mirror of
https://github.com/sergeyyarkov/educt-server.git
synced 2026-10-11 10:19:20 +03:00
added permission on show content for lesson
This commit is contained in:
parent
6979e0b912
commit
419495d39c
@ -1,3 +1,4 @@
|
|||||||
|
import { Exception } from '@adonisjs/core/build/standalone';
|
||||||
import { HttpContextContract } from '@ioc:Adonis/Core/HttpContext';
|
import { HttpContextContract } from '@ioc:Adonis/Core/HttpContext';
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@ -103,7 +104,20 @@ export default class LessonsController extends BaseController {
|
|||||||
* GET /lessons/:id/content
|
* GET /lessons/:id/content
|
||||||
*/
|
*/
|
||||||
public async getContent(ctx: HttpContextContract) {
|
public async getContent(ctx: HttpContextContract) {
|
||||||
const lesson = await this.Lesson.query().preload('content').where('id', ctx.params.id).firstOrFail();
|
const user = await ctx.auth.use('api').authenticate();
|
||||||
|
const lesson = await this.Lesson.query()
|
||||||
|
.preload('content')
|
||||||
|
.preload('course')
|
||||||
|
.where('id', ctx.params.id)
|
||||||
|
.firstOrFail();
|
||||||
|
|
||||||
|
await user.load('courses');
|
||||||
|
|
||||||
|
const userHasCourse = user.courses.find(course => course.id === lesson.course.id);
|
||||||
|
|
||||||
|
if (!userHasCourse) {
|
||||||
|
throw new Exception('The user is not a student of this course.', 403, 'E_ACCESS_DENIED');
|
||||||
|
}
|
||||||
|
|
||||||
return this.sendResponse(ctx, lesson.content, 'Lesson content fetched.');
|
return this.sendResponse(ctx, lesson.content, 'Lesson content fetched.');
|
||||||
}
|
}
|
||||||
|
|||||||
@ -8,7 +8,7 @@ export default class CreateLessonValidator {
|
|||||||
course_id: schema.string({}, [rules.exists({ table: 'courses', column: 'id' })]),
|
course_id: schema.string({}, [rules.exists({ table: 'courses', column: 'id' })]),
|
||||||
title: schema.string({}, [rules.maxLength(255)]),
|
title: schema.string({}, [rules.maxLength(255)]),
|
||||||
description: schema.string(),
|
description: schema.string(),
|
||||||
video_url: schema.string(),
|
video_url: schema.string({}, [rules.url()]),
|
||||||
});
|
});
|
||||||
|
|
||||||
public messages = {};
|
public messages = {};
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user