aboutsummaryrefslogtreecommitdiffstats
path: root/core/Controller/ProfileApiController.php
diff options
context:
space:
mode:
authorChristopher Ng <chrng8@gmail.com>2021-10-14 08:19:40 +0000
committerChristopher Ng <chrng8@gmail.com>2021-10-19 04:59:35 +0000
commit309354852f12ae88d5eef05d311d6ebcba8ee762 (patch)
tree640c4e2394ba2a868d8d1cb6b5271fd1271bbdab /core/Controller/ProfileApiController.php
parent7215148a242815a5064ce5d00a387c634dc936f3 (diff)
downloadnextcloud-server-309354852f12ae88d5eef05d311d6ebcba8ee762.tar.gz
nextcloud-server-309354852f12ae88d5eef05d311d6ebcba8ee762.zip
Profile backend
Signed-off-by: Christopher Ng <chrng8@gmail.com>
Diffstat (limited to 'core/Controller/ProfileApiController.php')
-rw-r--r--core/Controller/ProfileApiController.php98
1 files changed, 98 insertions, 0 deletions
diff --git a/core/Controller/ProfileApiController.php b/core/Controller/ProfileApiController.php
new file mode 100644
index 00000000000..d9e20701eaa
--- /dev/null
+++ b/core/Controller/ProfileApiController.php
@@ -0,0 +1,98 @@
+<?php
+
+declare(strict_types=1);
+
+/**
+ * @copyright 2021 Christopher Ng <chrng8@gmail.com>
+ *
+ * @author Christopher Ng <chrng8@gmail.com>
+ *
+ * @license GNU AGPL version 3 or any later version
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as
+ * published by the Free Software Foundation, either version 3 of the
+ * License, or (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program. If not, see <http://www.gnu.org/licenses/>.
+ *
+ */
+
+namespace OC\Core\Controller;
+
+use OC\Core\Db\ProfileConfigMapper;
+use OCP\AppFramework\Http\DataResponse;
+use OCP\AppFramework\OCS\OCSBadRequestException;
+use OCP\AppFramework\OCS\OCSForbiddenException;
+use OCP\AppFramework\OCS\OCSNotFoundException;
+use OCP\AppFramework\OCSController;
+use OCP\IRequest;
+use OCP\IUserManager;
+use OCP\IUserSession;
+use OC\Profile\ProfileManager;
+
+class ProfileApiController extends OCSController {
+
+ /** @var ProfileConfigMapper */
+ private $configMapper;
+
+ /** @var ProfileManager */
+ private $profileManager;
+
+ /** @var IUserManager */
+ private $userManager;
+
+ /** @var IUserSession */
+ private $userSession;
+
+ public function __construct(
+ IRequest $request,
+ ProfileConfigMapper $configMapper,
+ ProfileManager $profileManager,
+ IUserManager $userManager,
+ IUserSession $userSession
+ ) {
+ parent::__construct('core', $request);
+ $this->configMapper = $configMapper;
+ $this->profileManager = $profileManager;
+ $this->userManager = $userManager;
+ $this->userSession = $userSession;
+ }
+
+ /**
+ * @NoAdminRequired
+ * @NoSubAdminRequired
+ * @PasswordConfirmationRequired
+ */
+ public function setVisibility(string $targetUserId, string $paramId, string $visibility): DataResponse {
+ $requestingUser = $this->userSession->getUser();
+ $targetUser = $this->userManager->get($targetUserId);
+
+ if (!$this->userManager->userExists($targetUserId)) {
+ throw new OCSNotFoundException('User does not exist');
+ }
+
+ if ($requestingUser !== $targetUser) {
+ throw new OCSForbiddenException('Users can only edit their own visibility settings');
+ }
+
+ // Ensure that a profile config is created in the database
+ $this->profileManager->getProfileConfig($targetUser, $targetUser);
+ $config = $this->configMapper->get($targetUserId);
+
+ if (!in_array($paramId, array_keys($config->getVisibilityMap()), true)) {
+ throw new OCSBadRequestException('User does not have a profile parameter with ID: ' . $paramId);
+ }
+
+ $config->setVisibility($paramId, $visibility);
+ $this->configMapper->update($config);
+
+ return new DataResponse();
+ }
+}