144 specification_id checks
This commit is contained in:
@@ -3,6 +3,20 @@
|
||||
В данном случае никакого смысла смотреть на все CFS параметры нет, только в рамках операции
|
||||
Но: мы не хотели бы менять положение сущности в дереве. Либо она в корне, либо она ниже. И получится, когда мы выбираем один параметр, нам ни к чему контекст - мы к нему однозначно адресуемся.
|
||||
Проголосуем за отсутстие избыточности?
|
||||
--->
|
||||
<!--- Проверять принадлежность инстанса текущему клиенту
|
||||
При выборке CFS параметров проверятся принадлежность текущей спецификации пользователя
|
||||
--->
|
||||
<!--- Все методы неявно получают
|
||||
arguments.usrId
|
||||
arguments.contragentId
|
||||
arguments.contractId
|
||||
arguments.specificationId
|
||||
|
||||
arguments.requestArguments.usrId=usrCustomerInfo.usrId; //Integer!
|
||||
arguments.requestArguments.contragentId=usrCustomerInfo.contragentId; //Integer
|
||||
arguments.requestArguments.contractId=usrCustomerInfo.contractId; //Integer
|
||||
arguments.requestArguments.specificationId=usrCustomerInfo.specificationId; //Integer
|
||||
--->
|
||||
|
||||
<cfsilent>
|
||||
@@ -176,18 +190,23 @@
|
||||
|
||||
<!--- Проверка: параметр от нашего ли сервиса *** и операции --->
|
||||
<cfquery name="local.qInstanceService" result="local.result">
|
||||
select e.service_id, io.operation
|
||||
select e.service_id, io.operation, si.specification_id
|
||||
from instance_operation io
|
||||
join instance e on (io.instance_uid=e.instance_uid)
|
||||
left outer join specification_item si on (e.specification_item_id=si.specification_item_id)
|
||||
where io.instance_operation_uid=<cfqueryparam cfsqltype="cf_sql_other" value="#arguments.instanceOperationUid#"/>
|
||||
</cfquery>
|
||||
</cfquery>
|
||||
|
||||
<cfquery name="local.qTemplateSvc" result="local.result">
|
||||
select so.svc_id, so.operation
|
||||
from svc_operation_cfs_param sop
|
||||
join svc_operation so on (sop.svc_operation_id=so.svc_operation_id)
|
||||
where sop.svc_operation_cfs_param_id=<cfqueryparam cfsqltype="cf_sql_integer" value="#arguments.svcOperationCfsParamId#"/>
|
||||
</cfquery>
|
||||
<cfif local.qInstanceService.service_id NEQ local.qTemplateSvc.svc_id>
|
||||
<cfif local.qInstanceService.specification_id NEQ arguments.specificationId>
|
||||
<cfreturn representationOf(this.helper.formatMessage("Instance not accessible", "Instance does not belong to the current specification, contract or contragent")).withStatus(403)/>
|
||||
</cfif>
|
||||
<cfif local.qInstanceService.service_id NEQ local.qTemplateSvc.svc_id>
|
||||
<cfreturn representationOf(this.helper.formatMessage("Invalid CFS parameter", "Parameter specified does not belong to this service")).withStatus(400)/>
|
||||
</cfif>
|
||||
<cfif local.qInstanceService.operation NEQ local.qTemplateSvc.operation>
|
||||
@@ -252,7 +271,7 @@
|
||||
<cfif local.qSvcOperationCfsParam.is_required GT 0 AND len(arguments.paramValue) EQ 0>
|
||||
<cfthrow type="invalidParamValue" message="Missing required parameter (#local.qSvcOperationCfsParam.svc_operation_cfs_param#)"/>
|
||||
<cfelseif len(arguments.paramValue) AND NOT validateDataType(arguments.paramValue,local.qSvcOperationCfsParam.data_type)>
|
||||
<cfthrow type="invalidParamValue" message="Invalid format (#local.qSvcOperationCfsParam.svc_operation_cfs_param#)"/>
|
||||
<cfthrow type="invalidParamValue" message="Invalid format (#local.qSvcOperationCfsParam.svc_operation_cfs_param#)"/>
|
||||
</cfif>
|
||||
|
||||
<cfif len(arguments.paramValue) AND listLen(local.qSvcOperationCfsParam.value_list) GT 0 AND NOT listFind(local.qSvcOperationCfsParam.value_list, arguments.paramValue)>
|
||||
|
||||
Reference in New Issue
Block a user