2020-06-23 13:29:38 -04:00
|
|
|
/* eslint-disable
|
|
|
|
camelcase,
|
|
|
|
*/
|
2020-06-23 13:29:44 -04:00
|
|
|
let AuthorizationManager
|
|
|
|
module.exports = AuthorizationManager = {
|
|
|
|
assertClientCanViewProject(client, callback) {
|
2020-07-07 06:06:02 -04:00
|
|
|
AuthorizationManager._assertClientHasPrivilegeLevel(
|
2020-06-23 13:29:44 -04:00
|
|
|
client,
|
|
|
|
['readOnly', 'readAndWrite', 'owner'],
|
|
|
|
callback
|
|
|
|
)
|
|
|
|
},
|
2014-11-13 12:07:05 -05:00
|
|
|
|
2020-06-23 13:29:44 -04:00
|
|
|
assertClientCanEditProject(client, callback) {
|
2020-07-07 06:06:02 -04:00
|
|
|
AuthorizationManager._assertClientHasPrivilegeLevel(
|
2020-06-23 13:29:44 -04:00
|
|
|
client,
|
|
|
|
['readAndWrite', 'owner'],
|
|
|
|
callback
|
|
|
|
)
|
|
|
|
},
|
2016-09-02 11:35:00 -04:00
|
|
|
|
2020-06-23 13:29:44 -04:00
|
|
|
_assertClientHasPrivilegeLevel(client, allowedLevels, callback) {
|
2020-07-07 06:06:02 -04:00
|
|
|
if (allowedLevels.includes(client.ol_context.privilege_level)) {
|
|
|
|
callback(null)
|
2020-06-23 13:29:44 -04:00
|
|
|
} else {
|
2020-07-07 06:06:02 -04:00
|
|
|
callback(new Error('not authorized'))
|
2020-06-23 13:29:44 -04:00
|
|
|
}
|
|
|
|
},
|
2016-09-02 11:35:00 -04:00
|
|
|
|
2020-06-23 13:29:44 -04:00
|
|
|
assertClientCanViewProjectAndDoc(client, doc_id, callback) {
|
2020-07-07 06:06:02 -04:00
|
|
|
AuthorizationManager.assertClientCanViewProject(client, function (error) {
|
|
|
|
if (error) {
|
2020-06-23 13:29:44 -04:00
|
|
|
return callback(error)
|
|
|
|
}
|
2020-07-07 06:06:02 -04:00
|
|
|
AuthorizationManager._assertClientCanAccessDoc(client, doc_id, callback)
|
2020-06-23 13:29:44 -04:00
|
|
|
})
|
|
|
|
},
|
2016-09-02 11:35:00 -04:00
|
|
|
|
2020-06-23 13:29:44 -04:00
|
|
|
assertClientCanEditProjectAndDoc(client, doc_id, callback) {
|
2020-07-07 06:06:02 -04:00
|
|
|
AuthorizationManager.assertClientCanEditProject(client, function (error) {
|
|
|
|
if (error) {
|
2020-06-23 13:29:44 -04:00
|
|
|
return callback(error)
|
|
|
|
}
|
2020-07-07 06:06:02 -04:00
|
|
|
AuthorizationManager._assertClientCanAccessDoc(client, doc_id, callback)
|
2020-06-23 13:29:44 -04:00
|
|
|
})
|
|
|
|
},
|
2016-09-02 11:35:00 -04:00
|
|
|
|
2020-06-23 13:29:44 -04:00
|
|
|
_assertClientCanAccessDoc(client, doc_id, callback) {
|
|
|
|
if (client.ol_context[`doc:${doc_id}`] === 'allowed') {
|
2020-07-07 06:06:02 -04:00
|
|
|
callback(null)
|
2020-06-23 13:29:44 -04:00
|
|
|
} else {
|
2020-07-07 06:06:02 -04:00
|
|
|
callback(new Error('not authorized'))
|
2020-06-23 13:29:44 -04:00
|
|
|
}
|
|
|
|
},
|
2016-09-02 11:35:00 -04:00
|
|
|
|
2020-06-23 13:29:44 -04:00
|
|
|
addAccessToDoc(client, doc_id, callback) {
|
|
|
|
client.ol_context[`doc:${doc_id}`] = 'allowed'
|
2020-07-07 06:06:02 -04:00
|
|
|
callback(null)
|
2020-06-23 13:29:44 -04:00
|
|
|
},
|
|
|
|
|
|
|
|
removeAccessToDoc(client, doc_id, callback) {
|
|
|
|
delete client.ol_context[`doc:${doc_id}`]
|
2020-07-07 06:06:02 -04:00
|
|
|
callback(null)
|
2020-06-23 13:29:44 -04:00
|
|
|
}
|
|
|
|
}
|