]> Untitled Git - lemmy.git/blob - crates/api_crud/src/post/update.rs
Removing checking permissions when editing posts and comments. (#2727)
[lemmy.git] / crates / api_crud / src / post / update.rs
1 use crate::PerformCrud;
2 use actix_web::web::Data;
3 use lemmy_api_common::{
4   context::LemmyContext,
5   post::{EditPost, PostResponse},
6   request::fetch_site_data,
7   utils::{check_community_ban, get_local_user_view_from_jwt, local_site_to_slur_regex},
8   websocket::{send::send_post_ws_message, UserOperationCrud},
9 };
10 use lemmy_db_schema::{
11   source::{
12     actor_language::CommunityLanguage,
13     local_site::LocalSite,
14     post::{Post, PostUpdateForm},
15   },
16   traits::Crud,
17   utils::{diesel_option_overwrite, naive_now},
18 };
19 use lemmy_utils::{
20   error::LemmyError,
21   utils::{check_slurs_opt, clean_url_params, is_valid_post_title},
22   ConnectionId,
23 };
24
25 #[async_trait::async_trait(?Send)]
26 impl PerformCrud for EditPost {
27   type Response = PostResponse;
28
29   #[tracing::instrument(skip(context, websocket_id))]
30   async fn perform(
31     &self,
32     context: &Data<LemmyContext>,
33     websocket_id: Option<ConnectionId>,
34   ) -> Result<PostResponse, LemmyError> {
35     let data: &EditPost = self;
36     let local_user_view =
37       get_local_user_view_from_jwt(&data.auth, context.pool(), context.secret()).await?;
38     let local_site = LocalSite::read(context.pool()).await?;
39
40     let data_url = data.url.as_ref();
41
42     // TODO No good way to handle a clear.
43     // Issue link: https://github.com/LemmyNet/lemmy/issues/2287
44     let url = Some(data_url.map(clean_url_params).map(Into::into));
45     let body = diesel_option_overwrite(&data.body);
46
47     let slur_regex = local_site_to_slur_regex(&local_site);
48     check_slurs_opt(&data.name, &slur_regex)?;
49     check_slurs_opt(&data.body, &slur_regex)?;
50
51     if let Some(name) = &data.name {
52       if !is_valid_post_title(name) {
53         return Err(LemmyError::from_message("invalid_post_title"));
54       }
55     }
56
57     let post_id = data.post_id;
58     let orig_post = Post::read(context.pool(), post_id).await?;
59
60     check_community_ban(
61       local_user_view.person.id,
62       orig_post.community_id,
63       context.pool(),
64     )
65     .await?;
66
67     // Verify that only the creator can edit
68     if !Post::is_post_creator(local_user_view.person.id, orig_post.creator_id) {
69       return Err(LemmyError::from_message("no_post_edit_allowed"));
70     }
71
72     // Fetch post links and Pictrs cached image
73     let data_url = data.url.as_ref();
74     let (metadata_res, thumbnail_url) =
75       fetch_site_data(context.client(), context.settings(), data_url).await;
76     let (embed_title, embed_description, embed_video_url) = metadata_res
77       .map(|u| (Some(u.title), Some(u.description), Some(u.embed_video_url)))
78       .unwrap_or_default();
79
80     let language_id = self.language_id;
81     CommunityLanguage::is_allowed_community_language(
82       context.pool(),
83       language_id,
84       orig_post.community_id,
85     )
86     .await?;
87
88     let post_form = PostUpdateForm::builder()
89       .name(data.name.clone())
90       .url(url)
91       .body(body)
92       .nsfw(data.nsfw)
93       .embed_title(embed_title)
94       .embed_description(embed_description)
95       .embed_video_url(embed_video_url)
96       .language_id(data.language_id)
97       .thumbnail_url(Some(thumbnail_url))
98       .updated(Some(Some(naive_now())))
99       .build();
100
101     let post_id = data.post_id;
102     let res = Post::update(context.pool(), post_id, &post_form).await;
103     if let Err(e) = res {
104       let err_type = if e.to_string() == "value too long for type character varying(200)" {
105         "post_title_too_long"
106       } else {
107         "couldnt_update_post"
108       };
109
110       return Err(LemmyError::from_error_message(e, err_type));
111     }
112
113     send_post_ws_message(
114       data.post_id,
115       UserOperationCrud::EditPost,
116       websocket_id,
117       Some(local_user_view.person.id),
118       context,
119     )
120     .await
121   }
122 }