@intuitionrobotics/permissions
Version:
55 lines • 3.05 kB
JavaScript
;
/*
* ts-common is the basic building blocks of our typescript projects
*
* Copyright (C) 2020 Intuition Robotics
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) {
function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); }
return new (P || (P = Promise))(function (resolve, reject) {
function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } }
function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } }
function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); }
step((generator = generator.apply(thisArg, _arguments || [])).next());
});
};
Object.defineProperty(exports, "__esModule", { value: true });
const backend_1 = require("@intuitionrobotics/thunderstorm/backend");
const _imports_1 = require("../_imports");
const thunderstorm_1 = require("@intuitionrobotics/thunderstorm");
const AccountModule_1 = require("@intuitionrobotics/user-account/app-backend/modules/AccountModule");
class ServerApi_UserUrlsPermissions extends backend_1.ServerApi {
constructor() {
super(thunderstorm_1.HttpMethod.POST, "app-permissions");
this.dontPrintResponse();
}
process(request, response, queryParams, body) {
return __awaiter(this, void 0, void 0, function* () {
// TODO add to the request body the api that wants to use this feature.. in order to assert user permissions to perform an action
// TODO and save our ass from a potential application security bugs
const account = yield AccountModule_1.AccountModule.validateSession(request, this.getScopes(), response);
let assignAppPermissions;
if (body.appAccountId)
// when creating project
assignAppPermissions = Object.assign(Object.assign({}, body), { granterUserId: body.appAccountId, sharedUserIds: [account._id] });
else
// when I share with you
assignAppPermissions = Object.assign(Object.assign({}, body), { granterUserId: account._id, sharedUserIds: body.sharedUserIds });
yield _imports_1.UserPermissionsDB.assignAppPermissions(assignAppPermissions, request);
});
}
}
module.exports = new ServerApi_UserUrlsPermissions();
//# sourceMappingURL=app-permissions.js.map