lists.js 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808
  1. import { ReactiveCache } from '/imports/reactiveCache';
  2. import { ALLOWED_COLORS } from '/config/const';
  3. Lists = new Mongo.Collection('lists');
  4. /**
  5. * A list (column) in the Wekan board.
  6. */
  7. Lists.attachSchema(
  8. new SimpleSchema({
  9. title: {
  10. /**
  11. * the title of the list
  12. */
  13. type: String,
  14. },
  15. starred: {
  16. /**
  17. * if a list is stared
  18. * then we put it on the top
  19. */
  20. type: Boolean,
  21. optional: true,
  22. defaultValue: false,
  23. },
  24. archived: {
  25. /**
  26. * is the list archived
  27. */
  28. type: Boolean,
  29. // eslint-disable-next-line consistent-return
  30. autoValue() {
  31. if (this.isInsert && !this.isSet) {
  32. return false;
  33. }
  34. },
  35. },
  36. archivedAt: {
  37. /**
  38. * latest archiving date
  39. */
  40. type: Date,
  41. optional: true,
  42. },
  43. boardId: {
  44. /**
  45. * the board associated to this list
  46. */
  47. type: String,
  48. },
  49. swimlaneId: {
  50. /**
  51. * the swimlane associated to this list. Optional for backward compatibility
  52. */
  53. type: String,
  54. optional: true,
  55. defaultValue: '',
  56. },
  57. createdAt: {
  58. /**
  59. * creation date
  60. */
  61. type: Date,
  62. // eslint-disable-next-line consistent-return
  63. autoValue() {
  64. if (this.isInsert) {
  65. return new Date();
  66. } else if (this.isUpsert) {
  67. return { $setOnInsert: new Date() };
  68. } else {
  69. this.unset();
  70. }
  71. },
  72. },
  73. sort: {
  74. /**
  75. * is the list sorted
  76. */
  77. type: Number,
  78. decimal: true,
  79. // XXX We should probably provide a default
  80. optional: true,
  81. },
  82. updatedAt: {
  83. /**
  84. * last update of the list
  85. */
  86. type: Date,
  87. optional: true,
  88. // eslint-disable-next-line consistent-return
  89. autoValue() {
  90. if (this.isUpdate || this.isUpsert || this.isInsert) {
  91. return new Date();
  92. } else {
  93. this.unset();
  94. }
  95. },
  96. },
  97. modifiedAt: {
  98. type: Date,
  99. denyUpdate: false,
  100. // eslint-disable-next-line consistent-return
  101. autoValue() {
  102. // this is redundant with updatedAt
  103. /*if (this.isInsert || this.isUpsert || this.isUpdate) {
  104. return new Date();
  105. } else {
  106. this.unset();
  107. }*/
  108. if (!this.isSet) {
  109. return new Date();
  110. }
  111. },
  112. },
  113. wipLimit: {
  114. /**
  115. * WIP object, see below
  116. */
  117. type: Object,
  118. optional: true,
  119. },
  120. 'wipLimit.value': {
  121. /**
  122. * value of the WIP
  123. */
  124. type: Number,
  125. decimal: false,
  126. defaultValue: 1,
  127. },
  128. 'wipLimit.enabled': {
  129. /**
  130. * is the WIP enabled
  131. */
  132. type: Boolean,
  133. defaultValue: false,
  134. },
  135. 'wipLimit.soft': {
  136. /**
  137. * is the WIP a soft or hard requirement
  138. */
  139. type: Boolean,
  140. defaultValue: false,
  141. },
  142. color: {
  143. /**
  144. * the color of the list
  145. */
  146. type: String,
  147. optional: true,
  148. // silver is the default
  149. allowedValues: ALLOWED_COLORS,
  150. },
  151. type: {
  152. /**
  153. * The type of list
  154. */
  155. type: String,
  156. defaultValue: 'list',
  157. },
  158. collapsed: {
  159. /**
  160. * is the list collapsed
  161. */
  162. type: Boolean,
  163. defaultValue: false,
  164. },
  165. }),
  166. );
  167. Lists.allow({
  168. insert(userId, doc) {
  169. return allowIsBoardMemberCommentOnly(userId, ReactiveCache.getBoard(doc.boardId));
  170. },
  171. update(userId, doc) {
  172. return allowIsBoardMemberCommentOnly(userId, ReactiveCache.getBoard(doc.boardId));
  173. },
  174. remove(userId, doc) {
  175. return allowIsBoardMemberCommentOnly(userId, ReactiveCache.getBoard(doc.boardId));
  176. },
  177. fetch: ['boardId'],
  178. });
  179. Lists.helpers({
  180. copy(boardId, swimlaneId) {
  181. const oldId = this._id;
  182. const oldSwimlaneId = this.swimlaneId || null;
  183. this.boardId = boardId;
  184. this.swimlaneId = swimlaneId;
  185. let _id = null;
  186. const existingListWithSameName = ReactiveCache.getList({
  187. boardId,
  188. title: this.title,
  189. archived: false,
  190. });
  191. if (existingListWithSameName) {
  192. _id = existingListWithSameName._id;
  193. } else {
  194. delete this._id;
  195. this.swimlaneId = swimlaneId; // Set the target swimlane for the copied list
  196. _id = Lists.insert(this);
  197. }
  198. // Copy all cards in list
  199. ReactiveCache.getCards({
  200. swimlaneId: oldSwimlaneId,
  201. listId: oldId,
  202. archived: false,
  203. }).forEach(card => {
  204. card.copy(boardId, swimlaneId, _id);
  205. });
  206. },
  207. move(boardId, swimlaneId) {
  208. const boardList = ReactiveCache.getList({
  209. boardId,
  210. title: this.title,
  211. archived: false,
  212. });
  213. let listId;
  214. if (boardList) {
  215. listId = boardList._id;
  216. this.cards().forEach(card => {
  217. card.move(boardId, this._id, boardList._id);
  218. });
  219. } else {
  220. console.log('list.title:', this.title);
  221. console.log('boardList:', boardList);
  222. listId = Lists.insert({
  223. title: this.title,
  224. boardId,
  225. type: this.type,
  226. archived: false,
  227. wipLimit: this.wipLimit,
  228. swimlaneId: swimlaneId, // Set the target swimlane for the moved list
  229. });
  230. }
  231. this.cards(swimlaneId).forEach(card => {
  232. card.move(boardId, swimlaneId, listId);
  233. });
  234. },
  235. cards(swimlaneId) {
  236. const selector = {
  237. listId: this._id,
  238. archived: false,
  239. };
  240. if (swimlaneId) selector.swimlaneId = swimlaneId;
  241. const ret = ReactiveCache.getCards(Filter.mongoSelector(selector), { sort: ['sort'] });
  242. return ret;
  243. },
  244. cardsUnfiltered(swimlaneId) {
  245. const selector = {
  246. listId: this._id,
  247. archived: false,
  248. };
  249. if (swimlaneId) selector.swimlaneId = swimlaneId;
  250. const ret = ReactiveCache.getCards(selector, { sort: ['sort'] });
  251. return ret;
  252. },
  253. allCards() {
  254. const ret = ReactiveCache.getCards({ listId: this._id });
  255. return ret;
  256. },
  257. board() {
  258. return ReactiveCache.getBoard(this.boardId);
  259. },
  260. getWipLimit(option) {
  261. const list = ReactiveCache.getList(this._id);
  262. if (!list.wipLimit) {
  263. // Necessary check to avoid exceptions for the case where the doc doesn't have the wipLimit field yet set
  264. return 0;
  265. } else if (!option) {
  266. return list.wipLimit;
  267. } else {
  268. return list.wipLimit[option] ? list.wipLimit[option] : 0; // Necessary check to avoid exceptions for the case where the doc doesn't have the wipLimit field yet set
  269. }
  270. },
  271. colorClass() {
  272. if (this.color) return `list-header-${this.color}`;
  273. return '';
  274. },
  275. isTemplateList() {
  276. return this.type === 'template-list';
  277. },
  278. isStarred() {
  279. return this.starred === true;
  280. },
  281. isCollapsed() {
  282. return this.collapsed === true;
  283. },
  284. absoluteUrl() {
  285. const card = ReactiveCache.getCard({ listId: this._id });
  286. return card && card.absoluteUrl();
  287. },
  288. originRelativeUrl() {
  289. const card = ReactiveCache.getCard({ listId: this._id });
  290. return card && card.originRelativeUrl();
  291. },
  292. remove() {
  293. Lists.remove({ _id: this._id });
  294. },
  295. });
  296. Lists.mutations({
  297. rename(title) {
  298. // Basic client-side validation - server will handle full sanitization
  299. if (typeof title === 'string') {
  300. // Basic length check to prevent abuse
  301. const sanitizedTitle = title.length > 1000 ? title.substring(0, 1000) : title;
  302. return { $set: { title: sanitizedTitle } };
  303. }
  304. return { $set: { title } };
  305. },
  306. star(enable = true) {
  307. return { $set: { starred: !!enable } };
  308. },
  309. collapse(enable = true) {
  310. return { $set: { collapsed: !!enable } };
  311. },
  312. archive() {
  313. if (this.isTemplateList()) {
  314. this.cards().forEach(card => {
  315. return card.archive();
  316. });
  317. }
  318. return { $set: { archived: true, archivedAt: new Date() } };
  319. },
  320. restore() {
  321. if (this.isTemplateList()) {
  322. this.allCards().forEach(card => {
  323. return card.restore();
  324. });
  325. }
  326. return { $set: { archived: false } };
  327. },
  328. toggleSoftLimit(toggle) {
  329. return { $set: { 'wipLimit.soft': toggle } };
  330. },
  331. toggleWipLimit(toggle) {
  332. return { $set: { 'wipLimit.enabled': toggle } };
  333. },
  334. setWipLimit(limit) {
  335. return { $set: { 'wipLimit.value': limit } };
  336. },
  337. setColor(newColor) {
  338. return {
  339. $set: {
  340. color: newColor,
  341. },
  342. };
  343. },
  344. });
  345. Lists.userArchivedLists = userId => {
  346. return ReactiveCache.getLists({
  347. boardId: { $in: Boards.userBoardIds(userId, null) },
  348. archived: true,
  349. })
  350. };
  351. Lists.userArchivedListIds = () => {
  352. return Lists.userArchivedLists().map(list => { return list._id; });
  353. };
  354. Lists.archivedLists = () => {
  355. return ReactiveCache.getLists({ archived: true });
  356. };
  357. Lists.archivedListIds = () => {
  358. return Lists.archivedLists().map(list => {
  359. return list._id;
  360. });
  361. };
  362. Meteor.methods({
  363. applyWipLimit(listId, limit) {
  364. check(listId, String);
  365. check(limit, Number);
  366. if (limit === 0) {
  367. limit = 1;
  368. }
  369. ReactiveCache.getList(listId).setWipLimit(limit);
  370. },
  371. enableWipLimit(listId) {
  372. check(listId, String);
  373. const list = ReactiveCache.getList(listId);
  374. if (list.getWipLimit('value') === 0) {
  375. list.setWipLimit(1);
  376. }
  377. list.toggleWipLimit(!list.getWipLimit('enabled'));
  378. },
  379. enableSoftLimit(listId) {
  380. check(listId, String);
  381. const list = ReactiveCache.getList(listId);
  382. list.toggleSoftLimit(!list.getWipLimit('soft'));
  383. },
  384. myLists() {
  385. // my lists
  386. return _.uniq(
  387. ReactiveCache.getLists(
  388. {
  389. boardId: { $in: Boards.userBoardIds(this.userId) },
  390. archived: false,
  391. },
  392. {
  393. fields: { title: 1 },
  394. },
  395. )
  396. .map(list => {
  397. return list.title;
  398. }),
  399. ).sort();
  400. },
  401. });
  402. Lists.hookOptions.after.update = { fetchPrevious: false };
  403. if (Meteor.isServer) {
  404. Meteor.startup(() => {
  405. Lists._collection.createIndex({ modifiedAt: -1 });
  406. Lists._collection.createIndex({ boardId: 1 });
  407. Lists._collection.createIndex({ archivedAt: -1 });
  408. });
  409. Lists.after.insert((userId, doc) => {
  410. Activities.insert({
  411. userId,
  412. type: 'list',
  413. activityType: 'createList',
  414. boardId: doc.boardId,
  415. listId: doc._id,
  416. // this preserves the name so that the activity can be useful after the
  417. // list is deleted
  418. title: doc.title,
  419. });
  420. });
  421. Lists.before.remove((userId, doc) => {
  422. const cards = ReactiveCache.getCards({ listId: doc._id });
  423. if (cards) {
  424. cards.forEach(card => {
  425. Cards.remove(card._id);
  426. });
  427. }
  428. Activities.insert({
  429. userId,
  430. type: 'list',
  431. activityType: 'removeList',
  432. boardId: doc.boardId,
  433. listId: doc._id,
  434. title: doc.title,
  435. });
  436. });
  437. Lists.after.update((userId, doc, fieldNames) => {
  438. if (fieldNames.includes('title')) {
  439. Activities.insert({
  440. userId,
  441. type: 'list',
  442. activityType: 'changedListTitle',
  443. listId: doc._id,
  444. boardId: doc.boardId,
  445. // this preserves the name so that the activity can be useful after the
  446. // list is deleted
  447. title: doc.title,
  448. });
  449. } else if (doc.archived) {
  450. Activities.insert({
  451. userId,
  452. type: 'list',
  453. activityType: 'archivedList',
  454. listId: doc._id,
  455. boardId: doc.boardId,
  456. // this preserves the name so that the activity can be useful after the
  457. // list is deleted
  458. title: doc.title,
  459. });
  460. } else if (fieldNames.includes('archived')) {
  461. Activities.insert({
  462. userId,
  463. type: 'list',
  464. activityType: 'restoredList',
  465. listId: doc._id,
  466. boardId: doc.boardId,
  467. // this preserves the name so that the activity can be useful after the
  468. // list is deleted
  469. title: doc.title,
  470. });
  471. }
  472. });
  473. }
  474. //LISTS REST API
  475. if (Meteor.isServer) {
  476. /**
  477. * @operation get_all_lists
  478. * @summary Get the list of Lists attached to a board
  479. *
  480. * @param {string} boardId the board ID
  481. * @return_type [{_id: string,
  482. * title: string}]
  483. */
  484. JsonRoutes.add('GET', '/api/boards/:boardId/lists', function(req, res) {
  485. try {
  486. const paramBoardId = req.params.boardId;
  487. Authentication.checkBoardAccess(req.userId, paramBoardId);
  488. JsonRoutes.sendResult(res, {
  489. code: 200,
  490. data: ReactiveCache.getLists({ boardId: paramBoardId, archived: false }).map(
  491. function(doc) {
  492. return {
  493. _id: doc._id,
  494. title: doc.title,
  495. };
  496. },
  497. ),
  498. });
  499. } catch (error) {
  500. JsonRoutes.sendResult(res, {
  501. code: 200,
  502. data: error,
  503. });
  504. }
  505. });
  506. /**
  507. * @operation get_list
  508. * @summary Get a List attached to a board
  509. *
  510. * @param {string} boardId the board ID
  511. * @param {string} listId the List ID
  512. * @return_type Lists
  513. */
  514. JsonRoutes.add('GET', '/api/boards/:boardId/lists/:listId', function(
  515. req,
  516. res,
  517. ) {
  518. try {
  519. const paramBoardId = req.params.boardId;
  520. const paramListId = req.params.listId;
  521. Authentication.checkBoardAccess(req.userId, paramBoardId);
  522. JsonRoutes.sendResult(res, {
  523. code: 200,
  524. data: ReactiveCache.getList({
  525. _id: paramListId,
  526. boardId: paramBoardId,
  527. archived: false,
  528. }),
  529. });
  530. } catch (error) {
  531. JsonRoutes.sendResult(res, {
  532. code: 200,
  533. data: error,
  534. });
  535. }
  536. });
  537. /**
  538. * @operation new_list
  539. * @summary Add a List to a board
  540. *
  541. * @param {string} boardId the board ID
  542. * @param {string} title the title of the List
  543. * @return_type {_id: string}
  544. */
  545. JsonRoutes.add('POST', '/api/boards/:boardId/lists', function(req, res) {
  546. try {
  547. const paramBoardId = req.params.boardId;
  548. Authentication.checkBoardAccess(req.userId, paramBoardId);
  549. const board = ReactiveCache.getBoard(paramBoardId);
  550. const id = Lists.insert({
  551. title: req.body.title,
  552. boardId: paramBoardId,
  553. sort: board.lists().length,
  554. swimlaneId: req.body.swimlaneId || board.getDefaultSwimline()._id, // Use provided swimlaneId or default
  555. });
  556. JsonRoutes.sendResult(res, {
  557. code: 200,
  558. data: {
  559. _id: id,
  560. },
  561. });
  562. } catch (error) {
  563. JsonRoutes.sendResult(res, {
  564. code: 200,
  565. data: error,
  566. });
  567. }
  568. });
  569. /**
  570. * @operation edit_list
  571. * @summary Edit a List
  572. *
  573. * @description This updates a list on a board.
  574. * You can update the title, color, wipLimit, starred, and collapsed properties.
  575. *
  576. * @param {string} boardId the board ID
  577. * @param {string} listId the ID of the list to update
  578. * @param {string} [title] the new title of the list
  579. * @param {string} [color] the new color of the list
  580. * @param {Object} [wipLimit] the WIP limit configuration
  581. * @param {boolean} [starred] whether the list is starred
  582. * @param {boolean} [collapsed] whether the list is collapsed
  583. * @return_type {_id: string}
  584. */
  585. JsonRoutes.add('PUT', '/api/boards/:boardId/lists/:listId', function(
  586. req,
  587. res,
  588. ) {
  589. try {
  590. const paramBoardId = req.params.boardId;
  591. const paramListId = req.params.listId;
  592. let updated = false;
  593. Authentication.checkBoardAccess(req.userId, paramBoardId);
  594. const list = ReactiveCache.getList({
  595. _id: paramListId,
  596. boardId: paramBoardId,
  597. archived: false,
  598. });
  599. if (!list) {
  600. JsonRoutes.sendResult(res, {
  601. code: 404,
  602. data: { error: 'List not found' },
  603. });
  604. return;
  605. }
  606. // Update title if provided
  607. if (req.body.title) {
  608. // Basic client-side validation - server will handle full sanitization
  609. const newTitle = req.body.title.length > 1000 ? req.body.title.substring(0, 1000) : req.body.title;
  610. if (process.env.DEBUG === 'true' && newTitle !== req.body.title) {
  611. console.warn('Sanitized list title input:', req.body.title, '->', newTitle);
  612. }
  613. Lists.direct.update(
  614. {
  615. _id: paramListId,
  616. boardId: paramBoardId,
  617. archived: false,
  618. },
  619. {
  620. $set: {
  621. title: newTitle,
  622. },
  623. },
  624. );
  625. updated = true;
  626. }
  627. // Update color if provided
  628. if (req.body.color) {
  629. const newColor = req.body.color;
  630. Lists.direct.update(
  631. {
  632. _id: paramListId,
  633. boardId: paramBoardId,
  634. archived: false,
  635. },
  636. {
  637. $set: {
  638. color: newColor,
  639. },
  640. },
  641. );
  642. updated = true;
  643. }
  644. // Update starred status if provided
  645. if (req.body.hasOwnProperty('starred')) {
  646. const newStarred = req.body.starred;
  647. Lists.direct.update(
  648. {
  649. _id: paramListId,
  650. boardId: paramBoardId,
  651. archived: false,
  652. },
  653. {
  654. $set: {
  655. starred: newStarred,
  656. },
  657. },
  658. );
  659. updated = true;
  660. }
  661. // Update collapsed status if provided
  662. if (req.body.hasOwnProperty('collapsed')) {
  663. const newCollapsed = req.body.collapsed;
  664. Lists.direct.update(
  665. {
  666. _id: paramListId,
  667. boardId: paramBoardId,
  668. archived: false,
  669. },
  670. {
  671. $set: {
  672. collapsed: newCollapsed,
  673. },
  674. },
  675. );
  676. updated = true;
  677. }
  678. // Update wipLimit if provided
  679. if (req.body.wipLimit) {
  680. const newWipLimit = req.body.wipLimit;
  681. Lists.direct.update(
  682. {
  683. _id: paramListId,
  684. boardId: paramBoardId,
  685. archived: false,
  686. },
  687. {
  688. $set: {
  689. wipLimit: newWipLimit,
  690. },
  691. },
  692. );
  693. updated = true;
  694. }
  695. // Check if update is true or false
  696. if (!updated) {
  697. JsonRoutes.sendResult(res, {
  698. code: 404,
  699. data: {
  700. message: 'Error',
  701. },
  702. });
  703. return;
  704. }
  705. JsonRoutes.sendResult(res, {
  706. code: 200,
  707. data: {
  708. _id: paramListId,
  709. },
  710. });
  711. } catch (error) {
  712. JsonRoutes.sendResult(res, {
  713. code: 200,
  714. data: error,
  715. });
  716. }
  717. });
  718. /**
  719. * @operation delete_list
  720. * @summary Delete a List
  721. *
  722. * @description This **deletes** a list from a board.
  723. * The list is not put in the recycle bin.
  724. *
  725. * @param {string} boardId the board ID
  726. * @param {string} listId the ID of the list to remove
  727. * @return_type {_id: string}
  728. */
  729. JsonRoutes.add('DELETE', '/api/boards/:boardId/lists/:listId', function(
  730. req,
  731. res,
  732. ) {
  733. try {
  734. const paramBoardId = req.params.boardId;
  735. const paramListId = req.params.listId;
  736. Authentication.checkBoardAccess(req.userId, paramBoardId);
  737. Lists.remove({ _id: paramListId, boardId: paramBoardId });
  738. JsonRoutes.sendResult(res, {
  739. code: 200,
  740. data: {
  741. _id: paramListId,
  742. },
  743. });
  744. } catch (error) {
  745. JsonRoutes.sendResult(res, {
  746. code: 200,
  747. data: error,
  748. });
  749. }
  750. });
  751. }
  752. export default Lists;