/*Canopy - The next generation of stoner streaming software Copyright (C) 2024-2025 Rainbownapkin and the TTN Community This program is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Affero General Public License for more details. You should have received a copy of the GNU Affero General Public License along with this program. If not, see .*/ //NPM Imports const {validationResult, matchedData} = require('express-validator'); //local imports const banModel = require('../../../schemas/user/userBanSchema'); const permissionModel = require('../../../schemas/permissionSchema'); const {userModel} = require('../../../schemas/user/userSchema'); const {exceptionHandler, errorHandler} = require('../../../utils/loggerUtils'); module.exports.get = async function(req, res){ try{ //get bans const bans = await banModel.getBans(); //send bans res.status(200); return res.send(bans); }catch(err){ return exceptionHandler(res, err); } } module.exports.post = async function(req, res){ try{ const validResult = validationResult(req); if(validResult.isEmpty()){ const {user, permanent, ipBan, expirationDays} = matchedData(req); const userDB = await userModel.findOne({user}); if(userDB == null){ //If the user is null, scream and shout return errorHandler(res, `User not found.`, 'Bad Query', 400); }else if(userDB.user == req.session.user.user){ //If some smart-ass is trying self-privelege escalation return errorHandler(res, `Keep it up, maybe I will ban you!`, 'Unauthorized', 401); }else if(permissionModel.rankToNum(userDB.rank) >= permissionModel.rankToNum(req.session.user.rank)){ //If the user is below the original rank of the user they're setting, scream and shout return errorHandler(res, 'You cannot ban peer/outranking users', 'Unauthorized', 401); } await banModel.banByUserDoc(userDB, permanent, expirationDays, ipBan); res.status(200); return res.send(await banModel.getBans()); }else{ res.status(400); return res.send({errors: validResult.array()}) } }catch(err){ return exceptionHandler(res, err); } } module.exports.delete = async function(req, res){ try{ const validResult = validationResult(req); if(validResult.isEmpty()){ const {user} = matchedData(req); await banModel.unban({user}); res.status(200); return res.send(await banModel.getBans()); }else{ res.status(400); return res.send({errors: validResult.array()}) } }catch(err){ return exceptionHandler(res, err); } }