mirror of
https://github.com/nfonteyne/octane-website.git
synced 2026-09-03 23:24:48 +02:00
fix: let user add ical
This commit is contained in:
parent
6de6cfacf2
commit
23fc039ac3
6 changed files with 257 additions and 19 deletions
|
|
@ -166,6 +166,18 @@ async function removeFeed(feedId) {
|
|||
await pool.query('DELETE FROM calendar_feeds WHERE id = $1', [feedId]);
|
||||
}
|
||||
|
||||
// Scoped delete for the self-service "my calendars" endpoints — a user must
|
||||
// only ever be able to delete their own feeds, never guess another user's
|
||||
// feed id. Returns whether a row actually matched (both wrong id and
|
||||
// someone-else's feed look identical from the caller's side: nothing deleted).
|
||||
async function removeFeedForUser(feedId, userId) {
|
||||
const { rowCount } = await pool.query('DELETE FROM calendar_feeds WHERE id = $1 AND user_id = $2', [
|
||||
feedId,
|
||||
userId,
|
||||
]);
|
||||
return rowCount > 0;
|
||||
}
|
||||
|
||||
// Every app user (not just ones already on the calendar) with their
|
||||
// registered feeds attached — lets an admin give someone their first feed,
|
||||
// not just manage existing entries. The public getPeople() above deliberately
|
||||
|
|
@ -227,6 +239,7 @@ module.exports = {
|
|||
findFeedsForUser,
|
||||
addFeed,
|
||||
removeFeed,
|
||||
removeFeedForUser,
|
||||
getUsersWithFeeds,
|
||||
getSlotSettings,
|
||||
updateSlotSettings,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue