mirror of
https://github.com/Sendouc/sendou.ink.git
synced 2026-09-27 13:47:56 -05:00
Fix can add badges you don't own via template functionality
This commit is contained in:
@@ -5,6 +5,7 @@ import {
|
||||
type AuthenticatedUser,
|
||||
requireUser,
|
||||
} from "~/features/auth/core/user.server";
|
||||
import * as BadgeRepository from "~/features/badges/BadgeRepository.server";
|
||||
import * as CalendarRepository from "~/features/calendar/CalendarRepository.server";
|
||||
import { newCalendarEventActionSchema } from "~/features/calendar/calendar-schemas.server";
|
||||
import * as ShowcaseTournaments from "~/features/front-page/core/ShowcaseTournaments.server";
|
||||
@@ -22,6 +23,7 @@ import {
|
||||
} from "~/utils/dates";
|
||||
import {
|
||||
badRequestIfFalsy,
|
||||
errorToast,
|
||||
errorToastIfFalsy,
|
||||
parseFormData,
|
||||
uploadImageIfSubmitted,
|
||||
@@ -49,6 +51,18 @@ export const action: ActionFunction = async ({ request }) => {
|
||||
user,
|
||||
});
|
||||
|
||||
if (data.badges && data.badges.length > 0) {
|
||||
const managedBadges = await BadgeRepository.findManagedByUserId(user.id);
|
||||
|
||||
if (
|
||||
data.badges.some((badge) => !managedBadges.some((mb) => mb.id === badge))
|
||||
) {
|
||||
errorToast(
|
||||
"You don't manage any badges, so you cannot add any to the event",
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
const startTimes = data.date.map((date) => dateToDatabaseTimestamp(date));
|
||||
const commonArgs = {
|
||||
authorId: user.id,
|
||||
|
||||
@@ -62,18 +62,31 @@ export const loader = async ({ request }: LoaderFunctionArgs) => {
|
||||
);
|
||||
}
|
||||
|
||||
const managedBadges = await BadgeRepository.findManagedByUserId(user.id);
|
||||
|
||||
const eventToCopyRaw =
|
||||
user.roles.includes("TOURNAMENT_ADDER") && !eventToEdit
|
||||
? await eventWithTournament("copyEventId")
|
||||
: undefined;
|
||||
|
||||
const eventToCopy = eventToCopyRaw
|
||||
? {
|
||||
...eventToCopyRaw,
|
||||
badgePrizes: eventToCopyRaw.badgePrizes?.filter((badge) =>
|
||||
managedBadges.some((mb) => mb.id === badge.id),
|
||||
),
|
||||
}
|
||||
: undefined;
|
||||
|
||||
return {
|
||||
isAddingTournament: Boolean(
|
||||
url.searchParams.has("tournament") ||
|
||||
url.searchParams.has("copyEventId") ||
|
||||
eventToEdit?.tournament,
|
||||
),
|
||||
managedBadges: await BadgeRepository.findManagedByUserId(user.id),
|
||||
managedBadges,
|
||||
eventToEdit: canEditEvent ? eventToEdit : undefined,
|
||||
eventToCopy:
|
||||
user.roles.includes("TOURNAMENT_ADDER") && !eventToEdit
|
||||
? await eventWithTournament("copyEventId")
|
||||
: undefined,
|
||||
eventToCopy,
|
||||
recentTournaments:
|
||||
user.roles.includes("TOURNAMENT_ADDER") && !eventToEdit
|
||||
? await CalendarRepository.findRecentTournamentsByAuthorId(user.id)
|
||||
|
||||
Reference in New Issue
Block a user