2016-09-04 02:46:08 +02:00
|
|
|
<?php
|
|
|
|
use Respect\Validation\Validator as DataValidator;
|
|
|
|
DataValidator::with('CustomValidations', true);
|
2017-04-17 04:59:11 +02:00
|
|
|
/**
|
2017-05-12 06:58:40 +02:00
|
|
|
* @api {post} /ticket/get Get ticket
|
|
|
|
* @apiVersion 4.0.0
|
2017-04-17 04:59:11 +02:00
|
|
|
*
|
2017-05-12 06:58:40 +02:00
|
|
|
* @apiName Get ticket
|
2017-04-17 04:59:11 +02:00
|
|
|
*
|
|
|
|
* @apiGroup Ticket
|
|
|
|
*
|
2017-04-21 08:09:24 +02:00
|
|
|
* @apiDescription This path retrieves information about a ticket.
|
2017-04-17 04:59:11 +02:00
|
|
|
*
|
2017-05-12 06:58:40 +02:00
|
|
|
* @apiPermission user
|
2017-04-17 04:59:11 +02:00
|
|
|
*
|
2017-04-21 08:09:24 +02:00
|
|
|
* @apiParam {Number} ticketNumber The number of the ticket.
|
2017-04-17 04:59:11 +02:00
|
|
|
*
|
2017-04-20 05:55:38 +02:00
|
|
|
* @apiUse INVALID_TICKET
|
2017-04-21 08:09:24 +02:00
|
|
|
* @apiUse NO_PERMISSION
|
|
|
|
*
|
2017-04-20 07:23:30 +02:00
|
|
|
* @apiSuccess {[Ticket](#api-Data_Structures-ObjectTicket)} data Information about the requested ticket.
|
2017-04-21 08:09:24 +02:00
|
|
|
*
|
2017-04-17 04:59:11 +02:00
|
|
|
*/
|
|
|
|
|
2017-04-20 05:55:38 +02:00
|
|
|
|
2016-09-04 02:46:08 +02:00
|
|
|
class TicketGetController extends Controller {
|
|
|
|
const PATH = '/get';
|
2017-02-08 19:09:15 +01:00
|
|
|
const METHOD = 'POST';
|
2016-09-04 02:46:08 +02:00
|
|
|
|
2016-11-21 03:01:38 +01:00
|
|
|
private $ticket;
|
|
|
|
|
2016-09-04 02:46:08 +02:00
|
|
|
public function validations() {
|
2017-03-04 01:39:59 +01:00
|
|
|
$session = Session::getInstance();
|
|
|
|
|
|
|
|
if (Controller::isUserSystemEnabled() || Controller::isStaffLogged()) {
|
|
|
|
return [
|
|
|
|
'permission' => 'user',
|
|
|
|
'requestData' => [
|
|
|
|
'ticketNumber' => [
|
|
|
|
'validation' => DataValidator::validTicketNumber(),
|
|
|
|
'error' => ERRORS::INVALID_TICKET
|
|
|
|
]
|
2016-09-04 02:46:08 +02:00
|
|
|
]
|
2017-03-04 01:39:59 +01:00
|
|
|
];
|
|
|
|
} else {
|
|
|
|
return [
|
|
|
|
'permission' => 'any',
|
|
|
|
'requestData' => [
|
|
|
|
'ticketNumber' => [
|
|
|
|
'validation' => DataValidator::equals($session->getTicketNumber()),
|
|
|
|
'error' => ERRORS::INVALID_TICKET
|
|
|
|
],
|
|
|
|
'csrf_token' => [
|
|
|
|
'validation' => DataValidator::equals($session->getToken()),
|
|
|
|
'error' => $session->getToken() . ' != ' . Controller::request('csrf_token')
|
|
|
|
]
|
|
|
|
]
|
|
|
|
];
|
2017-01-16 20:07:53 +01:00
|
|
|
}
|
2016-09-04 02:46:08 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
public function handler() {
|
2016-11-21 03:01:38 +01:00
|
|
|
$this->ticket = Ticket::getByTicketNumber(Controller::request('ticketNumber'));
|
2016-09-04 02:46:08 +02:00
|
|
|
|
2017-03-04 01:39:59 +01:00
|
|
|
if(Controller::isUserSystemEnabled() || Controller::isStaffLogged()) {
|
|
|
|
if ($this->shouldDenyPermission()) {
|
2017-01-16 20:07:53 +01:00
|
|
|
throw new Exception(ERRORS::NO_PERMISSION);
|
2017-03-04 01:39:59 +01:00
|
|
|
} else {
|
|
|
|
Response::respondSuccess($this->ticket->toArray());
|
2017-01-16 20:07:53 +01:00
|
|
|
}
|
2016-09-09 05:38:58 +02:00
|
|
|
} else {
|
2016-11-21 03:01:38 +01:00
|
|
|
Response::respondSuccess($this->ticket->toArray());
|
2016-09-09 05:38:58 +02:00
|
|
|
}
|
2016-09-04 02:46:08 +02:00
|
|
|
}
|
2016-11-21 03:01:38 +01:00
|
|
|
|
|
|
|
private function shouldDenyPermission() {
|
|
|
|
$user = Controller::getLoggedUser();
|
|
|
|
|
2017-01-16 20:07:53 +01:00
|
|
|
return (!Controller::isStaffLogged() && (Controller::isUserSystemEnabled() && $this->ticket->author->id !== $user->id)) ||
|
2017-02-25 07:42:10 +01:00
|
|
|
(Controller::isStaffLogged() && (($this->ticket->owner && $this->ticket->owner->id !== $user->id) || !$user->sharedDepartmentList->includesId($this->ticket->department->id)));
|
2016-11-21 03:01:38 +01:00
|
|
|
}
|
2016-09-04 02:46:08 +02:00
|
|
|
}
|