mirror of
https://github.com/dadosfera/maestro.git
synced 2026-10-03 22:49:07 +00:00
Compare commits
8
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
76485f929d | ||
|
|
1f9d0c29ec | ||
|
|
31f8c2c1a6 | ||
|
|
adeb022818 | ||
|
|
f61c241dde | ||
|
|
e326cab44d | ||
|
|
3f8dc5cabe | ||
|
|
e7f410831f |
@@ -630,21 +630,39 @@ export class PlatformApiController {
|
|||||||
@ApiOperation({ summary: 'Execute a pipeline' })
|
@ApiOperation({ summary: 'Execute a pipeline' })
|
||||||
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.UPDATE)
|
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.UPDATE)
|
||||||
async executePipeline(@Body() body: any, @User() user: RequestUser) {
|
async executePipeline(@Body() body: any, @User() user: RequestUser) {
|
||||||
return this.platformApiService.proxy('POST', '/pipeline/execute', user, body);
|
// Inject customer_id (actually customer_name) into body for Platform-API
|
||||||
|
// Note: Platform-API was created before customer_id existed, so it expects customer_name in the customer_id field
|
||||||
|
const enrichedBody = {
|
||||||
|
...body,
|
||||||
|
customer_id: user.customer_name,
|
||||||
|
};
|
||||||
|
return this.platformApiService.proxy('POST', '/pipeline/execute', user, enrichedBody);
|
||||||
}
|
}
|
||||||
|
|
||||||
@Post('pipeline/pause')
|
@Post('pipeline/pause')
|
||||||
@ApiOperation({ summary: 'Pause a pipeline' })
|
@ApiOperation({ summary: 'Pause a pipeline' })
|
||||||
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.UPDATE)
|
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.UPDATE)
|
||||||
async pausePipeline(@Body() body: any, @User() user: RequestUser) {
|
async pausePipeline(@Body() body: any, @User() user: RequestUser) {
|
||||||
return this.platformApiService.proxy('POST', '/pipeline/pause', user, body);
|
// Inject customer_id (actually customer_name) into body for Platform-API
|
||||||
|
// Note: Platform-API was created before customer_id existed, so it expects customer_name in the customer_id field
|
||||||
|
const enrichedBody = {
|
||||||
|
...body,
|
||||||
|
customer_id: user.customer_name,
|
||||||
|
};
|
||||||
|
return this.platformApiService.proxy('POST', '/pipeline/pause', user, enrichedBody);
|
||||||
}
|
}
|
||||||
|
|
||||||
@Post('pipeline/unpause')
|
@Post('pipeline/unpause')
|
||||||
@ApiOperation({ summary: 'Unpause a pipeline' })
|
@ApiOperation({ summary: 'Unpause a pipeline' })
|
||||||
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.UPDATE)
|
@RequireAllPermissions(PERMISSIONS_GROUPS.PIPELINE.permissions.UPDATE)
|
||||||
async unpausePipeline(@Body() body: any, @User() user: RequestUser) {
|
async unpausePipeline(@Body() body: any, @User() user: RequestUser) {
|
||||||
return this.platformApiService.proxy('POST', '/pipeline/unpause', user, body);
|
// Inject customer_id (actually customer_name) into body for Platform-API
|
||||||
|
// Note: Platform-API was created before customer_id existed, so it expects customer_name in the customer_id field
|
||||||
|
const enrichedBody = {
|
||||||
|
...body,
|
||||||
|
customer_id: user.customer_name,
|
||||||
|
};
|
||||||
|
return this.platformApiService.proxy('POST', '/pipeline/unpause', user, enrichedBody);
|
||||||
}
|
}
|
||||||
|
|
||||||
@Put('pipeline/:pipelineId/memory')
|
@Put('pipeline/:pipelineId/memory')
|
||||||
|
|||||||
@@ -274,9 +274,17 @@ export class UsersController {
|
|||||||
@Language() language: LanguageEnum,
|
@Language() language: LanguageEnum,
|
||||||
) {
|
) {
|
||||||
|
|
||||||
if (user.user_id !== id || !user.permissions.includes(PERMISSIONS_GROUPS.USERS.permissions.ADMIN.seqid)) {
|
const isSameUser = user.user_id === id;
|
||||||
|
const isSuperAdmin = user.permissions.includes(PERMISSIONS_GROUPS.USERS.permissions.ADMIN.seqid)
|
||||||
|
if (!isSameUser && !isSuperAdmin) {
|
||||||
throw new ErrorBuilder(ErrorCodes.AUTH.FORBIDDEN);
|
throw new ErrorBuilder(ErrorCodes.AUTH.FORBIDDEN);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (isSameUser && !isSuperAdmin && body.roleNames) {
|
||||||
|
// Prevent users from updating their own roles
|
||||||
|
delete body.roleNames;
|
||||||
|
}
|
||||||
|
|
||||||
this.logger.info('updateUser', { user });
|
this.logger.info('updateUser', { user });
|
||||||
this.userService.setLanguage(language);
|
this.userService.setLanguage(language);
|
||||||
return await this.userService.updateUser(body, id, user.customer_id);
|
return await this.userService.updateUser(body, id, user.customer_id);
|
||||||
|
|||||||
Reference in New Issue
Block a user