Browse Source

blogging: Let users delete their own comments

pull/3036/head
Yunus Emre Kalkan 7 years ago
parent
commit
b0adb9ff09
  1. 5
      modules/blogging/src/Volo.Blogging.Application/Volo/Blogging/Comments/CommentAuthorizationHandler.cs
  2. 5
      modules/blogging/src/Volo.Blogging.Application/Volo/Blogging/Posts/PostAuthorizationHandler.cs
  3. 2
      modules/blogging/src/Volo.Blogging.HttpApi/Volo/Blogging/CommentsController.cs
  4. 2
      modules/blogging/src/Volo.Blogging.Web/Pages/Blogs/Posts/Detail.cshtml

5
modules/blogging/src/Volo.Blogging.Application/Volo/Blogging/Comments/CommentAuthorizationHandler.cs

@ -35,6 +35,11 @@ namespace Volo.Blogging.Comments
private async Task<bool> HasDeletePermission(AuthorizationHandlerContext context, Comment resource) private async Task<bool> HasDeletePermission(AuthorizationHandlerContext context, Comment resource)
{ {
if (resource.CreatorId != null && resource.CreatorId == context.User.FindUserId())
{
return true;
}
if (await _permissionChecker.IsGrantedAsync(context.User, BloggingPermissions.Comments.Delete)) if (await _permissionChecker.IsGrantedAsync(context.User, BloggingPermissions.Comments.Delete))
{ {
return true; return true;

5
modules/blogging/src/Volo.Blogging.Application/Volo/Blogging/Posts/PostAuthorizationHandler.cs

@ -35,6 +35,11 @@ namespace Volo.Blogging.Posts
private async Task<bool> HasDeletePermission(AuthorizationHandlerContext context, Post resource) private async Task<bool> HasDeletePermission(AuthorizationHandlerContext context, Post resource)
{ {
if (resource.CreatorId != null && resource.CreatorId == context.User.FindUserId())
{
return true;
}
if (await _permissionChecker.IsGrantedAsync(context.User, BloggingPermissions.Posts.Delete)) if (await _permissionChecker.IsGrantedAsync(context.User, BloggingPermissions.Posts.Delete))
{ {
return true; return true;

2
modules/blogging/src/Volo.Blogging.HttpApi/Volo/Blogging/CommentsController.cs

@ -45,7 +45,7 @@ namespace Volo.Blogging
[Route("{id}")] [Route("{id}")]
public Task DeleteAsync(Guid id) public Task DeleteAsync(Guid id)
{ {
throw new NotImplementedException(); return _commentAppService.DeleteAsync(id);
} }
} }
} }

2
modules/blogging/src/Volo.Blogging.Web/Pages/Blogs/Posts/Detail.cshtml

@ -147,7 +147,7 @@
</a> </a>
} }
@if (await Authorization.IsGrantedAsync(BloggingPermissions.Comments.Delete)) @if (await Authorization.IsGrantedAsync(BloggingPermissions.Comments.Delete) || (CurrentUser.Id == commentWithRepliesDto.Comment.CreatorId))
{ {
<span class="seperator">|</span> <span class="seperator">|</span>
<a href="#" class="tag deleteLink" data-deleteid="@commentWithRepliesDto.Comment.Id"> <a href="#" class="tag deleteLink" data-deleteid="@commentWithRepliesDto.Comment.Id">

Loading…
Cancel
Save