ArticleController.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Models\Article;
  4. use App\Models\ArticleCollection;
  5. use App\Models\Collection;
  6. use Illuminate\Http\Request;
  7. use Illuminate\Support\Str;
  8. use App\Http\Resources\ArticleResource;
  9. use App\Http\Api\AuthApi;
  10. use App\Http\Api\ShareApi;
  11. use App\Http\Api\StudioApi;
  12. use Illuminate\Support\Facades\DB;
  13. class ArticleController extends Controller
  14. {
  15. public static function userCanRead($user_uid,Article $article){
  16. if($article->status === 30 ){
  17. return true;
  18. }
  19. if(empty($user_uid)){
  20. return false;
  21. }
  22. //私有文章,判断是否为所有者
  23. if($user_uid === $article->owner){
  24. return true;
  25. }
  26. //非所有者
  27. //判断是否为文章协作者
  28. $power = ShareApi::getResPower($user_uid,$article->uid);
  29. if($power >= 10 ){
  30. return true;
  31. }
  32. //无读取权限
  33. //判断文集是否有读取权限
  34. $inCollection = ArticleCollection::where('article_id',$article->uid)
  35. ->select('collect_id')
  36. ->groupBy('collect_id')->get();
  37. if(!$inCollection){
  38. return false;
  39. }
  40. //查找与文章同主人的文集
  41. $collections = Collection::whereIn('uid',$inCollection)
  42. ->where('owner',$article->owner)
  43. ->select('uid')
  44. ->get();
  45. if(!$collections){
  46. return false;
  47. }
  48. //查找与文章同主人的文集是否是共享的
  49. $power = 0;
  50. foreach ($collections as $collection) {
  51. # code...
  52. $currPower = ShareApi::getResPower($user_uid,$collection->uid);
  53. if($currPower >= 10){
  54. return true;
  55. }
  56. }
  57. return false;
  58. }
  59. public static function userCanEdit($user_uid,$article){
  60. if(empty($user_uid)){
  61. return false;
  62. }
  63. //私有文章,判断是否为所有者
  64. if($user_uid === $article->owner){
  65. return true;
  66. }
  67. //非所有者
  68. //判断是否为文章协作者
  69. $power = ShareApi::getResPower($user_uid,$article->uid);
  70. if($power >= 20 ){
  71. return true;
  72. }
  73. //无读取权限
  74. //判断文集是否有读取权限
  75. $inCollection = ArticleCollection::where('article_id',$article->uid)
  76. ->select('collect_id')
  77. ->groupBy('collect_id')->get();
  78. if(!$inCollection){
  79. return false;
  80. }
  81. //查找与文章同主人的文集
  82. $collections = Collection::whereIn('uid',$inCollection)
  83. ->where('owner',$article->owner)
  84. ->select('uid')
  85. ->get();
  86. if(!$collections){
  87. return false;
  88. }
  89. //查找与文章同主人的文集是否是共享的
  90. $power = 0;
  91. foreach ($collections as $collection) {
  92. # code...
  93. $currPower = ShareApi::getResPower($user_uid,$collection->uid);
  94. if($currPower >= 20){
  95. return true;
  96. }
  97. }
  98. return false;
  99. }
  100. public static function userCanManage($user_uid,$studioName){
  101. if(empty($user_uid)){
  102. return false;
  103. }
  104. //判断是否为所有者
  105. if($user_uid === StudioApi::getIdByName($studioName)){
  106. return true;
  107. }else{
  108. return false;
  109. }
  110. }
  111. /**
  112. * Display a listing of the resource.
  113. *
  114. * @return \Illuminate\Http\Response
  115. */
  116. public function index(Request $request)
  117. {
  118. //
  119. $field = ['uid','title','subtitle',
  120. 'summary','owner','lang',
  121. 'status','editor_id','updated_at','created_at'];
  122. if($request->get('content')==="true"){
  123. $field[] = 'content';
  124. $field[] = 'content_type';
  125. }
  126. $table = Article::select($field);
  127. switch ($request->get('view')) {
  128. case 'template':
  129. $studioId = StudioApi::getIdByName($request->get('studio_name'));
  130. $table = $table->where('owner', $studioId);
  131. break;
  132. case 'studio':
  133. # 获取studio内所有 article
  134. $user = AuthApi::current($request);
  135. if(!$user){
  136. return $this->error(__('auth.failed'),[],401);
  137. }
  138. //判断当前用户是否有指定的studio的权限
  139. $studioId = StudioApi::getIdByName($request->get('name'));
  140. if($user['user_uid'] !== $studioId){
  141. return $this->error(__('auth.failed'),[],403);
  142. }
  143. if($request->get('view2','my')==='my'){
  144. $table = $table->where('owner', $studioId);
  145. }else{
  146. //协作
  147. $resList = ShareApi::getResList($studioId,3);
  148. $resId=[];
  149. foreach ($resList as $res) {
  150. $resId[] = $res['res_id'];
  151. }
  152. $table = $table->whereIn('uid', $resId)->where('owner','<>', $studioId);
  153. }
  154. //根据anthology过滤
  155. if($request->has('anthology')){
  156. switch ($request->get('anthology')) {
  157. case 'all':
  158. break;
  159. case 'none':
  160. # 我的文集
  161. $myCollection = Collection::where('owner',$studioId)->select('uid')->get();
  162. //收录在我的文集里面的文章
  163. $articles = ArticleCollection::whereIn('collect_id',$myCollection)
  164. ->select('article_id')->groupBy('article_id')->get();
  165. //不在这些范围之内的文章
  166. $table = $table->whereNotIn('uid',$articles);
  167. break;
  168. default:
  169. $articles = ArticleCollection::where('collect_id',$request->get('anthology'))
  170. ->select('article_id')->get();
  171. $table = $table->whereIn('uid',$articles);
  172. break;
  173. }
  174. }
  175. break;
  176. case 'public':
  177. $table = $table->where('status',30);
  178. break;
  179. default:
  180. $this->error("view error");
  181. break;
  182. }
  183. //处理搜索
  184. if($request->has("search") && !empty($request->get("search"))){
  185. $table = $table->where('title', 'like', "%".$request->get("search")."%");
  186. }
  187. if($request->has("subtitle") && !empty($request->get("subtitle"))){
  188. $table = $table->where('subtitle', 'like', $request->get("subtitle"));
  189. }
  190. //获取记录总条数
  191. $count = $table->count();
  192. //处理排序
  193. $table = $table->orderBy($request->get("order",'updated_at'),
  194. $request->get("dir",'desc'));
  195. //处理分页
  196. $table = $table->skip($request->get("offset",0))
  197. ->take($request->get("limit",1000));
  198. //获取数据
  199. $result = $table->get();
  200. return $this->ok(["rows"=>ArticleResource::collection($result),"count"=>$count]);
  201. }
  202. /**
  203. * Display a listing of the resource.
  204. *
  205. * @return \Illuminate\Http\Response
  206. */
  207. public function showMyNumber(Request $request){
  208. $user = AuthApi::current($request);
  209. if(!$user){
  210. return $this->error(__('auth.failed'));
  211. }
  212. //判断当前用户是否有指定的studio的权限
  213. $studioId = StudioApi::getIdByName($request->get('studio'));
  214. if($user['user_uid'] !== $studioId){
  215. return $this->error(__('auth.failed'));
  216. }
  217. //我的
  218. $my = Article::where('owner', $studioId)->count();
  219. //协作
  220. $resList = ShareApi::getResList($studioId,3);
  221. $resId=[];
  222. foreach ($resList as $res) {
  223. $resId[] = $res['res_id'];
  224. }
  225. $collaboration = Article::whereIn('uid', $resId)->where('owner','<>', $studioId)->count();
  226. return $this->ok(['my'=>$my,'collaboration'=>$collaboration]);
  227. }
  228. /**
  229. * Store a newly created resource in storage.
  230. *
  231. * @param \Illuminate\Http\Request $request
  232. * @return \Illuminate\Http\Response
  233. */
  234. public function store(Request $request)
  235. {
  236. //判断权限
  237. $user = AuthApi::current($request);
  238. if(!$user){
  239. return $this->error(__('auth.failed'),[],401);
  240. }else{
  241. $user_uid=$user['user_uid'];
  242. }
  243. $canManage = ArticleController::userCanManage($user_uid,$request->get('studio'));
  244. if(!$canManage){
  245. //判断是否有文集权限
  246. if($request->has('anthologyId')){
  247. $currPower = ShareApi::getResPower($user_uid,$request->get('anthologyId'));
  248. if($currPower <= 10){
  249. return $this->error(__('auth.failed'),[],403);
  250. }
  251. }else{
  252. return $this->error(__('auth.failed'),[],403);
  253. }
  254. }
  255. //权限判断结束
  256. //查询标题是否重复
  257. /*
  258. if(Article::where('title',$request->get('title'))->where('owner',$studioUuid)->exists()){
  259. return $this->error(__('validation.exists'));
  260. }*/
  261. $newArticle = new Article;
  262. DB::transaction(function() use($user,$request,$newArticle){
  263. $studioUuid = StudioApi::getIdByName($request->get('studio'));
  264. //新建文章,加入文集必须都成功。否则回滚
  265. $newArticle->id = app('snowflake')->id();
  266. $newArticle->uid = Str::uuid();
  267. $newArticle->title = $request->get('title');
  268. $newArticle->lang = $request->get('lang');
  269. $newArticle->owner = $studioUuid;
  270. $newArticle->owner_id = $user['user_id'];
  271. $newArticle->editor_id = $user['user_id'];
  272. $newArticle->create_time = time()*1000;
  273. $newArticle->modify_time = time()*1000;
  274. $newArticle->save();
  275. if(Str::isUuid($request->get('anthologyId'))){
  276. $articleMap = new ArticleCollection();
  277. $articleMap->id = app('snowflake')->id();
  278. $articleMap->article_id = $newArticle->uid;
  279. $articleMap->collect_id = $request->get('anthologyId');
  280. $articleMap->title = Article::find($newArticle->uid)->title;
  281. $articleMap->level = 1;
  282. $articleMap->save();
  283. }
  284. });
  285. if(Str::isUuid($newArticle->uid)){
  286. return $this->ok($newArticle);
  287. }else{
  288. return $this->error('fail');
  289. }
  290. }
  291. /**
  292. * Display the specified resource.
  293. * @param \Illuminate\Http\Request $request
  294. * @param \App\Models\Article $article
  295. * @return \Illuminate\Http\Response
  296. */
  297. public function show(Request $request,Article $article)
  298. {
  299. //
  300. if(!$article){
  301. return $this->error("no recorder");
  302. }
  303. //判断权限
  304. $user = AuthApi::current($request);
  305. if(!$user){
  306. $user_uid="";
  307. }else{
  308. $user_uid=$user['user_uid'];
  309. }
  310. $canRead = ArticleController::userCanRead($user_uid,$article);
  311. if(!$canRead){
  312. return $this->error(__('auth.failed'),[],403);
  313. }
  314. return $this->ok(new ArticleResource($article));
  315. }
  316. /**
  317. * Display the specified resource.
  318. * @param \Illuminate\Http\Request $request
  319. * @param string $article
  320. * @return \Illuminate\Http\Response
  321. */
  322. public function preview(Request $request,string $articleId)
  323. {
  324. //
  325. $article = Article::find($articleId);
  326. if(!$article){
  327. return $this->error("no recorder");
  328. }
  329. //判断权限
  330. $user = AuthApi::current($request);
  331. if(!$user){
  332. $user_uid="";
  333. }else{
  334. $user_uid=$user['user_uid'];
  335. }
  336. $canRead = ArticleController::userCanRead($user_uid,$article);
  337. if(!$canRead){
  338. return $this->error(__('auth.failed'),[],401);
  339. }
  340. if($request->has('content')){
  341. $article->content = $request->get('content');
  342. return $this->ok(new ArticleResource($article));
  343. }else{
  344. return $this->error('no content',[],200);
  345. }
  346. }
  347. /**
  348. * Update the specified resource in storage.
  349. *
  350. * @param \Illuminate\Http\Request $request
  351. * @param \App\Models\Article $article
  352. * @return \Illuminate\Http\Response
  353. */
  354. public function update(Request $request, Article $article)
  355. {
  356. //
  357. if(!$article){
  358. return $this->error("no recorder");
  359. }
  360. //鉴权
  361. $user = AuthApi::current($request);
  362. if(!$user){
  363. return $this->error(__('auth.failed'),[],401);
  364. }else{
  365. $user_uid=$user['user_uid'];
  366. }
  367. $canEdit = ArticleController::userCanEdit($user_uid,$article);
  368. if(!$canEdit){
  369. return $this->error(__('auth.failed'),[],401);
  370. }
  371. /*
  372. //查询标题是否重复
  373. if(Article::where('title',$request->get('title'))
  374. ->where('owner',$article->owner)
  375. ->where('uid',"<>",$article->uid)
  376. ->exists()){
  377. return $this->error(__('validation.exists'));
  378. }*/
  379. $article->title = $request->get('title');
  380. $article->subtitle = $request->get('subtitle');
  381. $article->summary = $request->get('summary');
  382. $article->content = $request->get('content');
  383. $article->lang = $request->get('lang');
  384. $article->status = $request->get('status',10);
  385. $article->editor_id = $user['user_id'];
  386. $article->modify_time = time()*1000;
  387. $article->save();
  388. return $this->ok($article);
  389. }
  390. /**
  391. * Remove the specified resource from storage.
  392. * @param \Illuminate\Http\Request $request
  393. * @param \App\Models\Article $article
  394. * @return \Illuminate\Http\Response
  395. */
  396. public function destroy(Request $request,Article $article)
  397. {
  398. //
  399. $user = AuthApi::current($request);
  400. if(!$user){
  401. return $this->error(__('auth.failed'));
  402. }
  403. //判断当前用户是否有指定的studio的权限
  404. if($user['user_uid'] !== $article->owner){
  405. return $this->error(__('auth.failed'));
  406. }
  407. $delete = 0;
  408. DB::transaction(function() use($article,$delete){
  409. //TODO 删除文集中的文章
  410. $delete = $article->delete();
  411. ArticleMapController::deleteArticle($article->uid);
  412. });
  413. return $this->ok($delete);
  414. }
  415. }