ArticleController.php 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Models\Article;
  4. use App\Models\ArticleCollection;
  5. use App\Models\Collection;
  6. use Illuminate\Http\Request;
  7. use Illuminate\Support\Str;
  8. use App\Http\Resources\ArticleResource;
  9. use App\Http\Api\AuthApi;
  10. use App\Http\Api\ShareApi;
  11. use App\Http\Api\StudioApi;
  12. use Illuminate\Support\Facades\DB;
  13. class ArticleController extends Controller
  14. {
  15. public static function userCanRead($user_uid,Article $article){
  16. if($article->status === 30 ){
  17. return true;
  18. }
  19. if(empty($user_uid)){
  20. return false;
  21. }
  22. //私有文章,判断是否为所有者
  23. if($user_uid === $article->owner){
  24. return true;
  25. }
  26. //非所有者
  27. //判断是否为文章协作者
  28. $power = ShareApi::getResPower($user_uid,$article->uid);
  29. if($power >= 10 ){
  30. return true;
  31. }
  32. //无读取权限
  33. //判断文集是否有读取权限
  34. $inCollection = ArticleCollection::where('article_id',$article->uid)
  35. ->select('collect_id')
  36. ->groupBy('collect_id')->get();
  37. if(!$inCollection){
  38. return false;
  39. }
  40. //查找与文章同主人的文集
  41. $collections = Collection::whereIn('uid',$inCollection)
  42. ->where('owner',$article->owner)
  43. ->select('uid')
  44. ->get();
  45. if(!$collections){
  46. return false;
  47. }
  48. //查找与文章同主人的文集是否是共享的
  49. $power = 0;
  50. foreach ($collections as $collection) {
  51. # code...
  52. $currPower = ShareApi::getResPower($user_uid,$collection->uid);
  53. if($currPower >= 10){
  54. return true;
  55. }
  56. }
  57. return false;
  58. }
  59. public static function userCanEdit($user_uid,$article){
  60. if(empty($user_uid)){
  61. return false;
  62. }
  63. //私有文章,判断是否为所有者
  64. if($user_uid === $article->owner){
  65. return true;
  66. }
  67. //非所有者
  68. //判断是否为文章协作者
  69. $power = ShareApi::getResPower($user_uid,$article->uid);
  70. if($power >= 20 ){
  71. return true;
  72. }
  73. //无读取权限
  74. //判断文集是否有读取权限
  75. $inCollection = ArticleCollection::where('article_id',$article->uid)
  76. ->select('collect_id')
  77. ->groupBy('collect_id')->get();
  78. if(!$inCollection){
  79. return false;
  80. }
  81. //查找与文章同主人的文集
  82. $collections = Collection::whereIn('uid',$inCollection)
  83. ->where('owner',$article->owner)
  84. ->select('uid')
  85. ->get();
  86. if(!$collections){
  87. return false;
  88. }
  89. //查找与文章同主人的文集是否是共享的
  90. $power = 0;
  91. foreach ($collections as $collection) {
  92. # code...
  93. $currPower = ShareApi::getResPower($user_uid,$collection->uid);
  94. if($currPower >= 20){
  95. return true;
  96. }
  97. }
  98. return false;
  99. }
  100. public static function userCanManage($user_uid,$studioName){
  101. if(empty($user_uid)){
  102. return false;
  103. }
  104. //判断是否为所有者
  105. if($user_uid === StudioApi::getIdByName($studioName)){
  106. return true;
  107. }else{
  108. return false;
  109. }
  110. }
  111. /**
  112. * Display a listing of the resource.
  113. *
  114. * @return \Illuminate\Http\Response
  115. */
  116. public function index(Request $request)
  117. {
  118. //
  119. $table = Article::select(['uid','title','subtitle',
  120. 'summary','owner','lang',
  121. 'status','editor_id','updated_at','created_at']);
  122. switch ($request->get('view')) {
  123. case 'studio':
  124. # 获取studio内所有channel
  125. $user = AuthApi::current($request);
  126. if(!$user){
  127. return $this->error(__('auth.failed'),[],401);
  128. }
  129. //判断当前用户是否有指定的studio的权限
  130. $studioId = StudioApi::getIdByName($request->get('name'));
  131. if($user['user_uid'] !== $studioId){
  132. return $this->error(__('auth.failed'),[],403);
  133. }
  134. if($request->get('view2','my')==='my'){
  135. $table = $table->where('owner', $studioId);
  136. }else{
  137. //协作
  138. $resList = ShareApi::getResList($studioId,3);
  139. $resId=[];
  140. foreach ($resList as $res) {
  141. $resId[] = $res['res_id'];
  142. }
  143. $table = $table->whereIn('uid', $resId)->where('owner','<>', $studioId);
  144. }
  145. //根据anthology过滤
  146. if($request->has('anthology')){
  147. switch ($request->get('anthology')) {
  148. case 'all':
  149. break;
  150. case 'none':
  151. # 我的文集
  152. $myCollection = Collection::where('owner',$studioId)->select('uid')->get();
  153. //收录在我的文集里面的文章
  154. $articles = ArticleCollection::whereIn('collect_id',$myCollection)
  155. ->select('article_id')->groupBy('article_id')->get();
  156. //不在这些范围之内的文章
  157. $table = $table->whereNotIn('uid',$articles);
  158. break;
  159. default:
  160. $articles = ArticleCollection::where('collect_id',$request->get('anthology'))
  161. ->select('article_id')->get();
  162. $table = $table->whereIn('uid',$articles);
  163. break;
  164. }
  165. }
  166. break;
  167. case 'public':
  168. $table = $table->where('status',30);
  169. break;
  170. default:
  171. $this->error("view error");
  172. break;
  173. }
  174. //处理搜索
  175. if($request->has("search") && !empty($request->has("search"))){
  176. $table = $table->where('title', 'like', "%".$request->get("search")."%");
  177. }
  178. //获取记录总条数
  179. $count = $table->count();
  180. //处理排序
  181. $table = $table->orderBy($request->get("order",'updated_at'),
  182. $request->get("dir",'desc'));
  183. //处理分页
  184. $table = $table->skip($request->get("offset",0))
  185. ->take($request->get("limit",1000));
  186. //获取数据
  187. $result = $table->get();
  188. return $this->ok(["rows"=>ArticleResource::collection($result),"count"=>$count]);
  189. }
  190. /**
  191. * Display a listing of the resource.
  192. *
  193. * @return \Illuminate\Http\Response
  194. */
  195. public function showMyNumber(Request $request){
  196. $user = AuthApi::current($request);
  197. if(!$user){
  198. return $this->error(__('auth.failed'));
  199. }
  200. //判断当前用户是否有指定的studio的权限
  201. $studioId = StudioApi::getIdByName($request->get('studio'));
  202. if($user['user_uid'] !== $studioId){
  203. return $this->error(__('auth.failed'));
  204. }
  205. //我的
  206. $my = Article::where('owner', $studioId)->count();
  207. //协作
  208. $resList = ShareApi::getResList($studioId,3);
  209. $resId=[];
  210. foreach ($resList as $res) {
  211. $resId[] = $res['res_id'];
  212. }
  213. $collaboration = Article::whereIn('uid', $resId)->where('owner','<>', $studioId)->count();
  214. return $this->ok(['my'=>$my,'collaboration'=>$collaboration]);
  215. }
  216. /**
  217. * Store a newly created resource in storage.
  218. *
  219. * @param \Illuminate\Http\Request $request
  220. * @return \Illuminate\Http\Response
  221. */
  222. public function store(Request $request)
  223. {
  224. //判断权限
  225. $user = AuthApi::current($request);
  226. if(!$user){
  227. return $this->error(__('auth.failed'),[],401);
  228. }else{
  229. $user_uid=$user['user_uid'];
  230. }
  231. $canManage = ArticleController::userCanManage($user_uid,$request->get('studio'));
  232. if(!$canManage){
  233. return $this->error(__('auth.failed'),[],403);
  234. }
  235. //权限判断结束
  236. //查询标题是否重复
  237. /*
  238. if(Article::where('title',$request->get('title'))->where('owner',$studioUuid)->exists()){
  239. return $this->error(__('validation.exists'));
  240. }*/
  241. $newArticle = new Article;
  242. DB::transaction(function() use($user,$request,$newArticle){
  243. $studioUuid = StudioApi::getIdByName($request->get('studio'));
  244. //新建文章,加入文集必须都成功。否则回滚
  245. $newArticle->id = app('snowflake')->id();
  246. $newArticle->uid = Str::uuid();
  247. $newArticle->title = $request->get('title');
  248. $newArticle->lang = $request->get('lang');
  249. $newArticle->owner = $studioUuid;
  250. $newArticle->owner_id = $user['user_id'];
  251. $newArticle->editor_id = $user['user_id'];
  252. $newArticle->create_time = time()*1000;
  253. $newArticle->modify_time = time()*1000;
  254. $newArticle->save();
  255. if(Str::isUuid($request->get('anthologyId'))){
  256. $articleMap = new ArticleCollection();
  257. $articleMap->id = app('snowflake')->id();
  258. $articleMap->article_id = $newArticle->uid;
  259. $articleMap->collect_id = $request->get('anthologyId');
  260. $articleMap->title = Article::find($newArticle->uid)->title;
  261. $articleMap->level = 1;
  262. $articleMap->save();
  263. }
  264. });
  265. if(Str::isUuid($newArticle->uid)){
  266. return $this->ok($newArticle);
  267. }else{
  268. return $this->error('fail');
  269. }
  270. }
  271. /**
  272. * Display the specified resource.
  273. * @param \Illuminate\Http\Request $request
  274. * @param \App\Models\Article $article
  275. * @return \Illuminate\Http\Response
  276. */
  277. public function show(Request $request,Article $article)
  278. {
  279. //
  280. if(!$article){
  281. return $this->error("no recorder");
  282. }
  283. //判断权限
  284. $user = AuthApi::current($request);
  285. if(!$user){
  286. $user_uid="";
  287. }else{
  288. $user_uid=$user['user_uid'];
  289. }
  290. $canRead = ArticleController::userCanRead($user_uid,$article);
  291. if(!$canRead){
  292. return $this->error(__('auth.failed'),[],401);
  293. }
  294. return $this->ok(new ArticleResource($article));
  295. }
  296. /**
  297. * Display the specified resource.
  298. * @param \Illuminate\Http\Request $request
  299. * @param string $article
  300. * @return \Illuminate\Http\Response
  301. */
  302. public function preview(Request $request,string $articleId)
  303. {
  304. //
  305. $article = Article::find($articleId);
  306. if(!$article){
  307. return $this->error("no recorder");
  308. }
  309. //判断权限
  310. $user = AuthApi::current($request);
  311. if(!$user){
  312. $user_uid="";
  313. }else{
  314. $user_uid=$user['user_uid'];
  315. }
  316. $canRead = ArticleController::userCanRead($user_uid,$article);
  317. if(!$canRead){
  318. return $this->error(__('auth.failed'),[],401);
  319. }
  320. if($request->has('content')){
  321. $article->content = $request->get('content');
  322. return $this->ok(new ArticleResource($article));
  323. }else{
  324. return $this->error('no content',[],200);
  325. }
  326. }
  327. /**
  328. * Update the specified resource in storage.
  329. *
  330. * @param \Illuminate\Http\Request $request
  331. * @param \App\Models\Article $article
  332. * @return \Illuminate\Http\Response
  333. */
  334. public function update(Request $request, Article $article)
  335. {
  336. //
  337. if(!$article){
  338. return $this->error("no recorder");
  339. }
  340. //鉴权
  341. $user = AuthApi::current($request);
  342. if(!$user){
  343. return $this->error(__('auth.failed'),[],401);
  344. }else{
  345. $user_uid=$user['user_uid'];
  346. }
  347. $canEdit = ArticleController::userCanEdit($user_uid,$article);
  348. if(!$canEdit){
  349. return $this->error(__('auth.failed'),[],401);
  350. }
  351. /*
  352. //查询标题是否重复
  353. if(Article::where('title',$request->get('title'))
  354. ->where('owner',$article->owner)
  355. ->where('uid',"<>",$article->uid)
  356. ->exists()){
  357. return $this->error(__('validation.exists'));
  358. }*/
  359. $article->title = $request->get('title');
  360. $article->subtitle = $request->get('subtitle');
  361. $article->summary = $request->get('summary');
  362. $article->content = $request->get('content');
  363. $article->lang = $request->get('lang');
  364. $article->status = $request->get('status',10);
  365. $article->editor_id = $user['user_id'];
  366. $article->modify_time = time()*1000;
  367. $article->save();
  368. return $this->ok($article);
  369. }
  370. /**
  371. * Remove the specified resource from storage.
  372. * @param \Illuminate\Http\Request $request
  373. * @param \App\Models\Article $article
  374. * @return \Illuminate\Http\Response
  375. */
  376. public function destroy(Request $request,Article $article)
  377. {
  378. //
  379. $user = AuthApi::current($request);
  380. if(!$user){
  381. return $this->error(__('auth.failed'));
  382. }
  383. //判断当前用户是否有指定的studio的权限
  384. if($user['user_uid'] !== $article->owner){
  385. return $this->error(__('auth.failed'));
  386. }
  387. $delete = 0;
  388. DB::transaction(function() use($article,$delete){
  389. //TODO 删除文集中的文章
  390. $delete = $article->delete();
  391. ArticleMapController::deleteArticle($article->uid);
  392. });
  393. return $this->ok($delete);
  394. }
  395. }