Merge pull request #2 from DieLustigenTierwesen/copilot/sub-pr-1
Add client-side ownership enforcement to CollectionService update/delete
This commit is contained in:
commit
9f9a0cb601
1 changed files with 30 additions and 0 deletions
|
|
@ -170,6 +170,21 @@ class CollectionService {
|
|||
required String name,
|
||||
String? description,
|
||||
}) async {
|
||||
final userId = supabase.auth.currentUser!.id;
|
||||
|
||||
final collection = await supabase
|
||||
.from('collections')
|
||||
.select('owner_id')
|
||||
.eq('id', collectionId)
|
||||
.maybeSingle();
|
||||
|
||||
if (collection == null) {
|
||||
throw Exception('Collection not found.');
|
||||
}
|
||||
if (collection['owner_id'] != userId) {
|
||||
throw Exception('Only the collection owner can perform this action.');
|
||||
}
|
||||
|
||||
await supabase.from('collections').update({
|
||||
'name': name,
|
||||
if (description != null && description.isNotEmpty)
|
||||
|
|
@ -179,6 +194,21 @@ class CollectionService {
|
|||
|
||||
/// Delete a collection. Owner only. Cascade deletes members & items.
|
||||
static Future<void> delete(String collectionId) async {
|
||||
final userId = supabase.auth.currentUser!.id;
|
||||
|
||||
final collection = await supabase
|
||||
.from('collections')
|
||||
.select('owner_id')
|
||||
.eq('id', collectionId)
|
||||
.maybeSingle();
|
||||
|
||||
if (collection == null) {
|
||||
throw Exception('Collection not found.');
|
||||
}
|
||||
if (collection['owner_id'] != userId) {
|
||||
throw Exception('Only the collection owner can perform this action.');
|
||||
}
|
||||
|
||||
await supabase.from('collections').delete().eq('id', collectionId);
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue