2018-07-24 19:31:43 +02:00
|
|
|
<?php
|
|
|
|
|
|
|
|
namespace Grocy\Controllers;
|
|
|
|
|
2020-08-29 12:05:32 +02:00
|
|
|
use Grocy\Controllers\Users\User;
|
|
|
|
|
2018-07-24 19:31:43 +02:00
|
|
|
class UsersApiController extends BaseApiController
|
|
|
|
{
|
2020-02-11 17:42:03 +01:00
|
|
|
public function __construct(\DI\Container $container)
|
2018-07-24 19:31:43 +02:00
|
|
|
{
|
|
|
|
parent::__construct($container);
|
|
|
|
}
|
|
|
|
|
2020-02-11 17:42:03 +01:00
|
|
|
public function GetUsers(\Psr\Http\Message\ServerRequestInterface $request, \Psr\Http\Message\ResponseInterface $response, array $args)
|
2018-07-25 19:28:15 +02:00
|
|
|
{
|
2020-08-29 12:05:32 +02:00
|
|
|
User::checkPermission($request, User::PERMISSION_READ_USER);
|
|
|
|
try
|
2018-07-25 19:28:15 +02:00
|
|
|
{
|
2020-03-01 23:47:47 +07:00
|
|
|
return $this->ApiResponse($response, $this->getUsersService()->GetUsersAsDto());
|
2018-07-25 19:28:15 +02:00
|
|
|
}
|
|
|
|
catch (\Exception $ex)
|
|
|
|
{
|
2019-01-19 14:51:51 +01:00
|
|
|
return $this->GenericErrorResponse($response, $ex->getMessage());
|
2018-07-25 19:28:15 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-02-11 17:42:03 +01:00
|
|
|
public function CreateUser(\Psr\Http\Message\ServerRequestInterface $request, \Psr\Http\Message\ResponseInterface $response, array $args)
|
2018-07-24 19:31:43 +02:00
|
|
|
{
|
2020-08-29 12:05:32 +02:00
|
|
|
User::checkPermission($request, User::PERMISSION_CREATE_USER);
|
2018-07-24 19:31:43 +02:00
|
|
|
$requestBody = $request->getParsedBody();
|
|
|
|
|
|
|
|
try
|
|
|
|
{
|
2019-01-05 20:39:22 +01:00
|
|
|
if ($requestBody === null)
|
|
|
|
{
|
|
|
|
throw new \Exception('Request body could not be parsed (probably invalid JSON format or missing/wrong Content-Type header)');
|
|
|
|
}
|
|
|
|
|
2020-03-01 23:47:47 +07:00
|
|
|
$this->getUsersService()->CreateUser($requestBody['username'], $requestBody['first_name'], $requestBody['last_name'], $requestBody['password']);
|
2019-01-19 14:51:51 +01:00
|
|
|
return $this->EmptyApiResponse($response);
|
2018-07-24 19:31:43 +02:00
|
|
|
}
|
|
|
|
catch (\Exception $ex)
|
|
|
|
{
|
2019-01-19 14:51:51 +01:00
|
|
|
return $this->GenericErrorResponse($response, $ex->getMessage());
|
2018-07-24 19:31:43 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-02-11 17:42:03 +01:00
|
|
|
public function DeleteUser(\Psr\Http\Message\ServerRequestInterface $request, \Psr\Http\Message\ResponseInterface $response, array $args)
|
2018-07-24 19:31:43 +02:00
|
|
|
{
|
2020-08-29 12:05:32 +02:00
|
|
|
User::checkPermission($request, User::PERMISSION_EDIT_USER);
|
|
|
|
try
|
2018-07-24 19:31:43 +02:00
|
|
|
{
|
2020-03-01 23:47:47 +07:00
|
|
|
$this->getUsersService()->DeleteUser($args['userId']);
|
2019-01-19 14:51:51 +01:00
|
|
|
return $this->EmptyApiResponse($response);
|
2018-07-24 19:31:43 +02:00
|
|
|
}
|
|
|
|
catch (\Exception $ex)
|
|
|
|
{
|
2019-01-19 14:51:51 +01:00
|
|
|
return $this->GenericErrorResponse($response, $ex->getMessage());
|
2018-07-24 19:31:43 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-02-11 17:42:03 +01:00
|
|
|
public function EditUser(\Psr\Http\Message\ServerRequestInterface $request, \Psr\Http\Message\ResponseInterface $response, array $args)
|
2018-07-24 19:31:43 +02:00
|
|
|
{
|
2020-08-29 12:05:32 +02:00
|
|
|
if ($args['userId'] == GROCY_USER_ID) {
|
|
|
|
User::checkPermission($request, User::PERMISSION_EDIT_SELF);
|
|
|
|
} else {
|
|
|
|
User::checkPermission($request, User::PERMISSION_EDIT_USER);
|
|
|
|
}
|
|
|
|
$requestBody = $request->getParsedBody();
|
2018-07-24 19:31:43 +02:00
|
|
|
|
|
|
|
try
|
|
|
|
{
|
2020-03-01 23:47:47 +07:00
|
|
|
$this->getUsersService()->EditUser($args['userId'], $requestBody['username'], $requestBody['first_name'], $requestBody['last_name'], $requestBody['password']);
|
2019-01-19 14:51:51 +01:00
|
|
|
return $this->EmptyApiResponse($response);
|
2018-07-24 19:31:43 +02:00
|
|
|
}
|
|
|
|
catch (\Exception $ex)
|
|
|
|
{
|
2019-01-19 14:51:51 +01:00
|
|
|
return $this->GenericErrorResponse($response, $ex->getMessage());
|
2018-07-24 19:31:43 +02:00
|
|
|
}
|
|
|
|
}
|
2018-09-30 10:47:56 +02:00
|
|
|
|
2020-04-13 10:35:20 +02:00
|
|
|
public function GetUserSettings(\Psr\Http\Message\ServerRequestInterface $request, \Psr\Http\Message\ResponseInterface $response, array $args)
|
|
|
|
{
|
|
|
|
try
|
|
|
|
{
|
|
|
|
return $this->ApiResponse($response, $this->getUsersService()->GetUserSettings(GROCY_USER_ID));
|
|
|
|
}
|
|
|
|
catch (\Exception $ex)
|
|
|
|
{
|
|
|
|
return $this->GenericErrorResponse($response, $ex->getMessage());
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-02-11 17:42:03 +01:00
|
|
|
public function GetUserSetting(\Psr\Http\Message\ServerRequestInterface $request, \Psr\Http\Message\ResponseInterface $response, array $args)
|
2018-09-30 10:47:56 +02:00
|
|
|
{
|
|
|
|
try
|
|
|
|
{
|
2020-03-01 23:47:47 +07:00
|
|
|
$value = $this->getUsersService()->GetUserSetting(GROCY_USER_ID, $args['settingKey']);
|
2020-02-11 17:42:03 +01:00
|
|
|
return $this->ApiResponse($response, array('value' => $value));
|
2018-09-30 10:47:56 +02:00
|
|
|
}
|
|
|
|
catch (\Exception $ex)
|
|
|
|
{
|
2019-01-19 14:51:51 +01:00
|
|
|
return $this->GenericErrorResponse($response, $ex->getMessage());
|
2018-09-30 10:47:56 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-02-11 17:42:03 +01:00
|
|
|
public function SetUserSetting(\Psr\Http\Message\ServerRequestInterface $request, \Psr\Http\Message\ResponseInterface $response, array $args)
|
2018-09-30 10:47:56 +02:00
|
|
|
{
|
|
|
|
try
|
|
|
|
{
|
|
|
|
$requestBody = $request->getParsedBody();
|
|
|
|
|
2020-03-01 23:47:47 +07:00
|
|
|
$value = $this->getUsersService()->SetUserSetting(GROCY_USER_ID, $args['settingKey'], $requestBody['value']);
|
2019-01-19 14:51:51 +01:00
|
|
|
return $this->EmptyApiResponse($response);
|
2018-09-30 10:47:56 +02:00
|
|
|
}
|
|
|
|
catch (\Exception $ex)
|
|
|
|
{
|
2019-01-19 14:51:51 +01:00
|
|
|
return $this->GenericErrorResponse($response, $ex->getMessage());
|
2018-09-30 10:47:56 +02:00
|
|
|
}
|
|
|
|
}
|
2020-08-29 12:05:32 +02:00
|
|
|
|
|
|
|
public function AddPermission(\Psr\Http\Message\ServerRequestInterface $request, \Psr\Http\Message\ResponseInterface $response, array $args)
|
|
|
|
{
|
|
|
|
try {
|
|
|
|
User::checkPermission($request, User::PERMISSION_ADMIN);
|
|
|
|
$requestBody = $request->getParsedBody();
|
|
|
|
|
|
|
|
$this->getDatabase()->user_permissions()->createRow(array(
|
|
|
|
'user_id' => $args['userId'],
|
|
|
|
'permission_id' => $requestBody['permission_id'],
|
|
|
|
))->save();
|
|
|
|
return $this->EmptyApiResponse($response);
|
|
|
|
} catch (\Slim\Exception\HttpSpecializedException $ex) {
|
|
|
|
return $this->GenericErrorResponse($response, $ex->getMessage(), $ex->getCode());
|
|
|
|
} catch (\Exception $ex) {
|
|
|
|
return $this->GenericErrorResponse($response, $ex->getMessage());
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
public function ListPermissions(\Psr\Http\Message\ServerRequestInterface $request, \Psr\Http\Message\ResponseInterface $response, array $args)
|
|
|
|
{
|
|
|
|
try {
|
|
|
|
User::checkPermission($request, User::PERMISSION_ADMIN);
|
|
|
|
|
|
|
|
return $this->ApiResponse($response,
|
|
|
|
$this->getDatabase()->user_permissions()->where($args['userId'])
|
|
|
|
);
|
|
|
|
} catch (\Slim\Exception\HttpSpecializedException $ex) {
|
|
|
|
return $this->GenericErrorResponse($response, $ex->getMessage(), $ex->getCode());
|
|
|
|
} catch (\Exception $ex) {
|
|
|
|
return $this->GenericErrorResponse($response, $ex->getMessage());
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
public function SetPermissions(\Psr\Http\Message\ServerRequestInterface $request, \Psr\Http\Message\ResponseInterface $response, array $args)
|
|
|
|
{
|
|
|
|
try {
|
|
|
|
User::checkPermission($request, User::PERMISSION_ADMIN);
|
|
|
|
$requestBody = $request->getParsedBody();
|
|
|
|
$db = $this->getDatabase();
|
|
|
|
$db->user_permissions()
|
|
|
|
->where('user_id', $args['userId'])
|
|
|
|
->delete();
|
|
|
|
|
|
|
|
$perms = [];
|
|
|
|
|
|
|
|
foreach ($requestBody['permissions'] as $perm_id) {
|
|
|
|
$perms[] = array(
|
|
|
|
'user_id' => $args['userId'],
|
|
|
|
'permission_id' => $perm_id
|
|
|
|
);
|
|
|
|
}
|
|
|
|
|
|
|
|
$db->insert('user_permissions', $perms, 'batch');
|
|
|
|
|
|
|
|
return $this->EmptyApiResponse($response);
|
|
|
|
} catch (\Slim\Exception\HttpSpecializedException $ex) {
|
|
|
|
return $this->GenericErrorResponse($response, $ex->getMessage(), $ex->getCode());
|
|
|
|
} catch (\Exception $ex) {
|
|
|
|
return $this->GenericErrorResponse($response, $ex->getMessage());
|
|
|
|
}
|
|
|
|
}
|
2018-07-24 19:31:43 +02:00
|
|
|
}
|