This PR moves the entire project to Typescript. Due to the ~1000 ignores this will lead to a messy codebase for a while, but the churn is worth it – all of those ignore comments are places that were never type-safe previously. closes #1282
25 lines
768 B
TypeScript
25 lines
768 B
TypeScript
import { Attachment, User, Team } from "@server/models";
|
|
import policy from "./policy";
|
|
|
|
const { allow } = policy;
|
|
|
|
allow(User, "createAttachment", Team, (user, team) => {
|
|
if (!team || user.isViewer || user.teamId !== team.id) return false;
|
|
return true;
|
|
});
|
|
|
|
allow(User, "read", Attachment, (actor, attachment) => {
|
|
if (!attachment || attachment.teamId !== actor.teamId) return false;
|
|
if (actor.isAdmin) return true;
|
|
if (actor.id === attachment.userId) return true;
|
|
return false;
|
|
});
|
|
|
|
allow(User, "delete", Attachment, (actor, attachment) => {
|
|
if (actor.isViewer) return false;
|
|
if (!attachment || attachment.teamId !== actor.teamId) return false;
|
|
if (actor.isAdmin) return true;
|
|
if (actor.id === attachment.userId) return true;
|
|
return false;
|
|
});
|