EZQMS-729: Restrict spaces operations (#5500)

This commit is contained in:
Alexey Zinoviev
2024-05-04 20:49:24 +07:00
committed by GitHub
parent ad59463057
commit 4bc1534ee0
57 changed files with 873 additions and 114 deletions
+5 -2
View File
@@ -120,7 +120,7 @@ import {
import { IndexedDocumentPreview } from '@hcengineering/presentation'
import { AggregationMiddleware, AnalyticsMiddleware } from './middleware'
import { showEmptyGroups } from './viewOptions'
import { canDeleteObject } from './visibilityTester'
import { canArchiveSpace, canDeleteObject, canDeleteSpace, canEditSpace } from './visibilityTester'
export { getActions, getContextActions, invokeAction, showMenu } from './actions'
export { default as ActionButton } from './components/ActionButton.svelte'
export { default as ActionHandler } from './components/ActionHandler.svelte'
@@ -303,6 +303,9 @@ export default async (): Promise<Resources> => ({
CreateDocMiddleware: AggregationMiddleware.create,
// eslint-disable-next-line @typescript-eslint/unbound-method
AnalyticsMiddleware: AnalyticsMiddleware.create,
CanDeleteObject: canDeleteObject
CanDeleteObject: canDeleteObject,
CanEditSpace: canEditSpace,
CanArchiveSpace: canArchiveSpace,
CanDeleteSpace: canDeleteSpace
}
})
+69 -1
View File
@@ -13,7 +13,7 @@
// limitations under the License.
//
import core, { checkPermission, type Space, type Doc, type TypedSpace } from '@hcengineering/core'
import core, { checkPermission, type Space, type Doc, type TypedSpace, getCurrentAccount } from '@hcengineering/core'
import { getClient } from '@hcengineering/presentation'
function isTypedSpace (space: Space): space is TypedSpace {
@@ -40,3 +40,71 @@ export async function canDeleteObject (doc?: Doc | Doc[]): Promise<boolean> {
)
).some((r) => r)
}
export async function canEditSpace (doc?: Doc | Doc[]): Promise<boolean> {
if (doc === undefined || Array.isArray(doc)) {
return false
}
const space = doc as Space
if (space.owners?.includes(getCurrentAccount()._id) ?? false) {
return true
}
const client = getClient()
if (await checkPermission(client, core.permission.UpdateObject, core.space.Space)) {
return true
}
if (isTypedSpace(space) && (await checkPermission(client, core.permission.UpdateSpace, space._id))) {
return true
}
return false
}
export async function canArchiveSpace (doc?: Doc | Doc[]): Promise<boolean> {
if (doc === undefined || Array.isArray(doc)) {
return false
}
const space = doc as Space
if (space.owners?.includes(getCurrentAccount()._id) ?? false) {
return true
}
const client = getClient()
if (await checkPermission(client, core.permission.DeleteObject, core.space.Space)) {
return true
}
if (isTypedSpace(space) && (await checkPermission(client, core.permission.ArchiveSpace, space._id))) {
return true
}
return false
}
export async function canDeleteSpace (doc?: Doc | Doc[]): Promise<boolean> {
if (doc === undefined || Array.isArray(doc)) {
return false
}
const space = doc as Space
if (space.owners?.includes(getCurrentAccount()._id) ?? false) {
return true
}
const client = getClient()
if (await checkPermission(client, core.permission.DeleteObject, core.space.Space)) {
return true
}
return false
}