54 lines
1.7 KiB
TypeScript
54 lines
1.7 KiB
TypeScript
import { Request, Router } from "express";
|
|
import { GetUserMiddleware } from "../middlewares/user";
|
|
import RequestError, { HttpStatusCode } from "../../helper/request_error";
|
|
import promiseMiddleware from "../../helper/promiseMiddleware";
|
|
import Permission from "../../models/permissions";
|
|
import verify, { Types } from "../middlewares/verify";
|
|
import Client from "../../models/client";
|
|
import { ObjectID } from "bson";
|
|
|
|
const PermissionRoute: Router = Router();
|
|
PermissionRoute.use(GetUserMiddleware(true, true), (req: Request, res, next) => {
|
|
if (!req.isAdmin) res.sendStatus(HttpStatusCode.FORBIDDEN)
|
|
else next()
|
|
});
|
|
|
|
|
|
PermissionRoute.route("/")
|
|
.get(promiseMiddleware(async (req, res) => {
|
|
let query = {};
|
|
if (req.query.client) {
|
|
query = { client: new ObjectID(req.query.client) }
|
|
}
|
|
let permission = await Permission.find(query);
|
|
res.json(permission);
|
|
}))
|
|
.post(verify({
|
|
client: {
|
|
type: Types.STRING
|
|
},
|
|
name: {
|
|
type: Types.STRING
|
|
},
|
|
description: {
|
|
type: Types.STRING
|
|
}
|
|
}, true), promiseMiddleware(async (req, res) => {
|
|
let client = await Client.findById(req.body.client);
|
|
if (!client) {
|
|
throw new RequestError("Client not found", HttpStatusCode.BAD_REQUEST);
|
|
}
|
|
let permission = Permission.new({
|
|
description: req.body.description,
|
|
name: req.body.name,
|
|
client: client._id
|
|
});
|
|
await Permission.save(permission);
|
|
res.json(permission);
|
|
})).delete(promiseMiddleware(async (req, res) => {
|
|
let { id } = req.query;
|
|
await Permission.delete(id);
|
|
res.json({ success: true });
|
|
}));
|
|
|
|
export default PermissionRoute; |