144 specification_id checks
This commit is contained in:
@@ -28,6 +28,18 @@
|
||||
<cfif local.qCheckOperation.cnt EQ 0>
|
||||
<cfthrow type="invalidParamValue" message="Operation unsupported for this service/instance" detail="#arguments.operation#"/>
|
||||
</cfif>
|
||||
|
||||
<cfquery name="local.qCheckAccess" result="local.result">
|
||||
select count(*) as cnt
|
||||
from instance e
|
||||
join specification_item si on (e.specification_item_id=si.specification_item_id)
|
||||
where e.instance_uid=<cfqueryparam cfsqltype="cf_sql_other" value="#arguments.instanceUid#" null=#!isValid('guid',arguments.instanceUid)#/>
|
||||
AND si.specification_id=<cfqueryparam cfsqltype="cf_sql_integer" value=#arguments.specificationId#/>
|
||||
</cfquery>
|
||||
<cfif local.qCheckAccess.cnt EQ 0>
|
||||
<!--- *** вместо выбрасывания исключения мы сразу прерываем выполнение метода --->
|
||||
<cfreturn representationOf(this.helper.formatMessage("Instance not accessible", "Instance is not accessible to the current user (at least does not belong to the default specification)")).withStatus(403)/>
|
||||
</cfif>
|
||||
<!--- *** Добавить проверку разрешенных переходов, например, create нельзя сделать на развернутом экземпляре
|
||||
*** Вероятно, допустимые переходы нужно либо специфицировать в документации, либо явно опубликовать (инстанс может публиковать список допустимых операций) --->
|
||||
|
||||
@@ -70,6 +82,7 @@
|
||||
/>
|
||||
</cffunction>
|
||||
|
||||
<!--- *** NOT USED --->
|
||||
<cffunction name="checkResourceRealmId" returntype="void" hint="deprecated">
|
||||
<!--- В данном случае мы проверяем соответствие платформы сервису, а не операции, поэтому вопрос, нужен ли для данной операции параметр resourceRealm, надо решать вне этой функции --->
|
||||
<cfargument name="resourceRealmId" type="numeric" required=true/>
|
||||
|
||||
Reference in New Issue
Block a user