-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathCompanyKnowledgeController.java
More file actions
64 lines (56 loc) · 2.88 KB
/
Copy pathCompanyKnowledgeController.java
File metadata and controls
64 lines (56 loc) · 2.88 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
package com.dbaagent.controller;
import com.dbaagent.model.CompanyKnowledgeEntry;
import com.dbaagent.service.CompanyKnowledgeService;
import com.dbaagent.service.security.AccessControlService;
import lombok.RequiredArgsConstructor;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.*;
import java.util.List;
@RestController
@RequestMapping("/company-knowledge")
@RequiredArgsConstructor
public class CompanyKnowledgeController {
private final CompanyKnowledgeService companyKnowledgeService;
private final AccessControlService accessControlService;
@GetMapping("/{connectionId}")
public ResponseEntity<List<CompanyKnowledgeEntry>> list(@PathVariable String connectionId) {
accessControlService.assertCanManageConnectionContent(connectionId);
return ResponseEntity.ok(companyKnowledgeService.listEntries(connectionId));
}
@PostMapping
public ResponseEntity<CompanyKnowledgeEntry> create(@RequestBody CompanyKnowledgeEntry entry) {
accessControlService.assertCanManageConnectionContent(entry.getConnectionId());
if (entry.getCreatedBy() == null || entry.getCreatedBy().isBlank()) {
entry.setCreatedBy(accessControlService.getCurrentUsername());
}
return ResponseEntity.ok(companyKnowledgeService.createEntry(entry));
}
@PutMapping("/{entryId}")
public ResponseEntity<CompanyKnowledgeEntry> update(
@PathVariable String entryId,
@RequestBody CompanyKnowledgeEntry entry) {
// Authorise against the stored entry's connection, unconditionally. The old check ran
// only when the body carried a connectionId, so omitting that field skipped it and let
// any authenticated user edit any tenant's entry. The body's connectionId is never
// trusted here; updateEntry already refuses to change it.
assertCanManageEntry(entryId);
if (entry.getCreatedBy() == null || entry.getCreatedBy().isBlank()) {
entry.setCreatedBy(accessControlService.getCurrentUsername());
}
return ResponseEntity.ok(companyKnowledgeService.updateEntry(entryId, entry));
}
@DeleteMapping("/{entryId}")
public ResponseEntity<Void> delete(
@PathVariable String entryId,
@RequestParam(required = false) String connectionId) {
// The connectionId param was never compared to the entry being deleted; authorise on
// the entry's own connection instead. Accepted for wire compatibility, not trusted.
assertCanManageEntry(entryId);
companyKnowledgeService.deleteEntry(entryId);
return ResponseEntity.ok().build();
}
private void assertCanManageEntry(String entryId) {
accessControlService.assertCanManageConnectionContentOrNotFound(
companyKnowledgeService.findConnectionIdForEntry(entryId).orElse(null), "Knowledge entry");
}
}