S14 and the privacy items of P0: - signing up as "admin" no longer grants admin; `PrivaPub admin promote <root>` (and `demote`) does, run on the box against the configured database; - Swagger is served in Development only; - every service and controller answers "Something went wrong." where it used to send ex.Message, and the SMTP warnings no longer log the recipient's address; - sign-up and login no longer log the IP, User-Agent and root id together; - invitation sign-up takes the persona's own AvatarUserName (and optional AvatarName) instead of naming the avatar after the private login, and refuses a persona username equal to the login's. Invitation login uses the named persona, creating it if it is new; - recovery mail comes from "PrivaPub", not collAnon's support address name. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
83 lines
2.6 KiB
C#
83 lines
2.6 KiB
C#
using Microsoft.AspNetCore.Authorization;
|
|
using Microsoft.AspNetCore.Mvc;
|
|
using Microsoft.Extensions.Localization;
|
|
using PrivaPub.ClientModels;
|
|
using PrivaPub.Extensions;
|
|
using PrivaPub.Resources;
|
|
using PrivaPub.Services.ClientToServer.Private;
|
|
using PrivaPub.ClientModels.User.Avatar;
|
|
|
|
namespace PrivaPub.Controllers.ClientToServer
|
|
{
|
|
[ApiController,
|
|
Route("clientapi/avatar/private"),
|
|
Authorize(Policy = Policies.IsUser)]
|
|
public class PrivateAvatarController : ControllerBase
|
|
{
|
|
readonly ILogger<PrivateAvatarController> _logger;
|
|
readonly IPrivateAvatarUsersService _privateAvatarUsersService;
|
|
readonly IStringLocalizer _localizer;
|
|
|
|
public PrivateAvatarController(IPrivateAvatarUsersService privateAvatarUsersService,
|
|
IStringLocalizer<GenericRes> localizer,
|
|
ILogger<PrivateAvatarController> logger)
|
|
{
|
|
_privateAvatarUsersService = privateAvatarUsersService;
|
|
_localizer = localizer;
|
|
_logger = logger;
|
|
}
|
|
|
|
[HttpGet, Route("/clientapi/avatar/private/list")]
|
|
public async Task<IActionResult> GetAvatars(CancellationToken token)
|
|
{
|
|
var result = await _privateAvatarUsersService.GetRootAvatars(User.GetUserId(), token);
|
|
return result.IsValid ? Ok(result.Data) : StatusCode(result.StatusCode, result);
|
|
}
|
|
|
|
[HttpPost, Route("/clientapi/avatar/private/insert")]
|
|
public async Task<IActionResult> InsertAvatar(InsertAvatarForm model)
|
|
{
|
|
var result = new WebResult();
|
|
if (!ModelState.IsValid)
|
|
return BadRequest(result.Invalidate(_localizer["Invalid model."]));
|
|
try
|
|
{
|
|
model.RootId = User.GetUserId();
|
|
result = await _privateAvatarUsersService.InsertAvatar(model);
|
|
if (!result.IsValid)
|
|
return StatusCode(result.StatusCode, result);
|
|
|
|
return Ok(result.Data);
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
_logger.LogError(ex, $"{nameof(PrivateAvatarController)}.{nameof(InsertAvatar)}()");
|
|
return BadRequest(result.Invalidate(_localizer["Something went wrong."]));
|
|
}
|
|
}
|
|
|
|
[HttpPost, Route("/clientapi/avatar/private/update")]
|
|
public async Task<IActionResult> UpdateAvatar(UpdateAvatarForm model)
|
|
{
|
|
var result = new WebResult();
|
|
if (!ModelState.IsValid)
|
|
return BadRequest(result.Invalidate(_localizer["Invalid model."]));
|
|
try
|
|
{
|
|
model.RootId = User.GetUserId();
|
|
result = await _privateAvatarUsersService.UpdateAvatar(model);
|
|
if (!result.IsValid)
|
|
return StatusCode(result.StatusCode, result);
|
|
|
|
return Ok(result.Data);
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
_logger.LogError(ex, $"{nameof(PrivateAvatarController)}.{nameof(UpdateAvatar)}()");
|
|
return BadRequest(result.Invalidate(_localizer["Something went wrong."]));
|
|
}
|
|
}
|
|
|
|
}
|
|
}
|