summaryrefslogtreecommitdiffstats
path: root/backend/src/resolvers
diff options
context:
space:
mode:
authorWes Bos <wesbos@gmail.com>2018-03-28 15:22:34 -0400
committerWes Bos <wesbos@gmail.com>2018-03-28 15:22:34 -0400
commit65c524251d49ade9d44a62337f3c1c1fed6eedd0 (patch)
treed504ba9cea8d89bbde4b2e809fddb048bd660548 /backend/src/resolvers
parenta1fd7eb33bb08610aaf381a64b7f963cd98bfdaa (diff)
Permissions
Diffstat (limited to 'backend/src/resolvers')
-rw-r--r--backend/src/resolvers/Mutation.js51
-rw-r--r--backend/src/resolvers/Query.js7
2 files changed, 53 insertions, 5 deletions
diff --git a/backend/src/resolvers/Mutation.js b/backend/src/resolvers/Mutation.js
index 3d9ebb8..e4d568d 100644
--- a/backend/src/resolvers/Mutation.js
+++ b/backend/src/resolvers/Mutation.js
@@ -1,17 +1,24 @@
const bcrypt = require('bcryptjs');
const jwt = require('jsonwebtoken');
-const { getUserId, Context } = require('../utils');
+const { getUserId, Context, hasPermission } = require('../utils');
const { randomBytes } = require('crypto');
const { promisify } = require('util');
const mail = require('../mail');
const stripe = require('../stripe');
+const wait = amount => new Promise(resolve => setTimeout(resolve, amount));
+
const mutations = {
// Signup Mutations
async signup(parent, args, ctx, info) {
+ args.email = args.email.toLowerCase();
const password = await bcrypt.hash(args.password, 10);
const user = await ctx.db.mutation.createUser({
- data: { ...args, password },
+ data: {
+ ...args,
+ password,
+ permissions: { set: ['USER'] },
+ },
});
return {
@@ -38,13 +45,27 @@ const mutations = {
// Creation of Post Mutations
async createItem(parent, args, ctx, info) {
- // TODO - they should be signed in when creating an item for sale
- // TODO: The user should be saved to the item so they can manage it
- return ctx.db.mutation.createItem({ data: { ...args } }, info);
+ const userId = getUserId(ctx);
+ const item = await ctx.db.mutation.createItem(
+ {
+ data: {
+ user: {
+ connect: {
+ id: userId,
+ },
+ },
+ ...args,
+ },
+ },
+ info
+ );
+ console.log(item);
+ return item;
},
async deleteItem(parent, args, ctx, info) {
// TODO - handle auth for deleting an item
+ // You Should Either Own this item, or have CAN_DELETE in roles
return ctx.db.mutation.deleteItem(
{
where: {
@@ -265,6 +286,26 @@ const mutations = {
console.log(updatedUser);
return updatedUser;
},
+
+ async updatePermissions(parent, args, ctx, info) {
+ const userId = getUserId(ctx);
+ await wait(20000);
+ const currentUser = await ctx.db.query.user({ where: { id: userId } }, info);
+ console.log(currentUser);
+ if (!currentUser) throw new Error('You Must be logged in to updat permissions!');
+ hasPermission(currentUser, ['ADMIN', 'PERMISSIONUPDATE']);
+ return ctx.db.mutation.updateUser(
+ {
+ data: {
+ permissions: {
+ set: args.permissions,
+ },
+ },
+ where: { id: args.userId },
+ },
+ info
+ );
+ },
};
module.exports = mutations;
diff --git a/backend/src/resolvers/Query.js b/backend/src/resolvers/Query.js
index 2aa4f5c..e69a671 100644
--- a/backend/src/resolvers/Query.js
+++ b/backend/src/resolvers/Query.js
@@ -24,6 +24,7 @@ const Query = {
async orders(parent, args, ctx, info) {
const userId = getUserId(ctx);
+ console.log(info);
return ctx.db.query.orders(
{
where: {
@@ -33,6 +34,12 @@ const Query = {
info
);
},
+
+ async users(parent, args, ctx, info) {
+ console.log('TODO: check their permissions');
+ const userId = getUserId(ctx);
+ return ctx.db.query.users({}, info);
+ },
};
module.exports = Query;