From 5a97115a89bd050d6813a436dcf0e74152bc60ef Mon Sep 17 00:00:00 2001 From: Hamid Reza Mohammadi Date: Wed, 10 Feb 2021 18:11:27 +0330 Subject: [PATCH] #74 protecting pinterest suggestion api --- RMuseum/Controllers/ArtifactController.cs | 12 +++--------- .../ViewModels/PinterestSuggestion.cs | 10 ---------- RMuseum/RMuseum.xml | 16 ++++------------ RMuseum/Services/IArtifactService.cs | 3 ++- .../Services/Implementation/ArtifactService.cs | 4 +++- 5 files changed, 12 insertions(+), 33 deletions(-) diff --git a/RMuseum/Controllers/ArtifactController.cs b/RMuseum/Controllers/ArtifactController.cs index d0f85d47..777f6dc3 100644 --- a/RMuseum/Controllers/ArtifactController.cs +++ b/RMuseum/Controllers/ArtifactController.cs @@ -1749,19 +1749,13 @@ namespace RMuseum.Controllers /// [HttpPost] [Route("pinterest")] - [AllowAnonymous] + [Authorize] [ProducesResponseType((int)HttpStatusCode.OK, Type = typeof(PinterestLinkViewModel))] [ProducesResponseType((int)HttpStatusCode.BadRequest, Type = typeof(string))] public async Task SuggestPinterestLink([FromBody]PinterestSuggestion suggestion) { - RServiceResult captchaRes = await _captchaService.Evaluate(suggestion.CaptchaImageId, suggestion.CaptchaValue); - if (!string.IsNullOrEmpty(captchaRes.ExceptionString)) - return BadRequest(captchaRes.ExceptionString); - - if (!captchaRes.Result) - return BadRequest("مقدار تصویر امنیتی درست وارد نشده است."); - - RServiceResult res = await _artifactService.SuggestPinterestLink(suggestion); + Guid loggedOnUserId = new Guid(User.Claims.FirstOrDefault(c => c.Type == "UserId").Value); + RServiceResult res = await _artifactService.SuggestPinterestLink(loggedOnUserId, suggestion); if (!string.IsNullOrEmpty(res.ExceptionString)) return BadRequest(res.ExceptionString); diff --git a/RMuseum/Models/GanjoorIntegration/ViewModels/PinterestSuggestion.cs b/RMuseum/Models/GanjoorIntegration/ViewModels/PinterestSuggestion.cs index 0014f769..f39bfc30 100644 --- a/RMuseum/Models/GanjoorIntegration/ViewModels/PinterestSuggestion.cs +++ b/RMuseum/Models/GanjoorIntegration/ViewModels/PinterestSuggestion.cs @@ -41,15 +41,5 @@ namespace RMuseum.Models.GanjoorIntegration.ViewModels /// pinterest image url /// public string PinterestImageUrl { get; set; } - - /// - /// Captcha Image Id - /// - public Guid CaptchaImageId { get; set; } - - /// - /// Captcha Value - /// - public string CaptchaValue { get; set; } } } diff --git a/RMuseum/RMuseum.xml b/RMuseum/RMuseum.xml index d57b8094..6883e81c 100644 --- a/RMuseum/RMuseum.xml +++ b/RMuseum/RMuseum.xml @@ -3480,16 +3480,6 @@ pinterest image url - - - Captcha Image Id - - - - - Captcha Value - - Ganjoor Category @@ -5813,10 +5803,11 @@ - + suggest pinterest link + @@ -6626,10 +6617,11 @@ - + suggest pinterest link + diff --git a/RMuseum/Services/IArtifactService.cs b/RMuseum/Services/IArtifactService.cs index afa7ba12..93dd3813 100644 --- a/RMuseum/Services/IArtifactService.cs +++ b/RMuseum/Services/IArtifactService.cs @@ -474,9 +474,10 @@ namespace RMuseum.Services /// /// suggest pinterest link /// + /// /// /// - Task> SuggestPinterestLink(PinterestSuggestion suggestion); + Task> SuggestPinterestLink(Guid userId, PinterestSuggestion suggestion); /// /// Review Suggested Pinterest Link diff --git a/RMuseum/Services/Implementation/ArtifactService.cs b/RMuseum/Services/Implementation/ArtifactService.cs index f043dca3..1806485c 100644 --- a/RMuseum/Services/Implementation/ArtifactService.cs +++ b/RMuseum/Services/Implementation/ArtifactService.cs @@ -3077,9 +3077,10 @@ namespace RMuseum.Services.Implementation /// /// suggest pinterest link /// + /// /// /// - public async Task> SuggestPinterestLink(PinterestSuggestion suggestion) + public async Task> SuggestPinterestLink(Guid userId, PinterestSuggestion suggestion) { try { @@ -3108,6 +3109,7 @@ namespace RMuseum.Services.Implementation PinterestImageUrl = suggestion.PinterestImageUrl, ReviewResult = ReviewResult.Awaiting, SuggestionDate = DateTime.Now, + SuggestedById = userId, Synchronized = false }; _context.PinterestLinks.Add(link);