diff options
| author | Wes Bos <wesbos@gmail.com> | 2018-09-07 12:15:53 -0400 |
|---|---|---|
| committer | Wes Bos <wesbos@gmail.com> | 2018-09-07 12:15:53 -0400 |
| commit | 093c172d16732ba8d01faa313e0af99d26902205 (patch) | |
| tree | 84838c4f6410b43f42b56219190a62e14e072ef3 /stepped-solutions/54/backend | |
| parent | 9876e7dfca6fa2bbf6ac383eeb8e2c82e05c2164 (diff) | |
getting there
Diffstat (limited to 'stepped-solutions/54/backend')
| -rwxr-xr-x | stepped-solutions/54/backend/src/resolvers/Query.js | 69 | ||||
| -rwxr-xr-x | stepped-solutions/54/backend/src/schema.graphql | 38 |
2 files changed, 107 insertions, 0 deletions
diff --git a/stepped-solutions/54/backend/src/resolvers/Query.js b/stepped-solutions/54/backend/src/resolvers/Query.js new file mode 100755 index 0000000..22a6414 --- /dev/null +++ b/stepped-solutions/54/backend/src/resolvers/Query.js @@ -0,0 +1,69 @@ +const { forwardTo } = require('prisma-binding'); +const { hasPermission } = require('../utils'); + +const Query = { + items: forwardTo('db'), + item: forwardTo('db'), + itemsConnection: forwardTo('db'), + me(parent, args, ctx, info) { + // check if there is a current user ID + if (!ctx.request.userId) { + return null; + } + return ctx.db.query.user( + { + where: { id: ctx.request.userId }, + }, + info + ); + }, + async users(parent, args, ctx, info) { + // 1. Check if they are logged in + if (!ctx.request.userId) { + throw new Error('You must be logged in!'); + } + console.log(ctx.request.userId); + // 2. Check if the user has the permissions to query all the users + hasPermission(ctx.request.user, ['ADMIN', 'PERMISSIONUPDATE']); + + // 2. if they do, query all the users! + return ctx.db.query.users({}, info); + }, + async order(parent, args, ctx, info) { + // 1. Make sure they are logged in + if (!ctx.request.userId) { + throw new Error('You arent logged in!'); + } + // 2. Query the current order + const order = await ctx.db.query.order( + { + where: { id: args.id }, + }, + info + ); + // 3. Check if the have the permissions to see this order + const ownsOrder = order.user.id === ctx.request.userId; + const hasPermissionToSeeOrder = ctx.request.user.permissions.includes('ADMIN'); + if (!ownsOrder || !hasPermission) { + throw new Error('You cant see this buddd'); + } + // 4. Return the order + return order; + }, + async orders(parent, args, ctx, info) { + const { userId } = ctx.request; + if (!userId) { + throw new Error('you must be signed in!'); + } + return ctx.db.query.orders( + { + where: { + user: { id: userId }, + }, + }, + info + ); + }, +}; + +module.exports = Query; diff --git a/stepped-solutions/54/backend/src/schema.graphql b/stepped-solutions/54/backend/src/schema.graphql new file mode 100755 index 0000000..d9ab917 --- /dev/null +++ b/stepped-solutions/54/backend/src/schema.graphql @@ -0,0 +1,38 @@ +# import * from './generated/prisma.graphql' + +type SuccessMessage { + message: String +} + +type Mutation { + createItem(title: String, description: String, price: Int, image: String, largeImage: String): Item! + updateItem(id: ID!, title: String, description: String, price: Int): Item! + deleteItem(id: ID!): Item + signup(email: String!, password: String!, name: String!): User! + signin(email: String!, password: String!): User! + signout: SuccessMessage + requestReset(email: String!): SuccessMessage + resetPassword(resetToken: String!, password: String!, confirmPassword: String!): User! + updatePermissions(permissions: [Permission], userId: ID!): User + addToCart(id: ID!): CartItem + removeFromCart(id: ID!): CartItem + createOrder(token: String!): Order! +} + +type Query { + items(where: ItemWhereInput, orderBy: ItemOrderByInput, skip: Int, first: Int): [Item]! + item(where: ItemWhereUniqueInput!): Item + itemsConnection(where: ItemWhereInput): ItemConnection! + me: User + users: [User]! + order(id: ID!): Order + orders(orderBy: OrderOrderByInput): [Order]! +} + +type User{ + id: ID! + name: String! + email: String! + permissions: [Permission!]! + cart: [CartItem!]! +} |
