAdmin = role === UserRole.ADMIN || role === UserRole.SUPER_ADMIN; await this.supportChatService.getChat(chatId, userId, isAdmin); return this.supportChatService.getMessages( @@ -98,10 +98,10 @@ export class SupportChatController { @Body() dto: SendSupportMessageDto, ) { // Validate access - const isAdmin = role === UserRole.ADMIN; + const isAdmin = role === UserRole.ADMIN || role === UserRole.SUPER_ADMIN; await this.supportChatService.getChat(chatId, userId, isAdmin); - const senderRole = role === UserRole.ADMIN ? 'ADMIN' : 'USER'; + const senderRole = (role === UserRole.ADMIN || role === UserRole.SUPER_ADMIN) ? 'ADMIN' : 'USER'; const message = await this.supportChatService.sendMessage(chatId, userId, senderRole, dto.content); // Emit WebSocket events for real-time updates @@ -136,7 +136,7 @@ export class SupportChatController { const result = await this.supportChatService.markAsRead(chatId, role); // If admin marked as read, update sidebar badge for all admins - if (role === UserRole.ADMIN) { + if (role === UserRole.ADMIN || role === UserRole.SUPER_ADMIN) { const unreadTotal = await this.supportChatService.getAdminUnreadTotal(); this.messagesGateway.server.to('admin_room').emit('support_unread_update', { unreadTotal }); }