From b3b9e9a056aa22a4f21185986a8b7f6d32450f62 Mon Sep 17 00:00:00 2001 From: darkskygit Date: Thu, 18 Apr 2024 14:42:45 +0000 Subject: [PATCH] chore: cleanup outdated api (#6604) --- .../server/src/core/workspaces/controller.ts | 7 +++++ .../server/src/core/workspaces/permission.ts | 31 +++++++++---------- .../core/workspaces/resolvers/workspace.ts | 17 ---------- packages/backend/server/src/schema.gql | 3 -- .../backend/server/tests/utils/workspace.ts | 20 ------------ .../backend/server/tests/workspace.e2e.ts | 15 --------- .../src/graphql/get-public-workspace.gql | 5 --- .../frontend/graphql/src/graphql/index.ts | 13 -------- packages/frontend/graphql/src/schema.ts | 14 --------- 9 files changed, 21 insertions(+), 104 deletions(-) delete mode 100644 packages/frontend/graphql/src/graphql/get-public-workspace.gql diff --git a/packages/backend/server/src/core/workspaces/controller.ts b/packages/backend/server/src/core/workspaces/controller.ts index cd37fe908..2b6014b2b 100644 --- a/packages/backend/server/src/core/workspaces/controller.ts +++ b/packages/backend/server/src/core/workspaces/controller.ts @@ -36,10 +36,17 @@ export class WorkspacesController { @Get('/:id/blobs/:name') @CallTimer('controllers', 'workspace_get_blob') async blob( + @CurrentUser() user: CurrentUser | undefined, @Param('id') workspaceId: string, @Param('name') name: string, @Res() res: Response ) { + // if workspace is public or have any public page, then allow to access + // otherwise, check permission + if (!(await this.permission.tryCheckWorkspace(workspaceId, user?.id))) { + throw new ForbiddenException('Permission denied'); + } + const { body, metadata } = await this.storage.get(workspaceId, name); if (!body) { diff --git a/packages/backend/server/src/core/workspaces/permission.ts b/packages/backend/server/src/core/workspaces/permission.ts index 9cca48766..4cf2a4fae 100644 --- a/packages/backend/server/src/core/workspaces/permission.ts +++ b/packages/backend/server/src/core/workspaces/permission.ts @@ -81,10 +81,22 @@ export class PermissionService { }); } + /** + * check if a doc binary is accessible by a user + */ async isAccessible(ws: string, id: string, user?: string): Promise { - // workspace if (ws === id) { - return this.tryCheckWorkspace(ws, user, Permission.Read); + // if workspace is public or have any public page, then allow to access + const [isPublicWorkspace, publicPages] = await Promise.all([ + this.tryCheckWorkspace(ws, user, Permission.Read), + await this.prisma.workspacePage.count({ + where: { + workspaceId: ws, + public: true, + }, + }), + ]); + return isPublicWorkspace || publicPages > 0; } return this.tryCheckPage(ws, id, user); @@ -155,21 +167,6 @@ export class PermissionService { if (count > 0) { return true; } - - const publicPage = await this.prisma.workspacePage.findFirst({ - select: { - pageId: true, - }, - where: { - workspaceId: ws, - public: true, - }, - }); - - // has any public pages - if (publicPage) { - return true; - } } if (user) { diff --git a/packages/backend/server/src/core/workspaces/resolvers/workspace.ts b/packages/backend/server/src/core/workspaces/resolvers/workspace.ts index 019bb7b32..a16b2d9e6 100644 --- a/packages/backend/server/src/core/workspaces/resolvers/workspace.ts +++ b/packages/backend/server/src/core/workspaces/resolvers/workspace.ts @@ -188,23 +188,6 @@ export class WorkspaceResolver { }); } - @Throttle('strict') - @Public() - @Query(() => WorkspaceType, { - description: 'Get public workspace by id', - }) - async publicWorkspace(@Args('id') id: string) { - const workspace = await this.prisma.workspace.findUnique({ - where: { id }, - }); - - if (workspace?.public) { - return workspace; - } - - throw new NotFoundException("Workspace doesn't exist"); - } - @Query(() => WorkspaceType, { description: 'Get workspace by id', }) diff --git a/packages/backend/server/src/schema.gql b/packages/backend/server/src/schema.gql index fc3454dbf..0955a1106 100644 --- a/packages/backend/server/src/schema.gql +++ b/packages/backend/server/src/schema.gql @@ -278,9 +278,6 @@ type Query { listWorkspaceFeatures(feature: FeatureType!): [WorkspaceType!]! prices: [SubscriptionPrice!]! - """Get public workspace by id""" - publicWorkspace(id: String!): WorkspaceType! - """server config""" serverConfig: ServerConfigType! diff --git a/packages/backend/server/tests/utils/workspace.ts b/packages/backend/server/tests/utils/workspace.ts index c90c08c53..f895d07c2 100644 --- a/packages/backend/server/tests/utils/workspace.ts +++ b/packages/backend/server/tests/utils/workspace.ts @@ -79,26 +79,6 @@ export async function getWorkspace( return res.body.data.workspace; } -export async function getPublicWorkspace( - app: INestApplication, - workspaceId: string -): Promise { - const res = await request(app.getHttpServer()) - .post(gql) - .set({ 'x-request-id': 'test', 'x-operation-name': 'test' }) - .send({ - query: ` - query { - publicWorkspace(id: "${workspaceId}") { - id - } - } - `, - }) - .expect(200); - return res.body.data.publicWorkspace; -} - export async function updateWorkspace( app: INestApplication, token: string, diff --git a/packages/backend/server/tests/workspace.e2e.ts b/packages/backend/server/tests/workspace.e2e.ts index 0adb0b0c6..4671b80b5 100644 --- a/packages/backend/server/tests/workspace.e2e.ts +++ b/packages/backend/server/tests/workspace.e2e.ts @@ -10,7 +10,6 @@ import { createTestingApp, createWorkspace, currentUser, - getPublicWorkspace, getWorkspacePublicPages, inviteUser, publishPage, @@ -87,20 +86,6 @@ test('should can publish workspace', async t => { t.false(isPrivate, 'failed to unpublish workspace'); }); -test('should can read published workspace', async t => { - const { app } = t.context; - const user = await signUp(app, 'u1', 'u1@affine.pro', '1'); - const workspace = await createWorkspace(app, user.token.token); - - await t.throwsAsync(() => getPublicWorkspace(app, 'not_exists_ws')); - await t.throwsAsync(() => getPublicWorkspace(app, workspace.id)); - - await updateWorkspace(app, user.token.token, workspace.id, true); - - const publicWorkspace = await getPublicWorkspace(app, workspace.id); - t.is(publicWorkspace.id, workspace.id, 'failed to get public workspace'); -}); - test('should share a page', async t => { const { app } = t.context; const u1 = await signUp(app, 'u1', 'u1@affine.pro', '1'); diff --git a/packages/frontend/graphql/src/graphql/get-public-workspace.gql b/packages/frontend/graphql/src/graphql/get-public-workspace.gql deleted file mode 100644 index 6da347222..000000000 --- a/packages/frontend/graphql/src/graphql/get-public-workspace.gql +++ /dev/null @@ -1,5 +0,0 @@ -query getPublicWorkspace($id: String!) { - publicWorkspace(id: $id) { - id - } -} diff --git a/packages/frontend/graphql/src/graphql/index.ts b/packages/frontend/graphql/src/graphql/index.ts index e429b004c..d381e9ec2 100644 --- a/packages/frontend/graphql/src/graphql/index.ts +++ b/packages/frontend/graphql/src/graphql/index.ts @@ -374,19 +374,6 @@ query oauthProviders { }`, }; -export const getPublicWorkspaceQuery = { - id: 'getPublicWorkspaceQuery' as const, - operationName: 'getPublicWorkspace', - definitionName: 'publicWorkspace', - containsFile: false, - query: ` -query getPublicWorkspace($id: String!) { - publicWorkspace(id: $id) { - id - } -}`, -}; - export const getUserFeaturesQuery = { id: 'getUserFeaturesQuery' as const, operationName: 'getUserFeatures', diff --git a/packages/frontend/graphql/src/schema.ts b/packages/frontend/graphql/src/schema.ts index 7d57eda72..86f0a3a66 100644 --- a/packages/frontend/graphql/src/schema.ts +++ b/packages/frontend/graphql/src/schema.ts @@ -474,15 +474,6 @@ export type OauthProvidersQuery = { }; }; -export type GetPublicWorkspaceQueryVariables = Exact<{ - id: Scalars['String']['input']; -}>; - -export type GetPublicWorkspaceQuery = { - __typename?: 'Query'; - publicWorkspace: { __typename?: 'WorkspaceType'; id: string }; -}; - export type GetUserFeaturesQueryVariables = Exact<{ [key: string]: never }>; export type GetUserFeaturesQuery = { @@ -1097,11 +1088,6 @@ export type Queries = variables: OauthProvidersQueryVariables; response: OauthProvidersQuery; } - | { - name: 'getPublicWorkspaceQuery'; - variables: GetPublicWorkspaceQueryVariables; - response: GetPublicWorkspaceQuery; - } | { name: 'getUserFeaturesQuery'; variables: GetUserFeaturesQueryVariables;