Added tokeCommand delete endpoint and ajax call, replaced all raw error responses.
This commit is contained in:
parent
af7f4219a5
commit
864304f13b
28 changed files with 93 additions and 64 deletions
|
|
@ -18,7 +18,7 @@ along with this program. If not, see <https://www.gnu.org/licenses/>.*/
|
|||
const {validationResult, matchedData} = require('express-validator');
|
||||
|
||||
//local imports
|
||||
const {exceptionHandler} = require('../../../utils/loggerUtils');
|
||||
const {exceptionHandler, errorHandler} = require('../../../utils/loggerUtils');
|
||||
const permissionModel = require('../../../schemas/permissionSchema');
|
||||
const {userModel} = require('../../../schemas/userSchema');
|
||||
|
||||
|
|
@ -36,20 +36,16 @@ module.exports.post = async function(req, res){
|
|||
|
||||
if(userDB == null){
|
||||
//If the user is null, scream and shout
|
||||
res.status(400);
|
||||
res.send({errors:[{type: "Bad Query", msg: "User not found.", date: new Date()}]});
|
||||
return errorHandler(res, 'User not found.', 'Bad Query');
|
||||
}else if(userDB.user == req.session.user.user){
|
||||
//If some smart-ass is trying self-privelege escalation
|
||||
res.status(401);
|
||||
return res.send({errors:[{type: "Unauthorized", msg: "No, you can't change your own rank. Fuck off.", date: new Date()}]});
|
||||
return errorHandler(res, "No, you can't change your own rank, fuck off.", 'Unauthorized', 401);
|
||||
}else if(permissionModel.rankToNum(data.rank) >= permissionModel.rankToNum(req.session.user.rank)){
|
||||
//If the user is below the new rank of the user they're setting, scream and shout
|
||||
res.status(401);
|
||||
return res.send({errors:[{type: "Unauthorized", msg: "New rank must be below that of the user changing it.", date: new Date()}]});
|
||||
return errorHandler(res, "New rank must be below that of the user changing it.", 'Unauthorized', 401);
|
||||
}else if(permissionModel.rankToNum(userDB.rank) >= permissionModel.rankToNum(req.session.user.rank)){
|
||||
//If the user is below the original rank of the user they're setting, scream and shout
|
||||
res.status(401);
|
||||
return res.send({errors:[{type: "Unauthorized", msg: "You cannot promote/demote peer/outranking users.", date: new Date()}]});
|
||||
return errorHandler(res, "You cannot promote/demote peer/outranking users.", 'Unauthorized', 401);
|
||||
}
|
||||
|
||||
userDB.rank = data.rank;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue