only have one session router

This commit is contained in:
mrjvs 2023-11-25 16:09:29 +01:00
parent 4663b2c1f7
commit 10e9e06c27
3 changed files with 5 additions and 68 deletions

View File

@ -2,7 +2,7 @@ import { loginAuthRouter } from '@/routes/auth/login';
import { manageAuthRouter } from '@/routes/auth/manage'; import { manageAuthRouter } from '@/routes/auth/manage';
import { metaRouter } from '@/routes/meta'; import { metaRouter } from '@/routes/meta';
import { metricsRouter } from '@/routes/metrics'; import { metricsRouter } from '@/routes/metrics';
import { sessionsRouter } from '@/routes/sessions'; import { sessionsRouter } from '@/routes/sessions/sessions';
import { userBookmarkRouter } from '@/routes/users/bookmark'; import { userBookmarkRouter } from '@/routes/users/bookmark';
import { userDeleteRouter } from '@/routes/users/delete'; import { userDeleteRouter } from '@/routes/users/delete';
import { userEditRouter } from '@/routes/users/edit'; import { userEditRouter } from '@/routes/users/edit';

View File

@ -1,63 +0,0 @@
import { Session, formatSession } from '@/db/models/Session';
import { StatusError } from '@/services/error';
import { handle } from '@/services/handler';
import { makeRouter } from '@/services/router';
import { z } from 'zod';
export const sessionRouter = makeRouter((app) => {
app.delete(
'/sessions/:sid',
{
schema: {
params: z.object({
sid: z.string(),
}),
},
},
handle(async ({ auth, params, em }) => {
await auth.assert();
const targetedSession = await em.findOne(Session, { id: params.sid });
if (!targetedSession)
return {
id: params.sid,
};
if (targetedSession.user !== auth.user.id)
throw new StatusError('Cannot delete sessions you do not own', 401);
await em.removeAndFlush(targetedSession);
return {
id: params.sid,
};
}),
);
app.patch(
'/sessions/:sid',
{
schema: {
params: z.object({
sid: z.string(),
}),
body: z.object({
deviceName: z.string().min(1).optional(),
}),
},
},
handle(async ({ auth, params, body, em }) => {
await auth.assert();
const targetedSession = await em.findOne(Session, { id: params.sid });
if (!targetedSession) throw new StatusError('Not found', 404);
if (targetedSession.id !== params.sid)
throw new StatusError('Cannot edit sessions other than your own', 401);
if (body.deviceName) targetedSession.device = body.deviceName;
await em.persistAndFlush(targetedSession);
return formatSession(targetedSession);
}),
);
});

View File

@ -13,7 +13,7 @@ export const sessionsRouter = makeRouter((app) => {
sid: z.string(), sid: z.string(),
}), }),
body: z.object({ body: z.object({
name: z.string().max(500).min(1).optional(), deviceName: z.string().max(500).min(1).optional(),
}), }),
}, },
}, },
@ -25,10 +25,10 @@ export const sessionsRouter = makeRouter((app) => {
if (!targetedSession) if (!targetedSession)
throw new StatusError('Session cannot be found', 404); throw new StatusError('Session cannot be found', 404);
if (targetedSession.user !== auth.user.id) if (targetedSession.id !== params.sid)
throw new StatusError('Cannot modify sessions you do not own', 401); throw new StatusError('Cannot edit sessions other than your own', 401);
if (body.name) targetedSession.device = body.name; if (body.deviceName) targetedSession.device = body.deviceName;
await em.persistAndFlush(targetedSession); await em.persistAndFlush(targetedSession);