mirror of
https://github.com/hcengineering/platform.git
synced 2026-09-28 12:35:02 +02:00
EZQMS-729: Restrict spaces operations (#5500)
This commit is contained in:
@@ -120,7 +120,7 @@ import {
|
||||
import { IndexedDocumentPreview } from '@hcengineering/presentation'
|
||||
import { AggregationMiddleware, AnalyticsMiddleware } from './middleware'
|
||||
import { showEmptyGroups } from './viewOptions'
|
||||
import { canDeleteObject } from './visibilityTester'
|
||||
import { canArchiveSpace, canDeleteObject, canDeleteSpace, canEditSpace } from './visibilityTester'
|
||||
export { getActions, getContextActions, invokeAction, showMenu } from './actions'
|
||||
export { default as ActionButton } from './components/ActionButton.svelte'
|
||||
export { default as ActionHandler } from './components/ActionHandler.svelte'
|
||||
@@ -303,6 +303,9 @@ export default async (): Promise<Resources> => ({
|
||||
CreateDocMiddleware: AggregationMiddleware.create,
|
||||
// eslint-disable-next-line @typescript-eslint/unbound-method
|
||||
AnalyticsMiddleware: AnalyticsMiddleware.create,
|
||||
CanDeleteObject: canDeleteObject
|
||||
CanDeleteObject: canDeleteObject,
|
||||
CanEditSpace: canEditSpace,
|
||||
CanArchiveSpace: canArchiveSpace,
|
||||
CanDeleteSpace: canDeleteSpace
|
||||
}
|
||||
})
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
// limitations under the License.
|
||||
//
|
||||
|
||||
import core, { checkPermission, type Space, type Doc, type TypedSpace } from '@hcengineering/core'
|
||||
import core, { checkPermission, type Space, type Doc, type TypedSpace, getCurrentAccount } from '@hcengineering/core'
|
||||
import { getClient } from '@hcengineering/presentation'
|
||||
|
||||
function isTypedSpace (space: Space): space is TypedSpace {
|
||||
@@ -40,3 +40,71 @@ export async function canDeleteObject (doc?: Doc | Doc[]): Promise<boolean> {
|
||||
)
|
||||
).some((r) => r)
|
||||
}
|
||||
|
||||
export async function canEditSpace (doc?: Doc | Doc[]): Promise<boolean> {
|
||||
if (doc === undefined || Array.isArray(doc)) {
|
||||
return false
|
||||
}
|
||||
|
||||
const space = doc as Space
|
||||
|
||||
if (space.owners?.includes(getCurrentAccount()._id) ?? false) {
|
||||
return true
|
||||
}
|
||||
|
||||
const client = getClient()
|
||||
|
||||
if (await checkPermission(client, core.permission.UpdateObject, core.space.Space)) {
|
||||
return true
|
||||
}
|
||||
|
||||
if (isTypedSpace(space) && (await checkPermission(client, core.permission.UpdateSpace, space._id))) {
|
||||
return true
|
||||
}
|
||||
|
||||
return false
|
||||
}
|
||||
|
||||
export async function canArchiveSpace (doc?: Doc | Doc[]): Promise<boolean> {
|
||||
if (doc === undefined || Array.isArray(doc)) {
|
||||
return false
|
||||
}
|
||||
|
||||
const space = doc as Space
|
||||
|
||||
if (space.owners?.includes(getCurrentAccount()._id) ?? false) {
|
||||
return true
|
||||
}
|
||||
|
||||
const client = getClient()
|
||||
|
||||
if (await checkPermission(client, core.permission.DeleteObject, core.space.Space)) {
|
||||
return true
|
||||
}
|
||||
|
||||
if (isTypedSpace(space) && (await checkPermission(client, core.permission.ArchiveSpace, space._id))) {
|
||||
return true
|
||||
}
|
||||
|
||||
return false
|
||||
}
|
||||
|
||||
export async function canDeleteSpace (doc?: Doc | Doc[]): Promise<boolean> {
|
||||
if (doc === undefined || Array.isArray(doc)) {
|
||||
return false
|
||||
}
|
||||
|
||||
const space = doc as Space
|
||||
|
||||
if (space.owners?.includes(getCurrentAccount()._id) ?? false) {
|
||||
return true
|
||||
}
|
||||
|
||||
const client = getClient()
|
||||
|
||||
if (await checkPermission(client, core.permission.DeleteObject, core.space.Space)) {
|
||||
return true
|
||||
}
|
||||
|
||||
return false
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user