ArticleController.php 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Models\Article;
  4. use App\Models\ArticleCollection;
  5. use App\Models\Collection;
  6. use Illuminate\Http\Request;
  7. use Illuminate\Support\Str;
  8. use App\Http\Resources\ArticleResource;
  9. use App\Http\Api\AuthApi;
  10. use App\Http\Api\ShareApi;
  11. use App\Http\Api\StudioApi;
  12. use Illuminate\Support\Facades\DB;
  13. class ArticleController extends Controller
  14. {
  15. public static function userCanRead($user_uid,Article $article){
  16. if($article->status === 30 ){
  17. return true;
  18. }
  19. if(empty($user_uid)){
  20. return false;
  21. }
  22. //私有文章,判断是否为所有者
  23. if($user_uid === $article->owner){
  24. return true;
  25. }
  26. //非所有者
  27. //判断是否为文章协作者
  28. $power = ShareApi::getResPower($user_uid,$article->uid);
  29. if($power >= 10 ){
  30. return true;
  31. }
  32. //无读取权限
  33. //判断文集是否有读取权限
  34. $inCollection = ArticleCollection::where('article_id',$article->uid)
  35. ->select('collect_id')
  36. ->groupBy('collect_id')->get();
  37. if(!$inCollection){
  38. return false;
  39. }
  40. //查找与文章同主人的文集
  41. $collections = Collection::whereIn('uid',$inCollection)
  42. ->where('owner',$article->owner)
  43. ->select('uid')
  44. ->get();
  45. if(!$collections){
  46. return false;
  47. }
  48. //查找与文章同主人的文集是否是共享的
  49. $power = 0;
  50. foreach ($collections as $collection) {
  51. # code...
  52. $currPower = ShareApi::getResPower($user_uid,$collection->uid);
  53. if($currPower >= 10){
  54. return true;
  55. }
  56. }
  57. return false;
  58. }
  59. public static function userCanEdit($user_uid,$article){
  60. if(empty($user_uid)){
  61. return false;
  62. }
  63. //私有文章,判断是否为所有者
  64. if($user_uid === $article->owner){
  65. return true;
  66. }
  67. //非所有者
  68. //判断是否为文章协作者
  69. $power = ShareApi::getResPower($user_uid,$article->uid);
  70. if($power >= 20 ){
  71. return true;
  72. }
  73. //无读取权限
  74. //判断文集是否有读取权限
  75. $inCollection = ArticleCollection::where('article_id',$article->uid)
  76. ->select('collect_id')
  77. ->groupBy('collect_id')->get();
  78. if(!$inCollection){
  79. return false;
  80. }
  81. //查找与文章同主人的文集
  82. $collections = Collection::whereIn('uid',$inCollection)
  83. ->where('owner',$article->owner)
  84. ->select('uid')
  85. ->get();
  86. if(!$collections){
  87. return false;
  88. }
  89. //查找与文章同主人的文集是否是共享的
  90. $power = 0;
  91. foreach ($collections as $collection) {
  92. # code...
  93. $currPower = ShareApi::getResPower($user_uid,$collection->uid);
  94. if($currPower >= 20){
  95. return true;
  96. }
  97. }
  98. return false;
  99. }
  100. public static function userCanManage($user_uid,$studioName){
  101. if(empty($user_uid)){
  102. return false;
  103. }
  104. //判断是否为所有者
  105. if($user_uid === StudioApi::getIdByName($studioName)){
  106. return true;
  107. }else{
  108. return false;
  109. }
  110. }
  111. /**
  112. * Display a listing of the resource.
  113. *
  114. * @return \Illuminate\Http\Response
  115. */
  116. public function index(Request $request)
  117. {
  118. //
  119. $indexCol = ['uid','title','subtitle','summary','owner','lang','status','updated_at','created_at'];
  120. switch ($request->get('view')) {
  121. case 'studio':
  122. # 获取studio内所有channel
  123. $user = \App\Http\Api\AuthApi::current($request);
  124. if(!$user){
  125. return $this->error(__('auth.failed'));
  126. }
  127. //判断当前用户是否有指定的studio的权限
  128. $studioId = StudioApi::getIdByName($request->get('name'));
  129. if($user['user_uid'] !== $studioId){
  130. return $this->error(__('auth.failed'));
  131. }
  132. $table = Article::select($indexCol)->where('owner', $studioId);
  133. //根据anthology过滤
  134. if($request->has('anthology')){
  135. switch ($request->get('anthology')) {
  136. case 'all':
  137. break;
  138. case 'none':
  139. # 我的文集
  140. $myCollection = Collection::where('owner',$studioId)->select('uid')->get();
  141. //收录在我的文集里面的文章
  142. $articles = ArticleCollection::whereIn('collect_id',$myCollection)
  143. ->select('article_id')->groupBy('article_id')->get();
  144. //不在这些范围之内的文章
  145. $table = $table->whereNotIn('uid',$articles);
  146. break;
  147. default:
  148. $articles = ArticleCollection::where('collect_id',$request->get('anthology'))
  149. ->select('article_id')->get();
  150. $table = $table->whereIn('uid',$articles);
  151. break;
  152. }
  153. }
  154. break;
  155. }
  156. //处理搜索
  157. if($request->has("search") && !empty($request->has("search"))){
  158. $table = $table->where('title', 'like', "%".$request->get("search")."%");
  159. }
  160. //获取记录总条数
  161. $count = $table->count();
  162. //处理排序
  163. if(isset($_GET["order"]) && isset($_GET["dir"])){
  164. $table = $table->orderBy($_GET["order"],$_GET["dir"]);
  165. }else{
  166. //默认排序
  167. $table = $table->orderBy('updated_at','desc');
  168. }
  169. //处理分页
  170. if($request->has("limit")){
  171. if($request->has("offset")){
  172. $offset = $request->get("offset");
  173. }else{
  174. $offset = 0;
  175. }
  176. $table = $table->skip($offset)->take($request->get("limit"));
  177. }
  178. //获取数据
  179. $result = $table->get();
  180. if($result){
  181. return $this->ok(["rows"=>ArticleResource::collection($result),"count"=>$count]);
  182. }else{
  183. return $this->error("没有查询到数据");
  184. }
  185. }
  186. /**
  187. * Store a newly created resource in storage.
  188. *
  189. * @param \Illuminate\Http\Request $request
  190. * @return \Illuminate\Http\Response
  191. */
  192. public function store(Request $request)
  193. {
  194. //判断权限
  195. $user = AuthApi::current($request);
  196. if(!$user){
  197. return $this->error(__('auth.failed'),[],401);
  198. }else{
  199. $user_uid=$user['user_uid'];
  200. }
  201. $canManage = ArticleController::userCanManage($user_uid,$request->get('studio'));
  202. if(!$canManage){
  203. return $this->error(__('auth.failed'),[],403);
  204. }
  205. //权限判断结束
  206. $studioUuid = StudioApi::getIdByName($request->get('studio'));
  207. //查询标题是否重复
  208. /*
  209. if(Article::where('title',$request->get('title'))->where('owner',$studioUuid)->exists()){
  210. return $this->error(__('validation.exists'));
  211. }*/
  212. $newOne = new Article;
  213. $newOne->id = app('snowflake')->id();
  214. $newOne->uid = Str::uuid();
  215. $newOne->title = $request->get('title');
  216. $newOne->lang = $request->get('lang');
  217. $newOne->owner = $studioUuid;
  218. $newOne->owner_id = $user['user_id'];
  219. $newOne->editor_id = $user['user_id'];
  220. $newOne->create_time = time()*1000;
  221. $newOne->modify_time = time()*1000;
  222. $newOne->save();
  223. return $this->ok($newOne);
  224. }
  225. /**
  226. * Display the specified resource.
  227. * @param \Illuminate\Http\Request $request
  228. * @param \App\Models\Article $article
  229. * @return \Illuminate\Http\Response
  230. */
  231. public function show(Request $request,Article $article)
  232. {
  233. //
  234. if(!$article){
  235. return $this->error("no recorder");
  236. }
  237. //判断权限
  238. $user = AuthApi::current($request);
  239. if(!$user){
  240. $user_uid="";
  241. }else{
  242. $user_uid=$user['user_uid'];
  243. }
  244. $canRead = ArticleController::userCanRead($user_uid,$article);
  245. if(!$canRead){
  246. return $this->error(__('auth.failed'),[],401);
  247. }
  248. return $this->ok(new ArticleResource($article));
  249. }
  250. /**
  251. * Update the specified resource in storage.
  252. *
  253. * @param \Illuminate\Http\Request $request
  254. * @param \App\Models\Article $article
  255. * @return \Illuminate\Http\Response
  256. */
  257. public function update(Request $request, Article $article)
  258. {
  259. //
  260. if(!$article){
  261. return $this->error("no recorder");
  262. }
  263. //鉴权
  264. $user = AuthApi::current($request);
  265. if(!$user){
  266. return $this->error(__('auth.failed'),[],401);
  267. }else{
  268. $user_uid=$user['user_uid'];
  269. }
  270. $canEdit = ArticleController::userCanEdit($user_uid,$article);
  271. if(!$canEdit){
  272. return $this->error(__('auth.failed'),[],401);
  273. }
  274. /*
  275. //查询标题是否重复
  276. if(Article::where('title',$request->get('title'))
  277. ->where('owner',$article->owner)
  278. ->where('uid',"<>",$article->uid)
  279. ->exists()){
  280. return $this->error(__('validation.exists'));
  281. }*/
  282. $article->title = $request->get('title');
  283. $article->subtitle = $request->get('subtitle');
  284. $article->summary = $request->get('summary');
  285. $article->content = $request->get('content');
  286. $article->lang = $request->get('lang');
  287. $article->status = $request->get('status',10);
  288. $article->editor_id = $user['user_id'];
  289. $article->modify_time = time()*1000;
  290. $article->save();
  291. return $this->ok($article);
  292. }
  293. /**
  294. * Remove the specified resource from storage.
  295. * @param \Illuminate\Http\Request $request
  296. * @param \App\Models\Article $article
  297. * @return \Illuminate\Http\Response
  298. */
  299. public function destroy(Request $request,Article $article)
  300. {
  301. //
  302. $user = AuthApi::current($request);
  303. if(!$user){
  304. return $this->error(__('auth.failed'));
  305. }
  306. //判断当前用户是否有指定的studio的权限
  307. if($user['user_uid'] !== $article->owner){
  308. return $this->error(__('auth.failed'));
  309. }
  310. $delete = 0;
  311. DB::transaction(function() use($article,$delete){
  312. //TODO 删除文集中的文章
  313. $delete = $article->delete();
  314. });
  315. return $this->ok($delete);
  316. }
  317. }