ArticleController.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Models\Article;
  4. use App\Models\ArticleCollection;
  5. use App\Models\Collection;
  6. use Illuminate\Http\Request;
  7. use Illuminate\Support\Str;
  8. use App\Http\Resources\ArticleResource;
  9. use App\Http\Api\AuthApi;
  10. use App\Http\Api\ShareApi;
  11. use App\Http\Api\StudioApi;
  12. use Illuminate\Support\Facades\DB;
  13. use Illuminate\Support\Facades\Log;
  14. class ArticleController extends Controller
  15. {
  16. public static function userCanRead($user_uid,Article $article){
  17. if($article->status === 30 ){
  18. return true;
  19. }
  20. if(empty($user_uid)){
  21. return false;
  22. }
  23. //私有文章,判断是否为所有者
  24. if($user_uid === $article->owner){
  25. return true;
  26. }
  27. //非所有者
  28. //判断是否为文章协作者
  29. $power = ShareApi::getResPower($user_uid,$article->uid);
  30. if($power >= 10 ){
  31. return true;
  32. }
  33. //无读取权限
  34. //判断文集是否有读取权限
  35. $inCollection = ArticleCollection::where('article_id',$article->uid)
  36. ->select('collect_id')
  37. ->groupBy('collect_id')->get();
  38. if(!$inCollection){
  39. return false;
  40. }
  41. //查找与文章同主人的文集
  42. $collections = Collection::whereIn('uid',$inCollection)
  43. ->where('owner',$article->owner)
  44. ->select('uid')
  45. ->get();
  46. if(!$collections){
  47. return false;
  48. }
  49. //查找与文章同主人的文集是否是共享的
  50. $power = 0;
  51. foreach ($collections as $collection) {
  52. # code...
  53. $currPower = ShareApi::getResPower($user_uid,$collection->uid);
  54. if($currPower >= 10){
  55. return true;
  56. }
  57. }
  58. return false;
  59. }
  60. public static function userCanEdit($user_uid,$article){
  61. if(empty($user_uid)){
  62. return false;
  63. }
  64. //私有文章,判断是否为所有者
  65. if($user_uid === $article->owner){
  66. return true;
  67. }
  68. //非所有者
  69. //判断是否为文章协作者
  70. $power = ShareApi::getResPower($user_uid,$article->uid);
  71. if($power >= 20 ){
  72. return true;
  73. }
  74. //无读取权限
  75. //判断文集是否有读取权限
  76. $inCollection = ArticleCollection::where('article_id',$article->uid)
  77. ->select('collect_id')
  78. ->groupBy('collect_id')->get();
  79. if(!$inCollection){
  80. return false;
  81. }
  82. //查找与文章同主人的文集
  83. $collections = Collection::whereIn('uid',$inCollection)
  84. ->where('owner',$article->owner)
  85. ->select('uid')
  86. ->get();
  87. if(!$collections){
  88. return false;
  89. }
  90. //查找与文章同主人的文集是否是共享的
  91. $power = 0;
  92. foreach ($collections as $collection) {
  93. # code...
  94. $currPower = ShareApi::getResPower($user_uid,$collection->uid);
  95. if($currPower >= 20){
  96. return true;
  97. }
  98. }
  99. return false;
  100. }
  101. public static function userCanManage($user_uid,$studioName){
  102. if(empty($user_uid)){
  103. return false;
  104. }
  105. //判断是否为所有者
  106. if($user_uid === StudioApi::getIdByName($studioName)){
  107. return true;
  108. }else{
  109. return false;
  110. }
  111. }
  112. /**
  113. * Display a listing of the resource.
  114. *
  115. * @return \Illuminate\Http\Response
  116. */
  117. public function index(Request $request)
  118. {
  119. //
  120. $field = ['uid','title','subtitle',
  121. 'summary','owner','lang',
  122. 'status','editor_id','updated_at','created_at'];
  123. if($request->get('content')==="true"){
  124. $field[] = 'content';
  125. $field[] = 'content_type';
  126. }
  127. $table = Article::select($field);
  128. switch ($request->get('view')) {
  129. case 'template':
  130. $studioId = StudioApi::getIdByName($request->get('studio_name'));
  131. $table = $table->where('owner', $studioId);
  132. break;
  133. case 'studio':
  134. # 获取studio内所有 article
  135. $user = AuthApi::current($request);
  136. if(!$user){
  137. return $this->error(__('auth.failed'),[],401);
  138. }
  139. //判断当前用户是否有指定的studio的权限
  140. $studioId = StudioApi::getIdByName($request->get('name'));
  141. if($user['user_uid'] !== $studioId){
  142. return $this->error(__('auth.failed'),[],403);
  143. }
  144. if($request->get('view2','my')==='my'){
  145. $table = $table->where('owner', $studioId);
  146. }else{
  147. //协作
  148. $resList = ShareApi::getResList($studioId,3);
  149. $resId=[];
  150. foreach ($resList as $res) {
  151. $resId[] = $res['res_id'];
  152. }
  153. $table = $table->whereIn('uid', $resId)->where('owner','<>', $studioId);
  154. }
  155. //根据anthology过滤
  156. if($request->has('anthology')){
  157. switch ($request->get('anthology')) {
  158. case 'all':
  159. break;
  160. case 'none':
  161. # 我的文集
  162. $myCollection = Collection::where('owner',$studioId)->select('uid')->get();
  163. //收录在我的文集里面的文章
  164. $articles = ArticleCollection::whereIn('collect_id',$myCollection)
  165. ->select('article_id')->groupBy('article_id')->get();
  166. //不在这些范围之内的文章
  167. $table = $table->whereNotIn('uid',$articles);
  168. break;
  169. default:
  170. $articles = ArticleCollection::where('collect_id',$request->get('anthology'))
  171. ->select('article_id')->get();
  172. $table = $table->whereIn('uid',$articles);
  173. break;
  174. }
  175. }
  176. break;
  177. case 'public':
  178. $table = $table->where('status',30);
  179. break;
  180. default:
  181. $this->error("view error");
  182. break;
  183. }
  184. //处理搜索
  185. if($request->has("search") && !empty($request->get("search"))){
  186. $table = $table->where('title', 'like', "%".$request->get("search")."%");
  187. }
  188. if($request->has("subtitle") && !empty($request->get("subtitle"))){
  189. $table = $table->where('subtitle', 'like', $request->get("subtitle"));
  190. }
  191. //获取记录总条数
  192. $count = $table->count();
  193. //处理排序
  194. $table = $table->orderBy($request->get("order",'updated_at'),
  195. $request->get("dir",'desc'));
  196. //处理分页
  197. $table = $table->skip($request->get("offset",0))
  198. ->take($request->get("limit",1000));
  199. //获取数据
  200. $result = $table->get();
  201. return $this->ok(["rows"=>ArticleResource::collection($result),"count"=>$count]);
  202. }
  203. /**
  204. * Display a listing of the resource.
  205. *
  206. * @return \Illuminate\Http\Response
  207. */
  208. public function showMyNumber(Request $request){
  209. $user = AuthApi::current($request);
  210. if(!$user){
  211. return $this->error(__('auth.failed'));
  212. }
  213. //判断当前用户是否有指定的studio的权限
  214. $studioId = StudioApi::getIdByName($request->get('studio'));
  215. if($user['user_uid'] !== $studioId){
  216. return $this->error(__('auth.failed'));
  217. }
  218. //我的
  219. $my = Article::where('owner', $studioId)->count();
  220. //协作
  221. $resList = ShareApi::getResList($studioId,3);
  222. $resId=[];
  223. foreach ($resList as $res) {
  224. $resId[] = $res['res_id'];
  225. }
  226. $collaboration = Article::whereIn('uid', $resId)->where('owner','<>', $studioId)->count();
  227. return $this->ok(['my'=>$my,'collaboration'=>$collaboration]);
  228. }
  229. /**
  230. * Store a newly created resource in storage.
  231. *
  232. * @param \Illuminate\Http\Request $request
  233. * @return \Illuminate\Http\Response
  234. */
  235. public function store(Request $request)
  236. {
  237. //判断权限
  238. $user = AuthApi::current($request);
  239. if(!$user){
  240. Log::error('未登录');
  241. return $this->error(__('auth.failed'),[],401);
  242. }else{
  243. $user_uid=$user['user_uid'];
  244. }
  245. $canManage = ArticleController::userCanManage($user_uid,$request->get('studio'));
  246. if(!$canManage){
  247. Log::error('userCanManage 失败');
  248. //判断是否有文集权限
  249. if($request->has('anthologyId')){
  250. $currPower = ShareApi::getResPower($user_uid,$request->get('anthologyId'));
  251. if($currPower <= 10){
  252. Log::error('没有文集编辑权限');
  253. return $this->error(__('auth.failed'),[],403);
  254. }
  255. }else{
  256. Log::error('没有文集id');
  257. return $this->error(__('auth.failed'),[],403);
  258. }
  259. }
  260. //权限判断结束
  261. //查询标题是否重复
  262. /*
  263. if(Article::where('title',$request->get('title'))->where('owner',$studioUuid)->exists()){
  264. return $this->error(__('validation.exists'));
  265. }*/
  266. $newArticle = new Article;
  267. DB::transaction(function() use($user,$request,$newArticle){
  268. $studioUuid = StudioApi::getIdByName($request->get('studio'));
  269. //新建文章,加入文集必须都成功。否则回滚
  270. $newArticle->id = app('snowflake')->id();
  271. $newArticle->uid = Str::uuid();
  272. $newArticle->title = $request->get('title');
  273. $newArticle->lang = $request->get('lang');
  274. $newArticle->owner = $studioUuid;
  275. $newArticle->owner_id = $user['user_id'];
  276. $newArticle->editor_id = $user['user_id'];
  277. $newArticle->create_time = time()*1000;
  278. $newArticle->modify_time = time()*1000;
  279. $newArticle->save();
  280. if(Str::isUuid($request->get('anthologyId'))){
  281. $articleMap = new ArticleCollection();
  282. $articleMap->id = app('snowflake')->id();
  283. $articleMap->article_id = $newArticle->uid;
  284. $articleMap->collect_id = $request->get('anthologyId');
  285. $articleMap->title = Article::find($newArticle->uid)->title;
  286. $articleMap->level = 1;
  287. $articleMap->save();
  288. }
  289. });
  290. if(Str::isUuid($newArticle->uid)){
  291. return $this->ok($newArticle);
  292. }else{
  293. return $this->error('fail');
  294. }
  295. }
  296. /**
  297. * Display the specified resource.
  298. * @param \Illuminate\Http\Request $request
  299. * @param \App\Models\Article $article
  300. * @return \Illuminate\Http\Response
  301. */
  302. public function show(Request $request,Article $article)
  303. {
  304. //
  305. if(!$article){
  306. return $this->error("no recorder");
  307. }
  308. //判断权限
  309. $user = AuthApi::current($request);
  310. if(!$user){
  311. $user_uid="";
  312. }else{
  313. $user_uid=$user['user_uid'];
  314. }
  315. $canRead = ArticleController::userCanRead($user_uid,$article);
  316. if(!$canRead){
  317. return $this->error(__('auth.failed'),[],403);
  318. }
  319. return $this->ok(new ArticleResource($article));
  320. }
  321. /**
  322. * Display the specified resource.
  323. * @param \Illuminate\Http\Request $request
  324. * @param string $article
  325. * @return \Illuminate\Http\Response
  326. */
  327. public function preview(Request $request,string $articleId)
  328. {
  329. //
  330. $article = Article::find($articleId);
  331. if(!$article){
  332. return $this->error("no recorder");
  333. }
  334. //判断权限
  335. $user = AuthApi::current($request);
  336. if(!$user){
  337. $user_uid="";
  338. }else{
  339. $user_uid=$user['user_uid'];
  340. }
  341. $canRead = ArticleController::userCanRead($user_uid,$article);
  342. if(!$canRead){
  343. return $this->error(__('auth.failed'),[],401);
  344. }
  345. if($request->has('content')){
  346. $article->content = $request->get('content');
  347. return $this->ok(new ArticleResource($article));
  348. }else{
  349. return $this->error('no content',[],200);
  350. }
  351. }
  352. /**
  353. * Update the specified resource in storage.
  354. *
  355. * @param \Illuminate\Http\Request $request
  356. * @param \App\Models\Article $article
  357. * @return \Illuminate\Http\Response
  358. */
  359. public function update(Request $request, Article $article)
  360. {
  361. //
  362. if(!$article){
  363. return $this->error("no recorder");
  364. }
  365. //鉴权
  366. $user = AuthApi::current($request);
  367. if(!$user){
  368. return $this->error(__('auth.failed'),[],401);
  369. }else{
  370. $user_uid=$user['user_uid'];
  371. }
  372. $canEdit = ArticleController::userCanEdit($user_uid,$article);
  373. if(!$canEdit){
  374. return $this->error(__('auth.failed'),[],401);
  375. }
  376. /*
  377. //查询标题是否重复
  378. if(Article::where('title',$request->get('title'))
  379. ->where('owner',$article->owner)
  380. ->where('uid',"<>",$article->uid)
  381. ->exists()){
  382. return $this->error(__('validation.exists'));
  383. }*/
  384. $article->title = $request->get('title');
  385. $article->subtitle = $request->get('subtitle');
  386. $article->summary = $request->get('summary');
  387. $article->content = $request->get('content');
  388. $article->lang = $request->get('lang');
  389. $article->status = $request->get('status',10);
  390. $article->editor_id = $user['user_id'];
  391. $article->modify_time = time()*1000;
  392. $article->save();
  393. return $this->ok($article);
  394. }
  395. /**
  396. * Remove the specified resource from storage.
  397. * @param \Illuminate\Http\Request $request
  398. * @param \App\Models\Article $article
  399. * @return \Illuminate\Http\Response
  400. */
  401. public function destroy(Request $request,Article $article)
  402. {
  403. //
  404. $user = AuthApi::current($request);
  405. if(!$user){
  406. return $this->error(__('auth.failed'));
  407. }
  408. //判断当前用户是否有指定的studio的权限
  409. if($user['user_uid'] !== $article->owner){
  410. return $this->error(__('auth.failed'));
  411. }
  412. $delete = 0;
  413. DB::transaction(function() use($article,$delete){
  414. //TODO 删除文集中的文章
  415. $delete = $article->delete();
  416. ArticleMapController::deleteArticle($article->uid);
  417. });
  418. return $this->ok($delete);
  419. }
  420. }