|
|
@ -81,11 +81,7 @@ public class AlarmCommentController extends BaseController { |
|
|
Alarm alarm = checkAlarmInfoId(alarmId, Operation.WRITE); |
|
|
Alarm alarm = checkAlarmInfoId(alarmId, Operation.WRITE); |
|
|
SecurityUser currentUser = getCurrentUser(); |
|
|
SecurityUser currentUser = getCurrentUser(); |
|
|
if (alarmComment.getId() != null) { |
|
|
if (alarmComment.getId() != null) { |
|
|
AlarmComment existingAlarmComment = checkAlarmCommentId(alarmComment.getId(), alarmId); |
|
|
checkUserPermission(alarmComment, alarmId, "edit", currentUser); |
|
|
if (existingAlarmComment.getUserId() != null && !existingAlarmComment.getUserId().equals(currentUser.getId())) { |
|
|
|
|
|
throw new ThingsboardException("User is not allowed to edit other user's comment", |
|
|
|
|
|
ThingsboardErrorCode.PERMISSION_DENIED); |
|
|
|
|
|
} |
|
|
|
|
|
} |
|
|
} |
|
|
alarmComment.setAlarmId(alarmId); |
|
|
alarmComment.setAlarmId(alarmId); |
|
|
alarmComment.setType(AlarmCommentType.OTHER); |
|
|
alarmComment.setType(AlarmCommentType.OTHER); |
|
|
@ -104,6 +100,9 @@ public class AlarmCommentController extends BaseController { |
|
|
AlarmCommentId alarmCommentId = new AlarmCommentId(toUUID(strCommentId)); |
|
|
AlarmCommentId alarmCommentId = new AlarmCommentId(toUUID(strCommentId)); |
|
|
AlarmComment alarmComment = checkAlarmCommentId(alarmCommentId, alarmId); |
|
|
AlarmComment alarmComment = checkAlarmCommentId(alarmCommentId, alarmId); |
|
|
SecurityUser currentUser = getCurrentUser(); |
|
|
SecurityUser currentUser = getCurrentUser(); |
|
|
|
|
|
if (!currentUser.isTenantAdmin()) { |
|
|
|
|
|
checkUserPermission(alarmComment, alarmId, "delete", currentUser); |
|
|
|
|
|
} |
|
|
tbAlarmCommentService.deleteAlarmComment(alarm, alarmComment, currentUser); |
|
|
tbAlarmCommentService.deleteAlarmComment(alarm, alarmComment, currentUser); |
|
|
} |
|
|
} |
|
|
|
|
|
|
|
|
@ -131,4 +130,12 @@ public class AlarmCommentController extends BaseController { |
|
|
return checkNotNull(alarmCommentService.findAlarmComments(alarm.getTenantId(), alarmId, pageLink)); |
|
|
return checkNotNull(alarmCommentService.findAlarmComments(alarm.getTenantId(), alarmId, pageLink)); |
|
|
} |
|
|
} |
|
|
|
|
|
|
|
|
|
|
|
private void checkUserPermission(AlarmComment alarmComment, AlarmId alarmId, String operation, SecurityUser currentUser) throws ThingsboardException { |
|
|
|
|
|
AlarmComment existingAlarmComment = checkAlarmCommentId(alarmComment.getId(), alarmId); |
|
|
|
|
|
if (existingAlarmComment.getUserId() != null && !existingAlarmComment.getUserId().equals(currentUser.getId())) { |
|
|
|
|
|
throw new ThingsboardException("User is not allowed to " + operation + " other user's comment", |
|
|
|
|
|
ThingsboardErrorCode.PERMISSION_DENIED); |
|
|
|
|
|
} |
|
|
|
|
|
} |
|
|
|
|
|
|
|
|
} |
|
|
} |
|
|
|