Add user id to the user object and fix thread user check
This commit is contained in:
parent
dc80ef022e
commit
4821746c5d
3 changed files with 22 additions and 19 deletions
|
|
@ -283,12 +283,13 @@ template createTFD() =
|
||||||
|
|
||||||
proc selectUser(userRow: seq[string], avatarSize: int=80): User =
|
proc selectUser(userRow: seq[string], avatarSize: int=80): User =
|
||||||
result = User(
|
result = User(
|
||||||
name: userRow[0],
|
id: userRow[0],
|
||||||
avatarUrl: userRow[1].getGravatarUrl(avatarSize),
|
name: userRow[1],
|
||||||
lastOnline: userRow[2].parseInt,
|
avatarUrl: userRow[2].getGravatarUrl(avatarSize),
|
||||||
previousVisitAt: userRow[3].parseInt,
|
lastOnline: userRow[3].parseInt,
|
||||||
rank: parseEnum[Rank](userRow[4]),
|
previousVisitAt: userRow[4].parseInt,
|
||||||
isDeleted: userRow[5] == "1"
|
rank: parseEnum[Rank](userRow[5]),
|
||||||
|
isDeleted: userRow[6] == "1"
|
||||||
)
|
)
|
||||||
|
|
||||||
# Don't give data about a deleted user.
|
# Don't give data about a deleted user.
|
||||||
|
|
@ -302,7 +303,7 @@ proc selectPost(postRow: seq[string], skippedPosts: seq[int],
|
||||||
return Post(
|
return Post(
|
||||||
id: postRow[0].parseInt,
|
id: postRow[0].parseInt,
|
||||||
replyingTo: replyingTo,
|
replyingTo: replyingTo,
|
||||||
author: selectUser(postRow[5..10]),
|
author: selectUser(postRow[5..11]),
|
||||||
likes: likes,
|
likes: likes,
|
||||||
seen: false, # TODO:
|
seen: false, # TODO:
|
||||||
history: history,
|
history: history,
|
||||||
|
|
@ -318,7 +319,7 @@ proc selectReplyingTo(replyingTo: string): Option[PostLink] =
|
||||||
|
|
||||||
const replyingToQuery = sql"""
|
const replyingToQuery = sql"""
|
||||||
select p.id, strftime('%s', p.creation), p.thread,
|
select p.id, strftime('%s', p.creation), p.thread,
|
||||||
u.name, u.email, strftime('%s', u.lastOnline),
|
u.id, u.name, u.email, strftime('%s', u.lastOnline),
|
||||||
strftime('%s', u.previousVisitAt), u.status,
|
strftime('%s', u.previousVisitAt), u.status,
|
||||||
u.isDeleted,
|
u.isDeleted,
|
||||||
t.name
|
t.name
|
||||||
|
|
@ -334,7 +335,7 @@ proc selectReplyingTo(replyingTo: string): Option[PostLink] =
|
||||||
topic: row[^1],
|
topic: row[^1],
|
||||||
threadId: row[2].parseInt(),
|
threadId: row[2].parseInt(),
|
||||||
postId: row[0].parseInt(),
|
postId: row[0].parseInt(),
|
||||||
author: some(selectUser(row[3..8]))
|
author: some(selectUser(row[3..9]))
|
||||||
))
|
))
|
||||||
|
|
||||||
proc selectHistory(postId: int): seq[PostInfo] =
|
proc selectHistory(postId: int): seq[PostInfo] =
|
||||||
|
|
@ -353,7 +354,7 @@ proc selectHistory(postId: int): seq[PostInfo] =
|
||||||
|
|
||||||
proc selectLikes(postId: int): seq[User] =
|
proc selectLikes(postId: int): seq[User] =
|
||||||
const likeQuery = sql"""
|
const likeQuery = sql"""
|
||||||
select u.name, u.email, strftime('%s', u.lastOnline),
|
select u.id, u.name, u.email, strftime('%s', u.lastOnline),
|
||||||
strftime('%s', u.previousVisitAt), u.status,
|
strftime('%s', u.previousVisitAt), u.status,
|
||||||
u.isDeleted
|
u.isDeleted
|
||||||
from like h, person u
|
from like h, person u
|
||||||
|
|
@ -368,9 +369,9 @@ proc selectLikes(postId: int): seq[User] =
|
||||||
proc selectThreadAuthor(threadId: int): User =
|
proc selectThreadAuthor(threadId: int): User =
|
||||||
const authorQuery =
|
const authorQuery =
|
||||||
sql"""
|
sql"""
|
||||||
select name, email, strftime('%s', lastOnline),
|
select u.id, name, email, strftime('%s', lastOnline),
|
||||||
strftime('%s', previousVisitAt), status, isDeleted
|
strftime('%s', previousVisitAt), status, isDeleted
|
||||||
from person where id in (
|
from person u where id in (
|
||||||
select author from post
|
select author from post
|
||||||
where thread = ?
|
where thread = ?
|
||||||
order by id
|
order by id
|
||||||
|
|
@ -386,7 +387,7 @@ proc selectThread(threadRow: seq[string], author: User): Thread =
|
||||||
where thread = ?;"""
|
where thread = ?;"""
|
||||||
const usersListQuery =
|
const usersListQuery =
|
||||||
sql"""
|
sql"""
|
||||||
select name, email, strftime('%s', lastOnline),
|
select u.id, name, email, strftime('%s', lastOnline),
|
||||||
strftime('%s', previousVisitAt), status, u.isDeleted,
|
strftime('%s', previousVisitAt), status, u.isDeleted,
|
||||||
count(*)
|
count(*)
|
||||||
from person u, post p where p.author = u.id and p.thread = ?
|
from person u, post p where p.author = u.id and p.thread = ?
|
||||||
|
|
@ -532,7 +533,7 @@ proc updateThread(c: TForumData, threadId: string, queryKeys: seq[string], query
|
||||||
let threadAuthor = selectThreadAuthor(threadId.parseInt)
|
let threadAuthor = selectThreadAuthor(threadId.parseInt)
|
||||||
|
|
||||||
# Verify that the current user has permissions to edit the specified thread.
|
# Verify that the current user has permissions to edit the specified thread.
|
||||||
let canEdit = c.rank in {Admin, Moderator} or c.userid == threadAuthor.name
|
let canEdit = c.rank in {Admin, Moderator} or c.userid == threadAuthor.id
|
||||||
if not canEdit:
|
if not canEdit:
|
||||||
raise newForumError("You cannot edit this thread")
|
raise newForumError("You cannot edit this thread")
|
||||||
|
|
||||||
|
|
@ -834,7 +835,7 @@ routes:
|
||||||
const threadsQuery =
|
const threadsQuery =
|
||||||
"""select t.id, t.name, views, strftime('%s', modified), isLocked,
|
"""select t.id, t.name, views, strftime('%s', modified), isLocked,
|
||||||
c.id, c.name, c.description, c.color,
|
c.id, c.name, c.description, c.color,
|
||||||
u.name, u.email, strftime('%s', u.lastOnline),
|
u.id, u.name, u.email, strftime('%s', u.lastOnline),
|
||||||
strftime('%s', u.previousVisitAt), u.status, u.isDeleted
|
strftime('%s', u.previousVisitAt), u.status, u.isDeleted
|
||||||
from thread t, category c, person u
|
from thread t, category c, person u
|
||||||
where t.isDeleted = 0 and category = c.id and $#
|
where t.isDeleted = 0 and category = c.id and $#
|
||||||
|
|
@ -879,7 +880,7 @@ routes:
|
||||||
sql(
|
sql(
|
||||||
"""select p.id, p.content, strftime('%s', p.creation), p.author,
|
"""select p.id, p.content, strftime('%s', p.creation), p.author,
|
||||||
p.replyingTo,
|
p.replyingTo,
|
||||||
u.name, u.email, strftime('%s', u.lastOnline),
|
u.id, u.name, u.email, strftime('%s', u.lastOnline),
|
||||||
strftime('%s', u.previousVisitAt), u.status,
|
strftime('%s', u.previousVisitAt), u.status,
|
||||||
u.isDeleted
|
u.isDeleted
|
||||||
from post p, person u
|
from post p, person u
|
||||||
|
|
@ -926,7 +927,7 @@ routes:
|
||||||
let postsQuery = sql("""
|
let postsQuery = sql("""
|
||||||
select p.id, p.content, strftime('%s', p.creation), p.author,
|
select p.id, p.content, strftime('%s', p.creation), p.author,
|
||||||
p.replyingTo,
|
p.replyingTo,
|
||||||
u.name, u.email, strftime('%s', u.lastOnline),
|
u.id, u.name, u.email, strftime('%s', u.lastOnline),
|
||||||
strftime('%s', u.previousVisitAt), u.status,
|
strftime('%s', u.previousVisitAt), u.status,
|
||||||
u.isDeleted
|
u.isDeleted
|
||||||
from post p, person u
|
from post p, person u
|
||||||
|
|
@ -995,7 +996,7 @@ routes:
|
||||||
""" % postsFrom)
|
""" % postsFrom)
|
||||||
|
|
||||||
let userQuery = sql("""
|
let userQuery = sql("""
|
||||||
select name, email, strftime('%s', lastOnline),
|
select id, name, email, strftime('%s', lastOnline),
|
||||||
strftime('%s', previousVisitAt), status, isDeleted,
|
strftime('%s', previousVisitAt), status, isDeleted,
|
||||||
strftime('%s', creation), id
|
strftime('%s', creation), id
|
||||||
from person
|
from person
|
||||||
|
|
@ -1570,7 +1571,7 @@ routes:
|
||||||
postId: rowFT[2].parseInt(),
|
postId: rowFT[2].parseInt(),
|
||||||
postContent: content,
|
postContent: content,
|
||||||
creation: rowFT[4].parseInt(),
|
creation: rowFT[4].parseInt(),
|
||||||
author: selectUser(rowFT[5 .. 10]),
|
author: selectUser(rowFT[5 .. 11]),
|
||||||
)
|
)
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -17,6 +17,7 @@ type
|
||||||
Admin ## Admin: can do everything
|
Admin ## Admin: can do everything
|
||||||
|
|
||||||
User* = object
|
User* = object
|
||||||
|
id*: string
|
||||||
name*: string
|
name*: string
|
||||||
avatarUrl*: string
|
avatarUrl*: string
|
||||||
lastOnline*: int64
|
lastOnline*: int64
|
||||||
|
|
|
||||||
|
|
@ -46,6 +46,7 @@ SELECT
|
||||||
THEN snippet(post_fts, '**', '**', '...', what, -45)
|
THEN snippet(post_fts, '**', '**', '...', what, -45)
|
||||||
ELSE SUBSTR(post_fts.content, 1, 200) END AS content,
|
ELSE SUBSTR(post_fts.content, 1, 200) END AS content,
|
||||||
cdate,
|
cdate,
|
||||||
|
person.id,
|
||||||
person.name AS author,
|
person.name AS author,
|
||||||
person.email AS email,
|
person.email AS email,
|
||||||
strftime('%s', person.lastOnline) AS lastOnline,
|
strftime('%s', person.lastOnline) AS lastOnline,
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue