(string appId, [FromQuery] AppRequestPurpose purpose)
| 370 | } |
| 371 | |
| 372 | [HttpPost("/api/_apps/{appId}/requests/accept")] |
| 373 | public async Task<IActionResult> AcceptAppRequest(string appId, [FromQuery] AppRequestPurpose purpose) |
| 374 | { |
| 375 | var user = this.GetCurrentUserIdentity(); |
| 376 | |
| 377 | // get the pending request |
| 378 | var request = await _db.Connection.QueryFirstOrDefaultAsync<dynamic>( |
| 379 | @"SELECT r.current_owner_id, u.email as requester_email, a.name as app_name, r.purpose |
| 380 | FROM app_requests r |
| 381 | INNER JOIN apps a ON a.id = r.app_id |
| 382 | INNER JOIN users u ON u.id = r.current_owner_id |
| 383 | WHERE r.app_id = @appId |
| 384 | AND r.target_user_email = @userEmail |
| 385 | AND r.purpose = @purpose |
| 386 | AND r.status = 'pending' |
| 387 | AND a.deleted_at IS NULL", |
| 388 | new { appId, userEmail = user.Email.ToLower(), purpose = purpose.ToString() }); |
| 389 | |
| 390 | if (request == null) |
| 391 | return NotFound("No pending app request found"); |
| 392 | |
| 393 | using (var cn = _db.Connection) { |
| 394 | cn.Open(); |
| 395 | |
| 396 | using (var transaction = cn.BeginTransaction()) |
| 397 | { |
| 398 | try |
| 399 | { |
| 400 | if (purpose == AppRequestPurpose.AppOwnership) |
| 401 | { |
| 402 | // transfer ownership |
| 403 | await cn.ExecuteAsync(@" |
| 404 | UPDATE apps SET owner_id = @newOwnerId WHERE id = @appId", |
| 405 | new { appId, newOwnerId = user.Id }, transaction); |
| 406 | |
| 407 | // add previous owner to shares |
| 408 | await cn.ExecuteAsync(@" |
| 409 | INSERT INTO app_shares (app_id, email, created_at) |
| 410 | VALUES (@appId, @email, @createdAt) |
| 411 | ON CONFLICT DO NOTHING", |
| 412 | new |
| 413 | { |
| 414 | appId, |
| 415 | email = request.requester_email, |
| 416 | createdAt = DateTime.UtcNow |
| 417 | }, transaction); |
| 418 | } |
| 419 | else if (purpose == AppRequestPurpose.AppShare) |
| 420 | { |
| 421 | // add user to shares |
| 422 | await cn.ExecuteAsync(@" |
| 423 | INSERT INTO app_shares (app_id, email, created_at) |
| 424 | VALUES (@appId, @email, @createdAt) |
| 425 | ON CONFLICT DO NOTHING", |
| 426 | new |
| 427 | { |
| 428 | appId, |
| 429 | email = user.Email.ToLower(), |
nothing calls this directly
no test coverage detected