mirror of
https://github.com/yu-i-i/overleaf-cep.git
synced 2026-05-25 10:10:08 +02:00
[web] Convert some Features files to ES modules (part 5) GitOrigin-RevId: 0cad67f9afe0095e2b066bf2f4d3717c00540dab
80 lines
2.7 KiB
JavaScript
80 lines
2.7 KiB
JavaScript
import EditorHttpController from './EditorHttpController.mjs'
|
|
import AuthenticationController from '../Authentication/AuthenticationController.js'
|
|
import AuthorizationMiddleware from '../Authorization/AuthorizationMiddleware.mjs'
|
|
import { RateLimiter } from '../../infrastructure/RateLimiter.js'
|
|
import RateLimiterMiddleware from '../Security/RateLimiterMiddleware.mjs'
|
|
|
|
const rateLimiters = {
|
|
addDocToProject: new RateLimiter('add-doc-to-project', {
|
|
points: 30,
|
|
duration: 60,
|
|
}),
|
|
addFolderToProject: new RateLimiter('add-folder-to-project', {
|
|
points: 60,
|
|
duration: 60,
|
|
}),
|
|
joinProject: new RateLimiter('join-project', { points: 45, duration: 60 }),
|
|
}
|
|
|
|
export default {
|
|
apply(webRouter, privateApiRouter) {
|
|
webRouter.post(
|
|
'/project/:Project_id/doc',
|
|
AuthorizationMiddleware.ensureUserCanWriteProjectContent,
|
|
RateLimiterMiddleware.rateLimit(rateLimiters.addDocToProject, {
|
|
params: ['Project_id'],
|
|
}),
|
|
EditorHttpController.addDoc
|
|
)
|
|
webRouter.post(
|
|
'/project/:Project_id/folder',
|
|
AuthorizationMiddleware.ensureUserCanWriteProjectContent,
|
|
RateLimiterMiddleware.rateLimit(rateLimiters.addFolderToProject, {
|
|
params: ['Project_id'],
|
|
}),
|
|
EditorHttpController.addFolder
|
|
)
|
|
|
|
webRouter.post(
|
|
'/project/:Project_id/:entity_type/:entity_id/rename',
|
|
AuthorizationMiddleware.ensureUserCanWriteProjectContent,
|
|
EditorHttpController.renameEntity
|
|
)
|
|
webRouter.post(
|
|
'/project/:Project_id/:entity_type/:entity_id/move',
|
|
AuthorizationMiddleware.ensureUserCanWriteProjectContent,
|
|
EditorHttpController.moveEntity
|
|
)
|
|
|
|
webRouter.delete(
|
|
'/project/:Project_id/file/:entity_id',
|
|
AuthorizationMiddleware.ensureUserCanWriteProjectContent,
|
|
EditorHttpController.deleteFile
|
|
)
|
|
webRouter.delete(
|
|
'/project/:Project_id/doc/:entity_id',
|
|
AuthorizationMiddleware.ensureUserCanWriteProjectContent,
|
|
EditorHttpController.deleteDoc
|
|
)
|
|
webRouter.delete(
|
|
'/project/:Project_id/folder/:entity_id',
|
|
AuthorizationMiddleware.ensureUserCanWriteProjectContent,
|
|
EditorHttpController.deleteFolder
|
|
)
|
|
|
|
// Called by the real-time API to load up the current project state.
|
|
// This is a post request because it's more than just a getting of data. We take actions
|
|
// whenever a user joins a project, like updating the deleted status.
|
|
privateApiRouter.post(
|
|
'/project/:Project_id/join',
|
|
AuthenticationController.requirePrivateApiAuth(),
|
|
RateLimiterMiddleware.rateLimit(rateLimiters.joinProject, {
|
|
params: ['Project_id'],
|
|
// keep schema in sync with controller
|
|
getUserId: req => req.body.userId,
|
|
}),
|
|
EditorHttpController.joinProject
|
|
)
|
|
},
|
|
}
|