Merge branch 'api-fixes' of https://github.com/bentiss/wekan into bentiss-api-fixes

This commit is contained in:
Lauri Ojansivu 2018-10-23 20:44:35 +03:00
commit 0de0135619
6 changed files with 63 additions and 14 deletions

View file

@ -136,6 +136,7 @@ ENV BUILD_DEPS="apt-utils bsdtar gnupg gosu wget curl bzip2 build-essential pyth
COPY ${SRC_PATH} /home/wekan/app COPY ${SRC_PATH} /home/wekan/app
RUN \ RUN \
set -o xtrace && \
# Add non-root user wekan # Add non-root user wekan
useradd --user-group --system --home-dir /home/wekan wekan && \ useradd --user-group --system --home-dir /home/wekan wekan && \
\ \

View file

@ -276,6 +276,10 @@ Boards.helpers({
return Users.find({ _id: { $in: _.pluck(this.members, 'userId') } }); return Users.find({ _id: { $in: _.pluck(this.members, 'userId') } });
}, },
getMember(id) {
return _.findWhere(this.members, { userId: id });
},
getLabel(name, color) { getLabel(name, color) {
return _.findWhere(this.labels, { name, color }); return _.findWhere(this.labels, { name, color });
}, },
@ -823,9 +827,9 @@ if (Meteor.isServer) {
} }
}); });
JsonRoutes.add('GET', '/api/boards/:id', function (req, res) { JsonRoutes.add('GET', '/api/boards/:boardId', function (req, res) {
try { try {
const id = req.params.id; const id = req.params.boardId;
Authentication.checkBoardAccess(req.userId, id); Authentication.checkBoardAccess(req.userId, id);
JsonRoutes.sendResult(res, { JsonRoutes.sendResult(res, {
@ -841,6 +845,34 @@ if (Meteor.isServer) {
} }
}); });
JsonRoutes.add('PUT', '/api/boards/:boardId/members', function (req, res) {
Authentication.checkUserId(req.userId);
try {
const boardId = req.params.boardId;
const board = Boards.findOne({ _id: boardId });
const userId = req.body.userId;
const user = Users.findOne({ _id: userId });
if (!board.getMember(userId)) {
user.addInvite(boardId);
board.addMember(userId);
JsonRoutes.sendResult(res, {
code: 200,
data: id,
});
} else {
JsonRoutes.sendResult(res, {
code: 200,
});
}
}
catch (error) {
JsonRoutes.sendResult(res, {
data: error,
});
}
});
JsonRoutes.add('POST', '/api/boards', function (req, res) { JsonRoutes.add('POST', '/api/boards', function (req, res) {
try { try {
Authentication.checkUserId(req.userId); Authentication.checkUserId(req.userId);
@ -878,10 +910,10 @@ if (Meteor.isServer) {
} }
}); });
JsonRoutes.add('DELETE', '/api/boards/:id', function (req, res) { JsonRoutes.add('DELETE', '/api/boards/:boardId', function (req, res) {
try { try {
Authentication.checkUserId(req.userId); Authentication.checkUserId(req.userId);
const id = req.params.id; const id = req.params.boardId;
Boards.remove({ _id: id }); Boards.remove({ _id: id });
JsonRoutes.sendResult(res, { JsonRoutes.sendResult(res, {
code: 200, code: 200,
@ -898,9 +930,9 @@ if (Meteor.isServer) {
} }
}); });
JsonRoutes.add('PUT', '/api/boards/:id/labels', function (req, res) { JsonRoutes.add('PUT', '/api/boards/:boardId/labels', function (req, res) {
Authentication.checkUserId(req.userId); Authentication.checkUserId(req.userId);
const id = req.params.id; const id = req.params.boardId;
try { try {
if (req.body.hasOwnProperty('label')) { if (req.body.hasOwnProperty('label')) {
const board = Boards.findOne({ _id: id }); const board = Boards.findOne({ _id: id });

View file

@ -1514,6 +1514,16 @@ if (Meteor.isServer) {
Cards.direct.update({_id: paramCardId, listId: paramListId, boardId: paramBoardId, archived: false}, Cards.direct.update({_id: paramCardId, listId: paramListId, boardId: paramBoardId, archived: false},
{$set: {customFields: newcustomFields}}); {$set: {customFields: newcustomFields}});
} }
if (req.body.hasOwnProperty('members')) {
const newmembers = req.body.members;
Cards.direct.update({_id: paramCardId, listId: paramListId, boardId: paramBoardId, archived: false},
{$set: {members: newmembers}});
}
if (req.body.hasOwnProperty('swimlaneId')) {
const newParamSwimlaneId = req.body.swimlaneId;
Cards.direct.update({_id: paramCardId, listId: paramListId, boardId: paramBoardId, archived: false},
{$set: {swimlaneId: newParamSwimlaneId}});
}
JsonRoutes.sendResult(res, { JsonRoutes.sendResult(res, {
code: 200, code: 200,
data: { data: {

View file

@ -87,7 +87,13 @@ if (Meteor.isServer) {
const paramBoardId = req.params.boardId; const paramBoardId = req.params.boardId;
JsonRoutes.sendResult(res, { JsonRoutes.sendResult(res, {
code: 200, code: 200,
data: CustomFields.find({ boardId: paramBoardId }), data: CustomFields.find({ boardId: paramBoardId }).map(function (cf) {
return {
_id: cf._id,
name: cf.name,
type: cf.type,
};
}),
}); });
}); });

View file

@ -48,7 +48,7 @@ class Exporter {
build() { build() {
const byBoard = { boardId: this._boardId }; const byBoard = { boardId: this._boardId };
const byBoardNoLinked = { boardId: this._boardId, linkedId: '' }; const byBoardNoLinked = { boardId: this._boardId, linkedId: {$in: ['', null] } };
// we do not want to retrieve boardId in related elements // we do not want to retrieve boardId in related elements
const noBoardId = { const noBoardId = {
fields: { fields: {

View file

@ -713,10 +713,10 @@ if (Meteor.isServer) {
} }
}); });
JsonRoutes.add('GET', '/api/users/:id', function (req, res) { JsonRoutes.add('GET', '/api/users/:userId', function (req, res) {
try { try {
Authentication.checkUserId(req.userId); Authentication.checkUserId(req.userId);
const id = req.params.id; const id = req.params.userId;
JsonRoutes.sendResult(res, { JsonRoutes.sendResult(res, {
code: 200, code: 200,
data: Meteor.users.findOne({ _id: id }), data: Meteor.users.findOne({ _id: id }),
@ -730,10 +730,10 @@ if (Meteor.isServer) {
} }
}); });
JsonRoutes.add('PUT', '/api/users/:id', function (req, res) { JsonRoutes.add('PUT', '/api/users/:userId', function (req, res) {
try { try {
Authentication.checkUserId(req.userId); Authentication.checkUserId(req.userId);
const id = req.params.id; const id = req.params.userId;
const action = req.body.action; const action = req.body.action;
let data = Meteor.users.findOne({ _id: id }); let data = Meteor.users.findOne({ _id: id });
if (data !== undefined) { if (data !== undefined) {
@ -872,10 +872,10 @@ if (Meteor.isServer) {
} }
}); });
JsonRoutes.add('DELETE', '/api/users/:id', function (req, res) { JsonRoutes.add('DELETE', '/api/users/:userId', function (req, res) {
try { try {
Authentication.checkUserId(req.userId); Authentication.checkUserId(req.userId);
const id = req.params.id; const id = req.params.userId;
Meteor.users.remove({ _id: id }); Meteor.users.remove({ _id: id });
JsonRoutes.sendResult(res, { JsonRoutes.sendResult(res, {
code: 200, code: 200,