- Updated privilege key structure to use a 3- or 4-part dotted hierarchy (e.g., `GROUP.PARENT.MODULE`). - Modified the `RequirePrivilege` decorator to accept multiple keys, allowing for OR logic in privilege checks. - Enhanced `PrivilegesGuard` to validate against multiple privilege keys, improving access control logic. - Created migration scripts to update existing privilege keys in the database to the new format. - Updated related services, controllers, and tests to accommodate the new privilege key structure and validation logic.
65 lines
1.8 KiB
TypeScript
65 lines
1.8 KiB
TypeScript
import { Controller, Get, Param, ParseUUIDPipe, Query } from '@nestjs/common';
|
|
import {
|
|
ApiBearerAuth,
|
|
ApiForbiddenResponse,
|
|
ApiNotFoundResponse,
|
|
ApiOkResponse,
|
|
ApiOperation,
|
|
ApiTags,
|
|
ApiUnauthorizedResponse,
|
|
} from '@nestjs/swagger';
|
|
import { RequirePrivilege } from '../../../common/decorators/require-privilege.decorator';
|
|
import {
|
|
Pagination,
|
|
type PaginationResponse,
|
|
PaginationMetaDto,
|
|
} from '../../../common/http/response';
|
|
import { BEARER_AUTH_NAME } from '../../../common/swagger/setup-swagger';
|
|
import { DivisionDto, ListDivisionsQueryDto } from './dto/division.dto';
|
|
import { DivisionsService } from './divisions.service';
|
|
|
|
export const DIVISION_PRIVILEGE_KEY = 'ADMIN.SETTINGS.DATA.DIVISION';
|
|
|
|
@ApiTags('divisions')
|
|
@ApiBearerAuth(BEARER_AUTH_NAME)
|
|
@Controller('divisions')
|
|
export class DivisionsReadController {
|
|
constructor(private readonly divisionsService: DivisionsService) {}
|
|
|
|
@Get()
|
|
@Pagination()
|
|
@RequirePrivilege(DIVISION_PRIVILEGE_KEY, 'view')
|
|
@ApiOperation({ summary: 'List divisions' })
|
|
@ApiOkResponse({
|
|
schema: {
|
|
properties: {
|
|
data: {
|
|
type: 'array',
|
|
items: { $ref: '#/components/schemas/DivisionDto' },
|
|
},
|
|
meta: { $ref: '#/components/schemas/PaginationMetaDto' },
|
|
},
|
|
},
|
|
})
|
|
@ApiUnauthorizedResponse()
|
|
@ApiForbiddenResponse()
|
|
list(
|
|
@Query() query: ListDivisionsQueryDto,
|
|
): Promise<PaginationResponse<DivisionDto>> {
|
|
return this.divisionsService.list(query);
|
|
}
|
|
|
|
@Get(':id')
|
|
@RequirePrivilege(DIVISION_PRIVILEGE_KEY, 'view')
|
|
@ApiOperation({ summary: 'Get division detail' })
|
|
@ApiOkResponse({ type: DivisionDto })
|
|
@ApiNotFoundResponse()
|
|
@ApiUnauthorizedResponse()
|
|
@ApiForbiddenResponse()
|
|
findOne(@Param('id', ParseUUIDPipe) id: string): Promise<DivisionDto> {
|
|
return this.divisionsService.findById(id);
|
|
}
|
|
}
|
|
|
|
void PaginationMetaDto;
|