Files
api/services/nginx/app/routes/userRoute.php
T
Jepp9350 d28cb172a0 Add permission definitions to route handlers
This update introduces explicit permission definitions for various route handlers across multiple routes. These changes enhance clarity and allow for more granular control over route access based on defined permissions. The updates ensure better manageability and scalability of endpoint permissions.
2025-02-20 14:33:42 +01:00

184 lines
7.7 KiB
PHP

<?php
namespace routes;
use classes\authentication;
use classes\response;
use objects\logs_o;
use objects\users_o;
use traits\route_t;
class userRoute
{
use route_t;
public function run(): void
{
$this->get('/superuser/user', function () {
// Require the user to be logged in
global $response;
$this->requirePermission('get_user');
// Get the user object
$user = (new authentication())->get_user();
// Check if the request was successful
if ($user) {
// Log the incident
(new logs_o())->add('users', 'global', 1, $user->id, 'GET_USER', 'Successfully fetched user');
$targetUser = (new users_o())->automaticGetTargetUserFromRequest();
// Check if the user was found
if (!$targetUser->exists()) {
// Log the incident
(new logs_o())->add('users', 'global', 1, $user->id, 'GET_USER', 'No user found');
// Return an error
$response->error('User not found', 404);
}
// Return the list of users
$response->success(
$targetUser->includeIncludes(['all'])->asArray()
);
} else {
// Log the incident
(new logs_o())->add('users', 'global', 1, 0, 'GET_USER', 'No user found, or invalid session');
// Return an error
$response->error('Invalid session', 400);
}
},
[
'get_user' => 'Get user'
]
);
$this->get('/superuser/user/discounts', function () {
// Require the user to be logged in
global $response;
$this->requirePermission('get_custom_prices_other');
// Get the user object
$user = (new authentication())->get_user();
// Check if the request was successful
if ($user) {
// Log the incident
(new logs_o())->add('users', 'global', 1, $user->id, 'GET_CUSTOM_PRICE', 'Successfully fetched custom price');
$targetUser = (new users_o())->automaticGetTargetUserFromRequest();
// Check if the user was found
if (!$targetUser->exists()) {
// Log the incident
(new logs_o())->add('users', 'global', 1, $user->id, 'GET_CUSTOM_PRICE', 'No user found');
// Return an error
$response->error('User not found', 404);
}
// Return the list of users
$response->success(
$targetUser->getCustomPrices()
);
} else {
// Log the incident
(new logs_o())->add('users', 'global', 1, 0, 'GET_CUSTOM_PRICE', 'No user found, or invalid session');
// Return an error
$response->error('Invalid session', 400);
}
},
[
'get_custom_prices_other' => 'Get custom prices for other users'
]
);
$this->post('/superuser/user/discounts', function () {
// Require the user to be logged in
global /** @var response $response */
$response;
$this->requirePermission('set_custom_price');
// Get the user object
$user = (new authentication())->get_user();
// Check if the request was successful
if ($user) {
// Set the custom price
$targetUser = (new users_o())->automaticGetTargetUserFromRequest();
if (!$targetUser->exists()) {
// Log the incident
(new logs_o())->add('users', 'global', 1, $user->id, 'SET_CUSTOM_PRICE', 'No user found');
// Return an error
$response->add_meta('user_id', (int)$this->fromRequest('user_id'));
$response->error('User not found (target)', 404);
}
// Check if the required fields are set
$data = json_decode(file_get_contents('php://input'), true);
if (!isset($data['discount'])) {
// Log the incident
(new logs_o())->add('users', 'global', 1, $user->id, 'SET_CUSTOM_PRICE', 'No discount set');
// Return an error
$response->error('No discount set', 400);
}
if (!isset($data['object_id'])) {
// Log the incident
(new logs_o())->add('users', 'global', 1, $user->id, 'SET_CUSTOM_PRICE', 'No object_id set');
// Return an error
$response->error('No object_id set', 400);
}
if (!isset($data['is_category'])) {
// Log the incident
(new logs_o())->add('users', 'global', 1, $user->id, 'SET_CUSTOM_PRICE', 'No is_category set');
// Return an error
$response->error('No is_category set', 400);
}
$discount = (int)$data['discount'];
$is_category = (bool)$data['is_category'];
if ($is_category) {
$object_id = (string)$data['object_id'];
} else {
$object_id = (int)$data['object_id'];
}
// Set the custom price
$targetUser->setCustomPrice($targetUser->id, $object_id, $discount, $is_category);
// Log the incident
(new logs_o())->add('users', 'global', 1, $user->id, 'SET_CUSTOM_PRICE', 'Successfully set custom price');
// Return a success message
$response->success('Successfully set custom price');
} else {
// Log the incident
(new logs_o())->add('users', 'global', 1, 0, 'SET_CUSTOM_PRICE', 'No user found, or invalid session');
// Return an error
$response->error('Invalid session', 400);
}
},
[
'set_custom_price' => 'Set custom price'
]
);
$this->get('/admin/customer/getUserId', function () {
// Require the user to be logged in
global $response;
$this->requirePermission('get_user_id');
// Get the user object
$user = (new authentication())->get_user();
// Check if the request was successful
if ($user) {
// Log the incident
(new logs_o())->add('users', 'global', 1, $user->id, 'GET_USER_ID', 'Successfully fetched user id');
$targetUser = (new users_o())->automaticGetTargetUserFromRequest();
// Check if the user was found
if (!$targetUser->exists()) {
// Log the incident
(new logs_o())->add('users', 'global', 1, $user->id, 'GET_USER_ID', 'No user found');
// Return an error
$response->error('User not found', 404);
}
// Return the list of users
$response->success(
[
'user_id' => $targetUser->id
]
);
} else {
// Log the incident
(new logs_o())->add('users', 'global', 1, 0, 'GET_USER_ID', 'No user found, or invalid session');
// Return an error
$response->error('Invalid session', 400);
}
},
[
'get_user_id' => 'Get user id'
]
);
}
}