diff --git a/app/Controllers/Http/Api/v1/LessonsController.ts b/app/Controllers/Http/Api/v1/LessonsController.ts index 8b535cc..43d8869 100644 --- a/app/Controllers/Http/Api/v1/LessonsController.ts +++ b/app/Controllers/Http/Api/v1/LessonsController.ts @@ -1,3 +1,4 @@ +import { Exception } from '@adonisjs/core/build/standalone'; import { HttpContextContract } from '@ioc:Adonis/Core/HttpContext'; /** @@ -103,7 +104,20 @@ export default class LessonsController extends BaseController { * GET /lessons/:id/content */ public async getContent(ctx: HttpContextContract) { - const lesson = await this.Lesson.query().preload('content').where('id', ctx.params.id).firstOrFail(); + const user = await ctx.auth.use('api').authenticate(); + const lesson = await this.Lesson.query() + .preload('content') + .preload('course') + .where('id', ctx.params.id) + .firstOrFail(); + + await user.load('courses'); + + const userHasCourse = user.courses.find(course => course.id === lesson.course.id); + + if (!userHasCourse) { + throw new Exception('The user is not a student of this course.', 403, 'E_ACCESS_DENIED'); + } return this.sendResponse(ctx, lesson.content, 'Lesson content fetched.'); } diff --git a/app/Validators/Lesson/CreateLessonValidator.ts b/app/Validators/Lesson/CreateLessonValidator.ts index 1827c2a..55d67c1 100644 --- a/app/Validators/Lesson/CreateLessonValidator.ts +++ b/app/Validators/Lesson/CreateLessonValidator.ts @@ -8,7 +8,7 @@ export default class CreateLessonValidator { course_id: schema.string({}, [rules.exists({ table: 'courses', column: 'id' })]), title: schema.string({}, [rules.maxLength(255)]), description: schema.string(), - video_url: schema.string(), + video_url: schema.string({}, [rules.url()]), }); public messages = {};