2025-05-10 02:09:06 +02:00
|
|
|
/*!
|
|
|
|
|
* Copyright (c) 2024 PLANKA Software GmbH
|
|
|
|
|
* Licensed under the Fair Use License: https://github.com/plankanban/planka/blob/master/LICENSE.md
|
|
|
|
|
*/
|
|
|
|
|
|
2025-09-08 16:20:27 +02:00
|
|
|
/**
|
|
|
|
|
* @swagger
|
2025-09-08 18:25:26 +02:00
|
|
|
* /cards/{cardId}/memberships/{userId}:
|
2025-09-08 16:20:27 +02:00
|
|
|
* delete:
|
|
|
|
|
* summary: Remove user from card
|
|
|
|
|
* description: Removes a user from a card. Requires board editor permissions.
|
|
|
|
|
* tags:
|
|
|
|
|
* - Card Memberships
|
2025-09-12 12:17:01 +02:00
|
|
|
* operationId: deleteCardMembership
|
2025-09-08 16:20:27 +02:00
|
|
|
* parameters:
|
|
|
|
|
* - name: cardId
|
|
|
|
|
* in: path
|
|
|
|
|
* required: true
|
|
|
|
|
* description: ID of the card to remove the user from
|
|
|
|
|
* schema:
|
|
|
|
|
* type: string
|
2025-09-08 19:14:31 +02:00
|
|
|
* example: "1357158568008091264"
|
2025-09-08 16:20:27 +02:00
|
|
|
* - name: userId
|
|
|
|
|
* in: path
|
|
|
|
|
* required: true
|
|
|
|
|
* description: ID of the user to remove from the card
|
|
|
|
|
* schema:
|
|
|
|
|
* type: string
|
2025-09-08 19:14:31 +02:00
|
|
|
* example: "1357158568008091265"
|
2025-09-08 16:20:27 +02:00
|
|
|
* responses:
|
|
|
|
|
* 200:
|
|
|
|
|
* description: User removed from card successfully
|
|
|
|
|
* content:
|
|
|
|
|
* application/json:
|
|
|
|
|
* schema:
|
|
|
|
|
* type: object
|
|
|
|
|
* required:
|
|
|
|
|
* - item
|
|
|
|
|
* properties:
|
|
|
|
|
* item:
|
|
|
|
|
* $ref: '#/components/schemas/CardMembership'
|
|
|
|
|
* 400:
|
|
|
|
|
* $ref: '#/components/responses/ValidationError'
|
|
|
|
|
* 401:
|
|
|
|
|
* $ref: '#/components/responses/Unauthorized'
|
|
|
|
|
* 403:
|
|
|
|
|
* $ref: '#/components/responses/Forbidden'
|
|
|
|
|
* 404:
|
|
|
|
|
* $ref: '#/components/responses/NotFound'
|
|
|
|
|
*/
|
|
|
|
|
|
2025-05-10 02:09:06 +02:00
|
|
|
const { idInput } = require('../../../utils/inputs');
|
|
|
|
|
|
2019-08-31 04:07:25 +05:00
|
|
|
const Errors = {
|
2022-08-19 14:00:40 +02:00
|
|
|
NOT_ENOUGH_RIGHTS: {
|
|
|
|
|
notEnoughRights: 'Not enough rights',
|
|
|
|
|
},
|
2019-08-31 04:07:25 +05:00
|
|
|
CARD_NOT_FOUND: {
|
2020-04-03 00:35:25 +05:00
|
|
|
cardNotFound: 'Card not found',
|
2019-08-31 04:07:25 +05:00
|
|
|
},
|
2020-04-03 00:35:25 +05:00
|
|
|
USER_NOT_CARD_MEMBER: {
|
|
|
|
|
userNotCardMember: 'User not card member',
|
2019-11-05 18:01:42 +05:00
|
|
|
},
|
2019-08-31 04:07:25 +05:00
|
|
|
};
|
|
|
|
|
|
|
|
|
|
module.exports = {
|
|
|
|
|
inputs: {
|
|
|
|
|
cardId: {
|
2025-05-10 02:09:06 +02:00
|
|
|
...idInput,
|
2019-11-05 18:01:42 +05:00
|
|
|
required: true,
|
2019-08-31 04:07:25 +05:00
|
|
|
},
|
|
|
|
|
userId: {
|
2025-05-10 02:09:06 +02:00
|
|
|
...idInput,
|
2019-11-05 18:01:42 +05:00
|
|
|
required: true,
|
|
|
|
|
},
|
2019-08-31 04:07:25 +05:00
|
|
|
},
|
|
|
|
|
|
|
|
|
|
exits: {
|
2022-08-19 14:00:40 +02:00
|
|
|
notEnoughRights: {
|
|
|
|
|
responseType: 'forbidden',
|
|
|
|
|
},
|
2020-04-03 00:35:25 +05:00
|
|
|
cardNotFound: {
|
|
|
|
|
responseType: 'notFound',
|
|
|
|
|
},
|
|
|
|
|
userNotCardMember: {
|
2019-11-05 18:01:42 +05:00
|
|
|
responseType: 'notFound',
|
|
|
|
|
},
|
2019-08-31 04:07:25 +05:00
|
|
|
},
|
|
|
|
|
|
2021-06-24 01:05:22 +05:00
|
|
|
async fn(inputs) {
|
2019-08-31 04:07:25 +05:00
|
|
|
const { currentUser } = this.req;
|
|
|
|
|
|
2024-06-12 00:51:36 +02:00
|
|
|
const { card, list, board, project } = await sails.helpers.cards
|
2025-05-10 02:09:06 +02:00
|
|
|
.getPathToProjectById(inputs.cardId)
|
2020-04-03 00:35:25 +05:00
|
|
|
.intercept('pathNotFound', () => Errors.CARD_NOT_FOUND);
|
2019-08-31 04:07:25 +05:00
|
|
|
|
2025-05-10 02:09:06 +02:00
|
|
|
const boardMembership = await BoardMembership.qm.getOneByBoardIdAndUserId(
|
|
|
|
|
board.id,
|
|
|
|
|
currentUser.id,
|
|
|
|
|
);
|
2019-08-31 04:07:25 +05:00
|
|
|
|
2022-08-19 14:00:40 +02:00
|
|
|
if (!boardMembership) {
|
2019-08-31 04:07:25 +05:00
|
|
|
throw Errors.CARD_NOT_FOUND; // Forbidden
|
|
|
|
|
}
|
|
|
|
|
|
2022-08-19 14:00:40 +02:00
|
|
|
if (boardMembership.role !== BoardMembership.Roles.EDITOR) {
|
|
|
|
|
throw Errors.NOT_ENOUGH_RIGHTS;
|
|
|
|
|
}
|
|
|
|
|
|
2025-05-10 02:09:06 +02:00
|
|
|
let cardMembership = await CardMembership.qm.getOneByCardIdAndUserId(
|
|
|
|
|
inputs.cardId,
|
|
|
|
|
inputs.userId,
|
|
|
|
|
);
|
2019-08-31 04:07:25 +05:00
|
|
|
|
|
|
|
|
if (!cardMembership) {
|
2020-04-03 00:35:25 +05:00
|
|
|
throw Errors.USER_NOT_CARD_MEMBER;
|
2019-08-31 04:07:25 +05:00
|
|
|
}
|
|
|
|
|
|
2025-05-17 22:24:37 +02:00
|
|
|
const user = await User.qm.getOneById(cardMembership.userId);
|
|
|
|
|
|
2022-12-26 21:10:50 +01:00
|
|
|
cardMembership = await sails.helpers.cardMemberships.deleteOne.with({
|
2025-05-17 22:24:37 +02:00
|
|
|
user,
|
2024-06-12 00:51:36 +02:00
|
|
|
project,
|
2022-12-26 21:10:50 +01:00
|
|
|
board,
|
2024-06-12 00:51:36 +02:00
|
|
|
list,
|
2024-06-06 20:22:14 +02:00
|
|
|
card,
|
2022-12-26 21:10:50 +01:00
|
|
|
record: cardMembership,
|
2024-06-12 00:51:36 +02:00
|
|
|
actorUser: currentUser,
|
2022-12-26 21:10:50 +01:00
|
|
|
request: this.req,
|
|
|
|
|
});
|
2019-08-31 04:07:25 +05:00
|
|
|
|
|
|
|
|
if (!cardMembership) {
|
2020-04-03 00:35:25 +05:00
|
|
|
throw Errors.USER_NOT_CARD_MEMBER;
|
2019-08-31 04:07:25 +05:00
|
|
|
}
|
|
|
|
|
|
2021-06-24 01:05:22 +05:00
|
|
|
return {
|
2019-11-05 18:01:42 +05:00
|
|
|
item: cardMembership,
|
2021-06-24 01:05:22 +05:00
|
|
|
};
|
2019-11-05 18:01:42 +05:00
|
|
|
},
|
2019-08-31 04:07:25 +05:00
|
|
|
};
|