Files
SocialPub/PrivaPub/Controllers/ClientToServer/PrivateAvatarController.cs
T
thepraandClaude Opus 5.5 0f85030744 No admin by username, no Swagger in production, no exception text to clients
S14 and the privacy items of P0:
- signing up as "admin" no longer grants admin; `PrivaPub admin promote
  <root>` (and `demote`) does, run on the box against the configured
  database;
- Swagger is served in Development only;
- every service and controller answers "Something went wrong." where it
  used to send ex.Message, and the SMTP warnings no longer log the
  recipient's address;
- sign-up and login no longer log the IP, User-Agent and root id together;
- invitation sign-up takes the persona's own AvatarUserName (and optional
  AvatarName) instead of naming the avatar after the private login, and
  refuses a persona username equal to the login's. Invitation login uses
  the named persona, creating it if it is new;
- recovery mail comes from "PrivaPub", not collAnon's support address name.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
2026-10-01 10:58:39 +02:00

83 lines
2.6 KiB
C#

using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using Microsoft.Extensions.Localization;
using PrivaPub.ClientModels;
using PrivaPub.Extensions;
using PrivaPub.Resources;
using PrivaPub.Services.ClientToServer.Private;
using PrivaPub.ClientModels.User.Avatar;
namespace PrivaPub.Controllers.ClientToServer
{
[ApiController,
Route("clientapi/avatar/private"),
Authorize(Policy = Policies.IsUser)]
public class PrivateAvatarController : ControllerBase
{
readonly ILogger<PrivateAvatarController> _logger;
readonly IPrivateAvatarUsersService _privateAvatarUsersService;
readonly IStringLocalizer _localizer;
public PrivateAvatarController(IPrivateAvatarUsersService privateAvatarUsersService,
IStringLocalizer<GenericRes> localizer,
ILogger<PrivateAvatarController> logger)
{
_privateAvatarUsersService = privateAvatarUsersService;
_localizer = localizer;
_logger = logger;
}
[HttpGet, Route("/clientapi/avatar/private/list")]
public async Task<IActionResult> GetAvatars(CancellationToken token)
{
var result = await _privateAvatarUsersService.GetRootAvatars(User.GetUserId(), token);
return result.IsValid ? Ok(result.Data) : StatusCode(result.StatusCode, result);
}
[HttpPost, Route("/clientapi/avatar/private/insert")]
public async Task<IActionResult> InsertAvatar(InsertAvatarForm model)
{
var result = new WebResult();
if (!ModelState.IsValid)
return BadRequest(result.Invalidate(_localizer["Invalid model."]));
try
{
model.RootId = User.GetUserId();
result = await _privateAvatarUsersService.InsertAvatar(model);
if (!result.IsValid)
return StatusCode(result.StatusCode, result);
return Ok(result.Data);
}
catch (Exception ex)
{
_logger.LogError(ex, $"{nameof(PrivateAvatarController)}.{nameof(InsertAvatar)}()");
return BadRequest(result.Invalidate(_localizer["Something went wrong."]));
}
}
[HttpPost, Route("/clientapi/avatar/private/update")]
public async Task<IActionResult> UpdateAvatar(UpdateAvatarForm model)
{
var result = new WebResult();
if (!ModelState.IsValid)
return BadRequest(result.Invalidate(_localizer["Invalid model."]));
try
{
model.RootId = User.GetUserId();
result = await _privateAvatarUsersService.UpdateAvatar(model);
if (!result.IsValid)
return StatusCode(result.StatusCode, result);
return Ok(result.Data);
}
catch (Exception ex)
{
_logger.LogError(ex, $"{nameof(PrivateAvatarController)}.{nameof(UpdateAvatar)}()");
return BadRequest(result.Invalidate(_localizer["Something went wrong."]));
}
}
}
}