CollectionController.php 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Models\Collection;
  4. use Illuminate\Http\Request;
  5. use Illuminate\Support\Str;
  6. use Illuminate\Support\Facades\Log;
  7. use App\Http\Api\AuthApi;
  8. use App\Http\Api\StudioApi;
  9. use App\Http\Api\ShareApi;
  10. use App\Http\Resources\CollectionResource;
  11. use Illuminate\Support\Facades\DB;
  12. class CollectionController extends Controller
  13. {
  14. /**
  15. * Display a listing of the resource.
  16. *
  17. * @return \Illuminate\Http\Response
  18. */
  19. public function index(Request $request)
  20. {
  21. $result = false;
  22. $indexCol = [
  23. 'uid',
  24. 'title',
  25. 'subtitle',
  26. 'summary',
  27. 'article_list',
  28. 'owner',
  29. 'status',
  30. 'default_channel',
  31. 'lang',
  32. 'updated_at',
  33. 'created_at'
  34. ];
  35. switch ($request->get('view')) {
  36. case 'studio_list':
  37. $indexCol = ['owner'];
  38. //TODO ?
  39. $table = Collection::select($indexCol)
  40. ->selectRaw('count(*) as count')
  41. ->where('status', 30)
  42. ->groupBy('owner');
  43. break;
  44. case 'studio':
  45. $user = AuthApi::current($request);
  46. if (!$user) {
  47. return $this->error(__('auth.failed'));
  48. }
  49. $studioId = StudioApi::getIdByName($request->get('name'));
  50. //判断当前用户是否有指定的studio的权限
  51. if ($user['user_uid'] !== $studioId) {
  52. return $this->error(__('auth.failed'));
  53. }
  54. $table = Collection::select($indexCol);
  55. if ($request->get('view2', 'my') === 'my') {
  56. $table = $table->where('owner', $studioId);
  57. } else {
  58. //协作
  59. $resList = ShareApi::getResList($studioId, 4);
  60. $resId = [];
  61. foreach ($resList as $res) {
  62. $resId[] = $res['res_id'];
  63. }
  64. $table = $table->whereIn('uid', $resId)->where('owner', '<>', $studioId);
  65. }
  66. break;
  67. case 'public':
  68. //全网公开
  69. $table = Collection::select($indexCol)->where('status', 30);
  70. if ($request->has('studio')) {
  71. $studioId = StudioApi::getIdByName($request->get('studio'));
  72. $table = $table->where('owner', $studioId);
  73. }
  74. break;
  75. default:
  76. # code...
  77. return $this->error("无法识别的view参数", 200, 200);
  78. break;
  79. }
  80. if ($request->has("search") && !empty($request->has("search"))) {
  81. $table = $table->where('title', 'like', "%" . $request->get("search") . "%");
  82. }
  83. $count = $table->count();
  84. if ($request->has("order") && $request->has("dir")) {
  85. $table = $table->orderBy($request->get("order"), $request->get("dir"));
  86. } else {
  87. if ($request->get('view') === 'studio_list') {
  88. $table = $table->orderBy('count', 'desc');
  89. } else {
  90. $table = $table->orderBy('updated_at', 'desc');
  91. }
  92. }
  93. $table = $table->skip($request->get("offset", 0))
  94. ->take($request->get("limit", 1000));
  95. $result = $table->get();
  96. return $this->ok(["rows" => CollectionResource::collection($result), "count" => $count]);
  97. }
  98. /**
  99. * Display a listing of the resource.
  100. *
  101. * @return \Illuminate\Http\Response
  102. */
  103. public function showMyNumber(Request $request)
  104. {
  105. $user = AuthApi::current($request);
  106. if (!$user) {
  107. return $this->error(__('auth.failed'));
  108. }
  109. //判断当前用户是否有指定的studio的权限
  110. $studioId = StudioApi::getIdByName($request->get('studio'));
  111. if ($user['user_uid'] !== $studioId) {
  112. return $this->error(__('auth.failed'));
  113. }
  114. //我的
  115. $my = Collection::where('owner', $studioId)->count();
  116. //协作
  117. $resList = ShareApi::getResList($studioId, 4);
  118. $resId = [];
  119. foreach ($resList as $res) {
  120. $resId[] = $res['res_id'];
  121. }
  122. $collaboration = Collection::whereIn('uid', $resId)->where('owner', '<>', $studioId)->count();
  123. return $this->ok(['my' => $my, 'collaboration' => $collaboration]);
  124. }
  125. public static function UserCanEdit($user_uid, $collection)
  126. {
  127. if ($collection->owner === $user_uid) {
  128. return true;
  129. }
  130. //查协作
  131. $currPower = ShareApi::getResPower($user_uid, $collection->uid);
  132. if ($currPower >= 20) {
  133. return true;
  134. }
  135. return false;
  136. }
  137. public static function UserCanRead($user_uid, $collection)
  138. {
  139. if ($collection->owner === $user_uid) {
  140. return true;
  141. }
  142. //查协作
  143. $currPower = ShareApi::getResPower($user_uid, $collection->uid);
  144. if ($currPower >= 10) {
  145. return true;
  146. }
  147. return false;
  148. }
  149. /**
  150. * Store a newly created resource in storage.
  151. *
  152. * @param \Illuminate\Http\Request $request
  153. * @return \Illuminate\Http\Response
  154. */
  155. public function store(Request $request)
  156. {
  157. $user = \App\Http\Api\AuthApi::current($request);
  158. if (!$user) {
  159. return $this->error(__('auth.failed'), 401, 401);
  160. }
  161. //判断当前用户是否有指定的studio的权限
  162. if ($user['user_uid'] !== \App\Http\Api\StudioApi::getIdByName($request->get('studio'))) {
  163. return $this->error(__('auth.failed'), 403, 403);
  164. }
  165. //查询是否重复
  166. if (Collection::where('title', $request->get('title'))->where('owner', $user['user_uid'])->exists()) {
  167. return $this->error(__('validation.exists'), 200, 200);
  168. } else {
  169. $newOne = new Collection;
  170. $newOne->id = app('snowflake')->id();
  171. $newOne->uid = Str::uuid();
  172. $newOne->title = $request->get('title');
  173. $newOne->lang = $request->get('lang');
  174. $newOne->article_list = "[]";
  175. $newOne->owner = $user['user_uid'];
  176. $newOne->owner_id = $user['user_id'];
  177. $newOne->editor_id = $user['user_id'];
  178. $newOne->create_time = time() * 1000;
  179. $newOne->modify_time = time() * 1000;
  180. $newOne->save();
  181. return $this->ok(new CollectionResource($newOne));
  182. }
  183. }
  184. /**
  185. * Display the specified resource.
  186. * @param \Illuminate\Http\Request $request
  187. * @param string $id
  188. * @return \Illuminate\Http\Response
  189. */
  190. public function show(Request $request, $id)
  191. {
  192. $result = Collection::where('uid', $id)->first();
  193. if (!$result) {
  194. Log::warning("没有查询到数据 id={$id}");
  195. return $this->error("没有查询到数据 id={$id}");
  196. }
  197. if ($result->status < 30) {
  198. //私有文章,判断权限
  199. Log::info('私有文章,判断权限' . $id);
  200. $user = \App\Http\Api\AuthApi::current($request);
  201. if (!$user) {
  202. Log::warning('未登录');
  203. return $this->error(__('auth.failed'), 403, 403);
  204. }
  205. //判断当前用户是否有指定的studio的权限
  206. if ($user['user_uid'] !== $result->owner) {
  207. Log::info($user["user_uid"] . '私有文章,判断权限' . $id);
  208. //非所有者
  209. if (CollectionController::UserCanRead($user['user_uid'], $result) === false) {
  210. Log::warning($user["user_uid"] . '没有读取权限');
  211. return $this->error(__('auth.failed'), 403, 403);
  212. }
  213. }
  214. }
  215. $result->fullArticleList = true;
  216. return $this->ok(new CollectionResource($result));
  217. }
  218. /**
  219. * Update the specified resource in storage.
  220. *
  221. * @param \Illuminate\Http\Request $request
  222. * @param string $id
  223. * @return \Illuminate\Http\Response
  224. */
  225. public function update(Request $request, string $id)
  226. {
  227. //
  228. $collection = Collection::find($id);
  229. if (!$collection) {
  230. return $this->error("no recorder");
  231. }
  232. //鉴权
  233. $user = AuthApi::current($request);
  234. if (!$user) {
  235. return $this->error(__('auth.failed'), 401, 401);
  236. }
  237. if (!CollectionController::UserCanEdit($user["user_uid"], $collection)) {
  238. return $this->error(__('auth.failed'), 403, 403);
  239. }
  240. $collection->title = $request->get('title');
  241. $collection->subtitle = $request->get('subtitle');
  242. $collection->summary = $request->get('summary');
  243. if ($request->has('aritcle_list')) {
  244. $collection->article_list = \json_encode($request->get('aritcle_list'));
  245. }
  246. $collection->lang = $request->get('lang');
  247. $collection->status = $request->get('status');
  248. $collection->default_channel = $request->get('default_channel');
  249. $collection->modify_time = time() * 1000;
  250. $collection->save();
  251. return $this->ok(new CollectionResource($collection));
  252. }
  253. /**
  254. * Remove the specified resource from storage.
  255. * @param \Illuminate\Http\Request $request
  256. * @param string $id
  257. * @return \Illuminate\Http\Response
  258. */
  259. public function destroy(Request $request, string $id)
  260. {
  261. //
  262. $user = AuthApi::current($request);
  263. if (!$user) {
  264. return $this->error(__('auth.failed'));
  265. }
  266. //判断当前用户是否有指定的studio的权限
  267. $collection = Collection::find($id);
  268. if ($user['user_uid'] !== $collection['owner']) {
  269. return $this->error(__('auth.failed'));
  270. }
  271. $delete = 0;
  272. DB::transaction(function () use ($collection, $delete) {
  273. //TODO 删除文集中的文章
  274. $delete = $collection->delete();
  275. });
  276. return $this->ok($delete);
  277. }
  278. }