PluralKit/PluralKit.API/Controllers/v1/MemberController.cs

106 lines
3.5 KiB
C#
Raw Normal View History

2019-07-09 22:19:18 +00:00
using System.Threading.Tasks;
using Microsoft.AspNetCore.Authorization;
2019-07-09 22:19:18 +00:00
using Microsoft.AspNetCore.Mvc;
using Newtonsoft.Json.Linq;
2019-07-09 22:19:18 +00:00
using PluralKit.Core;
namespace PluralKit.API
2019-07-09 22:19:18 +00:00
{
[ApiController]
[ApiVersion("1.0")]
2019-07-09 22:19:18 +00:00
[Route("m")]
[Route( "v{version:apiVersion}/m" )]
2019-07-09 22:19:18 +00:00
public class MemberController: ControllerBase
{
private IDataStore _data;
2020-06-29 12:15:30 +00:00
private IDatabase _db;
private IAuthorizationService _auth;
2019-07-09 22:19:18 +00:00
2020-06-29 12:15:30 +00:00
public MemberController(IDataStore data, IAuthorizationService auth, IDatabase db)
2019-07-09 22:19:18 +00:00
{
_data = data;
2019-07-09 22:19:18 +00:00
_auth = auth;
2020-06-29 12:15:30 +00:00
_db = db;
2019-07-09 22:19:18 +00:00
}
[HttpGet("{hid}")]
public async Task<ActionResult<JObject>> GetMember(string hid)
2019-07-09 22:19:18 +00:00
{
var member = await _data.GetMemberByHid(hid);
2019-07-09 22:19:18 +00:00
if (member == null) return NotFound("Member not found.");
return Ok(member.ToJson(User.ContextFor(member)));
2019-07-09 22:19:18 +00:00
}
[HttpPost]
[Authorize]
public async Task<ActionResult<JObject>> PostMember([FromBody] JObject properties)
{
var system = User.CurrentSystem();
if (!properties.ContainsKey("name"))
return BadRequest("Member name must be specified.");
// Enforce per-system member limit
2020-01-11 15:49:20 +00:00
var memberCount = await _data.GetSystemMemberCount(system, true);
if (memberCount >= Limits.MaxMemberCount)
return BadRequest($"Member limit reached ({memberCount} / {Limits.MaxMemberCount}).");
var member = await _data.CreateMember(system, properties.Value<string>("name"));
2020-06-29 12:15:30 +00:00
MemberPatch patch;
try
{
2020-06-29 12:15:30 +00:00
patch = JsonModelExt.ToMemberPatch(properties);
}
catch (JsonModelParseError e)
{
return BadRequest(e.Message);
}
2020-06-29 12:15:30 +00:00
var newMember = await _db.Execute(conn => conn.UpdateMember(member.Id, patch));
return Ok(member.ToJson(User.ContextFor(newMember)));
}
2019-07-09 22:19:18 +00:00
[HttpPatch("{hid}")]
[Authorize]
public async Task<ActionResult<JObject>> PatchMember(string hid, [FromBody] JObject changes)
2019-07-09 22:19:18 +00:00
{
var member = await _data.GetMemberByHid(hid);
2019-07-09 22:19:18 +00:00
if (member == null) return NotFound("Member not found.");
var res = await _auth.AuthorizeAsync(User, member, "EditMember");
if (!res.Succeeded) return Unauthorized($"Member '{hid}' is not part of your system.");
2019-07-09 22:19:18 +00:00
2020-06-29 12:15:30 +00:00
MemberPatch patch;
try
{
2020-06-29 12:15:30 +00:00
patch = JsonModelExt.ToMemberPatch(changes);
}
catch (JsonModelParseError e)
{
return BadRequest(e.Message);
}
2020-06-29 12:15:30 +00:00
var newMember = await _db.Execute(conn => conn.UpdateMember(member.Id, patch));
return Ok(member.ToJson(User.ContextFor(newMember)));
2019-07-09 22:19:18 +00:00
}
[HttpDelete("{hid}")]
[Authorize]
public async Task<ActionResult> DeleteMember(string hid)
{
var member = await _data.GetMemberByHid(hid);
if (member == null) return NotFound("Member not found.");
var res = await _auth.AuthorizeAsync(User, member, "EditMember");
if (!res.Succeeded) return Unauthorized($"Member '{hid}' is not part of your system.");
await _data.DeleteMember(member);
return Ok();
}
2019-07-09 22:19:18 +00:00
}
}