CollectionController.php 6.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Models\Collection;
  4. use Illuminate\Http\Request;
  5. use Illuminate\Support\Str;
  6. use Illuminate\Support\Facades\Log;
  7. use App\Http\Api\AuthApi;
  8. use App\Http\Api\StudioApi;
  9. use App\Http\Resources\CollectionResource;
  10. use App\Services\CollectionService;
  11. use Illuminate\Support\Facades\DB;
  12. use Illuminate\Database\Eloquent\Builder;
  13. class CollectionController extends Controller
  14. {
  15. public function __construct(protected CollectionService $service) {}
  16. public function index(Request $request)
  17. {
  18. try {
  19. $table = match ($request->input('view')) {
  20. 'studio_list' => $this->service->buildStudioListQuery(),
  21. 'studio' => $this->buildStudioIndex($request),
  22. 'public' => $this->service->buildPublicQuery(
  23. $request->has('studio')
  24. ? StudioApi::getIdByName($request->input('studio'))
  25. : null
  26. ),
  27. default => throw new \InvalidArgumentException('无法识别的view参数'),
  28. };
  29. } catch (\Illuminate\Auth\AuthenticationException $e) {
  30. return $this->error($e->getMessage(), 403, 403);
  31. } catch (\InvalidArgumentException $e) {
  32. return $this->error($e->getMessage(), 200, 200);
  33. }
  34. if ($request->filled('search')) {
  35. $table = $table->where('title', 'like', '%' . $request->input('search') . '%');
  36. }
  37. $count = $table->count();
  38. if ($request->has('order') && $request->has('dir')) {
  39. $table = $table->orderBy($request->input('order'), $request->input('dir'));
  40. } else {
  41. $orderCol = $request->input('view') === 'studio_list' ? 'count' : 'updated_at';
  42. $table = $table->orderBy($orderCol, 'desc');
  43. }
  44. $result = $table
  45. ->skip($request->input('offset', 0))
  46. ->take($request->input('limit', 1000))
  47. ->get();
  48. return $this->ok([
  49. 'rows' => CollectionResource::collection($result),
  50. 'count' => $count,
  51. ]);
  52. }
  53. // studio 分支的鉴权逻辑留在 controller
  54. private function buildStudioIndex(Request $request): Builder
  55. {
  56. $user = AuthApi::current($request);
  57. if (!$user) {
  58. throw new \Illuminate\Auth\AuthenticationException(__('auth.failed'));
  59. }
  60. $studioId = StudioApi::getIdByName($request->input('name'));
  61. if ($user['user_uid'] !== $studioId) {
  62. throw new \Illuminate\Auth\AuthenticationException(__('auth.failed'));
  63. }
  64. return $this->service->buildStudioQuery(
  65. $user['user_uid'],
  66. $studioId,
  67. $request->input('view2', 'my')
  68. );
  69. }
  70. public function showMyNumber(Request $request)
  71. {
  72. $result = $this->service->getMyNumber($request);
  73. if (isset($result['error'])) {
  74. return $this->error($result['error'], $result['code'], $result['code']);
  75. }
  76. return $this->ok($result['data']);
  77. }
  78. public function store(Request $request)
  79. {
  80. $user = AuthApi::current($request);
  81. if (!$user) {
  82. return $this->error(__('auth.failed'), 401, 401);
  83. }
  84. if ($user['user_uid'] !== StudioApi::getIdByName($request->input('studio'))) {
  85. return $this->error(__('auth.failed'), 403, 403);
  86. }
  87. if (Collection::where('title', $request->input('title'))->where('owner', $user['user_uid'])->exists()) {
  88. return $this->error(__('validation.exists'), 200, 200);
  89. }
  90. $newOne = new Collection;
  91. $newOne->id = app('snowflake')->id();
  92. $newOne->uid = Str::uuid();
  93. $newOne->title = $request->input('title');
  94. $newOne->lang = $request->input('lang');
  95. $newOne->article_list = '[]';
  96. $newOne->owner = $user['user_uid'];
  97. $newOne->owner_id = $user['user_id'];
  98. $newOne->editor_id = $user['user_id'];
  99. $newOne->create_time = time() * 1000;
  100. $newOne->modify_time = time() * 1000;
  101. $newOne->save();
  102. return $this->ok(new CollectionResource($newOne));
  103. }
  104. public function show(Request $request, $id)
  105. {
  106. $result = Collection::where('uid', $id)->first();
  107. if (!$result) {
  108. Log::warning("没有查询到数据 id={$id}");
  109. return $this->error("没有查询到数据 id={$id}");
  110. }
  111. if ($result->status < 30) {
  112. Log::info('私有文章,判断权限' . $id);
  113. $user = AuthApi::current($request);
  114. if (!$user) {
  115. Log::warning('未登录');
  116. return $this->error(__('auth.failed'), 403, 403);
  117. }
  118. if ($user['user_uid'] !== $result->owner) {
  119. Log::info($user['user_uid'] . '私有文章,判断权限' . $id);
  120. if (!$this->service->userCanRead($user['user_uid'], $result)) {
  121. Log::warning($user['user_uid'] . '没有读取权限');
  122. return $this->error(__('auth.failed'), 403, 403);
  123. }
  124. }
  125. }
  126. $result->fullArticleList = true;
  127. return $this->ok(new CollectionResource($result));
  128. }
  129. public function update(Request $request, string $id)
  130. {
  131. $collection = Collection::find($id);
  132. if (!$collection) {
  133. return $this->error('no recorder');
  134. }
  135. $user = AuthApi::current($request);
  136. if (!$user) {
  137. return $this->error(__('auth.failed'), 401, 401);
  138. }
  139. if (!$this->service->userCanEdit($user['user_uid'], $collection)) {
  140. return $this->error(__('auth.failed'), 403, 403);
  141. }
  142. $collection->title = $request->input('title');
  143. $collection->subtitle = $request->input('subtitle');
  144. $collection->summary = $request->input('summary');
  145. $collection->lang = $request->input('lang');
  146. $collection->status = $request->input('status');
  147. $collection->default_channel = $request->input('default_channel');
  148. $collection->modify_time = time() * 1000;
  149. if ($request->has('aritcle_list')) {
  150. $collection->article_list = json_encode($request->input('aritcle_list'));
  151. }
  152. $collection->save();
  153. return $this->ok(new CollectionResource($collection));
  154. }
  155. public function destroy(Request $request, string $id)
  156. {
  157. $user = AuthApi::current($request);
  158. if (!$user) {
  159. return $this->error(__('auth.failed'));
  160. }
  161. $collection = Collection::find($id);
  162. if ($user['user_uid'] !== $collection['owner']) {
  163. return $this->error(__('auth.failed'));
  164. }
  165. DB::transaction(function () use ($collection) {
  166. // TODO: 删除文集中的文章
  167. $collection->delete();
  168. });
  169. return $this->ok(true);
  170. }
  171. }