From 33962d4f07ac3bc383110dcdf86334dd765bd273 Mon Sep 17 00:00:00 2001 From: Hamid Reza Mohammadi Date: Mon, 9 Nov 2020 16:09:36 +0330 Subject: [PATCH] checking user id on updating narrations --- .../Controllers/AudioNarrationController.cs | 48 ++++++++++++------- RMuseum/RMuseum.xml | 3 +- 2 files changed, 33 insertions(+), 18 deletions(-) diff --git a/RMuseum/Controllers/AudioNarrationController.cs b/RMuseum/Controllers/AudioNarrationController.cs index b94b6c66..0e5cb592 100644 --- a/RMuseum/Controllers/AudioNarrationController.cs +++ b/RMuseum/Controllers/AudioNarrationController.cs @@ -167,7 +167,8 @@ namespace RMuseum.Controllers /// /// /// reviewstatus cannot be set to Approved or Rejected using this method, use moderate method instead - /// TODO: for approved narrations provide another API or solution + /// only these set of fields are updatable: AudioTitle, AudioArtist, AudioArtistUrl, AudioSrc, AudioSrcUrl, ReviewStatus (Draft to Pending and vice versa and Approved/Rejected to Pending) + /// only narrator or a moderator can update the narration /// /// @@ -178,6 +179,11 @@ namespace RMuseum.Controllers [ProducesResponseType((int)HttpStatusCode.Forbidden, Type = typeof(string))] public async Task UpdatePoemNarration(int id, [FromBody] PoemNarrationViewModel metadata) { + if (metadata.ReviewStatus == AudioReviewStatus.Approved || metadata.ReviewStatus == AudioReviewStatus.Rejected) + { + return StatusCode((int)HttpStatusCode.Forbidden); + } + Guid loggedOnUserId = new Guid(User.Claims.FirstOrDefault(c => c.Type == "UserId").Value); var narration = await _audioService.Get(id); @@ -185,18 +191,28 @@ namespace RMuseum.Controllers { return BadRequest(narration.ExceptionString); } - - if (!string.IsNullOrEmpty(narration.ExceptionString)) - { - return BadRequest(narration.ExceptionString); - } - + if (narration.Result == null) return NotFound(); - if (metadata.ReviewStatus == AudioReviewStatus.Approved || metadata.ReviewStatus == AudioReviewStatus.Rejected) + if(narration.Result.Owner.Id != loggedOnUserId) { - return StatusCode((int)HttpStatusCode.Forbidden); + Guid sessionId = new Guid(User.Claims.FirstOrDefault(c => c.Type == "SessionId").Value); + RServiceResult + serviceResult = + await _userPermissionChecker.Check + ( + loggedOnUserId, + sessionId, + RMuseumSecurableItem.AudioNarrationEntityShortName, + RMuseumSecurableItem.ModerateOperationShortName + ); + if (!string.IsNullOrEmpty(serviceResult.ExceptionString)) + return BadRequest(serviceResult.ExceptionString); + + if (!serviceResult.Result) + return StatusCode((int)HttpStatusCode.Forbidden); + } var res = await _audioService.UpdatePoemNarration(id, metadata); @@ -221,18 +237,16 @@ namespace RMuseum.Controllers { Guid loggedOnUserId = new Guid(User.Claims.FirstOrDefault(c => c.Type == "UserId").Value); - var narration = await _audioService.Get(id); - if (!string.IsNullOrEmpty(narration.ExceptionString)) - { - return BadRequest(narration.ExceptionString); - } - - if (narration.Result == null) - return NotFound(); var res = await _audioService.ModeratePoemNarration(id, loggedOnUserId, model); if (!string.IsNullOrEmpty(res.ExceptionString)) + { + if(res.ExceptionString == "404") + { + return NotFound(); + } return BadRequest(res.ExceptionString); + } return Ok(res.Result); } diff --git a/RMuseum/RMuseum.xml b/RMuseum/RMuseum.xml index 26bba5fb..d321be38 100644 --- a/RMuseum/RMuseum.xml +++ b/RMuseum/RMuseum.xml @@ -672,7 +672,8 @@ reviewstatus cannot be set to Approved or Rejected using this method, use moderate method instead - TODO: for approved narrations provide another API or solution + only these set of fields are updatable: AudioTitle, AudioArtist, AudioArtistUrl, AudioSrc, AudioSrcUrl, ReviewStatus (Draft to Pending and vice versa and Approved/Rejected to Pending) + only narrator or a moderator can update the narration