Version 4.5.0
This commit is contained in:
1 parent
1a0c7fd3c2
commit
f79dcf067a
3791 files changed
+248032
-76372
No files matched your search
@@ -0,0 +1,141 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Pages Databases API
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @subpackage Content
|
||||
* @since 21 Feb 2020
|
||||
*/
|
||||
|
||||
namespace IPS\cms\api;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* @brief Pages Databases API
|
||||
*/
|
||||
class _categories extends \IPS\Node\Api\NodeController
|
||||
{
|
||||
/**
|
||||
* Class
|
||||
*/
|
||||
protected $class;
|
||||
|
||||
/**
|
||||
* Get endpoint data
|
||||
*
|
||||
* @param array $pathBits The parts to the path called
|
||||
* @param string $method HTTP method verb
|
||||
* @return array
|
||||
* @throws \RuntimeException
|
||||
*/
|
||||
protected function _getEndpoint( $pathBits, $method = 'GET' )
|
||||
{
|
||||
if ( !\count( $pathBits ) )
|
||||
{
|
||||
throw new \RuntimeException;
|
||||
}
|
||||
|
||||
$database = array_shift( $pathBits );
|
||||
if ( !\count( $pathBits ) )
|
||||
{
|
||||
return array( 'endpoint' => 'index', 'params' => array( $database ) );
|
||||
}
|
||||
|
||||
$nextBit = array_shift( $pathBits );
|
||||
if ( \intval( $nextBit ) != 0 )
|
||||
{
|
||||
if ( \count( $pathBits ) )
|
||||
{
|
||||
return array( 'endpoint' => 'item_' . array_shift( $pathBits ), 'params' => array( $database, $nextBit ) );
|
||||
}
|
||||
else
|
||||
{
|
||||
return array( 'endpoint' => 'item', 'params' => array( $database, $nextBit ) );
|
||||
}
|
||||
}
|
||||
|
||||
throw new \RuntimeException;
|
||||
}
|
||||
|
||||
/**
|
||||
* GET /cms/categories/{database_id}
|
||||
* Get list of database categories
|
||||
*
|
||||
* @param int $database Database ID
|
||||
* @return \IPS\Api\PaginatedResponse<IPS\cms\Categories>
|
||||
* @throws 2T306/1 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
|
||||
* @throws 2T306/2 DATABASE_DOES_NOT_USE_CATEGORIES The database does not use categories
|
||||
*/
|
||||
public function GETindex( $database )
|
||||
{
|
||||
/* Load database */
|
||||
try
|
||||
{
|
||||
$database = \IPS\cms\Databases::load( $database );
|
||||
if ( $this->member and !$database->can( 'view', $this->member ) )
|
||||
{
|
||||
throw new \OutOfRangeException;
|
||||
}
|
||||
$this->class = 'IPS\cms\Categories' . $database->id;
|
||||
}
|
||||
catch ( \OutOfRangeException $e )
|
||||
{
|
||||
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T415/1', 404 );
|
||||
}
|
||||
if ( !$database->use_categories )
|
||||
{
|
||||
throw new \IPS\Api\Exception( 'DATABASE_DOES_NOT_USE_CATEGORIES', '2T415/2', 404 );
|
||||
}
|
||||
|
||||
/* Where clause */
|
||||
$where = array( 'category_database_id=?', $database->id );
|
||||
|
||||
/* Return */
|
||||
return $this->_list( $where );
|
||||
}
|
||||
|
||||
/**
|
||||
* GET /cms/databases/{database_id}/{category_id}
|
||||
* Get specific database
|
||||
*
|
||||
* @param int $id ID Number
|
||||
* @return \IPS\cms\Categories
|
||||
* @throws 2T306/3 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
|
||||
* @throws 2T306/4 INVALID_ID The category ID does not exist or the authorized user does not have permission to view it
|
||||
*/
|
||||
public function GETitem( $database, $id )
|
||||
{
|
||||
/* Load database */
|
||||
try
|
||||
{
|
||||
$database = \IPS\cms\Databases::load( $database );
|
||||
if ( $this->member and !$database->can( 'view', $this->member ) )
|
||||
{
|
||||
throw new \OutOfRangeException;
|
||||
}
|
||||
$this->class = 'IPS\cms\Categories' . $database->id;
|
||||
}
|
||||
catch ( \OutOfRangeException $e )
|
||||
{
|
||||
throw new \IPS\Api\Exception( 'INVALID_DATABASE', '2T415/3', 404 );
|
||||
}
|
||||
|
||||
/* Return */
|
||||
try
|
||||
{
|
||||
return $this->_view( $id );
|
||||
}
|
||||
catch ( \OutOfRangeException $e )
|
||||
{
|
||||
throw new \IPS\Api\Exception( 'INVALID_ID', '2T415/4', 404 );
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -6,13 +6,13 @@
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @subpackage Content
|
||||
* @since 10 Dec 2015
|
||||
* @since 21 Feb 2020
|
||||
*/
|
||||
|
||||
namespace IPS\cms\api;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -32,26 +32,27 @@ class _comments extends \IPS\Content\Api\CommentController
|
||||
* Get endpoint data
|
||||
*
|
||||
* @param array $pathBits The parts to the path called
|
||||
* @param string $method HTTP method verb
|
||||
* @return array
|
||||
* @throws \RuntimeException
|
||||
*/
|
||||
protected function _getEndpoint( $pathBits )
|
||||
protected function _getEndpoint( $pathBits, $method = 'GET' )
|
||||
{
|
||||
if ( !count( $pathBits ) )
|
||||
if ( !\count( $pathBits ) )
|
||||
{
|
||||
throw new \RuntimeException;
|
||||
}
|
||||
|
||||
$database = array_shift( $pathBits );
|
||||
if ( !count( $pathBits ) )
|
||||
if ( !\count( $pathBits ) )
|
||||
{
|
||||
return array( 'endpoint' => 'index', 'params' => array( $database ) );
|
||||
}
|
||||
|
||||
$nextBit = array_shift( $pathBits );
|
||||
if ( intval( $nextBit ) != 0 )
|
||||
if ( \intval( $nextBit ) != 0 )
|
||||
{
|
||||
if ( count( $pathBits ) )
|
||||
if ( \count( $pathBits ) )
|
||||
{
|
||||
return array( 'endpoint' => 'item_' . array_shift( $pathBits ), 'params' => array( $database, $nextBit ) );
|
||||
}
|
||||
@@ -154,7 +155,7 @@ class _comments extends \IPS\Content\Api\CommentController
|
||||
* POST /cms/comments/{database_id}
|
||||
* Create a comment
|
||||
*
|
||||
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, hidden will only be honoured if the authentictaed user has permission to hide content).
|
||||
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, hidden will only be honoured if the authenticated user has permission to hide content).
|
||||
* @param int $database Database ID
|
||||
* @reqapiparam int record The ID number of the record the comment is for
|
||||
* @reqapiparam int author The ID number of the member making the comment (0 for guest). Required for requests made using an API Key or the Client Credentials Grant Type. For requests using an OAuth Access Token for a particular member, that member will always be the author
|
||||
@@ -238,7 +239,7 @@ class _comments extends \IPS\Content\Api\CommentController
|
||||
* POST /cms/comments/{database_id}/{comment_id}
|
||||
* Edit a comment
|
||||
*
|
||||
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, hidden will only be honoured if the authentictaed user has permission to hide content).
|
||||
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, hidden will only be honoured if the authenticated user has permission to hide content).
|
||||
* @param int $database Database ID
|
||||
* @param int $comment Comment ID
|
||||
* @apiparam int author The ID number of the member making the comment (0 for guest). Ignored for requests using an OAuth Access Token for a particular member.
|
||||
@@ -272,7 +273,8 @@ class _comments extends \IPS\Content\Api\CommentController
|
||||
try
|
||||
{
|
||||
/* Load */
|
||||
$comment = call_user_func( array( $this->class, 'load' ), $comment );
|
||||
$className = $this->class;
|
||||
$comment = $className::load( $comment );
|
||||
if ( $this->member and !$comment->canView( $this->member ) )
|
||||
{
|
||||
throw new \OutOfRangeException;
|
||||
|
||||
@@ -0,0 +1,55 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Pages Databases API
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @subpackage Content
|
||||
* @since 21 Feb 2020
|
||||
*/
|
||||
|
||||
namespace IPS\cms\api;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* @brief Pages Databases API
|
||||
*/
|
||||
class _databases extends \IPS\Node\Api\NodeController
|
||||
{
|
||||
/**
|
||||
* Class
|
||||
*/
|
||||
protected $class = 'IPS\cms\Databases';
|
||||
|
||||
/**
|
||||
* GET /cms/databases
|
||||
* Get list of databases
|
||||
*
|
||||
* @apiclientonly
|
||||
* @return \IPS\Api\PaginatedResponse<IPS\cms\Databases>
|
||||
*/
|
||||
public function GETindex()
|
||||
{
|
||||
return $this->_list();
|
||||
}
|
||||
|
||||
/**
|
||||
* GET /cms/databases/{id}
|
||||
* Get specific database
|
||||
*
|
||||
* @apiclientonly
|
||||
* @param int $id ID Number
|
||||
* @return \IPS\cms\Databases
|
||||
*/
|
||||
public function GETitem( $id )
|
||||
{
|
||||
return $this->_view( $id );
|
||||
}
|
||||
}
|
||||
Whitespace-only changes.
@@ -6,13 +6,13 @@
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @subpackage Content
|
||||
* @since 9 Dec 2015
|
||||
* @since 21 Feb 2020
|
||||
*/
|
||||
|
||||
namespace IPS\cms\api;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -32,26 +32,27 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
* Get endpoint data
|
||||
*
|
||||
* @param array $pathBits The parts to the path called
|
||||
* @param string $method HTTP method verb
|
||||
* @return array
|
||||
* @throws \RuntimeException
|
||||
*/
|
||||
protected function _getEndpoint( $pathBits )
|
||||
protected function _getEndpoint( $pathBits, $method = 'GET' )
|
||||
{
|
||||
if ( !count( $pathBits ) )
|
||||
if ( !\count( $pathBits ) )
|
||||
{
|
||||
throw new \RuntimeException;
|
||||
}
|
||||
|
||||
$database = array_shift( $pathBits );
|
||||
if ( !count( $pathBits ) )
|
||||
if ( !\count( $pathBits ) )
|
||||
{
|
||||
return array( 'endpoint' => 'index', 'params' => array( $database ) );
|
||||
}
|
||||
|
||||
$nextBit = array_shift( $pathBits );
|
||||
if ( intval( $nextBit ) != 0 )
|
||||
if ( \intval( $nextBit ) != 0 )
|
||||
{
|
||||
if ( count( $pathBits ) )
|
||||
if ( \count( $pathBits ) )
|
||||
{
|
||||
return array( 'endpoint' => 'item_' . array_shift( $pathBits ), 'params' => array( $database, $nextBit ) );
|
||||
}
|
||||
@@ -76,7 +77,7 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
* @apiparam int hidden If 1, only records which are hidden are returned, if 0 only not hidden
|
||||
* @apiparam int pinned If 1, only records which are pinned are returned, if 0 only not pinned
|
||||
* @apiparam int featured If 1, only records which are featured are returned, if 0 only not featured
|
||||
* @apiparam string sortBy What to sort by. Can be 'date' for creation date, 'title' or leave unspecified for ID
|
||||
* @apiparam string sortBy What to sort by. Can be 'date' for creation date, 'title', 'updated' or leave unspecified for ID
|
||||
* @apiparam string sortDir Sort direction. Can be 'asc' or 'desc' - defaults to 'asc'
|
||||
* @apiparam int page Page number
|
||||
* @apiparam int perPage Number of results per page - defaults to 25
|
||||
@@ -138,7 +139,8 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
/* Return */
|
||||
try
|
||||
{
|
||||
$record = call_user_func( array( $this->class, 'load' ), $record );
|
||||
$className = $this->class;
|
||||
$record = $className::load( $record );
|
||||
if ( $this->member and !$record->can( 'read', $this->member ) )
|
||||
{
|
||||
throw new \OutOfRangeException;
|
||||
@@ -156,7 +158,7 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
* POST /cms/records/{database_id}
|
||||
* Create a record
|
||||
*
|
||||
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, locked will only be honoured if the authentictaed user has permission to lock records).
|
||||
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, locked will only be honoured if the authenticated user has permission to lock records).
|
||||
* @param int $database Database ID Number
|
||||
* @reqapiparam int category The ID number of the category the record should be created in. If the database does not use categories, this is not required
|
||||
* @reqapiparam int author The ID number of the member creating the record (0 for guest) Required for requests made using an API Key or the Client Credentials Grant Type. For requests using an OAuth Access Token for a particular member, that member will always be the author
|
||||
@@ -173,10 +175,11 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
* @throws 1T306/5 NO_CATEGORY The category ID does not exist
|
||||
* @throws 1T306/6 NO_AUTHOR The author ID does not exist
|
||||
* @throws 2T306/G NO_PERMISSION The authorized user does not have permission to create a record in that category
|
||||
* @throws 1T306/D TITLE_CONTENT_REQUIRED No title or content fields were supplied
|
||||
* @return \IPS\cms\Records
|
||||
*/
|
||||
public function POSTindex( $database )
|
||||
{
|
||||
{
|
||||
/* Load database */
|
||||
try
|
||||
{
|
||||
@@ -232,7 +235,14 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
}
|
||||
}
|
||||
|
||||
$record = $this->_create( $category, $author );
|
||||
try
|
||||
{
|
||||
$record = $this->_create( $category, $author );
|
||||
}
|
||||
catch( \DomainException $e )
|
||||
{
|
||||
throw new \IPS\Api\Exception( $e->getMessage(), '1T306/D', 400 );
|
||||
}
|
||||
|
||||
/* Sync Topic */
|
||||
$class = $this->class;
|
||||
@@ -245,6 +255,11 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
catch( \Exception $ex ) { }
|
||||
}
|
||||
|
||||
/* Refresh category and database caches */
|
||||
$record->container()->setLastComment();
|
||||
$record->container()->setLastReview();
|
||||
$record->container()->save();
|
||||
|
||||
/* Do it */
|
||||
return new \IPS\Api\Response( 201, $record->apiOutput( $this->member ) );
|
||||
}
|
||||
@@ -253,16 +268,14 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
* POST /cms/records/{database_id}/{record_id}
|
||||
* Edit a record
|
||||
*
|
||||
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, locked will only be honoured if the authentictaed user has permission to lock topics).
|
||||
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, locked will only be honoured if the authenticated user has permission to lock topics).
|
||||
* @param int $database Database ID Number
|
||||
* @param int $record Record ID Number
|
||||
* @param int $database Database ID Number
|
||||
* @apiparam int category The ID number of the category the record should be created in. If the database does not use categories, this is not required
|
||||
* @apiparam int author The ID number of the member creating the record (0 for guest). Ignored for requests using an OAuth Access Token for a particular member.
|
||||
* @reqapiparam object fields Field values. Keys should be the field ID, and the value should be the value. For requests using an OAuth Access Token for a particular member, values will be sanatised where necessary. For requests made using an API Key or the Client Credentials Grant Type values will be saved unchanged.
|
||||
* @apiparam string prefix Prefix tag
|
||||
* @apiparam string tags Comma-separated list of tags (do not include prefix)
|
||||
* @apiparam datetime date The date/time that should be used for the record date. If not provided, will use the current date/time. Ignored for requests using an OAuth Access Token for a particular member.
|
||||
* @apiparam string ip_address The IP address that should be stored for the record. If not provided, will use the IP address from the API request. Ignored for requests using an OAuth Access Token for a particular member.
|
||||
* @apiparam int locked 1/0 indicating if the record should be locked
|
||||
* @apiparam int hidden 0 = unhidden; 1 = hidden, pending moderator approval; -1 = hidden (as if hidden by a moderator)
|
||||
@@ -291,7 +304,8 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
/* Load record */
|
||||
try
|
||||
{
|
||||
$record = call_user_func( array( $this->class, 'load' ), $record );
|
||||
$className = $this->class;
|
||||
$record = $className::load( $record );
|
||||
if ( $this->member and !$record->can( 'read', $this->member ) )
|
||||
{
|
||||
throw new \OutOfRangeException;
|
||||
@@ -378,7 +392,7 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
/* Set field values */
|
||||
if ( isset( \IPS\Request::i()->fields ) )
|
||||
{
|
||||
$fieldsClass = str_replace( 'Records', 'Fields', get_class( $item ) );
|
||||
$fieldsClass = str_replace( 'Records', 'Fields', \get_class( $item ) );
|
||||
foreach ( $fieldsClass::data() as $key => $field )
|
||||
{
|
||||
if ( isset( \IPS\Request::i()->fields[ $field->id ] ) )
|
||||
@@ -398,6 +412,29 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
$date = ( !$this->member and \IPS\Request::i()->date ) ? new \IPS\DateTime( \IPS\Request::i()->date ) : \IPS\DateTime::create();
|
||||
|
||||
if( !$item->record_saved )
|
||||
{
|
||||
$item->record_saved = $date->getTimestamp();
|
||||
}
|
||||
|
||||
if( !$item->record_updated )
|
||||
{
|
||||
$item->record_updated = $item->record_saved;
|
||||
}
|
||||
|
||||
if( $type == 'add' AND ( !$item->_title OR !$item->_content ) )
|
||||
{
|
||||
throw new \DomainException( 'TITLE_CONTENT_REQUIRED' );
|
||||
}
|
||||
|
||||
/* Set FURL */
|
||||
if ( isset( \IPS\Request::i()->fields['fields'][ $item->database()->field_title ] ) )
|
||||
{
|
||||
$item->record_dynamic_furl = \IPS\Http\Url\Friendly::seoTitle( \IPS\Request::i()->fields['fields'][ $item->database()->field_title ] );
|
||||
}
|
||||
|
||||
/* Pass up */
|
||||
return parent::_createOrUpdate( $item, $type );
|
||||
@@ -407,7 +444,8 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
* GET /cms/records/{database_id}/{record_id}/comments
|
||||
* Get comments on a record
|
||||
*
|
||||
* @param int $id ID Number
|
||||
* @param int $database Database ID Number
|
||||
* @param int $record Record ID Number
|
||||
* @apiparam int hidden If 1, only comments which are hidden are returned, if 0 only not hidden
|
||||
* @apiparam string sortDir Sort direction. Can be 'asc' or 'desc' - defaults to 'asc'
|
||||
* @apiparam int page Page number
|
||||
@@ -449,7 +487,8 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
* GET /cms/records/{database_id}/{record_id}/reviews
|
||||
* Get reviews on a record
|
||||
*
|
||||
* @param int $id ID Number
|
||||
* @param int $database Database ID Number
|
||||
* @param int $record Record ID Number
|
||||
* @apiparam int hidden If 1, only comments which are hidden are returned, if 0 only not hidden
|
||||
* @apiparam string sortDir Sort direction. Can be 'asc' or 'desc' - defaults to 'asc'
|
||||
* @apiparam int page Page number
|
||||
@@ -519,7 +558,8 @@ class _records extends \IPS\Content\Api\ItemController
|
||||
/* Load record */
|
||||
try
|
||||
{
|
||||
$record = call_user_func( array( $this->class, 'load' ), $record );
|
||||
$className = $this->class;
|
||||
$record = $className::load( $record );
|
||||
}
|
||||
catch ( \OutOfRangeException $e )
|
||||
{
|
||||
|
||||
@@ -6,13 +6,13 @@
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @subpackage Content
|
||||
* @since 10 Dec 2015
|
||||
* @since 21 Feb 2020
|
||||
*/
|
||||
|
||||
namespace IPS\cms\api;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -32,26 +32,27 @@ class _reviews extends \IPS\Content\Api\CommentController
|
||||
* Get endpoint data
|
||||
*
|
||||
* @param array $pathBits The parts to the path called
|
||||
* @param string $method HTTP method verb
|
||||
* @return array
|
||||
* @throws \RuntimeException
|
||||
*/
|
||||
protected function _getEndpoint( $pathBits )
|
||||
protected function _getEndpoint( $pathBits, $method = 'GET' )
|
||||
{
|
||||
if ( !count( $pathBits ) )
|
||||
if ( !\count( $pathBits ) )
|
||||
{
|
||||
throw new \RuntimeException;
|
||||
}
|
||||
|
||||
$database = array_shift( $pathBits );
|
||||
if ( !count( $pathBits ) )
|
||||
if ( !\count( $pathBits ) )
|
||||
{
|
||||
return array( 'endpoint' => 'index', 'params' => array( $database ) );
|
||||
}
|
||||
|
||||
$nextBit = array_shift( $pathBits );
|
||||
if ( intval( $nextBit ) != 0 )
|
||||
if ( \intval( $nextBit ) != 0 )
|
||||
{
|
||||
if ( count( $pathBits ) )
|
||||
if ( \count( $pathBits ) )
|
||||
{
|
||||
return array( 'endpoint' => 'item_' . array_shift( $pathBits ), 'params' => array( $database, $nextBit ) );
|
||||
}
|
||||
@@ -154,7 +155,7 @@ class _reviews extends \IPS\Content\Api\CommentController
|
||||
* POST /cms/reviews/{database_id}
|
||||
* Create a comment
|
||||
*
|
||||
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, hidden will only be honoured if the authentictaed user has permission to hide content).
|
||||
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, hidden will only be honoured if the authenticated user has permission to hide content).
|
||||
* @param int $database Database ID
|
||||
* @reqapiparam int record The ID number of the record the comment is for
|
||||
* @reqapiparam int author The ID number of the member making the comment (0 for guest). Required for requests made using an API Key or the Client Credentials Grant Type. For requests using an OAuth Access Token for a particular member, that member will always be the author
|
||||
@@ -233,7 +234,7 @@ class _reviews extends \IPS\Content\Api\CommentController
|
||||
}
|
||||
|
||||
/* Check we have a rating */
|
||||
if ( !\IPS\Request::i()->rating or !in_array( (int) \IPS\Request::i()->rating, range( 1, \IPS\Settings::i()->reviews_rating_out_of ) ) )
|
||||
if ( !\IPS\Request::i()->rating or !\in_array( (int) \IPS\Request::i()->rating, range( 1, \IPS\Settings::i()->reviews_rating_out_of ) ) )
|
||||
{
|
||||
throw new \IPS\Api\Exception( 'INVALID_RATING', '1T312/8', 403 );
|
||||
}
|
||||
@@ -246,7 +247,7 @@ class _reviews extends \IPS\Content\Api\CommentController
|
||||
* POST /cms/reviews/{database_id}/{review_id}
|
||||
* Edit a comment
|
||||
*
|
||||
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, hidden will only be honoured if the authentictaed user has permission to hide content).
|
||||
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, hidden will only be honoured if the authenticated user has permission to hide content).
|
||||
* @param int $database Database ID
|
||||
* @param int $review Review ID
|
||||
* @apiparam int author The ID number of the member making the review (0 for guest). Ignored for requests using an OAuth Access Token for a particular member.
|
||||
@@ -281,7 +282,8 @@ class _reviews extends \IPS\Content\Api\CommentController
|
||||
try
|
||||
{
|
||||
/* Load */
|
||||
$review = call_user_func( array( $this->class, 'load' ), $review );
|
||||
$className = $this->class;
|
||||
$review = $className::load( $review );
|
||||
if ( $this->member and !$review->canView( $this->member ) )
|
||||
{
|
||||
throw new \OutOfRangeException;
|
||||
@@ -339,7 +341,7 @@ class _reviews extends \IPS\Content\Api\CommentController
|
||||
try
|
||||
{
|
||||
$class = $this->class;
|
||||
$object = $class::load( $id );
|
||||
$object = $class::load( $review );
|
||||
if ( $this->member and !$object->canDelete( $this->member ) )
|
||||
{
|
||||
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T312/G', 403 );
|
||||
|
||||
Reference in new issue
Block a user