mirror of
https://github.com/BobbyWibowo/lolisafe.git
synced 2025-01-19 01:31:34 +00:00
Updated albumsController to use new auth
This commit is contained in:
parent
16164115aa
commit
751a876360
@ -5,15 +5,18 @@ let albumsController = {}
|
||||
|
||||
albumsController.list = function(req, res, next){
|
||||
|
||||
if(req.headers.auth !== config.adminToken)
|
||||
return res.status(401).json({ success: false, description: 'not-authorized'})
|
||||
let token = req.headers.token
|
||||
if(token === undefined) return res.status(401).json({ success: false, description: 'No token provided' })
|
||||
|
||||
db.table('users').where('token', token).then((user) => {
|
||||
if(user.length === 0) return res.status(401).json({ success: false, description: 'Invalid token'})
|
||||
|
||||
let fields = ['id', 'name']
|
||||
|
||||
if(req.params.sidebar === undefined)
|
||||
fields.push('timestamp')
|
||||
|
||||
db.table('albums').select(fields).where('enabled', 1).then((albums) => {
|
||||
db.table('albums').select(fields).where({enabled: 1, userid: user.id}).then((albums) => {
|
||||
|
||||
if(req.params.sidebar !== undefined)
|
||||
return res.json({ success: true, albums })
|
||||
@ -37,46 +40,66 @@ albumsController.list = function(req, res, next){
|
||||
return res.json({ success: true, albums })
|
||||
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
|
||||
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
|
||||
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
|
||||
|
||||
}
|
||||
|
||||
albumsController.create = function(req, res, next){
|
||||
|
||||
if(req.headers.auth !== config.adminToken)
|
||||
return res.status(401).json({ success: false, description: 'not-authorized'})
|
||||
let token = req.headers.token
|
||||
if(token === undefined) return res.status(401).json({ success: false, description: 'No token provided' })
|
||||
|
||||
db.table('users').where('token', token).then((user) => {
|
||||
if(user.length === 0) return res.status(401).json({ success: false, description: 'Invalid token'})
|
||||
|
||||
let name = req.body.name
|
||||
if(name === undefined || name === '')
|
||||
return res.json({ success: false, description: 'No album name specified' })
|
||||
|
||||
db.table('albums').where('name', name).where('enabled', 1).then((album) => {
|
||||
db.table('albums').where({
|
||||
name: name,
|
||||
enabled: 1,
|
||||
userid: user.id
|
||||
}).then((album) => {
|
||||
if(album.length !== 0) return res.json({ success: false, description: 'There\'s already an album with that name' })
|
||||
|
||||
db.table('albums').insert({
|
||||
name: name,
|
||||
enabled: 1,
|
||||
userid: user.id,
|
||||
timestamp: Math.floor(Date.now() / 1000)
|
||||
}).then(() => {
|
||||
return res.json({ success: true })
|
||||
})
|
||||
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
|
||||
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
|
||||
|
||||
|
||||
}
|
||||
|
||||
albumsController.delete = function(req, res, next){
|
||||
if(req.headers.auth !== config.adminToken)
|
||||
return res.status(401).json({ success: false, description: 'not-authorized'})
|
||||
let token = req.headers.token
|
||||
if(token === undefined) return res.status(401).json({ success: false, description: 'No token provided' })
|
||||
|
||||
db.table('users').where('token', token).then((user) => {
|
||||
if(user.length === 0) return res.status(401).json({ success: false, description: 'Invalid token'})
|
||||
|
||||
let id = req.body.id
|
||||
if(id === undefined || id === '')
|
||||
return res.json({ success: false, description: 'No album specified' })
|
||||
|
||||
db.table('albums').where('id', id).update({ enabled: 0 }).then(() => {
|
||||
db.table('albums').where({id: id, userid: user.id}).update({ enabled: 0 }).then(() => {
|
||||
return res.json({ success: true })
|
||||
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
|
||||
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
|
||||
}
|
||||
|
||||
albumsController.rename = function(req, res, next){
|
||||
if(req.headers.auth !== config.adminToken)
|
||||
return res.status(401).json({ success: false, description: 'not-authorized'})
|
||||
let token = req.headers.token
|
||||
if(token === undefined) return res.status(401).json({ success: false, description: 'No token provided' })
|
||||
|
||||
db.table('users').where('token', token).then((user) => {
|
||||
if(user.length === 0) return res.status(401).json({ success: false, description: 'Invalid token'})
|
||||
|
||||
let id = req.body.id
|
||||
if(id === undefined || id === '')
|
||||
@ -86,14 +109,14 @@ albumsController.rename = function(req, res, next){
|
||||
if(name === undefined || name === '')
|
||||
return res.json({ success: false, description: 'No name specified' })
|
||||
|
||||
db.table('albums').where('name', name).then((results) => {
|
||||
if(results.length !== 0)
|
||||
return res.json({ success: false, description: 'Name already in use' })
|
||||
db.table('albums').where({name: name, userid: user.id}).then((results) => {
|
||||
if(results.length !== 0) return res.json({ success: false, description: 'Name already in use' })
|
||||
|
||||
db.table('albums').where('id', id).update({ name: name }).then(() => {
|
||||
db.table('albums').where({id: id, userid: user.id}).update({ name: name }).then(() => {
|
||||
return res.json({ success: true })
|
||||
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
|
||||
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
|
||||
}).catch(function(error) { console.log(error); res.json({success: false, description: 'error'}) })
|
||||
|
||||
}
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user