request = $request; $this->pdm = new PersistentDataManager(); $this->userRepository = new UserRepository(); $this->communityRepository = new CommunityRepository(); $this->communityMemberRepository = new CommunityMemberRepository(); } public function authorize(): bool { return $this->request->user() !== null; } public function getCommunityHome(): ?IContent { if (!$this->checkPermission($this->request->query('communityId'), false, $community, $ownCommunityMember)) { return null; } return new HtmlContent('communities/community', [ 'community' => $community, 'members' => $this->getMembers($community), 'currencyNames' => [], 'upcomingEvents' => [], 'editPermission' => $ownCommunityMember->getOwner() ]); } public function getCommunityNew(): IContent { return new HtmlContent('communities/community_edit'); } public function getCommunityEdit(): ?IContent { if (!$this->checkPermission($this->request->query('communityId'), true, $community, $ownCommunityMember)) { return null; } return new HtmlContent('communities/community_edit', [ 'community' => $community ]); } public function getMembersEdit(): ?IContent { if (!$this->checkPermission($this->request->query('communityId'), true, $community, $ownCommunityMember)) { return null; } return new HtmlContent('communities/community_members', [ 'community' => $community, 'members' => $this->getMembers($community) ]); } private function getMembers(Community $community): array { $members = iterator_to_array($this->communityMemberRepository->getAllByCommunity($community, true)); usort($members, function($a, $b) { return strnatcmp($a->getUser()->getDisplayName(), $b->getUser()->getDisplayName()); }); return $members; } public function newMember(): ?IContent { if (!$this->checkPermission($this->request->query('communityId'), true, $community, $ownCommunityMember)) { return null; } $user = $this->userRepository->getById($this->request->post('user_id')); $communityMember = new CommunityMember(); $communityMember->setCommunity($community); $communityMember->setUser($user); $this->pdm->saveToDb($communityMember); return new JsonContent(['success' => true]); } public function editMember(): ?IContent { if (!$this->checkPermission($this->request->query('communityId'), true, $community, $ownCommunityMember)) { return null; } $communityMember = $this->communityMemberRepository->getById($this->request->post('community_member_id')); if ($communityMember->getUserId() === $this->request->user()->getUniqueId()) { return new JsonContent([ 'error' => ['errorText' => 'Own user cannot be edited.'] ]); } $communityMember->setOwner($this->request->post('owner')); $this->pdm->saveToDb($communityMember); return new JsonContent(['success' => true]); } public function deleteMember(): ?IContent { if (!$this->checkPermission($this->request->query('communityId'), true, $community, $ownCommunityMember)) { return null; } $communityMember = $this->communityMemberRepository->getById($this->request->post('community_member_id')); if ($communityMember->getUserId() === $this->request->user()->getUniqueId()) { return new JsonContent([ 'error' => ['errorText' => 'Own user cannot be deleted.'] ]); } $this->pdm->deleteFromDb($communityMember); return new JsonContent(['success' => true]); } public function saveCommunity(): ?IContent { $communityId = $this->request->query('communityId'); if ($communityId){ if (!$this->checkPermission($communityId, true, $community, $ownCommunityMember)) { return null; } } else { $community = new Community(); } $name = $this->request->post('name'); $currency = $this->request->post('currency'); if (strlen($name) === 0 || strlen($currency) === 0 || strlen($currency) > 3) { return new JsonContent([ 'error' => ['errorText' => 'Please fill all required fields!'] ]); } $community->setName($name); $community->setCurrency($currency); if (!$communityId) { $community->setCreatedDate(new DateTime()); } $this->pdm->saveToDb($community); if (!$communityId) { /** * @var User $user */ $user = $this->request->user(); $communityMember = new CommunityMember(); $communityMember->setCommunity($community); $communityMember->setUser($user); $communityMember->setOwner(true); $this->pdm->saveToDb($communityMember); } return new JsonContent([ 'redirect' => ['target' => '/' . \Container::$routeCollection->getRoute('community')->generateLink(['communityId' => $community->getId()])] ]); } private function checkPermission( int $communityId, bool $needToBeOwner, ?Community &$community, ?CommunityMember &$ownCommunityMember): bool { $community = $this->communityRepository->getById($communityId); if ($community === null) { return false; } /** * @var User $user */ $user = $this->request->user(); $ownCommunityMember = $this->communityMemberRepository->getByCommunityAndUser($community, $user); if ($ownCommunityMember === null || ($needToBeOwner && !$ownCommunityMember->getOwner())) { return false; } return true; } }