Version 5.0.0 beta 1

This commit is contained in:
Neo committed 2025-12-19 16:27:35 -08:00
1 parent 25ddeb65d6
commit 15c7beabc5
6736 files changed
+627902 -497943

No files matched your search

+44 -28
View File
@@ -12,21 +12,34 @@
namespace IPS\cms\api;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
use IPS\Api\Exception;
use IPS\Api\PaginatedResponse;
use IPS\Api\Response;
use IPS\cms\Categories as CategoriesClass;
use IPS\cms\Databases;
use IPS\Node\Api\NodeController;
use OutOfRangeException;
use RuntimeException;
use function count;
use function defined;
use function intval;
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* @brief Pages Databases API
*/
class _categories extends \IPS\Node\Api\NodeController
class categories extends NodeController
{
/**
* Class
*/
protected $class;
protected string $class = '';
/**
* Get endpoint data
@@ -34,25 +47,25 @@ class _categories extends \IPS\Node\Api\NodeController
* @param array $pathBits The parts to the path called
* @param string $method HTTP method verb
* @return array
* @throws \RuntimeException
* @throws RuntimeException
*/
protected function _getEndpoint( $pathBits, $method = 'GET' )
protected function _getEndpoint( array $pathBits, string $method = 'GET' ): array
{
if ( !\count( $pathBits ) )
if ( !count( $pathBits ) )
{
throw new \RuntimeException;
throw new RuntimeException;
}
$database = array_shift( $pathBits );
if ( !\count( $pathBits ) )
if ( !count( $pathBits ) )
{
return array( 'endpoint' => 'index', 'params' => array( $database ) );
}
$nextBit = array_shift( $pathBits );
if ( \intval( $nextBit ) != 0 )
if ( intval( $nextBit ) != 0 )
{
if ( \count( $pathBits ) )
if ( count( $pathBits ) )
{
return array( 'endpoint' => 'item_' . array_shift( $pathBits ), 'params' => array( $database, $nextBit ) );
}
@@ -62,7 +75,7 @@ class _categories extends \IPS\Node\Api\NodeController
}
}
throw new \RuntimeException;
throw new RuntimeException;
}
/**
@@ -70,29 +83,30 @@ class _categories extends \IPS\Node\Api\NodeController
* Get list of database categories
*
* @param int $database Database ID
* @return \IPS\Api\PaginatedResponse<IPS\cms\Categories>
* @apireturn PaginatedResponse<IPS\cms\Categories>
* @return PaginatedResponse<CategoriesClass>
*@throws 2T306/2 DATABASE_DOES_NOT_USE_CATEGORIES The database does not use categories
* @throws 2T306/1 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T306/2 DATABASE_DOES_NOT_USE_CATEGORIES The database does not use categories
*/
public function GETindex( $database )
public function GETindex( int $database ): PaginatedResponse
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Categories' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T415/1', 404 );
throw new Exception( 'INVALID_DATABASE', '2T415/1', 404 );
}
if ( !$database->use_categories )
{
throw new \IPS\Api\Exception( 'DATABASE_DOES_NOT_USE_CATEGORIES', '2T415/2', 404 );
throw new Exception( 'DATABASE_DOES_NOT_USE_CATEGORIES', '2T415/2', 404 );
}
/* Where clause */
@@ -106,26 +120,28 @@ class _categories extends \IPS\Node\Api\NodeController
* GET /cms/databases/{database_id}/{category_id}
* Get specific database
*
* @param int $database
* @param int $id ID Number
* @return \IPS\cms\Categories
* @apireturn \IPS\cms\Categories
* @throws 2T306/3 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T306/4 INVALID_ID The category ID does not exist or the authorized user does not have permission to view it
* @return Response
*/
public function GETitem( $database, $id )
public function GETitem( int $database, int $id ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Categories' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T415/3', 404 );
throw new Exception( 'INVALID_DATABASE', '2T415/3', 404 );
}
/* Return */
@@ -133,9 +149,9 @@ class _categories extends \IPS\Node\Api\NodeController
{
return $this->_view( $id );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T415/4', 404 );
throw new Exception( 'INVALID_ID', '2T415/4', 404 );
}
}
}
+117 -99
View File
@@ -12,21 +12,37 @@
namespace IPS\cms\api;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
use InvalidArgumentException;
use IPS\Api\Exception;
use IPS\Api\PaginatedResponse;
use IPS\Api\Response;
use IPS\cms\Databases;
use IPS\cms\Records\Comment;
use IPS\Content\Api\CommentController;
use IPS\Member;
use IPS\Request;
use OutOfRangeException;
use RuntimeException;
use function count;
use function defined;
use function intval;
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* @brief Pages Database Comments API
*/
class _comments extends \IPS\Content\Api\CommentController
class comments extends CommentController
{
/**
* Class
*/
protected $class = NULL;
protected string $class = '';
/**
* Get endpoint data
@@ -34,25 +50,25 @@ class _comments extends \IPS\Content\Api\CommentController
* @param array $pathBits The parts to the path called
* @param string $method HTTP method verb
* @return array
* @throws \RuntimeException
* @throws RuntimeException
*/
protected function _getEndpoint( $pathBits, $method = 'GET' )
protected function _getEndpoint( array $pathBits, string $method = 'GET' ): array
{
if ( !\count( $pathBits ) )
if ( !count( $pathBits ) )
{
throw new \RuntimeException;
throw new RuntimeException;
}
$database = array_shift( $pathBits );
if ( !\count( $pathBits ) )
if ( !count( $pathBits ) )
{
return array( 'endpoint' => 'index', 'params' => array( $database ) );
}
$nextBit = array_shift( $pathBits );
if ( \intval( $nextBit ) != 0 )
if ( intval( $nextBit ) != 0 )
{
if ( \count( $pathBits ) )
if ( count( $pathBits ) )
{
return array( 'endpoint' => 'item_' . array_shift( $pathBits ), 'params' => array( $database, $nextBit ) );
}
@@ -62,7 +78,7 @@ class _comments extends \IPS\Content\Api\CommentController
}
}
throw new \RuntimeException;
throw new RuntimeException;
}
/**
@@ -81,27 +97,28 @@ class _comments extends \IPS\Content\Api\CommentController
* @apiparam int page Page number
* @apiparam int perPage Number of results per page - defaults to 25
* @throws 2T311/1 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @return \IPS\Api\PaginatedResponse<IPS\cms\Records\Comment>
* @apireturn PaginatedResponse<IPS\cms\Records\Comment>
* @return PaginatedResponse<Comment>
*/
public function GETindex( $database )
public function GETindex( int $database ): PaginatedResponse
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T311/1', 404 );
throw new Exception( 'INVALID_DATABASE', '2T311/1', 404 );
}
/* Return */
return $this->_list( array( array( 'comment_database_id=?', $database->id ) ), 'categories' );
return $this->_list( array( array( 'comment_database_id=?', $database->id ) ) );
}
/**
@@ -112,27 +129,29 @@ class _comments extends \IPS\Content\Api\CommentController
* @param int $comment Comment ID
* @throws 2T311/1 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T311/3 INVALID_ID The comment ID does not exist or the authorized user does not have permission to view it
* @return \IPS\cms\Records\Comment
* @apireturn \IPS\cms\Records\Comment
* @return Response
*/
public function GETitem( $database, $comment )
public function GETitem( int $database,int $comment ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T311/2', 404 );
throw new Exception( 'INVALID_DATABASE', '2T311/2', 404 );
}
/* Return */
try
{
/* @var Comment $class */
$class = 'IPS\cms\Records\Comment' . $database->id;
if ( $this->member )
{
@@ -143,11 +162,11 @@ class _comments extends \IPS\Content\Api\CommentController
$object = $class::load( $comment );
}
return new \IPS\Api\Response( 200, $object->apiOutput( $this->member ) );
return new Response( 200, $object->apiOutput( $this->member ) );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T311/3', 404 );
throw new Exception( 'INVALID_ID', '2T311/3', 404 );
}
}
@@ -170,44 +189,36 @@ class _comments extends \IPS\Content\Api\CommentController
* @throws 1T311/6 NO_AUTHOR The author ID does not exist
* @throws 1T311/7 NO_CONTENT No content was supplied
* @throws 2T311/D NO_PERMISSION The authorized user does not have permission to comment on that record
* @return \IPS\cms\Records\Comment
* @apireturn \IPS\cms\Records\Comment
* @return Response
*/
public function POSTindex( $database )
public function POSTindex( int $database ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T311/4', 404 );
throw new Exception( 'INVALID_DATABASE', '2T311/4', 404 );
}
/* Get record */
try
{
/* @var \IPS\cms\Records $recordClass */
$recordClass = 'IPS\cms\Records' . $database->id;
/** @var \IPS\cms\Records $record */
$record = $recordClass::load( \IPS\Request::i()->record );
$record = $recordClass::load( Request::i()->record );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T311/5', 403 );
}
if( $record->useForumComments() )
{
$this->class = 'IPS\cms\Records\CommentTopicSync' . $database->id;
}
else
{
$this->class = 'IPS\cms\Records\Comment' . $database->id;
throw new Exception( 'INVALID_ID', '2T311/5', 403 );
}
/* Get author */
@@ -215,38 +226,38 @@ class _comments extends \IPS\Content\Api\CommentController
{
if ( !$record->canComment( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T311/D', 403 );
throw new Exception( 'NO_PERMISSION', '2T311/D', 403 );
}
$author = $this->member;
}
else
{
if ( \IPS\Request::i()->author )
if ( Request::i()->author )
{
$author = \IPS\Member::load( \IPS\Request::i()->author );
$author = Member::load( Request::i()->author );
if ( !$author->member_id )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T311/6', 404 );
throw new Exception( 'NO_AUTHOR', '1T311/6', 404 );
}
}
else
{
if ( (int) \IPS\Request::i()->author === 0 )
if ( Request::i()->author === 0 )
{
$author = new \IPS\Member;
$author->name = \IPS\Request::i()->author_name;
$author = new Member;
$author->name = Request::i()->author_name;
}
else
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T311/6', 400 );
throw new Exception( 'NO_AUTHOR', '1T311/6', 400 );
}
}
}
/* Check we have a post */
if ( !\IPS\Request::i()->content )
if ( !Request::i()->content )
{
throw new \IPS\Api\Exception( 'NO_CONTENT', '1T311/7', 403 );
throw new Exception( 'NO_CONTENT', '1T311/7', 403 );
}
/* Do it */
@@ -269,38 +280,40 @@ class _comments extends \IPS\Content\Api\CommentController
* @throws 2T311/8 INVALID_ID The comment ID does not exist or the authorized user does not have permission to view it
* @throws 1T311/9 NO_AUTHOR The author ID does not exist
* @throws 2T311/E NO_PERMISSION The authorized user does not have permission to edit the comment
* @return \IPS\cms\Records\Comment
* @apireturn \IPS\cms\Records\Comment
* @return Response
*/
public function POSTitem( $database, $comment )
public function POSTitem( int $database, int $comment ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T311/7', 404 );
throw new Exception( 'INVALID_DATABASE', '2T311/7', 404 );
}
/* Do it */
try
{
/* Load */
/* @var Comment $className */
$className = $this->class;
$comment = $className::load( $comment );
if ( $this->member and !$comment->canView( $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
if ( $this->member and !$comment->canEdit( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T311/E', 403 );
throw new Exception( 'NO_PERMISSION', '2T311/E', 403 );
}
/* Do it */
@@ -308,14 +321,14 @@ class _comments extends \IPS\Content\Api\CommentController
{
return $this->_edit( $comment );
}
catch ( \InvalidArgumentException $e )
catch ( InvalidArgumentException $e )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T311/9', 400 );
throw new Exception( 'NO_AUTHOR', '1T311/9', 400 );
}
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T311/8', 404 );
throw new Exception( 'INVALID_ID', '2T311/8', 404 );
}
}
@@ -328,41 +341,43 @@ class _comments extends \IPS\Content\Api\CommentController
* @throws 2T311/A INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T311/B INVALID_ID The comment ID does not exist
* @throws 2T311/F NO_PERMISSION The authorized user does not have permission to delete the comment
* @return void
* @apireturn void
* @return Response
*/
public function DELETEitem( $database, $comment )
public function DELETEitem( int $database, int $comment ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T311/A', 404 );
throw new Exception( 'INVALID_DATABASE', '2T311/A', 404 );
}
/* Do it */
try
{
{
/* @var Comment $class */
$class = $this->class;
$object = $class::load( $comment );
if ( $this->member and !$object->canDelete( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T311/F', 403 );
throw new Exception( 'NO_PERMISSION', '2T311/F', 403 );
}
$object->delete();
return new \IPS\Api\Response( 200, NULL );
return new Response( 200, NULL );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T311/B', 404 );
throw new Exception( 'INVALID_ID', '2T311/B', 404 );
}
}
@@ -374,29 +389,30 @@ class _comments extends \IPS\Content\Api\CommentController
* @param int $comment Comment ID
* @apiparam int id ID of the reaction to add
* @apiparam int author ID of the member reacting
* @return \IPS\cms\Records\Comment
* @apireturn \IPS\cms\Records\Comment
* @throws 1S425/2 NO_REACTION The reaction ID does not exist
* @throws 1S425/3 NO_AUTHOR The author ID does not exist
* @throws 1S425/4 REACT_ERROR Error adding the reaction
* @throws 1S425/5 INVALID_ID Object ID does not exist
* @throws 2T311/C INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @note If the author has already reacted to this content, any existing reaction will be removed first
* @return Response
*/
public function POSTitem_react( $database, $comment )
public function POSTitem_react( int $database, int $comment ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T311/C', 404 );
throw new Exception( 'INVALID_DATABASE', '2T311/C', 404 );
}
return $this->_reactAdd( $comment );
@@ -409,28 +425,29 @@ class _comments extends \IPS\Content\Api\CommentController
* @param int $database Database ID
* @param int $comment Comment ID
* @apiparam int author ID of the member who reacted
* @return \IPS\cms\Records\Comment
* @apireturn \IPS\cms\Records\Comment
* @throws 1S425/6 NO_AUTHOR The author ID does not exist
* @throws 1S425/7 REACT_ERROR Error adding the reaction
* @throws 1S425/8 INVALID_ID Object ID does not exist
* @throws 2T311/D INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @note If the author has already reacted to this content, any existing reaction will be removed first
* @return Response
*/
public function DELETEitem_react( $database, $comment )
public function DELETEitem_react( int $database, int $comment ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T311/D', 404 );
throw new Exception( 'INVALID_DATABASE', '2T311/D', 404 );
}
return $this->_reactRemove( $comment );
@@ -447,23 +464,24 @@ class _comments extends \IPS\Content\Api\CommentController
* @apiparam string message Optional message
* @throws 1S425/B NO_AUTHOR The author ID does not exist
* @throws 1S425/C REPORTED_ALREADY The member has reported this item in the past 24 hours
* @return \IPS\cms\Records\Comment
* @apireturn \IPS\cms\Records\Comment
* @return Response
*/
public function POSTitem_report( $database, $comment )
public function POSTitem_report( int $database, int $comment ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T311/D', 404 );
throw new Exception( 'INVALID_DATABASE', '2T311/D', 404 );
}
return $this->_report( $comment );
+17 -8
View File
@@ -12,30 +12,38 @@
namespace IPS\cms\api;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
use IPS\Api\PaginatedResponse;
use IPS\Api\Response;
use IPS\cms\Databases as DatabasesClass;
use IPS\Node\Api\NodeController;
use function defined;
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* @brief Pages Databases API
*/
class _databases extends \IPS\Node\Api\NodeController
class databases extends NodeController
{
/**
* Class
*/
protected $class = 'IPS\cms\Databases';
protected string $class = 'IPS\cms\Databases';
/**
* GET /cms/databases
* Get list of databases
*
* @apiclientonly
* @return \IPS\Api\PaginatedResponse<IPS\cms\Databases>
* @apireturn PaginatedResponse<IPS\cms\Databases>
* @return PaginatedResponse<DatabasesClass>
*/
public function GETindex()
public function GETindex() : PaginatedResponse
{
return $this->_list();
}
@@ -46,9 +54,10 @@ class _databases extends \IPS\Node\Api\NodeController
*
* @apiclientonly
* @param int $id ID Number
* @return \IPS\cms\Databases
* @apireturn \IPS\cms\Databases
* @return Response
*/
public function GETitem( $id )
public function GETitem( int $id ): Response
{
return $this->_view( $id );
}
+224 -169
View File
@@ -1,4 +1,5 @@
<?php
/**
* @brief Database Records API
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
@@ -12,21 +13,56 @@
namespace IPS\cms\api;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
use DomainException;
use InvalidArgumentException;
use IPS\Api\Exception;
use IPS\Api\PaginatedResponse;
use IPS\Api\Response;
use IPS\Application;
use IPS\cms\Categories;
use IPS\cms\Databases;
use IPS\cms\Fields;
use IPS\cms\Records as RecordsClass;
use IPS\cms\Records\Comment;
use IPS\cms\Records\Review;
use IPS\cms\Records\Revisions;
use IPS\Content\Api\ItemController;
use IPS\Content\Item;
use IPS\Content\Reaction;
use IPS\DateTime;
use IPS\Db;
use IPS\File;
use IPS\Http\Url\Friendly;
use IPS\Image;
use IPS\Member;
use IPS\Request;
use IPS\Text\Parser;
use OutOfRangeException;
use RuntimeException;
use Throwable;
use function count;
use function defined;
use function get_class;
use function in_array;
use function intval;
use function is_array;
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* @brief Database Records API
*/
class _records extends \IPS\Content\Api\ItemController
class records extends ItemController
{
/**
* Class
*/
protected $class = NULL;
protected string $class = '';
/**
* Get endpoint data
@@ -34,25 +70,25 @@ class _records extends \IPS\Content\Api\ItemController
* @param array $pathBits The parts to the path called
* @param string $method HTTP method verb
* @return array
* @throws \RuntimeException
* @throws RuntimeException
*/
protected function _getEndpoint( $pathBits, $method = 'GET' )
protected function _getEndpoint( array $pathBits, string $method = 'GET' ): array
{
if ( !\count( $pathBits ) )
if ( !count( $pathBits ) )
{
throw new \RuntimeException;
throw new RuntimeException;
}
$database = array_shift( $pathBits );
if ( !\count( $pathBits ) )
if ( !count( $pathBits ) )
{
return array( 'endpoint' => 'index', 'params' => array( $database ) );
}
$nextBit = array_shift( $pathBits );
if ( \intval( $nextBit ) != 0 )
if ( intval( $nextBit ) != 0 )
{
if ( \count( $pathBits ) )
if ( count( $pathBits ) )
{
return array( 'endpoint' => 'item_' . array_shift( $pathBits ), 'params' => array( $database, $nextBit ) );
}
@@ -62,7 +98,7 @@ class _records extends \IPS\Content\Api\ItemController
}
}
throw new \RuntimeException;
throw new RuntimeException;
}
/**
@@ -83,30 +119,31 @@ class _records extends \IPS\Content\Api\ItemController
* @apiparam int page Page number
* @apiparam int perPage Number of results per page - defaults to 25
* @throws 2T306/1 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @return \IPS\Api\PaginatedResponse<IPS\cms\Records>
* @apireturn PaginatedResponse<IPS\cms\Records>
* @return PaginatedResponse<RecordsClass>
*/
public function GETindex( $database )
public function GETindex( int $database ): PaginatedResponse
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T306/1', 404 );
throw new Exception( 'INVALID_DATABASE', '2T306/1', 404 );
}
/* Where clause */
$where = array();
/* Return */
return $this->_list( $where, 'categories' );
return $this->_list( $where );
}
/**
@@ -117,41 +154,43 @@ class _records extends \IPS\Content\Api\ItemController
* @param int $record Record ID Number
* @throws 2T306/2 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T306/3 INVALID_ID The record ID does not exist or the authorized user does not have permission to view it
* @return \IPS\cms\Records
* @apireturn \IPS\cms\Records
* @return Response
*/
public function GETitem( $database, $record )
public function GETitem( int $database, int $record ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T306/2', 404 );
throw new Exception( 'INVALID_DATABASE', '2T306/2', 404 );
}
/* Return */
try
{
/* @var RecordsClass $className */
$className = $this->class;
$record = $className::load( $record );
if ( $this->member and !$record->can( 'read', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
return new \IPS\Api\Response( 200, $record->apiOutput( $this->member ) );
return new Response( 200, $record->apiOutput( $this->member ) );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T306/3', 404 );
throw new Exception( 'INVALID_ID', '2T306/3', 404 );
}
}
@@ -185,38 +224,40 @@ class _records extends \IPS\Content\Api\ItemController
* @throws 1T306/H UPLOAD_FIELD_IMAGE_NOT_SUPPORTED Field of type Upload was supplied with an image was of an unsupported extension
* @throws 1T306/I UPLOAD_FIELD_IMAGES_ONLY Field of type Upload set to be image only was supplied with a non-image attachment
* @throws 1T306/J UPLOAD_FIELD_EXTENSION_NOT_ALLOWED Field of type Upload was supplied with one or more attachments of a non-supported file extension
* @return \IPS\cms\Records
* @apireturn \IPS\cms\Records
* @return Response
*/
public function POSTindex( $database )
public function POSTindex( int $database ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T306/4', 404 );
throw new Exception( 'INVALID_DATABASE', '2T306/4', 404 );
}
/* Get category */
try
{
/* @var Categories $categoryClass */
$categoryClass = 'IPS\cms\Categories' . $database->id;
if ( $database->use_categories )
{
$category = $categoryClass::load( \IPS\Request::i()->category );
$category = $categoryClass::load( Request::i()->category );
}
else
{
$category = $categoryClass::load( $database->default_category );
}
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'NO_CATEGORY', '1T306/5', 400 );
throw new Exception( 'NO_CATEGORY', '1T306/5', 400 );
}
/* Get author */
@@ -224,30 +265,30 @@ class _records extends \IPS\Content\Api\ItemController
{
if ( !$category->can( 'add', $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T306/G', 403 );
throw new Exception( 'NO_PERMISSION', '2T306/G', 403 );
}
$author = $this->member;
}
else
{
if ( \IPS\Request::i()->author )
if ( Request::i()->author )
{
$author = \IPS\Member::load( \IPS\Request::i()->author );
$author = Member::load( Request::i()->author );
if ( !$author->member_id )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T306/6', 400 );
throw new Exception( 'NO_AUTHOR', '1T306/6', 400 );
}
}
else
{
if ( (int) \IPS\Request::i()->author === 0 )
if ( Request::i()->author === 0 )
{
$author = new \IPS\Member;
$author->name = \IPS\Request::i()->author_name;
$author = new Member;
$author->name = Request::i()->author_name;
}
else
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T306/6', 400 );
throw new Exception( 'NO_AUTHOR', '1T306/6', 400 );
}
}
}
@@ -256,14 +297,15 @@ class _records extends \IPS\Content\Api\ItemController
{
$record = $this->_create( $category, $author );
}
catch( \DomainException $e )
catch( DomainException $e )
{
throw new \IPS\Api\Exception( $e->getMessage(), '1T306/D', 400 );
throw new Exception( $e->getMessage(), '1T306/D', 400 );
}
/* Sync Topic */
/* @var RecordsClass $class */
$class = $this->class;
if ( !$class::$skipTopicCreation and \IPS\Application::appIsEnabled('forums') and $record->_forum_record and $record->_forum_forum and ! $record->hidden() and ! $record->record_future_date )
if ( !$class::$skipTopicCreation and Application::appIsEnabled('forums') and $record->_forum_record and $record->_forum_forum and ! $record->hidden() and ! $record->record_future_date )
{
try
{
@@ -278,7 +320,7 @@ class _records extends \IPS\Content\Api\ItemController
$record->container()->save();
/* Do it */
return new \IPS\Api\Response( 201, $record->apiOutput( $this->member ) );
return new Response( 201, $record->apiOutput( $this->member ) );
}
/**
@@ -311,77 +353,80 @@ class _records extends \IPS\Content\Api\ItemController
* @throws 1T306/H UPLOAD_FIELD_IMAGE_NOT_SUPPORTED Field of type Upload was supplied with an image was of an unsupported extension
* @throws 1T306/I UPLOAD_FIELD_IMAGES_ONLY Field of type Upload set to be image only was supplied with a non-image attachment
* @throws 1T306/J UPLOAD_FIELD_EXTENSION_NOT_ALLOWED Field of type Upload was supplied with one or more attachments of a non-supported file extension
* @return \IPS\cms\Records
* @apireturn \IPS\cms\Records
* @return Response
*/
public function POSTitem( $database, $record )
public function POSTitem( int $database, int $record ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T306/9', 404 );
throw new Exception( 'INVALID_DATABASE', '2T306/9', 404 );
}
/* Load record */
try
{
/* @var RecordsClass $className */
$className = $this->class;
$record = $className::load( $record );
if ( $this->member and !$record->can( 'read', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T306/6', 404 );
throw new Exception( 'INVALID_ID', '2T306/6', 404 );
}
if ( $this->member and !$record->canEdit( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T306/H', 403 );
throw new Exception( 'NO_PERMISSION', '2T306/H', 403 );
}
/* New category */
if ( $database->use_categories and isset( \IPS\Request::i()->category ) and \IPS\Request::i()->category != $record->category_id and ( !$this->member or $record->canMove( $this->member ) ) )
if ( $database->use_categories and isset( Request::i()->category ) and Request::i()->category != $record->category_id and ( !$this->member or $record->canMove( $this->member ) ) )
{
try
{
/* @var Categories $categoryClass */
$categoryClass = 'IPS\cms\Categories' . $database->id;
$newCategory = $categoryClass::load( \IPS\Request::i()->category );
$newCategory = $categoryClass::load( Request::i()->category );
if ( $this->member and !$newCategory->can( 'add', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$record->move( $newCategory );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'NO_CATEGORY', '1T306/7', 400 );
throw new Exception( 'NO_CATEGORY', '1T306/7', 400 );
}
}
/* New author */
if ( !$this->member and isset( \IPS\Request::i()->author ) )
if ( !$this->member and isset( Request::i()->author ) )
{
try
{
$member = \IPS\Member::load( \IPS\Request::i()->author );
$member = Member::load( Request::i()->author );
if ( !$member->member_id )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$record->changeAuthor( $member );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T306/8', 400 );
throw new Exception( 'NO_AUTHOR', '1T306/8', 400 );
}
}
@@ -392,8 +437,9 @@ class _records extends \IPS\Content\Api\ItemController
$record->save();
/* Sync Topic */
/* @var RecordsClass $class */
$class = $this->class;
if ( !$class::$skipTopicCreation and \IPS\Application::appIsEnabled('forums') and $record->_forum_record and $record->_forum_forum and ! $record->hidden() and ! $record->record_future_date )
if ( !$class::$skipTopicCreation and Application::appIsEnabled('forums') and $record->_forum_record and $record->_forum_forum and ! $record->hidden() and ! $record->record_future_date )
{
try
{
@@ -402,33 +448,34 @@ class _records extends \IPS\Content\Api\ItemController
catch( \Exception $ex ) { }
}
return new \IPS\Api\Response( 200, $record->apiOutput( $this->member ) );
return new Response( 200, $record->apiOutput( $this->member ) );
}
/**
* Create or update record
*
* @param \IPS\Content\Item $item The item
* @param Item $item The item
* @param string $type add or edit
* @return \IPS\Content\Item
* @return Item
*/
protected function _createOrUpdate( \IPS\Content\Item $item, $type='add' )
protected function _createOrUpdate( Item $item, string $type='add' ): Item
{
$thumbImages = [];
$linkedFields = [];
/* Set field values */
if ( isset( \IPS\Request::i()->fields ) )
if ( isset( Request::i()->fields ) )
{
$fieldsClass = str_replace( 'Records', 'Fields', \get_class( $item ) );
/* @var Fields $fieldsClass */
$fieldsClass = str_replace( 'Records', 'Fields', get_class( $item ) );
/* Store a revision before we change any values */
if ( $type == 'edit' AND $item::database()->revisions )
{
$revision = new \IPS\cms\Records\Revisions;
$revision = new Revisions;
$revision->database_id = $item::$customDatabaseId;
$revision->record_id = $item->_id;
$revision->data = $item->fieldValues( TRUE );
if ( $this->member )
{
$memberId = $this->member->member_id;
@@ -437,51 +484,51 @@ class _records extends \IPS\Content\Api\ItemController
{
$memberId = $item->author()->member_id;
}
$revision->member_id = $memberId;
$revision->save();
}
foreach ( $fieldsClass::data() as $key => $field )
{
if ( isset( \IPS\Request::i()->fields[ $field->id ] ) )
if ( isset( Request::i()->fields[ $field->id ] ) )
{
if ( !$this->member or $field->can( $type, $this->member ) )
{
$key = "field_{$field->_id}";
$value = \IPS\Request::i()->fields[ $field->id ];
$value = Request::i()->fields[ $field->id ];
if ( $field->type === 'Editor' and $this->member )
{
$value = \IPS\Text\Parser::parseStatic( $value, TRUE, NULL, $this->member, 'cms_Records' );
$value = Parser::parseStatic( $value, NULL, $this->member, 'cms_Records' );
}
elseif ( $field->type === 'Upload' )
{
$multiple = $field->is_multiple;
$imageOnly = ( isset( $field->extra[ 'type' ] ) AND $field->extra[ 'type' ] === 'image' );
$extensions = \is_array( $field->allowed_extensions ) ? $field->allowed_extensions : array();
$extensions = is_array( $field->allowed_extensions ) ? $field->allowed_extensions : array();
/* Did they meet the api parameter type requirement (the field must be an object) */
if ( !\is_array( \IPS\Request::i()->fields[ $field->id ] ) )
if ( !is_array( Request::i()->fields[ $field->id ] ) )
{
throw new \IPS\Api\Exception( 'UPLOAD_FIELD_NOT_OBJECT', '1S306/E', 400 );
throw new Exception( 'UPLOAD_FIELD_NOT_OBJECT', '1S306/E', 400 );
}
/* Are we actually uploading files? */
if ( empty( \IPS\Request::i()->fields[ $field->id ] ) )
if ( empty( Request::i()->fields[ $field->id ] ) )
{
throw new \IPS\Api\Exception( 'UPLOAD_FIELD_NO_FILES', '1T306/F', 400 );
throw new Exception( 'UPLOAD_FIELD_NO_FILES', '1T306/F', 400 );
}
/* Can we upload more than one file? */
if ( !$multiple AND ( \count( \IPS\Request::i()->fields[ $field->id ] ) > 1 ) )
if ( !$multiple AND ( count( Request::i()->fields[ $field->id ] ) > 1 ) )
{
throw new \IPS\Api\Exception( 'UPLOAD_FIELD_MULTIPLE_NOT_ALLOWED', '1T306/G', 400 );
throw new Exception( 'UPLOAD_FIELD_MULTIPLE_NOT_ALLOWED', '1T306/G', 400 );
}
/* Does each file meet the criteria? */
$files = array();
foreach ( array_keys( \IPS\Request::i()->fields[ $field->id ] ) as $name )
foreach ( array_keys( Request::i()->fields[ $field->id ] ) as $name )
{
$files[] = $name;
$components = explode( '.', $name );
@@ -491,44 +538,44 @@ class _records extends \IPS\Content\Api\ItemController
if ( $imageOnly )
{
/* Is the image type supported? */
if ( !\in_array( $extension, \IPS\Image::supportedExtensions() ) )
if ( !in_array( $extension, Image::supportedExtensions() ) )
{
throw new \IPS\Api\Exception( 'UPLOAD_FIELD_IMAGE_NOT_SUPPORTED', '1T306/H', 400 );
throw new Exception( 'UPLOAD_FIELD_IMAGE_NOT_SUPPORTED', '1T306/H', 400 );
}
/* Is there a max image dimensions specified? */
$maxSize = ( isset( $field->extra[ 'maxsize' ] ) AND \is_array( $field->extra[ 'maxsize' ] ) ) ? $field->extra[ 'maxsize' ] : array( 0, 0 );
$maxSize = ( isset( $field->extra[ 'maxsize' ] ) AND is_array( $field->extra[ 'maxsize' ] ) ) ? $field->extra[ 'maxsize' ] : array( 0, 0 );
try
{
/* Is it valid image data? */
$image = \IPS\Image::create( $_POST[ 'fields' ][ $field->id ][ $name ] );
$image = Image::create( $_POST[ 'fields' ][ $field->id ][ $name ] );
/* Resize if too large */
$image->resizeToMax( (int) $maxSize[0] ?: NULL, (int) $maxSize[1] ?: NULL );
$_POST[ 'fields' ][ $field->id ][ $name ] = (string) $image;
}
catch ( \InvalidArgumentException $e )
catch ( InvalidArgumentException $e )
{
throw new \IPS\Api\Exception( 'UPLOAD_FIELD_IMAGES_ONLY', '1T306/I', 400 );
throw new Exception( 'UPLOAD_FIELD_IMAGES_ONLY', '1T306/I', 400 );
}
}
/* Can we add a file of this type? */
if ( ( \count( $extensions ) > 0 ) AND !\in_array( '.' . $extension, $extensions ) )
if ( ( count( $extensions ) > 0 ) AND !in_array( '.' . $extension, $extensions ) )
{
throw new \IPS\Api\Exception( 'UPLOAD_FIELD_EXTENSION_NOT_ALLOWED', '1T306/J', 400 );
throw new Exception( 'UPLOAD_FIELD_EXTENSION_NOT_ALLOWED', '1T306/J', 400 );
}
}
$urls = array();
foreach ( $files as $name )
{
$file = \IPS\File::create( 'cms_Records', $name, $_POST[ 'fields' ][ $field->id ][ $name ] );
$file = File::create( 'cms_Records', $name, $_POST[ 'fields' ][ $field->id ][ $name ] );
$urls[] = (string) $file;
/* Do we have to create a thumbnail? */
if ( $imageOnly AND isset( $field->extra['thumbsize'] ) AND \is_array( $field->extra['thumbsize'] ) AND ( (int) $field->extra['thumbsize'][0] OR (int) $field->extra['thumbsize'][1] ) )
if ( $imageOnly AND isset( $field->extra['thumbsize'] ) AND is_array( $field->extra['thumbsize'] ) AND ( (int) $field->extra['thumbsize'][0] OR (int) $field->extra['thumbsize'][1] ) )
{
$thumbImages[$name] = array( $file, $field );
}
@@ -546,7 +593,7 @@ class _records extends \IPS\Content\Api\ItemController
}
}
$date = ( !$this->member and \IPS\Request::i()->date ) ? new \IPS\DateTime( \IPS\Request::i()->date ) : \IPS\DateTime::create();
$date = ( !$this->member and Request::i()->date ) ? new DateTime( Request::i()->date ) : DateTime::create();
if( !$item->record_saved )
{
@@ -558,11 +605,11 @@ class _records extends \IPS\Content\Api\ItemController
$item->record_updated = $item->record_saved;
}
if ( isset( \IPS\Request::i()->image ) AND isset( \IPS\Request::i()->image['name'] ) AND isset( \IPS\Request::i()->image['contents'] ) )
if ( isset( Request::i()->image ) AND isset( Request::i()->image['name'] ) AND isset( Request::i()->image['contents'] ) )
{
try
{
$image = \IPS\File::create( 'cms_Records', \IPS\Request::i()->image['name'], base64_decode( \IPS\Request::i()->image['contents'] ) );
$image = File::create( 'cms_Records', Request::i()->image['name'], base64_decode( Request::i()->image['contents'] ) );
$image->save();
$fixedFieldSettings = $item::database()->fixed_field_settings;
@@ -580,32 +627,32 @@ class _records extends \IPS\Content\Api\ItemController
{
if ( $item->record_image )
{
\IPS\File::get( 'cms_Records', $item->record_image )->delete();
File::get( 'cms_Records', $item->record_image )->delete();
}
if ( $item->record_image_thumb )
{
\IPS\File::get( 'cms_Records', $item->record_image_thumb )->delete();
File::get( 'cms_Records', $item->record_image_thumb )->delete();
}
}
catch( \Throwable ) { }
catch( Throwable ) { }
$item->record_image = (string) $image;
$item->record_image_thumb = (string) $thumb;
}
catch( \Throwable $e ) { }
catch( Throwable $e ) { }
}
if( $type == 'add' AND ( !$item->_title OR !$item->_content ) )
{
throw new \DomainException( 'TITLE_CONTENT_REQUIRED' );
throw new DomainException( 'TITLE_CONTENT_REQUIRED' );
}
/* Set FURL */
if ( isset( \IPS\Request::i()->fields['fields'][ $item->database()->field_title ] ) )
if ( isset( Request::i()->fields['fields'][ $item->database()->field_title ] ) )
{
$item->record_dynamic_furl = \IPS\Http\Url\Friendly::seoTitle( \IPS\Request::i()->fields['fields'][ $item->database()->field_title ] );
$item->record_dynamic_furl = Friendly::seoTitle( Request::i()->fields['fields'][ $item->database()->field_title ] );
}
$item = parent::_createOrUpdate( $item, $type );
@@ -619,7 +666,7 @@ class _records extends \IPS\Content\Api\ItemController
$thumbWidth = ( isset( $field->extra['thumbsize'][0] ) ) ? (int) $field->extra[ 'thumbsize' ][0] : NULL;
$thumbHeight = ( isset( $field->extra['thumbsize'][1] ) ) ? (int) $field->extra[ 'thumbsize' ][1] : NULL;
$thumbnail = $file->thumbnail( 'cms_Records', $thumbWidth ?: NULL, $thumbHeight ?: NULL );
\IPS\Db::i()->insert( 'cms_database_fields_thumbnails', array(
Db::i()->insert( 'cms_database_fields_thumbnails', array(
'thumb_original_location' => (string) $file,
'thumb_location' => (string) $thumbnail,
'thumb_field_id' => $field->id,
@@ -650,24 +697,25 @@ class _records extends \IPS\Content\Api\ItemController
* @apiparam int perPage Number of results per page - defaults to 25
* @throws 2T306/C INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T306/D INVALID_ID The entry ID does not exist or the authorized user does not have permission to view it
* @return \IPS\Api\PaginatedResponse<IPS\cms\Records\Comment>
* @apireturn PaginatedResponse<IPS\cms\Records\Comment>
* @return PaginatedResponse<Comment>
*/
public function GETitem_comments( $database, $record )
public function GETitem_comments( int $database, int $record ): PaginatedResponse
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T306/C', 404 );
throw new Exception( 'INVALID_DATABASE', '2T306/C', 404 );
}
/* Return */
@@ -675,9 +723,9 @@ class _records extends \IPS\Content\Api\ItemController
{
return $this->_comments( $record, 'IPS\cms\Records\Comment' . $database->id );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T306/D', 404 );
throw new Exception( 'INVALID_ID', '2T306/D', 404 );
}
}
@@ -693,24 +741,25 @@ class _records extends \IPS\Content\Api\ItemController
* @apiparam int perPage Number of results per page - defaults to 25
* @throws 2T306/E INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T306/F INVALID_ID The entry ID does not exist or the authorized user does not have permission to view it
* @return \IPS\Api\PaginatedResponse<IPS\cms\Records\Review>
* @apireturn PaginatedResponse<IPS\cms\Records\Review>
* @return PaginatedResponse<Review>
*/
public function GETitem_reviews( $database, $record )
public function GETitem_reviews( int $database, int $record ): PaginatedResponse
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T306/E', 404 );
throw new Exception( 'INVALID_DATABASE', '2T306/E', 404 );
}
/* Return */
@@ -718,9 +767,9 @@ class _records extends \IPS\Content\Api\ItemController
{
return $this->_comments( $record, 'IPS\cms\Records\Review' . $database->id );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T306/F', 404 );
throw new Exception( 'INVALID_ID', '2T306/F', 404 );
}
}
@@ -733,44 +782,46 @@ class _records extends \IPS\Content\Api\ItemController
* @throws 2T306/A INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T306/B INVALID_ID The entry ID does not exist
* @throws 2T306/I NO_PERMISSION The authorized user does not have permission to delete the record.
* @return void
* @apireturn void
* @return Response
*/
public function DELETEitem( $database, $record )
public function DELETEitem(int $database, int $record ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T306/A', 404 );
throw new Exception( 'INVALID_DATABASE', '2T306/A', 404 );
}
/* Load record */
try
{
/* @var RecordsClass $className */
$className = $this->class;
$record = $className::load( $record );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T306/B', 404 );
throw new Exception( 'INVALID_ID', '2T306/B', 404 );
}
if ( $this->member and !$record->canDelete( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T306/I', 404 );
throw new Exception( 'NO_PERMISSION', '2T306/I', 404 );
}
/* Delete and return */
$record->delete();
return new \IPS\Api\Response( 200, NULL );
return new Response( 200, NULL );
}
/**
@@ -781,56 +832,58 @@ class _records extends \IPS\Content\Api\ItemController
* @param int $record Record ID Number
* @apiparam int id ID of the reaction to add
* @apiparam int author ID of the member reacting
* @return \IPS\cms\Records
* @apireturn \IPS\cms\Records
* @throws 1T306/K INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 1T306/L NO_REACTION The reaction ID does not exist
* @throws 1T306/M REACT_ERROR Error adding the reaction
* @throws 1T306/N INVALID_ID Object ID does not exist
* @note If the author has already reacted to this content, any existing reaction will be removed first
* @return Response
*/
public function DELETEitem_react( $database, $record ): \IPS\Api\Response
public function DELETEitem_react( int $database, int $record ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '1T306/K', 404 );
throw new Exception( 'INVALID_DATABASE', '1T306/K', 404 );
}
try
{
$member = \IPS\Member::load( \IPS\Request::i()->author );
$member = Member::load( Request::i()->author );
}
catch( \OutOfRangeException $e )
catch( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T306/L', 404 );
throw new Exception( 'NO_AUTHOR', '1T306/L', 404 );
}
try
{
/* @var RecordsClass $class */
$class = $this->class;
$object = $class::load( $id );
$object = $class::load( $record );
$object->removeReaction( $member );
return new \IPS\Api\Response( 200, $object->apiOutput( $this->member ) );
return new Response( 200, $object->apiOutput( $this->member ) );
}
catch ( \DomainException $e )
catch ( DomainException $e )
{
throw new \IPS\Api\Exception( $e->getMessage(), '1T306/M', 403 );
throw new Exception( $e->getMessage(), '1T306/M', 403 );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '1T306/N', 404 );
throw new Exception( 'INVALID_ID', '1T306/N', 404 );
}
}
@@ -842,65 +895,67 @@ class _records extends \IPS\Content\Api\ItemController
* @param int $record Record ID Number
* @apiparam int id ID of the reaction to add
* @apiparam int author ID of the member reacting
* @return \IPS\cms\Records
* @apireturn \IPS\cms\Records
* @throws 1T306/O INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 1T306/P NO_REACTION The reaction ID does not exist
* @throws 1T306/Q NO_AUTHOR The author ID does not exist
* @throws 1T306/R REACT_ERROR Error adding the reaction
* @throws 1T306/S INVALID_ID Object ID does not exist
* @note If the author has already reacted to this content, any existing reaction will be removed first
* @return Response
*/
public function POSTitem_react( $database, $record ): \IPS\Api\Response
public function POSTitem_react( int $database, int $record ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '1T306/O', 404 );
throw new Exception( 'INVALID_DATABASE', '1T306/O', 404 );
}
try
{
$reaction = \IPS\Content\Reaction::load( \IPS\Request::i()->id );
$reaction = Reaction::load( Request::i()->id );
}
catch( \OutOfRangeException $e )
catch( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'NO_REACTION', '1T306/P', 404 );
throw new Exception( 'NO_REACTION', '1T306/P', 404 );
}
try
{
$member = \IPS\Member::load( \IPS\Request::i()->author );
$member = Member::load( Request::i()->author );
}
catch( \OutOfRangeException $e )
catch( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T306/Q', 404 );
throw new Exception( 'NO_AUTHOR', '1T306/Q', 404 );
}
try
{
/* @var RecordsClass $class */
$class = $this->class;
$object = $class::load( $record );
$object->react( $reaction, $member );
return new \IPS\Api\Response( 200, $object->apiOutput( $this->member ) );
return new Response( 200, $object->apiOutput( $this->member ) );
}
catch ( \DomainException $e )
catch ( DomainException $e )
{
throw new \IPS\Api\Exception( 'REACT_ERROR_' . $e->getMessage(), '1T306/R', 403 );
throw new Exception( 'REACT_ERROR_' . $e->getMessage(), '1T306/R', 403 );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '1T306/S', 404 );
throw new Exception( 'INVALID_ID', '1T306/S', 404 );
}
}
}
+127 -96
View File
@@ -12,21 +12,40 @@
namespace IPS\cms\api;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
use InvalidArgumentException;
use IPS\Api\Exception;
use IPS\Api\PaginatedResponse;
use IPS\Api\Response;
use IPS\cms\Databases;
use IPS\cms\Records;
use IPS\cms\Records\Review;
use IPS\Content\Api\CommentController;
use IPS\Member;
use IPS\Request;
use IPS\Settings;
use OutOfRangeException;
use RuntimeException;
use function count;
use function defined;
use function in_array;
use function intval;
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* @brief Pages Database Reviews API
*/
class _reviews extends \IPS\Content\Api\CommentController
class reviews extends CommentController
{
/**
* Class
*/
protected $class = NULL;
protected string $class = '';
/**
* Get endpoint data
@@ -34,25 +53,25 @@ class _reviews extends \IPS\Content\Api\CommentController
* @param array $pathBits The parts to the path called
* @param string $method HTTP method verb
* @return array
* @throws \RuntimeException
* @throws RuntimeException
*/
protected function _getEndpoint( $pathBits, $method = 'GET' )
protected function _getEndpoint( array $pathBits, string $method = 'GET' ): array
{
if ( !\count( $pathBits ) )
if ( !count( $pathBits ) )
{
throw new \RuntimeException;
throw new RuntimeException;
}
$database = array_shift( $pathBits );
if ( !\count( $pathBits ) )
if ( !count( $pathBits ) )
{
return array( 'endpoint' => 'index', 'params' => array( $database ) );
}
$nextBit = array_shift( $pathBits );
if ( \intval( $nextBit ) != 0 )
if ( intval( $nextBit ) != 0 )
{
if ( \count( $pathBits ) )
if ( count( $pathBits ) )
{
return array( 'endpoint' => 'item_' . array_shift( $pathBits ), 'params' => array( $database, $nextBit ) );
}
@@ -62,7 +81,7 @@ class _reviews extends \IPS\Content\Api\CommentController
}
}
throw new \RuntimeException;
throw new RuntimeException;
}
/**
@@ -81,27 +100,28 @@ class _reviews extends \IPS\Content\Api\CommentController
* @apiparam int page Page number
* @apiparam int perPage Number of results per page - defaults to 25
* @throws 2T312/1 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @return \IPS\Api\PaginatedResponse<IPS\cms\Records\Review>
* @apireturn PaginatedResponse<IPS\cms\Records\Review>
* @return PaginatedResponse<Review>
*/
public function GETindex( $database )
public function GETindex( int $database ): PaginatedResponse
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Review' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T312/1', 404 );
throw new Exception( 'INVALID_DATABASE', '2T312/1', 404 );
}
/* Return */
return $this->_list( array( array( 'review_database_id=?', $database->id ) ), 'categories' );
return $this->_list( array( array( 'review_database_id=?', $database->id ) ) );
}
/**
@@ -112,27 +132,29 @@ class _reviews extends \IPS\Content\Api\CommentController
* @param int $review Comment ID
* @throws 2T312/2 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T311/3 INVALID_ID The comment ID does not exist or the authorized user does not have permission to view it
* @return \IPS\cms\Records\Review
* @apireturn \IPS\cms\Records\Review
* @return Response
*/
public function GETitem( $database, $review )
public function GETitem( int $database, int $review ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T312/2', 404 );
throw new Exception( 'INVALID_DATABASE', '2T312/2', 404 );
}
/* Return */
try
{
/* @var Review $class */
$class = 'IPS\cms\Records\Review' . $database->id;
if ( $this->member )
{
@@ -143,11 +165,11 @@ class _reviews extends \IPS\Content\Api\CommentController
$object = $class::load( $review );
}
return new \IPS\Api\Response( 200, $object->apiOutput( $this->member ) );
return new Response( 200, $object->apiOutput( $this->member ) );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T312/3', 404 );
throw new Exception( 'INVALID_ID', '2T312/3', 404 );
}
}
@@ -172,34 +194,36 @@ class _reviews extends \IPS\Content\Api\CommentController
* @throws 1T312/7 NO_CONTENT No content was supplied
* @throws 1T312/8 INVALID_RATING The rating is not a valid number up to the maximum rating
* @throws 2T312/E NO_PERMISSION The authorized user does not have permission to review that record
* @return \IPS\cms\Records\Review
* @apireturn \IPS\cms\Records\Review
* @return Response
*/
public function POSTindex( $database )
public function POSTindex( int $database ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Review' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T312/4', 404 );
throw new Exception( 'INVALID_DATABASE', '2T312/4', 404 );
}
/* Get record */
try
{
/* @var Records $recordClass */
$recordClass = 'IPS\cms\Records' . $database->id;
$record = $recordClass::load( \IPS\Request::i()->record );
$record = $recordClass::load( Request::i()->record );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T312/5', 403 );
throw new Exception( 'INVALID_ID', '2T312/5', 403 );
}
/* Get author */
@@ -207,44 +231,44 @@ class _reviews extends \IPS\Content\Api\CommentController
{
if ( !$record->canReview( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T312/E', 403 );
throw new Exception( 'NO_PERMISSION', '2T312/E', 403 );
}
$author = $this->member;
}
else
{
if ( \IPS\Request::i()->author )
if ( Request::i()->author )
{
$author = \IPS\Member::load( \IPS\Request::i()->author );
$author = Member::load( Request::i()->author );
if ( !$author->member_id )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T312/6', 404 );
throw new Exception( 'NO_AUTHOR', '1T312/6', 404 );
}
}
else
{
if ( (int) \IPS\Request::i()->author === 0 )
if ( Request::i()->author === 0 )
{
$author = new \IPS\Member;
$author->name = \IPS\Request::i()->author_name;
$author = new Member;
$author->name = Request::i()->author_name;
}
else
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T312/6', 400 );
throw new Exception( 'NO_AUTHOR', '1T312/6', 400 );
}
}
}
/* Check we have a post */
if ( !\IPS\Request::i()->content )
if ( !Request::i()->content )
{
throw new \IPS\Api\Exception( 'NO_CONTENT', '1T311/7', 403 );
throw new Exception( 'NO_CONTENT', '1T311/7', 403 );
}
/* Check we have a rating */
if ( !\IPS\Request::i()->rating or !\in_array( (int) \IPS\Request::i()->rating, range( 1, \IPS\Settings::i()->reviews_rating_out_of ) ) )
if ( !Request::i()->rating or !in_array( (int) Request::i()->rating, range( 1, Settings::i()->reviews_rating_out_of ) ) )
{
throw new \IPS\Api\Exception( 'INVALID_RATING', '1T312/8', 403 );
throw new Exception( 'INVALID_RATING', '1T312/8', 403 );
}
/* Do it */
@@ -268,38 +292,40 @@ class _reviews extends \IPS\Content\Api\CommentController
* @throws 2T312/A INVALID_ID The comment ID does not exist or the authorized user does not have permission to view it
* @throws 1T312/B NO_AUTHOR The author ID does not exist
* @throws 2T312/F NO_PERMISSION The authorized user does not have permission to edit the review
* @return \IPS\cms\Records\Review
* @apireturn \IPS\cms\Records\Review
* @return Response
*/
public function POSTitem( $database, $review )
public function POSTitem( int $database, int $review ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Review' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T312/9', 404 );
throw new Exception( 'INVALID_DATABASE', '2T312/9', 404 );
}
/* Do it */
try
{
/* Load */
/* @var Review $className */
$className = $this->class;
$review = $className::load( $review );
if ( $this->member and !$review->canView( $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
if ( $this->member and !$review->canEdit( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T312/F', 403 );
throw new Exception( 'NO_PERMISSION', '2T312/F', 403 );
}
/* Do it */
@@ -307,14 +333,14 @@ class _reviews extends \IPS\Content\Api\CommentController
{
return $this->_edit( $review );
}
catch ( \InvalidArgumentException $e )
catch ( InvalidArgumentException $e )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T312/B', 400 );
throw new Exception( 'NO_AUTHOR', '1T312/B', 400 );
}
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T312/A', 404 );
throw new Exception( 'INVALID_ID', '2T312/A', 404 );
}
}
@@ -327,41 +353,43 @@ class _reviews extends \IPS\Content\Api\CommentController
* @throws 2T312/C INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T312/D INVALID_ID The comment ID does not exist
* @throws 2T312/G NO_PERMISSION The authorized user does not have permission to delete the review
* @return void
* @apireturn void
* @return Response
*/
public function DELETEitem( $database, $review )
public function DELETEitem( int $database, int $review ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Review' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T312/C', 404 );
throw new Exception( 'INVALID_DATABASE', '2T312/C', 404 );
}
/* Do it */
try
{
{
/* @var Review $class */
$class = $this->class;
$object = $class::load( $review );
if ( $this->member and !$object->canDelete( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T312/G', 403 );
throw new Exception( 'NO_PERMISSION', '2T312/G', 403 );
}
$object->delete();
return new \IPS\Api\Response( 200, NULL );
return new Response( 200, NULL );
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T312/D', 404 );
throw new Exception( 'INVALID_ID', '2T312/D', 404 );
}
}
@@ -370,35 +398,36 @@ class _reviews extends \IPS\Content\Api\CommentController
* Add a reaction
*
* @param int $database Database ID
* @param int $comment Comment ID
* @param int $review Review ID
* @apiparam int id ID of the reaction to add
* @apiparam int author ID of the member reacting
* @return \IPS\cms\Records\Review
* @apireturn \IPS\cms\Records\Review
* @throws 1S425/2 NO_REACTION The reaction ID does not exist
* @throws 1S425/3 NO_AUTHOR The author ID does not exist
* @throws 1S425/4 REACT_ERROR Error adding the reaction
* @throws 1S425/5 INVALID_ID Object ID does not exist
* @throws 2T312/E INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @note If the author has already reacted to this content, any existing reaction will be removed first
* @return Response
*/
public function POSTitem_react( $database, $comment )
public function POSTitem_react( int $database, int $review ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T312/E', 404 );
throw new Exception( 'INVALID_DATABASE', '2T312/E', 404 );
}
return $this->_reactAdd( $comment );
return $this->_reactAdd( $review );
}
/**
@@ -406,33 +435,34 @@ class _reviews extends \IPS\Content\Api\CommentController
* Delete a reaction
*
* @param int $database Database ID
* @param int $comment Comment ID
* @param int $review Review ID
* @apiparam int author ID of the member who reacted
* @return \IPS\cms\Records\Review
* @apireturn \IPS\cms\Records\Review
* @throws 1S425/6 NO_AUTHOR The author ID does not exist
* @throws 1S425/7 REACT_ERROR Error adding the reaction
* @throws 1S425/8 INVALID_ID Object ID does not exist
* @throws 2T312/F INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @note If the author has already reacted to this content, any existing reaction will be removed first
* @return Response
*/
public function DELETEitem_react( $database, $comment )
public function DELETEitem_react( int $database, int $review ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T312/F', 404 );
throw new Exception( 'INVALID_DATABASE', '2T312/F', 404 );
}
return $this->_reactRemove( $comment );
return $this->_reactRemove( $review );
}
/**
@@ -440,31 +470,32 @@ class _reviews extends \IPS\Content\Api\CommentController
* Reports a review
*
* @param int $database Database ID
* @param int $comment Comment ID
* @param int $review Review ID
* @apiparam int author ID of the member reporting
* @apiparam int report_type Report type (0 is default and is for letting CMGR team know, more options via core_automatic_moderation_types)
* @apiparam string message Optional message
* @throws 1S425/B NO_AUTHOR The author ID does not exist
* @throws 1S425/C REPORTED_ALREADY The member has reported this item in the past 24 hours
* @return \IPS\cms\Records\Review
* @apireturn \IPS\cms\Records\Review
* @return Response
*/
public function POSTitem_report( $database, $comment )
public function POSTitem_report( int $database, int $review ): Response
{
/* Load database */
try
{
$database = \IPS\cms\Databases::load( $database );
$database = Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
throw new OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
catch ( OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T311/D', 404 );
throw new Exception( 'INVALID_DATABASE', '2T311/D', 404 );
}
return $this->_report( $comment );
return $this->_report( $review );
}
}