Added tokeCommand delete endpoint and ajax call, replaced all raw error responses.
This commit is contained in:
parent
af7f4219a5
commit
864304f13b
28 changed files with 93 additions and 64 deletions
|
|
@ -21,7 +21,7 @@ const {validationResult, matchedData} = require('express-validator');
|
|||
const banModel = require('../../../schemas/userBanSchema');
|
||||
const permissionModel = require('../../../schemas/permissionSchema');
|
||||
const {userModel} = require('../../../schemas/userSchema');
|
||||
const {exceptionHandler} = require('../../../utils/loggerUtils');
|
||||
const {exceptionHandler, errorHandler} = require('../../../utils/loggerUtils');
|
||||
|
||||
module.exports.get = async function(req, res){
|
||||
try{
|
||||
|
|
@ -45,16 +45,13 @@ module.exports.post = async function(req, res){
|
|||
|
||||
if(userDB == null){
|
||||
//If the user is null, scream and shout
|
||||
res.status(400);
|
||||
return res.send({errors:[{type: "Bad Query", msg: "User not found.", date: new Date()}]});
|
||||
return errorHandler(res, `User not found.`, 'Bad Query', 400);
|
||||
}else if(userDB.user == req.session.user.user){
|
||||
//If some smart-ass is trying self-privelege escalation
|
||||
res.status(401);
|
||||
return res.send({errors:[{type: "Unauthorized", msg: "Keep it up, maybe I will ban you!", date: new Date()}]});
|
||||
return errorHandler(res, `Keep it up, maybe I will ban you!`, 'Unauthorized', 401);
|
||||
}else if(permissionModel.rankToNum(userDB.rank) >= permissionModel.rankToNum(req.session.user.rank)){
|
||||
//If the user is below the original rank of the user they're setting, scream and shout
|
||||
res.status(401);
|
||||
return res.send({errors:[{type: "Unauthorized", msg: "You cannot ban peer/outranking users.", date: new Date()}]});
|
||||
return errorHandler(res, 'You cannot ban peer/outranking users', 'Unauthorized', 401);
|
||||
}
|
||||
|
||||
await banModel.banByUserDoc(userDB, permanent, expirationDays);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue