boards.js 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758
  1. Boards = new Mongo.Collection('boards');
  2. Boards.attachSchema(new SimpleSchema({
  3. title: {
  4. type: String,
  5. },
  6. slug: {
  7. type: String,
  8. autoValue() { // eslint-disable-line consistent-return
  9. // XXX We need to improve slug management. Only the id should be necessary
  10. // to identify a board in the code.
  11. // XXX If the board title is updated, the slug should also be updated.
  12. // In some cases (Chinese and Japanese for instance) the `getSlug` function
  13. // return an empty string. This is causes bugs in our application so we set
  14. // a default slug in this case.
  15. if (this.isInsert && !this.isSet) {
  16. let slug = 'board';
  17. const title = this.field('title');
  18. if (title.isSet) {
  19. slug = getSlug(title.value) || slug;
  20. }
  21. return slug;
  22. }
  23. },
  24. },
  25. archived: {
  26. type: Boolean,
  27. autoValue() { // eslint-disable-line consistent-return
  28. if (this.isInsert && !this.isSet) {
  29. return false;
  30. }
  31. },
  32. },
  33. createdAt: {
  34. type: Date,
  35. autoValue() { // eslint-disable-line consistent-return
  36. if (this.isInsert) {
  37. return new Date();
  38. } else {
  39. this.unset();
  40. }
  41. },
  42. },
  43. // XXX Inconsistent field naming
  44. modifiedAt: {
  45. type: Date,
  46. optional: true,
  47. autoValue() { // eslint-disable-line consistent-return
  48. if (this.isUpdate) {
  49. return new Date();
  50. } else {
  51. this.unset();
  52. }
  53. },
  54. },
  55. // De-normalized number of users that have starred this board
  56. stars: {
  57. type: Number,
  58. autoValue() { // eslint-disable-line consistent-return
  59. if (this.isInsert) {
  60. return 0;
  61. }
  62. },
  63. },
  64. // De-normalized label system
  65. 'labels': {
  66. type: [Object],
  67. autoValue() { // eslint-disable-line consistent-return
  68. if (this.isInsert && !this.isSet) {
  69. const colors = Boards.simpleSchema()._schema['labels.$.color'].allowedValues;
  70. const defaultLabelsColors = _.clone(colors).splice(0, 6);
  71. return defaultLabelsColors.map((color) => ({
  72. color,
  73. _id: Random.id(6),
  74. name: '',
  75. }));
  76. }
  77. },
  78. },
  79. 'labels.$._id': {
  80. // We don't specify that this field must be unique in the board because that
  81. // will cause performance penalties and is not necessary since this field is
  82. // always set on the server.
  83. // XXX Actually if we create a new label, the `_id` is set on the client
  84. // without being overwritten by the server, could it be a problem?
  85. type: String,
  86. },
  87. 'labels.$.name': {
  88. type: String,
  89. optional: true,
  90. },
  91. 'labels.$.color': {
  92. type: String,
  93. allowedValues: [
  94. 'green', 'yellow', 'orange', 'red', 'purple',
  95. 'blue', 'sky', 'lime', 'pink', 'black',
  96. 'silver', 'peachpuff', 'crimson', 'plum', 'darkgreen',
  97. 'slateblue', 'magenta', 'gold', 'navy', 'gray',
  98. 'saddlebrown', 'paleturquoise', 'mistyrose', 'indigo',
  99. ],
  100. },
  101. // XXX We might want to maintain more informations under the member sub-
  102. // documents like de-normalized meta-data (the date the member joined the
  103. // board, the number of contributions, etc.).
  104. 'members': {
  105. type: [Object],
  106. autoValue() { // eslint-disable-line consistent-return
  107. if (this.isInsert && !this.isSet) {
  108. return [{
  109. userId: this.userId,
  110. isAdmin: true,
  111. isActive: true,
  112. isCommentOnly: false,
  113. }];
  114. }
  115. },
  116. },
  117. 'members.$.userId': {
  118. type: String,
  119. },
  120. 'members.$.isAdmin': {
  121. type: Boolean,
  122. },
  123. 'members.$.isActive': {
  124. type: Boolean,
  125. },
  126. 'members.$.isCommentOnly': {
  127. type: Boolean,
  128. },
  129. permission: {
  130. type: String,
  131. allowedValues: ['public', 'private'],
  132. },
  133. color: {
  134. type: String,
  135. allowedValues: [
  136. 'belize',
  137. 'nephritis',
  138. 'pomegranate',
  139. 'pumpkin',
  140. 'wisteria',
  141. 'midnight',
  142. ],
  143. autoValue() { // eslint-disable-line consistent-return
  144. if (this.isInsert && !this.isSet) {
  145. return Boards.simpleSchema()._schema.color.allowedValues[0];
  146. }
  147. },
  148. },
  149. description: {
  150. type: String,
  151. optional: true,
  152. },
  153. }));
  154. Boards.helpers({
  155. /**
  156. * Is supplied user authorized to view this board?
  157. */
  158. isVisibleBy(user) {
  159. if (this.isPublic()) {
  160. // public boards are visible to everyone
  161. return true;
  162. } else {
  163. // otherwise you have to be logged-in and active member
  164. return user && this.isActiveMember(user._id);
  165. }
  166. },
  167. /**
  168. * Is the user one of the active members of the board?
  169. *
  170. * @param userId
  171. * @returns {boolean} the member that matches, or undefined/false
  172. */
  173. isActiveMember(userId) {
  174. if (userId) {
  175. return this.members.find((member) => (member.userId === userId && member.isActive));
  176. } else {
  177. return false;
  178. }
  179. },
  180. isPublic() {
  181. return this.permission === 'public';
  182. },
  183. lists() {
  184. return Lists.find({ boardId: this._id, archived: false }, { sort: { sort: 1 } });
  185. },
  186. swimlanes() {
  187. return Swimlanes.find({ boardId: this._id, archived: false }, { sort: { sort: 1 } });
  188. },
  189. hasOvertimeCards(){
  190. const card = Cards.findOne({isOvertime: true, boardId: this._id, archived: false} );
  191. return card !== undefined;
  192. },
  193. hasSpentTimeCards(){
  194. const card = Cards.findOne({spentTime: { $gt: 0 }, boardId: this._id, archived: false} );
  195. return card !== undefined;
  196. },
  197. activities() {
  198. return Activities.find({ boardId: this._id }, { sort: { createdAt: -1 } });
  199. },
  200. activeMembers() {
  201. return _.where(this.members, { isActive: true });
  202. },
  203. activeAdmins() {
  204. return _.where(this.members, { isActive: true, isAdmin: true });
  205. },
  206. memberUsers() {
  207. return Users.find({ _id: { $in: _.pluck(this.members, 'userId') } });
  208. },
  209. getLabel(name, color) {
  210. return _.findWhere(this.labels, { name, color });
  211. },
  212. labelIndex(labelId) {
  213. return _.pluck(this.labels, '_id').indexOf(labelId);
  214. },
  215. memberIndex(memberId) {
  216. return _.pluck(this.members, 'userId').indexOf(memberId);
  217. },
  218. hasMember(memberId) {
  219. return !!_.findWhere(this.members, { userId: memberId, isActive: true });
  220. },
  221. hasAdmin(memberId) {
  222. return !!_.findWhere(this.members, { userId: memberId, isActive: true, isAdmin: true });
  223. },
  224. hasCommentOnly(memberId) {
  225. return !!_.findWhere(this.members, { userId: memberId, isActive: true, isAdmin: false, isCommentOnly: true });
  226. },
  227. absoluteUrl() {
  228. return FlowRouter.url('board', { id: this._id, slug: this.slug });
  229. },
  230. colorClass() {
  231. return `board-color-${this.color}`;
  232. },
  233. customFields() {
  234. return CustomFields.find({ boardId: this._id }, { sort: { name: 1 } });
  235. },
  236. // XXX currently mutations return no value so we have an issue when using addLabel in import
  237. // XXX waiting on https://github.com/mquandalle/meteor-collection-mutations/issues/1 to remove...
  238. pushLabel(name, color) {
  239. const _id = Random.id(6);
  240. Boards.direct.update(this._id, { $push: { labels: { _id, name, color } } });
  241. return _id;
  242. },
  243. searchCards(term) {
  244. check(term, Match.OneOf(String, null, undefined));
  245. let query = { boardId: this._id };
  246. const projection = { limit: 10, sort: { createdAt: -1 } };
  247. if (term) {
  248. const regex = new RegExp(term, 'i');
  249. query = {
  250. boardId: this._id,
  251. $or: [
  252. { title: regex },
  253. { description: regex },
  254. ],
  255. };
  256. }
  257. return Cards.find(query, projection);
  258. },
  259. });
  260. Boards.mutations({
  261. archive() {
  262. return { $set: { archived: true } };
  263. },
  264. restore() {
  265. return { $set: { archived: false } };
  266. },
  267. rename(title) {
  268. return { $set: { title } };
  269. },
  270. setDescription(description) {
  271. return { $set: { description } };
  272. },
  273. setColor(color) {
  274. return { $set: { color } };
  275. },
  276. setVisibility(visibility) {
  277. return { $set: { permission: visibility } };
  278. },
  279. addLabel(name, color) {
  280. // If label with the same name and color already exists we don't want to
  281. // create another one because they would be indistinguishable in the UI
  282. // (they would still have different `_id` but that is not exposed to the
  283. // user).
  284. if (!this.getLabel(name, color)) {
  285. const _id = Random.id(6);
  286. return { $push: { labels: { _id, name, color } } };
  287. }
  288. return {};
  289. },
  290. editLabel(labelId, name, color) {
  291. if (!this.getLabel(name, color)) {
  292. const labelIndex = this.labelIndex(labelId);
  293. return {
  294. $set: {
  295. [`labels.${labelIndex}.name`]: name,
  296. [`labels.${labelIndex}.color`]: color,
  297. },
  298. };
  299. }
  300. return {};
  301. },
  302. removeLabel(labelId) {
  303. return { $pull: { labels: { _id: labelId } } };
  304. },
  305. changeOwnership(fromId, toId) {
  306. const memberIndex = this.memberIndex(fromId);
  307. return {
  308. $set: {
  309. [`members.${memberIndex}.userId`]: toId,
  310. },
  311. };
  312. },
  313. addMember(memberId) {
  314. const memberIndex = this.memberIndex(memberId);
  315. if (memberIndex >= 0) {
  316. return {
  317. $set: {
  318. [`members.${memberIndex}.isActive`]: true,
  319. },
  320. };
  321. }
  322. return {
  323. $push: {
  324. members: {
  325. userId: memberId,
  326. isAdmin: false,
  327. isActive: true,
  328. isCommentOnly: false,
  329. },
  330. },
  331. };
  332. },
  333. removeMember(memberId) {
  334. const memberIndex = this.memberIndex(memberId);
  335. // we do not allow the only one admin to be removed
  336. const allowRemove = (!this.members[memberIndex].isAdmin) || (this.activeAdmins().length > 1);
  337. if (!allowRemove) {
  338. return {
  339. $set: {
  340. [`members.${memberIndex}.isActive`]: true,
  341. },
  342. };
  343. }
  344. return {
  345. $set: {
  346. [`members.${memberIndex}.isActive`]: false,
  347. [`members.${memberIndex}.isAdmin`]: false,
  348. },
  349. };
  350. },
  351. setMemberPermission(memberId, isAdmin, isCommentOnly) {
  352. const memberIndex = this.memberIndex(memberId);
  353. // do not allow change permission of self
  354. if (memberId === Meteor.userId()) {
  355. isAdmin = this.members[memberIndex].isAdmin;
  356. }
  357. return {
  358. $set: {
  359. [`members.${memberIndex}.isAdmin`]: isAdmin,
  360. [`members.${memberIndex}.isCommentOnly`]: isCommentOnly,
  361. },
  362. };
  363. },
  364. });
  365. if (Meteor.isServer) {
  366. Boards.allow({
  367. insert: Meteor.userId,
  368. update: allowIsBoardAdmin,
  369. remove: allowIsBoardAdmin,
  370. fetch: ['members'],
  371. });
  372. // The number of users that have starred this board is managed by trusted code
  373. // and the user is not allowed to update it
  374. Boards.deny({
  375. update(userId, board, fieldNames) {
  376. return _.contains(fieldNames, 'stars');
  377. },
  378. fetch: [],
  379. });
  380. // We can't remove a member if it is the last administrator
  381. Boards.deny({
  382. update(userId, doc, fieldNames, modifier) {
  383. if (!_.contains(fieldNames, 'members'))
  384. return false;
  385. // We only care in case of a $pull operation, ie remove a member
  386. if (!_.isObject(modifier.$pull && modifier.$pull.members))
  387. return false;
  388. // If there is more than one admin, it's ok to remove anyone
  389. const nbAdmins = _.where(doc.members, { isActive: true, isAdmin: true }).length;
  390. if (nbAdmins > 1)
  391. return false;
  392. // If all the previous conditions were verified, we can't remove
  393. // a user if it's an admin
  394. const removedMemberId = modifier.$pull.members.userId;
  395. return Boolean(_.findWhere(doc.members, {
  396. userId: removedMemberId,
  397. isAdmin: true,
  398. }));
  399. },
  400. fetch: ['members'],
  401. });
  402. Meteor.methods({
  403. quitBoard(boardId) {
  404. check(boardId, String);
  405. const board = Boards.findOne(boardId);
  406. if (board) {
  407. const userId = Meteor.userId();
  408. const index = board.memberIndex(userId);
  409. if (index >= 0) {
  410. board.removeMember(userId);
  411. return true;
  412. } else throw new Meteor.Error('error-board-notAMember');
  413. } else throw new Meteor.Error('error-board-doesNotExist');
  414. },
  415. });
  416. }
  417. if (Meteor.isServer) {
  418. // Let MongoDB ensure that a member is not included twice in the same board
  419. Meteor.startup(() => {
  420. Boards._collection._ensureIndex({
  421. _id: 1,
  422. 'members.userId': 1,
  423. }, { unique: true });
  424. Boards._collection._ensureIndex({ 'members.userId': 1 });
  425. });
  426. // Genesis: the first activity of the newly created board
  427. Boards.after.insert((userId, doc) => {
  428. Activities.insert({
  429. userId,
  430. type: 'board',
  431. activityTypeId: doc._id,
  432. activityType: 'createBoard',
  433. boardId: doc._id,
  434. });
  435. });
  436. // If the user remove one label from a board, we cant to remove reference of
  437. // this label in any card of this board.
  438. Boards.after.update((userId, doc, fieldNames, modifier) => {
  439. if (!_.contains(fieldNames, 'labels') ||
  440. !modifier.$pull ||
  441. !modifier.$pull.labels ||
  442. !modifier.$pull.labels._id) {
  443. return;
  444. }
  445. const removedLabelId = modifier.$pull.labels._id;
  446. Cards.update(
  447. { boardId: doc._id },
  448. {
  449. $pull: {
  450. labelIds: removedLabelId,
  451. },
  452. },
  453. { multi: true }
  454. );
  455. });
  456. const foreachRemovedMember = (doc, modifier, callback) => {
  457. Object.keys(modifier).forEach((set) => {
  458. if (modifier[set] !== false) {
  459. return;
  460. }
  461. const parts = set.split('.');
  462. if (parts.length === 3 && parts[0] === 'members' && parts[2] === 'isActive') {
  463. callback(doc.members[parts[1]].userId);
  464. }
  465. });
  466. };
  467. // Remove a member from all objects of the board before leaving the board
  468. Boards.before.update((userId, doc, fieldNames, modifier) => {
  469. if (!_.contains(fieldNames, 'members')) {
  470. return;
  471. }
  472. if (modifier.$set) {
  473. const boardId = doc._id;
  474. foreachRemovedMember(doc, modifier.$set, (memberId) => {
  475. Cards.update(
  476. { boardId },
  477. {
  478. $pull: {
  479. members: memberId,
  480. watchers: memberId,
  481. },
  482. },
  483. { multi: true }
  484. );
  485. Lists.update(
  486. { boardId },
  487. {
  488. $pull: {
  489. watchers: memberId,
  490. },
  491. },
  492. { multi: true }
  493. );
  494. const board = Boards._transform(doc);
  495. board.setWatcher(memberId, false);
  496. // Remove board from users starred list
  497. if (!board.isPublic()) {
  498. Users.update(
  499. memberId,
  500. {
  501. $pull: {
  502. 'profile.starredBoards': boardId,
  503. },
  504. }
  505. );
  506. }
  507. });
  508. }
  509. });
  510. // Add a new activity if we add or remove a member to the board
  511. Boards.after.update((userId, doc, fieldNames, modifier) => {
  512. if (!_.contains(fieldNames, 'members')) {
  513. return;
  514. }
  515. // Say hello to the new member
  516. if (modifier.$push && modifier.$push.members) {
  517. const memberId = modifier.$push.members.userId;
  518. Activities.insert({
  519. userId,
  520. memberId,
  521. type: 'member',
  522. activityType: 'addBoardMember',
  523. boardId: doc._id,
  524. });
  525. }
  526. // Say goodbye to the former member
  527. if (modifier.$set) {
  528. foreachRemovedMember(doc, modifier.$set, (memberId) => {
  529. Activities.insert({
  530. userId,
  531. memberId,
  532. type: 'member',
  533. activityType: 'removeBoardMember',
  534. boardId: doc._id,
  535. });
  536. });
  537. }
  538. });
  539. }
  540. //BOARDS REST API
  541. if (Meteor.isServer) {
  542. JsonRoutes.add('GET', '/api/users/:userId/boards', function (req, res) {
  543. try {
  544. Authentication.checkLoggedIn(req.userId);
  545. const paramUserId = req.params.userId;
  546. // A normal user should be able to see their own boards,
  547. // admins can access boards of any user
  548. Authentication.checkAdminOrCondition(req.userId, req.userId === paramUserId);
  549. const data = Boards.find({
  550. archived: false,
  551. 'members.userId': paramUserId,
  552. }, {
  553. sort: ['title'],
  554. }).map(function(board) {
  555. return {
  556. _id: board._id,
  557. title: board.title,
  558. };
  559. });
  560. JsonRoutes.sendResult(res, {code: 200, data});
  561. }
  562. catch (error) {
  563. JsonRoutes.sendResult(res, {
  564. code: 200,
  565. data: error,
  566. });
  567. }
  568. });
  569. JsonRoutes.add('GET', '/api/boards', function (req, res) {
  570. try {
  571. Authentication.checkUserId(req.userId);
  572. JsonRoutes.sendResult(res, {
  573. code: 200,
  574. data: Boards.find({ permission: 'public' }).map(function (doc) {
  575. return {
  576. _id: doc._id,
  577. title: doc.title,
  578. };
  579. }),
  580. });
  581. }
  582. catch (error) {
  583. JsonRoutes.sendResult(res, {
  584. code: 200,
  585. data: error,
  586. });
  587. }
  588. });
  589. JsonRoutes.add('GET', '/api/boards/:id', function (req, res) {
  590. try {
  591. const id = req.params.id;
  592. Authentication.checkBoardAccess(req.userId, id);
  593. JsonRoutes.sendResult(res, {
  594. code: 200,
  595. data: Boards.findOne({ _id: id }),
  596. });
  597. }
  598. catch (error) {
  599. JsonRoutes.sendResult(res, {
  600. code: 200,
  601. data: error,
  602. });
  603. }
  604. });
  605. JsonRoutes.add('POST', '/api/boards', function (req, res) {
  606. try {
  607. Authentication.checkUserId(req.userId);
  608. const id = Boards.insert({
  609. title: req.body.title,
  610. members: [
  611. {
  612. userId: req.body.owner,
  613. isAdmin: true,
  614. isActive: true,
  615. isCommentOnly: false,
  616. },
  617. ],
  618. permission: 'public',
  619. color: 'belize',
  620. });
  621. JsonRoutes.sendResult(res, {
  622. code: 200,
  623. data: {
  624. _id: id,
  625. },
  626. });
  627. }
  628. catch (error) {
  629. JsonRoutes.sendResult(res, {
  630. code: 200,
  631. data: error,
  632. });
  633. }
  634. });
  635. JsonRoutes.add('DELETE', '/api/boards/:id', function (req, res) {
  636. try {
  637. Authentication.checkUserId(req.userId);
  638. const id = req.params.id;
  639. Boards.remove({ _id: id });
  640. JsonRoutes.sendResult(res, {
  641. code: 200,
  642. data:{
  643. _id: id,
  644. },
  645. });
  646. }
  647. catch (error) {
  648. JsonRoutes.sendResult(res, {
  649. code: 200,
  650. data: error,
  651. });
  652. }
  653. });
  654. JsonRoutes.add('PUT', '/api/boards/:id/labels', function (req, res) {
  655. Authentication.checkUserId(req.userId);
  656. const id = req.params.id;
  657. try {
  658. if (req.body.hasOwnProperty('label')) {
  659. const board = Boards.findOne({ _id: id });
  660. const color = req.body.label.color;
  661. const name = req.body.label.name;
  662. const labelId = Random.id(6);
  663. if (!board.getLabel(name, color)) {
  664. Boards.direct.update({ _id: id }, { $push: { labels: { _id: labelId, name, color } } });
  665. JsonRoutes.sendResult(res, {
  666. code: 200,
  667. data: labelId,
  668. });
  669. } else {
  670. JsonRoutes.sendResult(res, {
  671. code: 200,
  672. });
  673. }
  674. }
  675. }
  676. catch (error) {
  677. JsonRoutes.sendResult(res, {
  678. data: error,
  679. });
  680. }
  681. });
  682. }