|
@@ -301,8 +301,8 @@ if (Meteor.isServer) {
|
|
req,
|
|
req,
|
|
res,
|
|
res,
|
|
) {
|
|
) {
|
|
- Authentication.checkUserId(req.userId);
|
|
|
|
const paramBoardId = req.params.boardId;
|
|
const paramBoardId = req.params.boardId;
|
|
|
|
+ Authentication.checkBoardAccess(req.userId, paramBoardId);
|
|
JsonRoutes.sendResult(res, {
|
|
JsonRoutes.sendResult(res, {
|
|
code: 200,
|
|
code: 200,
|
|
data: CustomFields.find({ boardIds: { $in: [paramBoardId] } }).map(
|
|
data: CustomFields.find({ boardIds: { $in: [paramBoardId] } }).map(
|
|
@@ -330,9 +330,9 @@ if (Meteor.isServer) {
|
|
'GET',
|
|
'GET',
|
|
'/api/boards/:boardId/custom-fields/:customFieldId',
|
|
'/api/boards/:boardId/custom-fields/:customFieldId',
|
|
function(req, res) {
|
|
function(req, res) {
|
|
- Authentication.checkUserId(req.userId);
|
|
|
|
const paramBoardId = req.params.boardId;
|
|
const paramBoardId = req.params.boardId;
|
|
const paramCustomFieldId = req.params.customFieldId;
|
|
const paramCustomFieldId = req.params.customFieldId;
|
|
|
|
+ Authentication.checkBoardAccess(req.userId, paramBoardId);
|
|
JsonRoutes.sendResult(res, {
|
|
JsonRoutes.sendResult(res, {
|
|
code: 200,
|
|
code: 200,
|
|
data: CustomFields.findOne({
|
|
data: CustomFields.findOne({
|
|
@@ -361,8 +361,8 @@ if (Meteor.isServer) {
|
|
req,
|
|
req,
|
|
res,
|
|
res,
|
|
) {
|
|
) {
|
|
- Authentication.checkUserId(req.userId);
|
|
|
|
const paramBoardId = req.params.boardId;
|
|
const paramBoardId = req.params.boardId;
|
|
|
|
+ Authentication.checkBoardAccess(req.userId, paramBoardId);
|
|
const board = Boards.findOne({ _id: paramBoardId });
|
|
const board = Boards.findOne({ _id: paramBoardId });
|
|
const id = CustomFields.direct.insert({
|
|
const id = CustomFields.direct.insert({
|
|
name: req.body.name,
|
|
name: req.body.name,
|
|
@@ -406,9 +406,9 @@ if (Meteor.isServer) {
|
|
'PUT',
|
|
'PUT',
|
|
'/api/boards/:boardId/custom-fields/:customFieldId',
|
|
'/api/boards/:boardId/custom-fields/:customFieldId',
|
|
(req, res) => {
|
|
(req, res) => {
|
|
- Authentication.checkUserId(req.userId);
|
|
|
|
const paramBoardId = req.params.boardId;
|
|
const paramBoardId = req.params.boardId;
|
|
const paramFieldId = req.params.customFieldId;
|
|
const paramFieldId = req.params.customFieldId;
|
|
|
|
+ Authentication.checkBoardAccess(req.userId, paramBoardId);
|
|
|
|
|
|
if (req.body.hasOwnProperty('name')) {
|
|
if (req.body.hasOwnProperty('name')) {
|
|
CustomFields.direct.update(
|
|
CustomFields.direct.update(
|
|
@@ -479,9 +479,9 @@ if (Meteor.isServer) {
|
|
'POST',
|
|
'POST',
|
|
'/api/boards/:boardId/custom-fields/:customFieldId/dropdown-items',
|
|
'/api/boards/:boardId/custom-fields/:customFieldId/dropdown-items',
|
|
(req, res) => {
|
|
(req, res) => {
|
|
- Authentication.checkUserId(req.userId);
|
|
|
|
const paramBoardId = req.params.boardId;
|
|
const paramBoardId = req.params.boardId;
|
|
const paramCustomFieldId = req.params.customFieldId;
|
|
const paramCustomFieldId = req.params.customFieldId;
|
|
|
|
+ Authentication.checkBoardAccess(req.userId, paramBoardId);
|
|
const paramItems = req.body.items;
|
|
const paramItems = req.body.items;
|
|
|
|
|
|
if (req.body.hasOwnProperty('items')) {
|
|
if (req.body.hasOwnProperty('items')) {
|
|
@@ -522,10 +522,10 @@ if (Meteor.isServer) {
|
|
'PUT',
|
|
'PUT',
|
|
'/api/boards/:boardId/custom-fields/:customFieldId/dropdown-items/:dropdownItemId',
|
|
'/api/boards/:boardId/custom-fields/:customFieldId/dropdown-items/:dropdownItemId',
|
|
(req, res) => {
|
|
(req, res) => {
|
|
- Authentication.checkUserId(req.userId);
|
|
|
|
const paramBoardId = req.params.boardId;
|
|
const paramBoardId = req.params.boardId;
|
|
const paramDropdownItemId = req.params.dropdownItemId;
|
|
const paramDropdownItemId = req.params.dropdownItemId;
|
|
const paramCustomFieldId = req.params.customFieldId;
|
|
const paramCustomFieldId = req.params.customFieldId;
|
|
|
|
+ Authentication.checkBoardAccess(req.userId, paramBoardId);
|
|
const paramName = req.body.name;
|
|
const paramName = req.body.name;
|
|
|
|
|
|
if (req.body.hasOwnProperty('name')) {
|
|
if (req.body.hasOwnProperty('name')) {
|
|
@@ -563,10 +563,10 @@ if (Meteor.isServer) {
|
|
'DELETE',
|
|
'DELETE',
|
|
'/api/boards/:boardId/custom-fields/:customFieldId/dropdown-items/:dropdownItemId',
|
|
'/api/boards/:boardId/custom-fields/:customFieldId/dropdown-items/:dropdownItemId',
|
|
(req, res) => {
|
|
(req, res) => {
|
|
- Authentication.checkUserId(req.userId);
|
|
|
|
const paramBoardId = req.params.boardId;
|
|
const paramBoardId = req.params.boardId;
|
|
paramCustomFieldId = req.params.customFieldId;
|
|
paramCustomFieldId = req.params.customFieldId;
|
|
paramDropdownItemId = req.params.dropdownItemId;
|
|
paramDropdownItemId = req.params.dropdownItemId;
|
|
|
|
+ Authentication.checkBoardAccess(req.userId, paramBoardId);
|
|
|
|
|
|
CustomFields.direct.update(
|
|
CustomFields.direct.update(
|
|
{ _id: paramCustomFieldId },
|
|
{ _id: paramCustomFieldId },
|
|
@@ -598,8 +598,8 @@ if (Meteor.isServer) {
|
|
'DELETE',
|
|
'DELETE',
|
|
'/api/boards/:boardId/custom-fields/:customFieldId',
|
|
'/api/boards/:boardId/custom-fields/:customFieldId',
|
|
function(req, res) {
|
|
function(req, res) {
|
|
- Authentication.checkUserId(req.userId);
|
|
|
|
const paramBoardId = req.params.boardId;
|
|
const paramBoardId = req.params.boardId;
|
|
|
|
+ Authentication.checkBoardAccess(req.userId, paramBoardId);
|
|
const id = req.params.customFieldId;
|
|
const id = req.params.customFieldId;
|
|
CustomFields.remove({ _id: id, boardIds: { $in: [paramBoardId] } });
|
|
CustomFields.remove({ _id: id, boardIds: { $in: [paramBoardId] } });
|
|
JsonRoutes.sendResult(res, {
|
|
JsonRoutes.sendResult(res, {
|