Merge branch 'feature/stock-item-link' into dev
This commit is contained in:
@@ -120,6 +120,7 @@ public class StockModule extends BaseHandler implements StockService {
|
||||
yield super.doGet(path,ex);
|
||||
}
|
||||
}
|
||||
case Path.ITEM -> getItemById(user.get(),path,ex);
|
||||
case Path.LOCATION -> {
|
||||
try {
|
||||
var location = Location.of(Long.parseLong(path.pop()));
|
||||
@@ -162,6 +163,22 @@ public class StockModule extends BaseHandler implements StockService {
|
||||
}
|
||||
}
|
||||
|
||||
private boolean getItemById(UmbrellaUser user, de.srsoftware.tools.Path path, HttpExchange ex) throws IOException {
|
||||
var head = path.pop();
|
||||
if (head == null) throw missingField(Field.ID);
|
||||
try {
|
||||
var itemId = Long.parseLong(head);
|
||||
var item = stockDb.loadItem(itemId);
|
||||
var owner = item.location().resolve().owner().resolve();
|
||||
boolean allowed = owner instanceof UmbrellaUser u && user.equals(u);
|
||||
allowed = allowed || owner instanceof Company c && companyService().membership(c.id(),user.id());
|
||||
if (!allowed) throw forbidden("You are not allowed to access item {id}",ID,itemId);
|
||||
return sendContent(ex,item);
|
||||
} catch (NumberFormatException e) {
|
||||
throw invalidField(Field.ID, Text.NUMBER);
|
||||
}
|
||||
}
|
||||
|
||||
@Override
|
||||
public boolean doPatch(de.srsoftware.tools.Path path, HttpExchange ex) throws IOException {
|
||||
addCors(ex);
|
||||
|
||||
Reference in New Issue
Block a user