fix: lỗi các thành viên không thể upload ảnh và không có nút xóa ảnh của user

This commit is contained in:
2026-06-16 18:54:24 +07:00
parent 88b2182789
commit 00554224a1
8 changed files with 318 additions and 34 deletions
+12
View File
@@ -1,6 +1,18 @@
import 'reflect-metadata';
import { OnGatewayConnection } from '@nestjs/websockets';
import { Server, Socket } from 'socket.io';
import { PrismaService } from '../prisma/prisma.service';
import { ParticipantRole } from '@prisma/client';
import { Reflector } from '@nestjs/core';
import { CanActivate, ExecutionContext } from '@nestjs/common';
export declare const ROLES_KEY = "roles";
export declare const Roles: (...roles: ParticipantRole[]) => import("@nestjs/common").CustomDecorator<string>;
export declare class TourRoleGuard implements CanActivate {
private reflector;
private prisma;
constructor(reflector: Reflector, prisma: PrismaService);
canActivate(context: ExecutionContext): Promise<boolean>;
}
export declare class CommentGateway implements OnGatewayConnection {
server: Server;
handleConnection(client: Socket): void;
+157 -22
View File
@@ -48,7 +48,7 @@ var __importDefault = (this && this.__importDefault) || function (mod) {
return (mod && mod.__esModule) ? mod : { "default": mod };
};
Object.defineProperty(exports, "__esModule", { value: true });
exports.CommentGateway = void 0;
exports.CommentGateway = exports.TourRoleGuard = exports.Roles = exports.ROLES_KEY = void 0;
const dotenv = __importStar(require("dotenv"));
const path = __importStar(require("path"));
const envPath = path.resolve(process.cwd(), '..', '.env');
@@ -62,12 +62,14 @@ const platform_express_1 = require("@nestjs/platform-express");
const websockets_1 = require("@nestjs/websockets");
const socket_io_1 = require("socket.io");
const prisma_service_1 = require("../prisma/prisma.service");
const client_1 = require("@prisma/client");
const bcrypt = __importStar(require("bcrypt"));
const admin_guard_1 = require("./auth/admin.guard");
const jwt_1 = require("@nestjs/jwt");
const jwt_auth_guard_1 = require("./auth/jwt-auth.guard");
const jwt_strategy_1 = require("./auth/jwt.strategy");
const rbac_middleware_1 = require("./common/rbac.middleware");
const core_2 = require("@nestjs/core");
const common_2 = require("@nestjs/common");
const UPLOAD_ROOT = path.join(process.cwd(), 'uploads');
async function bootstrap() {
if (!process.env.DATABASE_URL) {
@@ -88,6 +90,41 @@ async function bootstrap() {
await app.listen(3001);
console.log(`🚀 Server is running on: http://localhost:3001`);
}
exports.ROLES_KEY = 'roles';
const Roles = (...roles) => (0, common_2.SetMetadata)(exports.ROLES_KEY, roles);
exports.Roles = Roles;
let TourRoleGuard = class TourRoleGuard {
constructor(reflector, prisma) {
this.reflector = reflector;
this.prisma = prisma;
}
async canActivate(context) {
const requiredRoles = this.reflector.getAllAndOverride(exports.ROLES_KEY, [
context.getHandler(),
context.getClass(),
]);
const defaultRoles = [client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER];
const rolesToCheck = requiredRoles && requiredRoles.length > 0 ? requiredRoles : defaultRoles;
const request = context.switchToHttp().getRequest();
const user = request.user;
const tourId = request.params.tourId || request.params.id;
if (!user || !tourId) {
return false;
}
const participation = await this.prisma.tourParticipant.findUnique({
where: { tourId_userId: { tourId, userId: user.id } },
});
if (!participation || !rolesToCheck.some(role => participation.role === role)) {
throw new common_1.ForbiddenException('Bạn không có quyền thực hiện hành động này trong tour này.');
}
return true;
}
};
exports.TourRoleGuard = TourRoleGuard;
exports.TourRoleGuard = TourRoleGuard = __decorate([
(0, common_1.Injectable)(),
__metadata("design:paramtypes", [core_2.Reflector, prisma_service_1.PrismaService])
], TourRoleGuard);
let AppController = class AppController {
getHello() {
return 'Travel Planning API is running!';
@@ -412,11 +449,17 @@ let TourController = class TourController {
where: { tourId: id }
});
for (const photo of photos) {
const displayFilePath = path.join(process.cwd(), photo.imageUrl.replace(/^\//, ''));
if (fs.existsSync(displayFilePath)) {
fs.unlinkSync(displayFilePath);
if (photo.imageUrl) {
const displayFilePath = path.join(process.cwd(), photo.imageUrl.replace(/^\//, ''));
if (fs.existsSync(displayFilePath)) {
fs.unlinkSync(displayFilePath);
}
}
}
await this.prisma.photo.updateMany({
where: { tourId: id },
data: { imageUrl: null }
});
await this.prisma.tour.delete({
where: { id },
});
@@ -694,7 +737,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "createTour", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER, client_1.ParticipantRole.MEMBER),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Post)(':tourId/locations'),
__param(0, (0, common_1.Param)('tourId', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Body)()),
@@ -704,7 +748,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "addLocation", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Post)(':tourId/start-point'),
__param(0, (0, common_1.Param)('tourId', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Body)()),
@@ -714,7 +759,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "updateTourStartPoint", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Post)(':tourId/end-point'),
__param(0, (0, common_1.Param)('tourId', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Body)()),
@@ -724,7 +770,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "updateTourEndPoint", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Post)(':tourId/legs/batch'),
__param(0, (0, common_1.Param)('tourId', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Body)()),
@@ -733,7 +780,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "initializeLegs", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Post)(':tourId/legs'),
__param(0, (0, common_1.Param)('tourId', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Body)()),
@@ -742,7 +790,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "addLeg", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Patch)(':id'),
__param(0, (0, common_1.Param)('id', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Body)()),
@@ -751,7 +800,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "updateTour", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Delete)(':id'),
__param(0, (0, common_1.Param)('id', common_1.ParseUUIDPipe)),
__metadata("design:type", Function),
@@ -767,7 +817,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "getPublicTours", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER, client_1.ParticipantRole.MEMBER, client_1.ParticipantRole.MEMBER_NO_FINANCE, client_1.ParticipantRole.VIEWER_ONLY),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Get)(':id'),
__param(0, (0, common_1.Param)('id', common_1.ParseUUIDPipe)),
__metadata("design:type", Function),
@@ -775,7 +826,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "getTourDetails", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Post)(':tourId/members'),
__param(0, (0, common_1.Param)('tourId', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Body)()),
@@ -785,7 +837,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "addMember", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Get)(':tourId/join-requests'),
__param(0, (0, common_1.Param)('tourId', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Req)()),
@@ -794,7 +847,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "getJoinRequests", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER, client_1.ParticipantRole.MEMBER, client_1.ParticipantRole.MEMBER_NO_FINANCE, client_1.ParticipantRole.VIEWER_ONLY),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Post)(':tourId/join-requests'),
__param(0, (0, common_1.Param)('tourId', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Body)()),
@@ -804,7 +858,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "createJoinRequest", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Post)(':tourId/join-requests/:requestId/accept'),
__param(0, (0, common_1.Param)('tourId', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Param)('requestId')),
@@ -814,7 +869,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "acceptJoinRequest", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Post)(':tourId/join-requests/:requestId/reject'),
__param(0, (0, common_1.Param)('tourId', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Param)('requestId')),
@@ -824,7 +880,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "rejectJoinRequest", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Delete)(':tourId/members/:userId'),
__param(0, (0, common_1.Param)('tourId', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Param)('userId', common_1.ParseUUIDPipe)),
@@ -833,7 +890,8 @@ __decorate([
__metadata("design:returntype", Promise)
], TourController.prototype, "removeMember", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, rbac_middleware_1.TourRoleGuard),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER, client_1.ParticipantRole.MEMBER, client_1.ParticipantRole.MEMBER_NO_FINANCE),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard, TourRoleGuard),
(0, common_1.Post)(':tourId/photos'),
(0, common_1.UseInterceptors)((0, platform_express_1.FilesInterceptor)('images', 10)),
__param(0, (0, common_1.Param)('tourId', common_1.ParseUUIDPipe)),
@@ -961,6 +1019,7 @@ __decorate([
], LegController.prototype, "deleteLeg", null);
LegController = __decorate([
(0, common_1.Controller)('legs'),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard),
__metadata("design:paramtypes", [prisma_service_1.PrismaService])
], LegController);
@@ -1063,8 +1122,53 @@ __decorate([
], RoutingController.prototype, "optimize", null);
RoutingController = __decorate([
(0, common_1.Controller)('routing'),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
__metadata("design:paramtypes", [prisma_service_1.PrismaService])
], RoutingController);
let PhotoController = class PhotoController {
constructor(prisma) {
this.prisma = prisma;
}
async deletePhoto(id, req) {
const photo = await this.prisma.photo.findUnique({
where: { id },
});
if (!photo) {
throw new common_1.NotFoundException('Không tìm thấy ảnh.');
}
if (photo.uploaderId !== req.user.id) {
throw new common_1.ForbiddenException('Bạn không có quyền xóa ảnh này.');
}
if (photo.imageUrl) {
const displayFilePath = path.join(process.cwd(), photo.imageUrl.replace(/^\//, ''));
if (fs.existsSync(displayFilePath)) {
fs.unlinkSync(displayFilePath);
}
}
if (photo.originalUrl) {
const originalFilePath = path.join(process.cwd(), photo.originalUrl.replace(/^\//, ''));
if (fs.existsSync(originalFilePath)) {
fs.unlinkSync(originalFilePath);
}
}
await this.prisma.photo.delete({ where: { id } });
return { message: 'Ảnh đã được xóa thành công.' };
}
};
__decorate([
(0, common_1.Delete)(':id'),
__param(0, (0, common_1.Param)('id', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Req)()),
__metadata("design:type", Function),
__metadata("design:paramtypes", [String, Object]),
__metadata("design:returntype", Promise)
], PhotoController.prototype, "deletePhoto", null);
PhotoController = __decorate([
(0, common_1.Controller)('photos'),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER, client_1.ParticipantRole.MEMBER, client_1.ParticipantRole.MEMBER_NO_FINANCE),
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard),
__metadata("design:paramtypes", [prisma_service_1.PrismaService])
], PhotoController);
let UserController = class UserController {
constructor(prisma) {
this.prisma = prisma;
@@ -1084,6 +1188,15 @@ let UserController = class UserController {
});
return users.filter((u) => u.id !== currentUserId);
}
async getMyPhotos(req) {
return this.prisma.photo.findMany({
where: { uploaderId: req.user.id },
include: {
tour: { select: { title: true } }
},
orderBy: { capturedAt: 'desc' }
});
}
async updateUser(id, data) {
if (data.password) {
data.passwordHash = await bcrypt.hash(data.password, 10);
@@ -1105,6 +1218,16 @@ let UserController = class UserController {
throw new common_1.BadRequestException('Không thể xóa Quản trị viên cuối cùng');
}
const memberDir = path.join(UPLOAD_ROOT, 'members', id);
const photos = await this.prisma.photo.findMany({
where: { uploaderId: id }
});
for (const photo of photos) {
if (photo.imageUrl) {
const displayFilePath = path.join(process.cwd(), photo.imageUrl.replace(/^\//, ''));
if (fs.existsSync(displayFilePath))
fs.unlinkSync(displayFilePath);
}
}
await this.prisma.photo.deleteMany({ where: { uploaderId: id } });
await this.prisma.tourParticipant.deleteMany({ where: { userId: id } });
await this.prisma.user.delete({ where: { id } });
@@ -1134,6 +1257,15 @@ __decorate([
__metadata("design:returntype", Promise)
], UserController.prototype, "getAllUsers", null);
__decorate([
(0, common_1.UseGuards)(jwt_auth_guard_1.JwtAuthGuard),
(0, common_1.Get)('me/photos'),
__param(0, (0, common_1.Req)()),
__metadata("design:type", Function),
__metadata("design:paramtypes", [Object]),
__metadata("design:returntype", Promise)
], UserController.prototype, "getMyPhotos", null);
__decorate([
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
(0, common_1.Patch)(':id'),
__param(0, (0, common_1.Param)('id', common_1.ParseUUIDPipe)),
__param(1, (0, common_1.Body)()),
@@ -1142,6 +1274,7 @@ __decorate([
__metadata("design:returntype", Promise)
], UserController.prototype, "updateUser", null);
__decorate([
(0, exports.Roles)(client_1.ParticipantRole.OWNER),
(0, common_1.Delete)(':id'),
__param(0, (0, common_1.Param)('id', common_1.ParseUUIDPipe)),
__metadata("design:type", Function),
@@ -1149,6 +1282,7 @@ __decorate([
__metadata("design:returntype", Promise)
], UserController.prototype, "deleteUser", null);
__decorate([
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
(0, common_1.Post)('block/:id'),
__param(0, (0, common_1.Param)('id', common_1.ParseUUIDPipe)),
__metadata("design:type", Function),
@@ -1157,6 +1291,7 @@ __decorate([
], UserController.prototype, "toggleBlock", null);
UserController = __decorate([
(0, common_1.Controller)('users'),
(0, exports.Roles)(client_1.ParticipantRole.OWNER, client_1.ParticipantRole.MANAGER),
__metadata("design:paramtypes", [prisma_service_1.PrismaService])
], UserController);
let CommentGateway = class CommentGateway {
@@ -1253,8 +1388,8 @@ AppModule = __decorate([
signOptions: { expiresIn: '1d' },
}),
],
controllers: [AppController, AuthController, PublicTourController, TourController, UserController, RoutingController, LegController, LocationController, CommentController],
providers: [prisma_service_1.PrismaService, jwt_strategy_1.JwtStrategy, rbac_middleware_1.TourRoleGuard, jwt_auth_guard_1.JwtAuthGuard, admin_guard_1.AdminGuard, CommentGateway],
controllers: [AppController, AuthController, PublicTourController, TourController, UserController, RoutingController, LegController, LocationController, CommentController, PhotoController],
providers: [prisma_service_1.PrismaService, jwt_strategy_1.JwtStrategy, TourRoleGuard, jwt_auth_guard_1.JwtAuthGuard, admin_guard_1.AdminGuard, CommentGateway, core_2.Reflector],
exports: [prisma_service_1.PrismaService]
})
], AppModule);
+1 -1
View File
File diff suppressed because one or more lines are too long