Version 4.3.0

This commit is contained in:
Neo committed 2025-12-19 05:47:12 -08:00
1 parent 96997ddd8e
commit fe1acf984a
1349 files changed
+116159 -67711

No files matched your search

+82 -21
View File
@@ -68,6 +68,7 @@ class _comments extends \IPS\Content\Api\CommentController
* GET /cms/comments/{database_id}
* Get list of comments
*
* @note For requests using an OAuth Access Token for a particular member, only comments the authorized user can view will be included
* @param int $database Database ID
* @apiparam string categories Comma-delimited list of category IDs
* @apiparam string authors Comma-delimited list of member IDs - if provided, only topics started by those members are returned
@@ -77,7 +78,8 @@ class _comments extends \IPS\Content\Api\CommentController
* @apiparam string sortBy What to sort by. Can be 'date', 'title' or leave unspecified for ID
* @apiparam string sortDir Sort direction. Can be 'asc' or 'desc' - defaults to 'asc'
* @apiparam int page Page number
* @throws 2T311/1 INVALID_DATABASE The database ID does not exist
* @apiparam int perPage Number of results per page - defaults to 25
* @throws 2T311/1 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @return \IPS\Api\PaginatedResponse<IPS\cms\Records\Comment>
*/
public function GETindex( $database )
@@ -86,6 +88,10 @@ class _comments extends \IPS\Content\Api\CommentController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
@@ -103,8 +109,8 @@ class _comments extends \IPS\Content\Api\CommentController
*
* @param int $database Database ID
* @param int $comment Comment ID
* @throws 2T311/1 INVALID_DATABASE The database ID does not exist
* @throws 2T311/3 INVALID_ID The comment ID does not exist
* @throws 2T311/1 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T311/3 INVALID_ID The comment ID does not exist or the authorized user does not have permission to view it
* @return \IPS\cms\Records\Comment
*/
public function GETitem( $database, $comment )
@@ -113,6 +119,10 @@ class _comments extends \IPS\Content\Api\CommentController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
}
catch ( \OutOfRangeException $e )
{
@@ -123,7 +133,16 @@ class _comments extends \IPS\Content\Api\CommentController
try
{
$class = 'IPS\cms\Records\Comment' . $database->id;
return new \IPS\Api\Response( 200, $class::load( $comment )->apiOutput() );
if ( $this->member )
{
$object = $class::loadAndCheckPerms( $comment, $this->member );
}
else
{
$object = $class::load( $comment );
}
return new \IPS\Api\Response( 200, $object->apiOutput( $this->member ) );
}
catch ( \OutOfRangeException $e )
{
@@ -135,18 +154,20 @@ class _comments extends \IPS\Content\Api\CommentController
* POST /cms/comments/{database_id}
* Create a comment
*
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, hidden will only be honoured if the authentictaed user has permission to hide content).
* @param int $database Database ID
* @reqapiparam int record The ID number of the record the comment is for
* @reqapiparam int author The ID number of the member making the comment (0 for guest)
* @reqapiparam int author The ID number of the member making the comment (0 for guest). Required for requests made using an API Key or the Client Credentials Grant Type. For requests using an OAuth Access Token for a particular member, that member will always be the author
* @apiparam string author_name If author is 0, the guest name that should be used
* @reqapiparam string content The comment content as HTML (e.g. "<p>This is a comment.</p>")
* @apiparam datetime date The date/time that should be used for the comment date. If not provided, will use the current date/time
* @apiparam string ip_address The IP address that should be stored for the comment. If not provided, will use the IP address from the API request
* @reqapiparam string content The comment content as HTML (e.g. "<p>This is a comment.</p>"). Will be sanatized for requests using an OAuth Access Token for a particular member; will be saved unaltered for requests made using an API Key or the Client Credentials Grant Type.
* @apiparam datetime date The date/time that should be used for the comment date. If not provided, will use the current date/time. Ignored for requests using an OAuth Access Token for a particular member
* @apiparam string ip_address The IP address that should be stored for the comment. If not provided, will use the IP address from the API request. Ignored for requests using an OAuth Access Token for a particular member
* @apiparam int hidden 0 = unhidden; 1 = hidden, pending moderator approval; -1 = hidden (as if hidden by a moderator)
* @throws 2T311/4 INVALID_DATABASE The database ID does not exist
* @throws 2T311/4 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T311/5 INVALID_ID The comment ID does not exist
* @throws 1T311/6 NO_AUTHOR The author ID does not exist
* @throws 1T311/7 NO_CONTENT No content was supplied
* @throws 2T311/D NO_PERMISSION The authorized user does not have permission to comment on that record
* @return \IPS\cms\Records\Comment
*/
public function POSTindex( $database )
@@ -155,6 +176,10 @@ class _comments extends \IPS\Content\Api\CommentController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
@@ -174,18 +199,29 @@ class _comments extends \IPS\Content\Api\CommentController
}
/* Get author */
if ( \IPS\Request::i()->author )
if ( $this->member )
{
$author = \IPS\Member::load( \IPS\Request::i()->author );
if ( !$author->member_id )
if ( !$record->canComment( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T311/6', 404 );
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T311/D', 403 );
}
$author = $this->member;
}
else
{
$author = new \IPS\Member;
$author->name = \IPS\Request::i()->author_name;
if ( \IPS\Request::i()->author )
{
$author = \IPS\Member::load( \IPS\Request::i()->author );
if ( !$author->member_id )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T311/6', 404 );
}
}
else
{
$author = new \IPS\Member;
$author->name = \IPS\Request::i()->author_name;
}
}
/* Check we have a post */
@@ -202,15 +238,17 @@ class _comments extends \IPS\Content\Api\CommentController
* POST /cms/comments/{database_id}/{comment_id}
* Edit a comment
*
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, hidden will only be honoured if the authentictaed user has permission to hide content).
* @param int $database Database ID
* @param int $comment Comment ID
* @apiparam int author The ID number of the member making the comment (0 for guest)
* @apiparam int author The ID number of the member making the comment (0 for guest). Ignored for requests using an OAuth Access Token for a particular member.
* @apiparam string author_name If author is 0, the guest name that should be used
* @apiparam string content The comment content as HTML (e.g. "<p>This is a comment.</p>")
* @apiparam string content The comment content as HTML (e.g. "<p>This is a comment.</p>"). Will be sanatized for requests using an OAuth Access Token for a particular member; will be saved unaltered for requests made using an API Key or the Client Credentials Grant Type.
* @apiparam int hidden 1/0 indicating if the topic should be hidden
* @throws 2T311/7 INVALID_DATABASE The database ID does not exist
* @throws 2T311/8 INVALID_ID The comment ID does not exist
* @throws 2T311/7 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T311/8 INVALID_ID The comment ID does not exist or the authorized user does not have permission to view it
* @throws 1T311/9 NO_AUTHOR The author ID does not exist
* @throws 2T311/E NO_PERMISSION The authorized user does not have permission to edit the comment
* @return \IPS\cms\Records\Comment
*/
public function POSTitem( $database, $comment )
@@ -219,6 +257,10 @@ class _comments extends \IPS\Content\Api\CommentController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
@@ -231,6 +273,14 @@ class _comments extends \IPS\Content\Api\CommentController
{
/* Load */
$comment = call_user_func( array( $this->class, 'load' ), $comment );
if ( $this->member and !$comment->canView( $this->member ) )
{
throw new \OutOfRangeException;
}
if ( $this->member and !$comment->canEdit( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T311/E', 403 );
}
/* Do it */
try
@@ -254,8 +304,9 @@ class _comments extends \IPS\Content\Api\CommentController
*
* @param int $database Database ID
* @param int $comment Comment ID
* @throws 2T311/A INVALID_DATABASE The database ID does not exist
* @throws 2T311/A INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T311/B INVALID_ID The comment ID does not exist
* @throws 2T311/F NO_PERMISSION The authorized user does not have permission to delete the comment
* @return void
*/
public function DELETEitem( $database, $comment )
@@ -264,6 +315,10 @@ class _comments extends \IPS\Content\Api\CommentController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Comment' . $database->id;
}
catch ( \OutOfRangeException $e )
@@ -274,7 +329,13 @@ class _comments extends \IPS\Content\Api\CommentController
/* Do it */
try
{
call_user_func( array( $this->class, 'load' ), $comment )->delete();
$class = $this->class;
$object = $class::load( $comment );
if ( $this->member and !$object->canDelete( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T311/F', 403 );
}
$object->delete();
return new \IPS\Api\Response( 200, NULL );
}
+150 -40
View File
@@ -68,6 +68,7 @@ class _records extends \IPS\Content\Api\ItemController
* GET /cms/records/{database_id}
* Get list of records
*
* @note For requests using an OAuth Access Token for a particular member, only records the authorized user can view will be included
* @param int $database Database ID
* @apiparam string categories Comma-delimited list of category IDs
* @apiparam string authors Comma-delimited list of member IDs - if provided, only records started by those members are returned
@@ -78,7 +79,8 @@ class _records extends \IPS\Content\Api\ItemController
* @apiparam string sortBy What to sort by. Can be 'date' for creation date, 'title' or leave unspecified for ID
* @apiparam string sortDir Sort direction. Can be 'asc' or 'desc' - defaults to 'asc'
* @apiparam int page Page number
* @throws 2T306/1 INVALID_DATABASE The database ID does not exist
* @apiparam int perPage Number of results per page - defaults to 25
* @throws 2T306/1 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @return \IPS\Api\PaginatedResponse<IPS\cms\Records>
*/
public function GETindex( $database )
@@ -87,6 +89,10 @@ class _records extends \IPS\Content\Api\ItemController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
@@ -107,8 +113,8 @@ class _records extends \IPS\Content\Api\ItemController
*
* @param int $database Database ID Number
* @param int $record Record ID Number
* @throws 2T306/2 INVALID_DATABASE The database ID does not exist
* @throws 2T306/3 INVALID_ID The record ID does not exist
* @throws 2T306/2 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T306/3 INVALID_ID The record ID does not exist or the authorized user does not have permission to view it
* @return \IPS\cms\Records
*/
public function GETitem( $database, $record )
@@ -117,6 +123,11 @@ class _records extends \IPS\Content\Api\ItemController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
@@ -127,7 +138,13 @@ class _records extends \IPS\Content\Api\ItemController
/* Return */
try
{
return new \IPS\Api\Response( 200, call_user_func( array( $this->class, 'load' ), $record )->apiOutput() );
$record = call_user_func( array( $this->class, 'load' ), $record );
if ( $this->member and !$record->can( 'read', $this->member ) )
{
throw new \OutOfRangeException;
}
return new \IPS\Api\Response( 200, $record->apiOutput( $this->member ) );
}
catch ( \OutOfRangeException $e )
{
@@ -139,14 +156,15 @@ class _records extends \IPS\Content\Api\ItemController
* POST /cms/records/{database_id}
* Create a record
*
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, locked will only be honoured if the authentictaed user has permission to lock records).
* @param int $database Database ID Number
* @reqapiparam int category The ID number of the category the record should be created in. If the database does not use categories, this is not required
* @reqapiparam int author The ID number of the member creating the record (0 for guest)
* @reqapiparam object fields Field values. Keys should be the field ID, and the value should be the value
* @reqapiparam int author The ID number of the member creating the record (0 for guest) Required for requests made using an API Key or the Client Credentials Grant Type. For requests using an OAuth Access Token for a particular member, that member will always be the author
* @reqapiparam object fields Field values. Keys should be the field ID, and the value should be the value. For requests using an OAuth Access Token for a particular member, values will be sanatised where necessary. For requests made using an API Key or the Client Credentials Grant Type values will be saved unchanged.
* @apiparam string prefix Prefix tag
* @apiparam string tags Comma-separated list of tags (do not include prefix)
* @apiparam datetime date The date/time that should be used for the record date. If not provided, will use the current date/time
* @apiparam string ip_address The IP address that should be stored for the record. If not provided, will use the IP address from the API request
* @apiparam datetime date The date/time that should be used for the record date. If not provided, will use the current date/time. Ignored for requests using an OAuth Access Token for a particular member.
* @apiparam string ip_address The IP address that should be stored for the record. If not provided, will use the IP address from the API request. Ignored for requests using an OAuth Access Token for a particular member.
* @apiparam int locked 1/0 indicating if the record should be locked
* @apiparam int hidden 0 = unhidden; 1 = hidden, pending moderator approval; -1 = hidden (as if hidden by a moderator)
* @apiparam int pinned 1/0 indicating if the record should be pinned
@@ -154,6 +172,7 @@ class _records extends \IPS\Content\Api\ItemController
* @throws 2T306/4 INVALID_DATABASE The database ID does not exist
* @throws 1T306/5 NO_CATEGORY The category ID does not exist
* @throws 1T306/6 NO_AUTHOR The author ID does not exist
* @throws 2T306/G NO_PERMISSION The authorized user does not have permission to create a record in that category
* @return \IPS\cms\Records
*/
public function POSTindex( $database )
@@ -172,13 +191,15 @@ class _records extends \IPS\Content\Api\ItemController
/* Get category */
try
{
$categoryClass = 'IPS\cms\Categories' . $database->id;
if ( $database->use_categories )
{
$category = \IPS\cms\Categories::load( \IPS\Request::i()->category );
$category = $categoryClass::load( \IPS\Request::i()->category );
}
else
{
$category = \IPS\cms\Categories::load( $database->default_category );
$category = $categoryClass::load( $database->default_category );
}
}
catch ( \OutOfRangeException $e )
@@ -187,45 +208,71 @@ class _records extends \IPS\Content\Api\ItemController
}
/* Get author */
if ( \IPS\Request::i()->author )
if ( $this->member )
{
$author = \IPS\Member::load( \IPS\Request::i()->author );
if ( !$author->member_id )
if ( !$category->can( 'add', $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T306/6', 400 );
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T306/G', 403 );
}
$author = $this->member;
}
else
{
$author = new \IPS\Member;
if ( \IPS\Request::i()->author )
{
$author = \IPS\Member::load( \IPS\Request::i()->author );
if ( !$author->member_id )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T306/6', 400 );
}
}
else
{
$author = new \IPS\Member;
}
}
$record = $this->_create( $category, $author );
/* Sync Topic */
$class = $this->class;
if ( !$class::$skipTopicCreation and \IPS\Application::appIsEnabled('forums') and $record->_forum_record and $record->_forum_forum and ! $record->hidden() and ! $record->record_future_date )
{
try
{
$record->syncTopic();
}
catch( \Exception $ex ) { }
}
/* Do it */
return new \IPS\Api\Response( 201, $this->_create( $category, $author )->apiOutput() );
return new \IPS\Api\Response( 201, $record->apiOutput( $this->member ) );
}
/**
* POST /cms/records/{database_id}/{record_id}
* Edit a record
*
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, locked will only be honoured if the authentictaed user has permission to lock topics).
* @param int $database Database ID Number
* @param int $record Record ID Number
* @param int $database Database ID Number
* @apiparam int category The ID number of the category the record should be created in. If the database does not use categories, this is not required
* @apiparam int author The ID number of the member creating the record (0 for guest)
* @apiparam object fields Field values. Keys should be the field ID, and the value should be the value
* @apiparam int author The ID number of the member creating the record (0 for guest). Ignored for requests using an OAuth Access Token for a particular member.
* @reqapiparam object fields Field values. Keys should be the field ID, and the value should be the value. For requests using an OAuth Access Token for a particular member, values will be sanatised where necessary. For requests made using an API Key or the Client Credentials Grant Type values will be saved unchanged.
* @apiparam string prefix Prefix tag
* @apiparam string tags Comma-separated list of tags (do not include prefix)
* @apiparam datetime date The date/time that should be used for the record date. If not provided, will use the current date/time
* @apiparam string ip_address The IP address that should be stored for the record. If not provided, will use the IP address from the API request
* @apiparam datetime date The date/time that should be used for the record date. If not provided, will use the current date/time. Ignored for requests using an OAuth Access Token for a particular member.
* @apiparam string ip_address The IP address that should be stored for the record. If not provided, will use the IP address from the API request. Ignored for requests using an OAuth Access Token for a particular member.
* @apiparam int locked 1/0 indicating if the record should be locked
* @apiparam int hidden 0 = unhidden; 1 = hidden, pending moderator approval; -1 = hidden (as if hidden by a moderator)
* @apiparam int pinned 1/0 indicating if the record should be pinned
* @apiparam int featured 1/0 indicating if the record should be featured
* @throws 2T306/9 INVALID_DATABASE The database ID does not exist
* @throws 2T306/6 INVALID_ID The record ID is invalid
* @throws 1T306/7 NO_CATEGORY The category ID does not exist
* @throws 2T306/6 INVALID_ID The record ID is invalid or the authorized user does not have permission to view it
* @throws 1T306/7 NO_CATEGORY The category ID does not exist or the authorized user does not have permission to post in it
* @throws 1T306/8 NO_AUTHOR The author ID does not exist
* @throws 2T306/H NO_PERMISSION The authorized user does not have permission to edit the record
* @return \IPS\cms\Records
*/
public function POSTitem( $database, $record )
@@ -245,18 +292,33 @@ class _records extends \IPS\Content\Api\ItemController
try
{
$record = call_user_func( array( $this->class, 'load' ), $record );
if ( $this->member and !$record->can( 'read', $this->member ) )
{
throw new \OutOfRangeException;
}
}
catch ( \OutOfRangeException $e )
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T306/6', 404 );
}
if ( $this->member and !$record->canEdit( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T306/H', 403 );
}
/* New category */
if ( $database->use_categories and isset( \IPS\Request::i()->category ) and \IPS\Request::i()->category != $record->category_id )
if ( $database->use_categories and isset( \IPS\Request::i()->category ) and \IPS\Request::i()->category != $record->category_id and ( !$this->member or $record->canMove( $this->member ) ) )
{
try
{
$newCategory = \IPS\blog\Blog::load( \IPS\Request::i()->blog );
$categoryClass = 'IPS\cms\Categories' . $database->id;
$newCategory = $categoryClass::load( \IPS\Request::i()->category );
if ( $this->member and !$newCategory->can( 'add', $this->member ) )
{
throw new \OutOfRangeException;
}
$record->move( $newCategory );
}
catch ( \OutOfRangeException $e )
@@ -266,7 +328,7 @@ class _records extends \IPS\Content\Api\ItemController
}
/* New author */
if ( isset( \IPS\Request::i()->author ) )
if ( !$this->member and isset( \IPS\Request::i()->author ) )
{
try
{
@@ -285,20 +347,33 @@ class _records extends \IPS\Content\Api\ItemController
}
/* Everything else */
$this->_createOrUpdate( $record );
$this->_createOrUpdate( $record, 'edit' );
/* Save and return */
$record->save();
return new \IPS\Api\Response( 200, $record->apiOutput() );
/* Sync Topic */
$class = $this->class;
if ( !$class::$skipTopicCreation and \IPS\Application::appIsEnabled('forums') and $record->_forum_record and $record->_forum_forum and ! $record->hidden() and ! $record->record_future_date )
{
try
{
$record->syncTopic();
}
catch( \Exception $ex ) { }
}
return new \IPS\Api\Response( 200, $record->apiOutput( $this->member ) );
}
/**
* Create or update record
*
* @param \IPS\Content\Item $item The item
* @param string $type add or edit
* @return \IPS\Content\Item
*/
protected function _createOrUpdate( \IPS\Content\Item $item )
protected function _createOrUpdate( \IPS\Content\Item $item, $type='add' )
{
/* Set field values */
if ( isset( \IPS\Request::i()->fields ) )
@@ -306,13 +381,26 @@ class _records extends \IPS\Content\Api\ItemController
$fieldsClass = str_replace( 'Records', 'Fields', get_class( $item ) );
foreach ( $fieldsClass::data() as $key => $field )
{
$key = "field_{$field->_id}";
$item->$key = \IPS\Request::i()->fields[ $field->id ];
if ( isset( \IPS\Request::i()->fields[ $field->id ] ) )
{
if ( !$this->member or $field->can( $type, $this->member ) )
{
$key = "field_{$field->_id}";
$value = \IPS\Request::i()->fields[ $field->id ];
if ( $field->type === 'Editor' and $this->member )
{
$value = \IPS\Text\Parser::parseStatic( $value, TRUE, NULL, $this->member, 'cms_Records' );
}
$item->$key = $value;
}
}
}
}
/* Pass up */
return parent::_createOrUpdate( $item );
return parent::_createOrUpdate( $item, $type );
}
/**
@@ -323,9 +411,10 @@ class _records extends \IPS\Content\Api\ItemController
* @apiparam int hidden If 1, only comments which are hidden are returned, if 0 only not hidden
* @apiparam string sortDir Sort direction. Can be 'asc' or 'desc' - defaults to 'asc'
* @apiparam int page Page number
* @throws 2T306/C INVALID_DATABASE The database ID does not exist
* @throws 2T306/D INVALID_ID The entry ID does not exist
* @return \IPS\Api\PaginatedResponse<IPS\calendar\Event\Comment>
* @apiparam int perPage Number of results per page - defaults to 25
* @throws 2T306/C INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T306/D INVALID_ID The entry ID does not exist or the authorized user does not have permission to view it
* @return \IPS\Api\PaginatedResponse<IPS\cms\Records\Comment>
*/
public function GETitem_comments( $database, $record )
{
@@ -333,6 +422,11 @@ class _records extends \IPS\Content\Api\ItemController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
@@ -359,9 +453,10 @@ class _records extends \IPS\Content\Api\ItemController
* @apiparam int hidden If 1, only comments which are hidden are returned, if 0 only not hidden
* @apiparam string sortDir Sort direction. Can be 'asc' or 'desc' - defaults to 'asc'
* @apiparam int page Page number
* @throws 2T306/E INVALID_DATABASE The database ID does not exist
* @throws 2T306/F INVALID_ID The entry ID does not exist
* @return \IPS\Api\PaginatedResponse<IPS\calendar\Event\Review>
* @apiparam int perPage Number of results per page - defaults to 25
* @throws 2T306/E INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T306/F INVALID_ID The entry ID does not exist or the authorized user does not have permission to view it
* @return \IPS\Api\PaginatedResponse<IPS\cms\Records\Review>
*/
public function GETitem_reviews( $database, $record )
{
@@ -369,6 +464,11 @@ class _records extends \IPS\Content\Api\ItemController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
@@ -393,8 +493,9 @@ class _records extends \IPS\Content\Api\ItemController
*
* @param int $database Database ID Number
* @param int $record Record ID Number
* @throws 2T306/A INVALID_DATABASE The database ID does not exist
* @throws 2T306/B INVALID_ID The entry ID does not exist
* @throws 2T306/A INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T306/B INVALID_ID The entry ID does not exist
* @throws 2T306/I NO_PERMISSION The authorized user does not have permission to delete the record.
* @return void
*/
public function DELETEitem( $database, $record )
@@ -403,6 +504,11 @@ class _records extends \IPS\Content\Api\ItemController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
$this->class = 'IPS\cms\Records' . $database->id;
}
catch ( \OutOfRangeException $e )
@@ -419,6 +525,10 @@ class _records extends \IPS\Content\Api\ItemController
{
throw new \IPS\Api\Exception( 'INVALID_ID', '2T306/B', 404 );
}
if ( $this->member and !$record->canDelete( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T306/I', 404 );
}
/* Delete and return */
$record->delete();
+82 -21
View File
@@ -68,6 +68,7 @@ class _reviews extends \IPS\Content\Api\CommentController
* GET /cms/reviews/{database_id}
* Get list of comments
*
* @note For requests using an OAuth Access Token for a particular member, only reviews the authorized user can view will be included
* @param int $database Database ID
* @apiparam string categories Comma-delimited list of category IDs
* @apiparam string authors Comma-delimited list of member IDs - if provided, only topics started by those members are returned
@@ -77,7 +78,8 @@ class _reviews extends \IPS\Content\Api\CommentController
* @apiparam string sortBy What to sort by. Can be 'date', 'title' or leave unspecified for ID
* @apiparam string sortDir Sort direction. Can be 'asc' or 'desc' - defaults to 'asc'
* @apiparam int page Page number
* @throws 2T312/1 INVALID_DATABASE The database ID does not exist
* @apiparam int perPage Number of results per page - defaults to 25
* @throws 2T312/1 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @return \IPS\Api\PaginatedResponse<IPS\cms\Records\Review>
*/
public function GETindex( $database )
@@ -86,6 +88,10 @@ class _reviews extends \IPS\Content\Api\CommentController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Review' . $database->id;
}
catch ( \OutOfRangeException $e )
@@ -103,8 +109,8 @@ class _reviews extends \IPS\Content\Api\CommentController
*
* @param int $database Database ID
* @param int $review Comment ID
* @throws 2T312/2 INVALID_DATABASE The database ID does not exist
* @throws 2T311/3 INVALID_ID The comment ID does not exist
* @throws 2T312/2 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T311/3 INVALID_ID The comment ID does not exist or the authorized user does not have permission to view it
* @return \IPS\cms\Records\Review
*/
public function GETitem( $database, $review )
@@ -113,6 +119,10 @@ class _reviews extends \IPS\Content\Api\CommentController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
}
catch ( \OutOfRangeException $e )
{
@@ -123,7 +133,16 @@ class _reviews extends \IPS\Content\Api\CommentController
try
{
$class = 'IPS\cms\Records\Review' . $database->id;
return new \IPS\Api\Response( 200, $class::load( $review )->apiOutput() );
if ( $this->member )
{
$object = $class::loadAndCheckPerms( $id, $this->member );
}
else
{
$object = $class::load( $id );
}
return new \IPS\Api\Response( 200, $object->apiOutput( $this->member ) );
}
catch ( \OutOfRangeException $e )
{
@@ -135,20 +154,22 @@ class _reviews extends \IPS\Content\Api\CommentController
* POST /cms/reviews/{database_id}
* Create a comment
*
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, hidden will only be honoured if the authentictaed user has permission to hide content).
* @param int $database Database ID
* @reqapiparam int record The ID number of the record the comment is for
* @reqapiparam int author The ID number of the member making the comment (0 for guest)
* @reqapiparam int author The ID number of the member making the comment (0 for guest). Required for requests made using an API Key or the Client Credentials Grant Type. For requests using an OAuth Access Token for a particular member, that member will always be the author
* @apiparam string author_name If author is 0, the guest name that should be used
* @reqapiparam string content The comment content as HTML (e.g. "<p>This is a comment.</p>")
* @apiparam datetime date The date/time that should be used for the comment date. If not provided, will use the current date/time
* @apiparam string ip_address The IP address that should be stored for the comment. If not provided, will use the IP address from the API request
* @reqapiparam string content The comment content as HTML (e.g. "<p>This is a comment.</p>"). Will be sanatized for requests using an OAuth Access Token for a particular member; will be saved unaltered for requests made using an API Key or the Client Credentials Grant Type.
* @apiparam datetime date The date/time that should be used for the comment date. If not provided, will use the current date/time. Ignored for requests using an OAuth Access Token for a particular member
* @apiparam string ip_address The IP address that should be stored for the comment. If not provided, will use the IP address from the API request. Ignored for requests using an OAuth Access Token for a particular member
* @apiparam int hidden 0 = unhidden; 1 = hidden, pending moderator approval; -1 = hidden (as if hidden by a moderator)
* @reqapiparam int rating Star rating
* @throws 2T312/4 INVALID_DATABASE The database ID does not exist
* @throws 2T312/4 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T312/5 INVALID_ID The comment ID does not exist
* @throws 1T312/6 NO_AUTHOR The author ID does not exist
* @throws 1T312/7 NO_CONTENT No content was supplied
* @throws 1T312/8 INVALID_RATING The rating is not a valid number up to the maximum rating
* @throws 2T312/E NO_PERMISSION The authorized user does not have permission to review that record
* @return \IPS\cms\Records\Review
*/
public function POSTindex( $database )
@@ -157,6 +178,10 @@ class _reviews extends \IPS\Content\Api\CommentController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Review' . $database->id;
}
catch ( \OutOfRangeException $e )
@@ -176,18 +201,29 @@ class _reviews extends \IPS\Content\Api\CommentController
}
/* Get author */
if ( \IPS\Request::i()->author )
if ( $this->member )
{
$author = \IPS\Member::load( \IPS\Request::i()->author );
if ( !$author->member_id )
if ( !$record->canReview( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T312/6', 404 );
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T312/E', 403 );
}
$author = $this->member;
}
else
{
$author = new \IPS\Member;
$author->name = \IPS\Request::i()->author_name;
if ( \IPS\Request::i()->author )
{
$author = \IPS\Member::load( \IPS\Request::i()->author );
if ( !$author->member_id )
{
throw new \IPS\Api\Exception( 'NO_AUTHOR', '1T312/6', 404 );
}
}
else
{
$author = new \IPS\Member;
$author->name = \IPS\Request::i()->author_name;
}
}
/* Check we have a post */
@@ -210,16 +246,18 @@ class _reviews extends \IPS\Content\Api\CommentController
* POST /cms/reviews/{database_id}/{review_id}
* Edit a comment
*
* @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, hidden will only be honoured if the authentictaed user has permission to hide content).
* @param int $database Database ID
* @param int $review Review ID
* @apiparam int author The ID number of the member making the review (0 for guest)
* @apiparam int author The ID number of the member making the review (0 for guest). Ignored for requests using an OAuth Access Token for a particular member.
* @apiparam string author_name If author is 0, the guest name that should be used
* @apiparam string content The comment content as HTML (e.g. "<p>This is a comment.</p>")
* @apiparam string content The comment content as HTML (e.g. "<p>This is a comment.</p>"). Will be sanatized for requests using an OAuth Access Token for a particular member; will be saved unaltered for requests made using an API Key or the Client Credentials Grant Type.
* @apiparam int hidden 1/0 indicating if the topic should be hidden
* @apiparam int rating Star rating
* @throws 2T312/9 INVALID_DATABASE The database ID does not exist
* @throws 2T312/A INVALID_ID The comment ID does not exist
* @throws 2T312/9 INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T312/A INVALID_ID The comment ID does not exist or the authorized user does not have permission to view it
* @throws 1T312/B NO_AUTHOR The author ID does not exist
* @throws 2T312/F NO_PERMISSION The authorized user does not have permission to edit the review
* @return \IPS\cms\Records\Review
*/
public function POSTitem( $database, $review )
@@ -228,6 +266,10 @@ class _reviews extends \IPS\Content\Api\CommentController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Review' . $database->id;
}
catch ( \OutOfRangeException $e )
@@ -240,6 +282,14 @@ class _reviews extends \IPS\Content\Api\CommentController
{
/* Load */
$review = call_user_func( array( $this->class, 'load' ), $review );
if ( $this->member and !$review->canView( $this->member ) )
{
throw new \OutOfRangeException;
}
if ( $this->member and !$review->canEdit( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T312/F', 403 );
}
/* Do it */
try
@@ -263,8 +313,9 @@ class _reviews extends \IPS\Content\Api\CommentController
*
* @param int $database Database ID
* @param int $review Comment ID
* @throws 2T312/C INVALID_DATABASE The database ID does not exist
* @throws 2T312/C INVALID_DATABASE The database ID does not exist or the authorized user does not have permission to view it
* @throws 2T312/D INVALID_ID The comment ID does not exist
* @throws 2T312/G NO_PERMISSION The authorized user does not have permission to delete the review
* @return void
*/
public function DELETEitem( $database, $review )
@@ -273,6 +324,10 @@ class _reviews extends \IPS\Content\Api\CommentController
try
{
$database = \IPS\cms\Databases::load( $database );
if ( $this->member and !$database->can( 'view', $this->member ) )
{
throw new \OutOfRangeException;
}
$this->class = 'IPS\cms\Records\Review' . $database->id;
}
catch ( \OutOfRangeException $e )
@@ -283,7 +338,13 @@ class _reviews extends \IPS\Content\Api\CommentController
/* Do it */
try
{
call_user_func( array( $this->class, 'load' ), $review )->delete();
$class = $this->class;
$object = $class::load( $id );
if ( $this->member and !$object->canDelete( $this->member ) )
{
throw new \IPS\Api\Exception( 'NO_PERMISSION', '2T312/G', 403 );
}
$object->delete();
return new \IPS\Api\Response( 200, NULL );
}