mirror of
https://github.com/Athou/commafeed.git
synced 2026-09-27 22:44:42 +00:00
prevent users from starring/tagging entries that are not theirs
This commit is contained in:
@@ -166,7 +166,6 @@ export const starEntry = createAppAsyncThunk(
|
|||||||
(arg: { entry: Entry; starred: boolean }) => {
|
(arg: { entry: Entry; starred: boolean }) => {
|
||||||
client.entry.star({
|
client.entry.star({
|
||||||
id: arg.entry.id,
|
id: arg.entry.id,
|
||||||
feedId: +arg.entry.feedId,
|
|
||||||
starred: arg.starred,
|
starred: arg.starred,
|
||||||
})
|
})
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -297,7 +297,6 @@ export interface LocalSettings {
|
|||||||
|
|
||||||
export interface StarRequest {
|
export interface StarRequest {
|
||||||
id: string
|
id: string
|
||||||
feedId: number
|
|
||||||
starred: boolean
|
starred: boolean
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -98,15 +98,14 @@ public class FeedEntryService {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public void starEntry(User user, Long entryId, Long subscriptionId, boolean starred) {
|
public void starEntry(User user, Long entryId, boolean starred) {
|
||||||
|
FeedEntry entry = feedEntryDAO.findById(entryId);
|
||||||
FeedSubscription sub = feedSubscriptionDAO.findById(user, subscriptionId);
|
if (entry == null) {
|
||||||
if (sub == null) {
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
FeedEntry entry = feedEntryDAO.findById(entryId);
|
FeedSubscription sub = feedSubscriptionDAO.findByFeed(user, entry.getFeed());
|
||||||
if (entry == null) {
|
if (sub == null) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -2,8 +2,10 @@ package com.commafeed.backend.service;
|
|||||||
|
|
||||||
import com.commafeed.backend.dao.FeedEntryDAO;
|
import com.commafeed.backend.dao.FeedEntryDAO;
|
||||||
import com.commafeed.backend.dao.FeedEntryTagDAO;
|
import com.commafeed.backend.dao.FeedEntryTagDAO;
|
||||||
|
import com.commafeed.backend.dao.FeedSubscriptionDAO;
|
||||||
import com.commafeed.backend.model.FeedEntry;
|
import com.commafeed.backend.model.FeedEntry;
|
||||||
import com.commafeed.backend.model.FeedEntryTag;
|
import com.commafeed.backend.model.FeedEntryTag;
|
||||||
|
import com.commafeed.backend.model.FeedSubscription;
|
||||||
import com.commafeed.backend.model.User;
|
import com.commafeed.backend.model.User;
|
||||||
|
|
||||||
import jakarta.inject.Singleton;
|
import jakarta.inject.Singleton;
|
||||||
@@ -20,6 +22,7 @@ public class FeedEntryTagService {
|
|||||||
|
|
||||||
private final FeedEntryDAO feedEntryDAO;
|
private final FeedEntryDAO feedEntryDAO;
|
||||||
private final FeedEntryTagDAO feedEntryTagDAO;
|
private final FeedEntryTagDAO feedEntryTagDAO;
|
||||||
|
private final FeedSubscriptionDAO feedSubscriptionDAO;
|
||||||
|
|
||||||
public void updateTags(User user, Long entryId, List<String> tagNames) {
|
public void updateTags(User user, Long entryId, List<String> tagNames) {
|
||||||
FeedEntry entry = feedEntryDAO.findById(entryId);
|
FeedEntry entry = feedEntryDAO.findById(entryId);
|
||||||
@@ -27,6 +30,11 @@ public class FeedEntryTagService {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
FeedSubscription sub = feedSubscriptionDAO.findByFeed(user, entry.getFeed());
|
||||||
|
if (sub == null) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
List<FeedEntryTag> existingTags = feedEntryTagDAO.findByEntry(user, entry);
|
List<FeedEntryTag> existingTags = feedEntryTagDAO.findByEntry(user, entry);
|
||||||
Set<String> existingTagNames =
|
Set<String> existingTagNames =
|
||||||
existingTags.stream().map(FeedEntryTag::getName).collect(Collectors.toSet());
|
existingTags.stream().map(FeedEntryTag::getName).collect(Collectors.toSet());
|
||||||
|
|||||||
@@ -19,9 +19,6 @@ public class StarRequest implements Serializable {
|
|||||||
@Size(max = 128)
|
@Size(max = 128)
|
||||||
private String id;
|
private String id;
|
||||||
|
|
||||||
@Schema(description = "feed id", required = true)
|
|
||||||
private Long feedId;
|
|
||||||
|
|
||||||
@Schema(description = "starred or not", required = true)
|
@Schema(description = "starred or not", required = true)
|
||||||
private boolean starred;
|
private boolean starred;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -89,11 +89,9 @@ public class EntryREST {
|
|||||||
@Valid @Parameter(description = "Star Request", required = true) StarRequest req) {
|
@Valid @Parameter(description = "Star Request", required = true) StarRequest req) {
|
||||||
Preconditions.checkNotNull(req);
|
Preconditions.checkNotNull(req);
|
||||||
Preconditions.checkNotNull(req.getId());
|
Preconditions.checkNotNull(req.getId());
|
||||||
Preconditions.checkNotNull(req.getFeedId());
|
|
||||||
|
|
||||||
User user = authenticationContext.getCurrentUser();
|
User user = authenticationContext.getCurrentUser();
|
||||||
feedEntryService.starEntry(
|
feedEntryService.starEntry(user, Long.valueOf(req.getId()), req.isStarred());
|
||||||
user, Long.valueOf(req.getId()), req.getFeedId(), req.isStarred());
|
|
||||||
|
|
||||||
return Response.ok().build();
|
return Response.ok().build();
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -388,9 +388,7 @@ public class FeverREST {
|
|||||||
if ("read".equals(action) || "unread".equals(action)) {
|
if ("read".equals(action) || "unread".equals(action)) {
|
||||||
feedEntryService.markEntry(user, id, "read".equals(action));
|
feedEntryService.markEntry(user, id, "read".equals(action));
|
||||||
} else if ("saved".equals(action) || "unsaved".equals(action)) {
|
} else if ("saved".equals(action) || "unsaved".equals(action)) {
|
||||||
FeedEntry entry = feedEntryDAO.findById(id);
|
feedEntryService.starEntry(user, id, "saved".equals(action));
|
||||||
FeedSubscription sub = feedSubscriptionDAO.findByFeed(user, entry.getFeed());
|
|
||||||
feedEntryService.starEntry(user, id, sub.getId(), "saved".equals(action));
|
|
||||||
}
|
}
|
||||||
} else if ("feed".equals(source)) {
|
} else if ("feed".equals(source)) {
|
||||||
FeedSubscription subscription = feedSubscriptionDAO.findById(user, id);
|
FeedSubscription subscription = feedSubscriptionDAO.findById(user, id);
|
||||||
|
|||||||
@@ -402,16 +402,11 @@ public class GoogleReaderREST {
|
|||||||
if (markUnread) {
|
if (markUnread) {
|
||||||
feedEntryService.markEntry(user, entryId, false);
|
feedEntryService.markEntry(user, entryId, false);
|
||||||
}
|
}
|
||||||
if (star || unstar) {
|
if (star) {
|
||||||
FeedSubscription sub = feedSubscriptionDAO.findByFeed(user, entry.getFeed());
|
feedEntryService.starEntry(user, entryId, true);
|
||||||
if (sub != null) {
|
}
|
||||||
if (star) {
|
if (unstar) {
|
||||||
feedEntryService.starEntry(user, entryId, sub.getId(), true);
|
feedEntryService.starEntry(user, entryId, false);
|
||||||
}
|
|
||||||
if (unstar) {
|
|
||||||
feedEntryService.starEntry(user, entryId, sub.getId(), false);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -45,7 +45,6 @@ class DatabaseCleaningIT extends BaseIT {
|
|||||||
private void starEntry(String entryId, Long subscriptionId) {
|
private void starEntry(String entryId, Long subscriptionId) {
|
||||||
StarRequest starRequest = new StarRequest();
|
StarRequest starRequest = new StarRequest();
|
||||||
starRequest.setId(entryId);
|
starRequest.setId(entryId);
|
||||||
starRequest.setFeedId(subscriptionId);
|
|
||||||
starRequest.setStarred(true);
|
starRequest.setStarred(true);
|
||||||
RestAssured.given()
|
RestAssured.given()
|
||||||
.body(starRequest)
|
.body(starRequest)
|
||||||
@@ -58,7 +57,6 @@ class DatabaseCleaningIT extends BaseIT {
|
|||||||
private void unstarEntry(String entryId, Long subscriptionId) {
|
private void unstarEntry(String entryId, Long subscriptionId) {
|
||||||
StarRequest starRequest = new StarRequest();
|
StarRequest starRequest = new StarRequest();
|
||||||
starRequest.setId(entryId);
|
starRequest.setId(entryId);
|
||||||
starRequest.setFeedId(subscriptionId);
|
|
||||||
starRequest.setStarred(false);
|
starRequest.setStarred(false);
|
||||||
RestAssured.given()
|
RestAssured.given()
|
||||||
.body(starRequest)
|
.body(starRequest)
|
||||||
|
|||||||
@@ -240,7 +240,6 @@ class CategoryIT extends BaseIT {
|
|||||||
|
|
||||||
StarRequest starRequest = new StarRequest();
|
StarRequest starRequest = new StarRequest();
|
||||||
starRequest.setId(entry.getId());
|
starRequest.setId(entry.getId());
|
||||||
starRequest.setFeedId(subscriptionId);
|
|
||||||
starRequest.setStarred(true);
|
starRequest.setStarred(true);
|
||||||
RestAssured.given()
|
RestAssured.given()
|
||||||
.body(starRequest)
|
.body(starRequest)
|
||||||
|
|||||||
@@ -121,7 +121,6 @@ class FeverIT extends BaseIT {
|
|||||||
|
|
||||||
StarRequest starRequest = new StarRequest();
|
StarRequest starRequest = new StarRequest();
|
||||||
starRequest.setId(entry.getId());
|
starRequest.setId(entry.getId());
|
||||||
starRequest.setFeedId(subscriptionId);
|
|
||||||
starRequest.setStarred(true);
|
starRequest.setStarred(true);
|
||||||
RestAssured.given().body(starRequest).contentType(ContentType.JSON).post("rest/entry/star");
|
RestAssured.given().body(starRequest).contentType(ContentType.JSON).post("rest/entry/star");
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user