1
0
mirror of https://github.com/bpatrik/pigallery2.git synced 2025-01-18 04:58:59 +02:00
pigallery2/backend/middlewares/user/UserRequestConstrainsMWs.ts

55 lines
1.7 KiB
TypeScript
Raw Normal View History

import {NextFunction, Request, Response} from "express";
2016-05-25 20:17:42 +02:00
import {Error, ErrorCodes} from "../../../common/entities/Error";
import {UserRoles} from "../../../common/entities/User";
import {ObjectManagerRepository} from "../../model/ObjectManagerRepository";
export class UserRequestConstrainsMWs {
2016-05-09 17:04:56 +02:00
public static forceSelfRequest(req:Request, res:Response, next:NextFunction) {
if ((typeof req.params === 'undefined') || (typeof req.params.id === 'undefined')) {
return next();
}
2016-05-09 17:04:56 +02:00
if (req.session.user.id !== req.params.id) {
return next(new Error(ErrorCodes.NOT_AUTHORISED));
}
2016-05-09 17:04:56 +02:00
return next();
}
2016-05-09 17:04:56 +02:00
public static notSelfRequest(req:Request, res:Response, next:NextFunction) {
if ((typeof req.params === 'undefined') || (typeof req.params.id === 'undefined')) {
return next();
}
2016-05-09 17:04:56 +02:00
if (req.session.user.id === req.params.id) {
return next(new Error(ErrorCodes.NOT_AUTHORISED));
}
return next();
}
2016-05-09 17:04:56 +02:00
public static notSelfRequestOr2Admins(req:Request, res:Response, next:NextFunction) {
if ((typeof req.params === 'undefined') || (typeof req.params.id === 'undefined')) {
return next();
}
2016-05-09 17:04:56 +02:00
if (req.session.user.id !== req.params.id) {
return next();
}
//TODO: fix it!
2016-05-09 17:04:56 +02:00
ObjectManagerRepository.getInstance().getUserManager().find({minRole: UserRoles.Admin}, (err, result) => {
if ((err) || (!result)) {
return next(new Error(ErrorCodes.GENERAL_ERROR));
}
2016-05-09 17:04:56 +02:00
if (result.length <= 1) {
return next(new Error(ErrorCodes.GENERAL_ERROR));
}
2016-05-09 17:04:56 +02:00
});
2016-05-09 17:04:56 +02:00
return next();
}
}