UNPKG

@intuitionrobotics/permissions

Version:
55 lines 3.05 kB
"use strict"; /* * ts-common is the basic building blocks of our typescript projects * * Copyright (C) 2020 Intuition Robotics * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. * You may obtain a copy of the License at * * http://www.apache.org/licenses/LICENSE-2.0 * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. * See the License for the specific language governing permissions and * limitations under the License. */ var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) { function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); } return new (P || (P = Promise))(function (resolve, reject) { function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } } function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } } function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); } step((generator = generator.apply(thisArg, _arguments || [])).next()); }); }; Object.defineProperty(exports, "__esModule", { value: true }); const backend_1 = require("@intuitionrobotics/thunderstorm/backend"); const _imports_1 = require("../_imports"); const thunderstorm_1 = require("@intuitionrobotics/thunderstorm"); const AccountModule_1 = require("@intuitionrobotics/user-account/app-backend/modules/AccountModule"); class ServerApi_UserUrlsPermissions extends backend_1.ServerApi { constructor() { super(thunderstorm_1.HttpMethod.POST, "app-permissions"); this.dontPrintResponse(); } process(request, response, queryParams, body) { return __awaiter(this, void 0, void 0, function* () { // TODO add to the request body the api that wants to use this feature.. in order to assert user permissions to perform an action // TODO and save our ass from a potential application security bugs const account = yield AccountModule_1.AccountModule.validateSession(request, this.getScopes(), response); let assignAppPermissions; if (body.appAccountId) // when creating project assignAppPermissions = Object.assign(Object.assign({}, body), { granterUserId: body.appAccountId, sharedUserIds: [account._id] }); else // when I share with you assignAppPermissions = Object.assign(Object.assign({}, body), { granterUserId: account._id, sharedUserIds: body.sharedUserIds }); yield _imports_1.UserPermissionsDB.assignAppPermissions(assignAppPermissions, request); }); } } module.exports = new ServerApi_UserUrlsPermissions(); //# sourceMappingURL=app-permissions.js.map