make em private
This commit is contained in:
parent
1394ce1e0c
commit
02cdca748d
4 changed files with 123 additions and 37 deletions
29
index.js
29
index.js
|
|
@ -320,7 +320,12 @@ wsRouter.ws("*", (ws, req) => {
|
|||
}
|
||||
|
||||
const { route } = found;
|
||||
if (!model.canAccessStructure(req.session && req.session.userId, route.structure_id)) {
|
||||
if (
|
||||
!model.canAccessStructure(
|
||||
req.session && req.session.userId,
|
||||
route.structure_id,
|
||||
)
|
||||
) {
|
||||
return ws.close(1008, "WebSocket route not found");
|
||||
}
|
||||
req.params = found.params;
|
||||
|
|
@ -382,7 +387,11 @@ buildRoutes();
|
|||
// crafted ?next= can't bounce someone to another origin (open redirect). A
|
||||
// leading `//` is protocol-relative and would escape our origin, so reject it.
|
||||
function safeNext(next) {
|
||||
if (typeof next !== "string" || !next.startsWith("/") || next.startsWith("//")) {
|
||||
if (
|
||||
typeof next !== "string" ||
|
||||
!next.startsWith("/") ||
|
||||
next.startsWith("//")
|
||||
) {
|
||||
return null;
|
||||
}
|
||||
return next;
|
||||
|
|
@ -1000,14 +1009,18 @@ app.put("/workshop/:structure_id/settings", (req, res) => {
|
|||
routePrefix = routePrefix.substring(0, routePrefix.length - 1);
|
||||
}
|
||||
|
||||
// An unchecked checkbox sends no field at all, so absence means "public".
|
||||
// An unchecked checkbox sends no field at all, so absence means "off".
|
||||
const wantPrivate = req.body.private === "on" || req.body.private === "1";
|
||||
const wantPublic = req.body.public === "on" || req.body.public === "1";
|
||||
if (wantPrivate && !req.session.userId) {
|
||||
return res
|
||||
.status(403)
|
||||
.send("log in before making a structure private, or you'll lock everyone out");
|
||||
.send(
|
||||
"log in before making a structure private, or you'll lock everyone out",
|
||||
);
|
||||
}
|
||||
model.setStructurePrivacy(structId, wantPrivate, req.session.userId);
|
||||
model.setStructurePublic(structId, wantPublic);
|
||||
|
||||
model.updateStruct({
|
||||
...struct,
|
||||
|
|
@ -1093,9 +1106,13 @@ app.all("*", async (req, res) => {
|
|||
// logged-in non-members still 404.
|
||||
if (!model.canAccessStructure(req.session.userId, route.structure_id)) {
|
||||
if (!req.session.userId && verb === "GET") {
|
||||
return res.redirect("/login?next=" + encodeURIComponent(req.originalUrl));
|
||||
return res.redirect(
|
||||
"/login?next=" + encodeURIComponent(req.originalUrl),
|
||||
);
|
||||
}
|
||||
return res.status(404).json({ success: false, message: "Path not found" });
|
||||
return res
|
||||
.status(404)
|
||||
.json({ success: false, message: "Path not found" });
|
||||
}
|
||||
|
||||
// Minimal, handcrafted view of the logged-in Bliss user for user routes.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue