| 1 |
|
| 2 |
|
| 3 |
|
| 4 |
|
| 5 |
|
| 6 |
|
| 7 |
|
| 8 |
|
| 9 |
|
| 10 |
|
| 11 |
|
| 12 |
|
| 13 |
|
| 14 |
|
| 15 |
|
| 16 |
|
| 17 |
|
| 18 |
|
| 19 |
|
| 20 |
|
| 21 |
|
| 22 |
|
| 23 |
|
| 24 |
|
| 25 |
|
| 26 |
|
| 27 |
|
| 28 |
|
| 29 |
|
| 30 |
|
| 31 |
|
| 32 |
|
| 33 |
|
| 34 |
|
| 35 |
use axum::response::{IntoResponse, Response}; |
| 36 |
use uuid::Uuid; |
| 37 |
|
| 38 |
use mt_core::types::CommunityRole; |
| 39 |
use mt_db::queries::{CommunityRow, PostForEdit, ThreadWithBreadcrumb, Unscoped}; |
| 40 |
|
| 41 |
use super::{check_write_access, db_error, get_community, get_role, is_mod_or_owner, parse_uuid}; |
| 42 |
|
| 43 |
|
| 44 |
|
| 45 |
|
| 46 |
|
| 47 |
|
| 48 |
pub(crate) trait ScopedResource: Sized + Send { |
| 49 |
fn load( |
| 50 |
db: &sqlx::PgPool, |
| 51 |
id: Uuid, |
| 52 |
) -> impl std::future::Future<Output = Result<Option<Unscoped<Self>>, sqlx::Error>> + Send; |
| 53 |
} |
| 54 |
|
| 55 |
impl ScopedResource for ThreadWithBreadcrumb { |
| 56 |
async fn load(db: &sqlx::PgPool, id: Uuid) -> Result<Option<Unscoped<Self>>, sqlx::Error> { |
| 57 |
mt_db::queries::get_thread_with_breadcrumb(db, id).await |
| 58 |
} |
| 59 |
} |
| 60 |
|
| 61 |
impl ScopedResource for PostForEdit { |
| 62 |
async fn load(db: &sqlx::PgPool, id: Uuid) -> Result<Option<Unscoped<Self>>, sqlx::Error> { |
| 63 |
mt_db::queries::get_post_for_edit(db, id).await |
| 64 |
} |
| 65 |
} |
| 66 |
|
| 67 |
|
| 68 |
|
| 69 |
|
| 70 |
|
| 71 |
|
| 72 |
pub(crate) struct CommunityScope<T> { |
| 73 |
pub(crate) community: CommunityRow, |
| 74 |
pub(crate) resource: T, |
| 75 |
} |
| 76 |
|
| 77 |
impl<T: ScopedResource> CommunityScope<T> { |
| 78 |
|
| 79 |
|
| 80 |
#[allow(clippy::result_large_err)] |
| 81 |
pub(crate) async fn resolve( |
| 82 |
db: &sqlx::PgPool, |
| 83 |
slug: &str, |
| 84 |
resource_id_str: &str, |
| 85 |
) -> Result<Self, Response> { |
| 86 |
let community = get_community(db, slug).await?; |
| 87 |
let id = parse_uuid(resource_id_str)?; |
| 88 |
|
| 89 |
|
| 90 |
|
| 91 |
|
| 92 |
let resource = T::load(db, id) |
| 93 |
.await |
| 94 |
.map_err(db_error)? |
| 95 |
.and_then(|scoped| scoped.in_community(community.id)) |
| 96 |
.ok_or_else(crate::error_page::not_found)?; |
| 97 |
Ok(Self { |
| 98 |
community, |
| 99 |
resource, |
| 100 |
}) |
| 101 |
} |
| 102 |
|
| 103 |
|
| 104 |
#[allow(clippy::result_large_err)] |
| 105 |
pub(crate) async fn require_write_access( |
| 106 |
&self, |
| 107 |
db: &sqlx::PgPool, |
| 108 |
user_id: Uuid, |
| 109 |
) -> Result<(), Response> { |
| 110 |
check_write_access( |
| 111 |
db, |
| 112 |
self.community.id, |
| 113 |
user_id, |
| 114 |
self.community.suspended_at.is_some(), |
| 115 |
) |
| 116 |
.await |
| 117 |
} |
| 118 |
|
| 119 |
|
| 120 |
#[allow(clippy::result_large_err)] |
| 121 |
pub(crate) async fn role( |
| 122 |
&self, |
| 123 |
db: &sqlx::PgPool, |
| 124 |
user_id: Uuid, |
| 125 |
) -> Result<Option<CommunityRole>, Response> { |
| 126 |
get_role(db, user_id, self.community.id).await |
| 127 |
} |
| 128 |
|
| 129 |
|
| 130 |
|
| 131 |
|
| 132 |
|
| 133 |
|
| 134 |
|
| 135 |
|
| 136 |
|
| 137 |
|
| 138 |
#[allow(clippy::result_large_err)] |
| 139 |
pub(crate) async fn require_mod_write( |
| 140 |
&self, |
| 141 |
db: &sqlx::PgPool, |
| 142 |
user_id: Uuid, |
| 143 |
) -> Result<Option<CommunityRole>, Response> { |
| 144 |
let role = self.role(db, user_id).await?; |
| 145 |
if !is_mod_or_owner(role) { |
| 146 |
return Err(axum::http::StatusCode::FORBIDDEN.into_response()); |
| 147 |
} |
| 148 |
if self.community.suspended_at.is_some() { |
| 149 |
return Err(( |
| 150 |
axum::http::StatusCode::FORBIDDEN, |
| 151 |
"This community has been suspended.", |
| 152 |
) |
| 153 |
.into_response()); |
| 154 |
} |
| 155 |
Ok(role) |
| 156 |
} |
| 157 |
} |
| 158 |
|