forked from tsai/budibase
15 changed files with 65 additions and 21 deletions
@ -0,0 +1,9 @@ |
|||||
|
module.exports = async (ctx, next) => { |
||||
|
if ( |
||||
|
!ctx.internal && |
||||
|
(!ctx.user || !ctx.user.admin || !ctx.user.admin.global) |
||||
|
) { |
||||
|
ctx.throw(403, "Admin user only endpoint.") |
||||
|
} |
||||
|
return next() |
||||
|
} |
||||
@ -0,0 +1,28 @@ |
|||||
|
function validate(schema, property) { |
||||
|
// Return a Koa middleware function
|
||||
|
return (ctx, next) => { |
||||
|
if (!schema) { |
||||
|
return next() |
||||
|
} |
||||
|
let params = null |
||||
|
if (ctx[property] != null) { |
||||
|
params = ctx[property] |
||||
|
} else if (ctx.request[property] != null) { |
||||
|
params = ctx.request[property] |
||||
|
} |
||||
|
const { error } = schema.validate(params) |
||||
|
if (error) { |
||||
|
ctx.throw(400, `Invalid ${property} - ${error.message}`) |
||||
|
return |
||||
|
} |
||||
|
return next() |
||||
|
} |
||||
|
} |
||||
|
|
||||
|
module.exports.body = schema => { |
||||
|
return validate(schema, "body") |
||||
|
} |
||||
|
|
||||
|
module.exports.params = schema => { |
||||
|
return validate(schema, "params") |
||||
|
} |
||||
Loading…
Reference in new issue