ArticleController.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Models\Article;
  4. use App\Models\ArticleCollection;
  5. use App\Models\Collection;
  6. use Illuminate\Http\Request;
  7. use Illuminate\Support\Str;
  8. use App\Http\Resources\ArticleResource;
  9. use App\Http\Api\AuthApi;
  10. use App\Http\Api\ShareApi;
  11. use App\Http\Api\StudioApi;
  12. use Illuminate\Support\Facades\DB;
  13. class ArticleController extends Controller
  14. {
  15. public static function userCanRead($user_uid,Article $article){
  16. if($article->status === 30 ){
  17. return true;
  18. }
  19. if(empty($user_uid)){
  20. return false;
  21. }
  22. //私有文章,判断是否为所有者
  23. if($user_uid === $article->owner){
  24. return true;
  25. }
  26. //非所有者
  27. //判断是否为文章协作者
  28. $power = ShareApi::getResPower($user_uid,$article->uid);
  29. if($power >= 10 ){
  30. return true;
  31. }
  32. //无读取权限
  33. //判断文集是否有读取权限
  34. $inCollection = ArticleCollection::where('article_id',$article->uid)
  35. ->select('collect_id')
  36. ->groupBy('collect_id')->get();
  37. if(!$inCollection){
  38. return false;
  39. }
  40. //查找与文章同主人的文集
  41. $collections = Collection::whereIn('uid',$inCollection)
  42. ->where('owner',$article->owner)
  43. ->select('uid')
  44. ->get();
  45. if(!$collections){
  46. return false;
  47. }
  48. //查找与文章同主人的文集是否是共享的
  49. $power = 0;
  50. foreach ($collections as $collection) {
  51. # code...
  52. $currPower = ShareApi::getResPower($user_uid,$collection->uid);
  53. if($currPower >= 10){
  54. return true;
  55. }
  56. }
  57. return false;
  58. }
  59. public static function userCanEdit($user_uid,$article){
  60. if(empty($user_uid)){
  61. return false;
  62. }
  63. //私有文章,判断是否为所有者
  64. if($user_uid === $article->owner){
  65. return true;
  66. }
  67. //非所有者
  68. //判断是否为文章协作者
  69. $power = ShareApi::getResPower($user_uid,$article->uid);
  70. if($power >= 20 ){
  71. return true;
  72. }
  73. //无读取权限
  74. //判断文集是否有读取权限
  75. $inCollection = ArticleCollection::where('article_id',$article->uid)
  76. ->select('collect_id')
  77. ->groupBy('collect_id')->get();
  78. if(!$inCollection){
  79. return false;
  80. }
  81. //查找与文章同主人的文集
  82. $collections = Collection::whereIn('uid',$inCollection)
  83. ->where('owner',$article->owner)
  84. ->select('uid')
  85. ->get();
  86. if(!$collections){
  87. return false;
  88. }
  89. //查找与文章同主人的文集是否是共享的
  90. $power = 0;
  91. foreach ($collections as $collection) {
  92. # code...
  93. $currPower = ShareApi::getResPower($user_uid,$collection->uid);
  94. if($currPower >= 20){
  95. return true;
  96. }
  97. }
  98. return false;
  99. }
  100. public static function userCanManage($user_uid,$studioName){
  101. if(empty($user_uid)){
  102. return false;
  103. }
  104. //判断是否为所有者
  105. if($user_uid === StudioApi::getIdByName($studioName)){
  106. return true;
  107. }else{
  108. return false;
  109. }
  110. }
  111. /**
  112. * Display a listing of the resource.
  113. *
  114. * @return \Illuminate\Http\Response
  115. */
  116. public function index(Request $request)
  117. {
  118. //
  119. $field = ['uid','title','subtitle',
  120. 'summary','owner','lang',
  121. 'status','editor_id','updated_at','created_at'];
  122. if($request->get('content')==="true"){
  123. $field[] = 'content';
  124. $field[] = 'content_type';
  125. }
  126. $table = Article::select($field);
  127. switch ($request->get('view')) {
  128. case 'template':
  129. $studioId = StudioApi::getIdByName($request->get('studio_name'));
  130. $table = $table->where('owner', $studioId);
  131. break;
  132. case 'studio':
  133. # 获取studio内所有 article
  134. $user = AuthApi::current($request);
  135. if(!$user){
  136. return $this->error(__('auth.failed'),[],401);
  137. }
  138. //判断当前用户是否有指定的studio的权限
  139. $studioId = StudioApi::getIdByName($request->get('name'));
  140. if($user['user_uid'] !== $studioId){
  141. return $this->error(__('auth.failed'),[],403);
  142. }
  143. if($request->get('view2','my')==='my'){
  144. $table = $table->where('owner', $studioId);
  145. }else{
  146. //协作
  147. $resList = ShareApi::getResList($studioId,3);
  148. $resId=[];
  149. foreach ($resList as $res) {
  150. $resId[] = $res['res_id'];
  151. }
  152. $table = $table->whereIn('uid', $resId)->where('owner','<>', $studioId);
  153. }
  154. //根据anthology过滤
  155. if($request->has('anthology')){
  156. switch ($request->get('anthology')) {
  157. case 'all':
  158. break;
  159. case 'none':
  160. # 我的文集
  161. $myCollection = Collection::where('owner',$studioId)->select('uid')->get();
  162. //收录在我的文集里面的文章
  163. $articles = ArticleCollection::whereIn('collect_id',$myCollection)
  164. ->select('article_id')->groupBy('article_id')->get();
  165. //不在这些范围之内的文章
  166. $table = $table->whereNotIn('uid',$articles);
  167. break;
  168. default:
  169. $articles = ArticleCollection::where('collect_id',$request->get('anthology'))
  170. ->select('article_id')->get();
  171. $table = $table->whereIn('uid',$articles);
  172. break;
  173. }
  174. }
  175. break;
  176. case 'public':
  177. $table = $table->where('status',30);
  178. break;
  179. default:
  180. $this->error("view error");
  181. break;
  182. }
  183. //处理搜索
  184. if($request->has("search") && !empty($request->get("search"))){
  185. $table = $table->where('title', 'like', "%".$request->get("search")."%");
  186. }
  187. if($request->has("subtitle") && !empty($request->get("subtitle"))){
  188. $table = $table->where('subtitle', 'like', $request->get("subtitle"));
  189. }
  190. //获取记录总条数
  191. $count = $table->count();
  192. //处理排序
  193. $table = $table->orderBy($request->get("order",'updated_at'),
  194. $request->get("dir",'desc'));
  195. //处理分页
  196. $table = $table->skip($request->get("offset",0))
  197. ->take($request->get("limit",1000));
  198. //获取数据
  199. $result = $table->get();
  200. return $this->ok(["rows"=>ArticleResource::collection($result),"count"=>$count]);
  201. }
  202. /**
  203. * Display a listing of the resource.
  204. *
  205. * @return \Illuminate\Http\Response
  206. */
  207. public function showMyNumber(Request $request){
  208. $user = AuthApi::current($request);
  209. if(!$user){
  210. return $this->error(__('auth.failed'));
  211. }
  212. //判断当前用户是否有指定的studio的权限
  213. $studioId = StudioApi::getIdByName($request->get('studio'));
  214. if($user['user_uid'] !== $studioId){
  215. return $this->error(__('auth.failed'));
  216. }
  217. //我的
  218. $my = Article::where('owner', $studioId)->count();
  219. //协作
  220. $resList = ShareApi::getResList($studioId,3);
  221. $resId=[];
  222. foreach ($resList as $res) {
  223. $resId[] = $res['res_id'];
  224. }
  225. $collaboration = Article::whereIn('uid', $resId)->where('owner','<>', $studioId)->count();
  226. return $this->ok(['my'=>$my,'collaboration'=>$collaboration]);
  227. }
  228. /**
  229. * Store a newly created resource in storage.
  230. *
  231. * @param \Illuminate\Http\Request $request
  232. * @return \Illuminate\Http\Response
  233. */
  234. public function store(Request $request)
  235. {
  236. //判断权限
  237. $user = AuthApi::current($request);
  238. if(!$user){
  239. return $this->error(__('auth.failed'),[],401);
  240. }else{
  241. $user_uid=$user['user_uid'];
  242. }
  243. $canManage = ArticleController::userCanManage($user_uid,$request->get('studio'));
  244. if(!$canManage){
  245. return $this->error(__('auth.failed'),[],403);
  246. }
  247. //权限判断结束
  248. //查询标题是否重复
  249. /*
  250. if(Article::where('title',$request->get('title'))->where('owner',$studioUuid)->exists()){
  251. return $this->error(__('validation.exists'));
  252. }*/
  253. $newArticle = new Article;
  254. DB::transaction(function() use($user,$request,$newArticle){
  255. $studioUuid = StudioApi::getIdByName($request->get('studio'));
  256. //新建文章,加入文集必须都成功。否则回滚
  257. $newArticle->id = app('snowflake')->id();
  258. $newArticle->uid = Str::uuid();
  259. $newArticle->title = $request->get('title');
  260. $newArticle->lang = $request->get('lang');
  261. $newArticle->owner = $studioUuid;
  262. $newArticle->owner_id = $user['user_id'];
  263. $newArticle->editor_id = $user['user_id'];
  264. $newArticle->create_time = time()*1000;
  265. $newArticle->modify_time = time()*1000;
  266. $newArticle->save();
  267. if(Str::isUuid($request->get('anthologyId'))){
  268. $articleMap = new ArticleCollection();
  269. $articleMap->id = app('snowflake')->id();
  270. $articleMap->article_id = $newArticle->uid;
  271. $articleMap->collect_id = $request->get('anthologyId');
  272. $articleMap->title = Article::find($newArticle->uid)->title;
  273. $articleMap->level = 1;
  274. $articleMap->save();
  275. }
  276. });
  277. if(Str::isUuid($newArticle->uid)){
  278. return $this->ok($newArticle);
  279. }else{
  280. return $this->error('fail');
  281. }
  282. }
  283. /**
  284. * Display the specified resource.
  285. * @param \Illuminate\Http\Request $request
  286. * @param \App\Models\Article $article
  287. * @return \Illuminate\Http\Response
  288. */
  289. public function show(Request $request,Article $article)
  290. {
  291. //
  292. if(!$article){
  293. return $this->error("no recorder");
  294. }
  295. //判断权限
  296. $user = AuthApi::current($request);
  297. if(!$user){
  298. $user_uid="";
  299. }else{
  300. $user_uid=$user['user_uid'];
  301. }
  302. $canRead = ArticleController::userCanRead($user_uid,$article);
  303. if(!$canRead){
  304. return $this->error(__('auth.failed'),[],403);
  305. }
  306. return $this->ok(new ArticleResource($article));
  307. }
  308. /**
  309. * Display the specified resource.
  310. * @param \Illuminate\Http\Request $request
  311. * @param string $article
  312. * @return \Illuminate\Http\Response
  313. */
  314. public function preview(Request $request,string $articleId)
  315. {
  316. //
  317. $article = Article::find($articleId);
  318. if(!$article){
  319. return $this->error("no recorder");
  320. }
  321. //判断权限
  322. $user = AuthApi::current($request);
  323. if(!$user){
  324. $user_uid="";
  325. }else{
  326. $user_uid=$user['user_uid'];
  327. }
  328. $canRead = ArticleController::userCanRead($user_uid,$article);
  329. if(!$canRead){
  330. return $this->error(__('auth.failed'),[],401);
  331. }
  332. if($request->has('content')){
  333. $article->content = $request->get('content');
  334. return $this->ok(new ArticleResource($article));
  335. }else{
  336. return $this->error('no content',[],200);
  337. }
  338. }
  339. /**
  340. * Update the specified resource in storage.
  341. *
  342. * @param \Illuminate\Http\Request $request
  343. * @param \App\Models\Article $article
  344. * @return \Illuminate\Http\Response
  345. */
  346. public function update(Request $request, Article $article)
  347. {
  348. //
  349. if(!$article){
  350. return $this->error("no recorder");
  351. }
  352. //鉴权
  353. $user = AuthApi::current($request);
  354. if(!$user){
  355. return $this->error(__('auth.failed'),[],401);
  356. }else{
  357. $user_uid=$user['user_uid'];
  358. }
  359. $canEdit = ArticleController::userCanEdit($user_uid,$article);
  360. if(!$canEdit){
  361. return $this->error(__('auth.failed'),[],401);
  362. }
  363. /*
  364. //查询标题是否重复
  365. if(Article::where('title',$request->get('title'))
  366. ->where('owner',$article->owner)
  367. ->where('uid',"<>",$article->uid)
  368. ->exists()){
  369. return $this->error(__('validation.exists'));
  370. }*/
  371. $article->title = $request->get('title');
  372. $article->subtitle = $request->get('subtitle');
  373. $article->summary = $request->get('summary');
  374. $article->content = $request->get('content');
  375. $article->lang = $request->get('lang');
  376. $article->status = $request->get('status',10);
  377. $article->editor_id = $user['user_id'];
  378. $article->modify_time = time()*1000;
  379. $article->save();
  380. return $this->ok($article);
  381. }
  382. /**
  383. * Remove the specified resource from storage.
  384. * @param \Illuminate\Http\Request $request
  385. * @param \App\Models\Article $article
  386. * @return \Illuminate\Http\Response
  387. */
  388. public function destroy(Request $request,Article $article)
  389. {
  390. //
  391. $user = AuthApi::current($request);
  392. if(!$user){
  393. return $this->error(__('auth.failed'));
  394. }
  395. //判断当前用户是否有指定的studio的权限
  396. if($user['user_uid'] !== $article->owner){
  397. return $this->error(__('auth.failed'));
  398. }
  399. $delete = 0;
  400. DB::transaction(function() use($article,$delete){
  401. //TODO 删除文集中的文章
  402. $delete = $article->delete();
  403. ArticleMapController::deleteArticle($article->uid);
  404. });
  405. return $this->ok($delete);
  406. }
  407. }