Files
planka/server/api/controllers/comments/index.js
2025-09-08 16:20:27 +02:00

125 lines
3.2 KiB
JavaScript

/*!
* Copyright (c) 2024 PLANKA Software GmbH
* Licensed under the Fair Use License: https://github.com/plankanban/planka/blob/master/LICENSE.md
*/
/**
* @swagger
* /api/cards/{cardId}/comments:
* get:
* summary: Get card comments
* description: Retrieves comments for a card with pagination support. Requires access to the card.
* tags:
* - Comments
* parameters:
* - name: cardId
* in: path
* required: true
* description: ID of the card to retrieve comments for
* schema:
* type: string
* example: 1357158568008091264
* - name: beforeId
* in: query
* required: false
* description: ID to get comments before (for pagination)
* schema:
* type: string
* example: 1357158568008091265
* responses:
* 200:
* description: Comments retrieved successfully
* content:
* application/json:
* schema:
* type: object
* required:
* - items
* - included
* properties:
* items:
* type: array
* items:
* $ref: '#/components/schemas/Comment'
* included:
* type: object
* required:
* - users
* properties:
* users:
* type: array
* description: Related users
* items:
* $ref: '#/components/schemas/User'
* 400:
* $ref: '#/components/responses/ValidationError'
* 401:
* $ref: '#/components/responses/Unauthorized'
* 404:
* $ref: '#/components/responses/NotFound'
*/
const { idInput } = require('../../../utils/inputs');
const Errors = {
CARD_NOT_FOUND: {
cardNotFound: 'Card not found',
},
};
module.exports = {
inputs: {
cardId: {
...idInput,
required: true,
},
beforeId: idInput,
},
exits: {
cardNotFound: {
responseType: 'notFound',
},
},
async fn(inputs) {
const { currentUser } = this.req;
const { card, project } = await sails.helpers.cards
.getPathToProjectById(inputs.cardId)
.intercept('pathNotFound', () => Errors.CARD_NOT_FOUND);
if (currentUser.role !== User.Roles.ADMIN || project.ownerProjectManagerId) {
const isProjectManager = await sails.helpers.users.isProjectManager(
currentUser.id,
project.id,
);
if (!isProjectManager) {
const boardMembership = await BoardMembership.qm.getOneByBoardIdAndUserId(
card.boardId,
currentUser.id,
);
if (!boardMembership) {
throw Errors.CARD_NOT_FOUND; // Forbidden
}
}
}
const comments = await Comment.qm.getByCardId(card.id, {
beforeId: inputs.beforeId,
});
const userIds = sails.helpers.utils.mapRecords(comments, 'userId', true, true);
const users = await User.qm.getByIds(userIds);
return {
items: comments,
included: {
users: sails.helpers.users.presentMany(users, currentUser),
},
};
},
};