summaryrefslogtreecommitdiffstats
path: root/sick-fits/backend/src/resolvers/Query.js
diff options
context:
space:
mode:
authorWes Bos <wesbos@gmail.com>2018-06-14 16:44:21 -0400
committerWes Bos <wesbos@gmail.com>2018-06-14 16:44:21 -0400
commitb1600adec47a04f60e1da07d94a3ed3906ff5aee (patch)
tree828f786da6806d7237ee5cbc5df61e552353b85b /sick-fits/backend/src/resolvers/Query.js
parenta95e08cd2dd5d7ec0a0412adae02515a5f9cec4f (diff)
starter files
Diffstat (limited to 'sick-fits/backend/src/resolvers/Query.js')
-rw-r--r--sick-fits/backend/src/resolvers/Query.js62
1 files changed, 62 insertions, 0 deletions
diff --git a/sick-fits/backend/src/resolvers/Query.js b/sick-fits/backend/src/resolvers/Query.js
new file mode 100644
index 0000000..51c2c42
--- /dev/null
+++ b/sick-fits/backend/src/resolvers/Query.js
@@ -0,0 +1,62 @@
+const { hasPermission } = require('../utils');
+
+const { forwardTo } = require('prisma-binding');
+
+const Query = {
+ items: forwardTo('db'),
+ itemsConnection: forwardTo('db'),
+
+ async order(parent, args, ctx, info) {
+ // 1. make sure they are signed in
+ if (!ctx.request.userId) {
+ throw new Error('You Must be signed in to view an order');
+ }
+
+ // 2. Create the query
+ const where = {
+ id: args.id,
+ user: {
+ id: ctx.request.userId,
+ },
+ };
+ // 3. Fire off the query
+ const [order] = await ctx.db.query.orders({ where }, info);
+
+ // 4. Check that they are allowed to view the order
+ if (order.user.id !== ctx.request.userId || hasPermission(ctx.request.user, ['ADMIN'])) {
+ throw new Error("You don't have permission");
+ }
+ // 5. If everything checks out, return the order
+ return order;
+ },
+
+ me(parent, args, ctx, info) {
+ if (!ctx.request.userId) {
+ return null; // don't error out, just return nothing
+ }
+
+ return ctx.db.query.user(
+ {
+ where: { id: ctx.request.userId },
+ },
+ info
+ );
+ },
+
+ async orders(parent, args, ctx, info) {
+ const { userId } = ctx.request;
+ if (!userId) {
+ throw new Error('You must be signed in to see your orders');
+ }
+ return ctx.db.query.orders(
+ {
+ where: {
+ user: { id: userId },
+ },
+ },
+ info
+ );
+ },
+};
+
+module.exports = Query;