race condition security patch
This commit is contained in:
@@ -4,6 +4,7 @@ import type { LayoutServerLoad } from './$types';
|
||||
import { env } from "$env/dynamic/private";
|
||||
import type { Settings } from '$lib/models/settings';
|
||||
import { notifications_index } from '$lib/stores/notification_store';
|
||||
import type { AuthRecord } from 'pocketbase';
|
||||
|
||||
export const load: LayoutServerLoad = async ({ locals, url, fetch }) => {
|
||||
|
||||
@@ -11,5 +12,5 @@ export const load: LayoutServerLoad = async ({ locals, url, fetch }) => {
|
||||
if (locals.user?.id) {
|
||||
notifications = await notifications_index({ recipient: locals.user.id }, 1, 10, fetch);
|
||||
}
|
||||
return { settings: locals.settings as Settings, notifications, origin: env.ORIGIN }
|
||||
return { settings: locals.settings as Settings, user: locals.user as AuthRecord, notifications, origin: env.ORIGIN }
|
||||
}
|
||||
@@ -15,11 +15,14 @@
|
||||
import "../css/app.css";
|
||||
import "../css/components.css";
|
||||
import "../css/theme.css";
|
||||
import type { LayoutData } from "./$types";
|
||||
|
||||
interface Props {
|
||||
data: LayoutData;
|
||||
children?: Snippet;
|
||||
}
|
||||
|
||||
let { children }: Props = $props();
|
||||
let { data, children }: Props = $props();
|
||||
|
||||
beforeNavigate((n) => {
|
||||
if (!$currentUser && isRouteProtected(n.to?.url?.pathname ?? "")) {
|
||||
@@ -80,7 +83,7 @@
|
||||
</div>
|
||||
{/if}
|
||||
|
||||
<NavBar></NavBar>
|
||||
<NavBar user={data.user}></NavBar>
|
||||
<PageLoadingBar class="text-content"></PageLoadingBar>
|
||||
<Toast></Toast>
|
||||
<UploadDialog></UploadDialog>
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { handleError } from "$lib/util/api_util";
|
||||
import { error, json, type RequestEvent } from "@sveltejs/kit";
|
||||
import { json, type RequestEvent } from "@sveltejs/kit";
|
||||
import { z } from "zod";
|
||||
|
||||
export async function POST(event: RequestEvent) {
|
||||
@@ -11,7 +10,7 @@ export async function POST(event: RequestEvent) {
|
||||
password: z.string().min(8).max(72),
|
||||
passwordConfirm: z.string().min(8).max(72)
|
||||
}).refine(d => d.password === d.passwordConfirm).parse(data)
|
||||
const r = await pb.collection('users').confirmPasswordReset(safeData.token, safeData.password, safeData.passwordConfirm);
|
||||
const r = await event.locals.pb.collection('users').confirmPasswordReset(safeData.token, safeData.password, safeData.passwordConfirm);
|
||||
return json(r);
|
||||
} catch (e: any) {
|
||||
throw handleError(e);
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { handleError } from "$lib/util/api_util";
|
||||
import { error, json, type RequestEvent } from "@sveltejs/kit";
|
||||
import { json, type RequestEvent } from "@sveltejs/kit";
|
||||
import { z } from "zod";
|
||||
|
||||
export async function POST(event: RequestEvent) {
|
||||
@@ -13,7 +12,7 @@ export async function POST(event: RequestEvent) {
|
||||
}).refine(d => d.email !== undefined || d.username !== undefined).parse(data);
|
||||
|
||||
|
||||
const r = await pb.collection('users').authWithPassword(safeData.email ?? safeData.username!, data.password);
|
||||
const r = await event.locals.pb.collection('users').authWithPassword(safeData.email ?? safeData.username!, data.password);
|
||||
return json(r);
|
||||
} catch (e: any) {
|
||||
throw handleError(e);
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
import { env } from "$env/dynamic/public";
|
||||
import { env as private_env } from "$env/dynamic/private";
|
||||
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { error, json, type RequestEvent } from "@sveltejs/kit";
|
||||
import { z } from "zod";
|
||||
import { handleError } from "$lib/util/api_util";
|
||||
@@ -10,7 +9,7 @@ const redirectURL = private_env.ORIGIN + "/login/redirect"
|
||||
|
||||
export async function GET(event: RequestEvent) {
|
||||
try {
|
||||
const r = await pb.collection('users').listAuthMethods();
|
||||
const r = await event.locals.pb.collection('users').listAuthMethods();
|
||||
|
||||
for (const provider of r.oauth2.providers) {
|
||||
const imageURL = `${env.PUBLIC_POCKETBASE_URL}/_/images/oauth2/${provider.name}.svg`
|
||||
@@ -33,7 +32,7 @@ export async function POST(event: RequestEvent) {
|
||||
codeVerifier: z.string()
|
||||
}).parse(data)
|
||||
|
||||
const r = await pb.collection('users').authWithOAuth2Code(
|
||||
const r = await event.locals.pb.collection('users').authWithOAuth2Code(
|
||||
safeData.name,
|
||||
safeData.code,
|
||||
safeData.codeVerifier,
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { handleError } from "$lib/util/api_util";
|
||||
import { error, json, type RequestEvent } from "@sveltejs/kit";
|
||||
import { z } from "zod";
|
||||
@@ -10,7 +9,7 @@ export async function POST(event: RequestEvent) {
|
||||
email: z.string().email()
|
||||
}).parse(data)
|
||||
|
||||
const r = await pb.collection('users').requestPasswordReset(safeData.email);
|
||||
const r = await event.locals.pb.collection('users').requestPasswordReset(safeData.email);
|
||||
return json(r);
|
||||
} catch (e: any) {
|
||||
throw handleError(e);
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
import { CommentCreateSchema } from '$lib/models/api/comment_schema';
|
||||
import type { Comment } from '$lib/models/comment';
|
||||
import { pb } from '$lib/pocketbase';
|
||||
import { Collection, create, handleError, list } from '$lib/util/api_util';
|
||||
import { json, type RequestEvent } from '@sveltejs/kit';
|
||||
|
||||
@@ -10,7 +9,7 @@ export async function GET(event: RequestEvent) {
|
||||
for (const comment of r.items) {
|
||||
if (!comment.expand?.author) {
|
||||
comment.expand = {
|
||||
author: await pb.collection('users_anonymous').getOne(comment.author)
|
||||
author: await event.locals.pb.collection('users_anonymous').getOne(comment.author)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
import { CommentUpdateSchema } from "$lib/models/api/comment_schema";
|
||||
import type { Comment } from "$lib/models/comment";
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { Collection, handleError, remove, show, update } from "$lib/util/api_util";
|
||||
import { json, type RequestEvent } from "@sveltejs/kit";
|
||||
|
||||
@@ -10,7 +9,7 @@ export async function GET(event: RequestEvent) {
|
||||
if (!r.expand) {
|
||||
r.expand = {} as any
|
||||
}
|
||||
r.expand!.author = await pb.collection('users_anonymous').getOne(r.author)
|
||||
r.expand!.author = await event.locals.pb.collection('users_anonymous').getOne(r.author)
|
||||
|
||||
return json(r)
|
||||
} catch (e: any) {
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { error, type RequestEvent } from "@sveltejs/kit";
|
||||
import { z } from "zod";
|
||||
|
||||
@@ -21,7 +20,7 @@ export async function GET(event: RequestEvent) {
|
||||
parts.push(encodeURIComponent(safeParams.data.record));
|
||||
parts.push(encodeURIComponent(safeParams.data.file));
|
||||
|
||||
let fileURL = pb.buildURL(parts.join("/"));
|
||||
let fileURL = event.locals.pb.buildURL(parts.join("/"));
|
||||
|
||||
try {
|
||||
const r = await event.fetch(fileURL)
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
import { FollowCreateSchema } from '$lib/models/api/follow_schema';
|
||||
import type { Follow } from '$lib/models/follow';
|
||||
import type { UserAnonymous } from '$lib/models/user';
|
||||
import { pb } from '$lib/pocketbase';
|
||||
import { Collection, create, handleError, list } from '$lib/util/api_util';
|
||||
import { json, type RequestEvent } from '@sveltejs/kit';
|
||||
|
||||
@@ -9,8 +8,8 @@ export async function GET(event: RequestEvent) {
|
||||
try {
|
||||
const r = await list<Follow>(event, Collection.follows);
|
||||
for (const follow of r.items) {
|
||||
const follower = await pb.collection('users_anonymous').getOne<UserAnonymous>(follow.follower, { requestKey: null })
|
||||
const followee = await pb.collection('users_anonymous').getOne<UserAnonymous>(follow.followee, { requestKey: null })
|
||||
const follower = await event.locals.pb.collection('users_anonymous').getOne<UserAnonymous>(follow.follower, { requestKey: null })
|
||||
const followee = await event.locals.pb.collection('users_anonymous').getOne<UserAnonymous>(follow.followee, { requestKey: null })
|
||||
follow.expand = {
|
||||
follower, followee
|
||||
}
|
||||
|
||||
@@ -1,10 +1,9 @@
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { handleError } from "$lib/util/api_util";
|
||||
import { json } from "@sveltejs/kit";
|
||||
import { json, type RequestEvent } from "@sveltejs/kit";
|
||||
|
||||
export async function GET() {
|
||||
export async function GET(event: RequestEvent) {
|
||||
try {
|
||||
const r = await pb.send("/integration/komoot/login", {
|
||||
const r = await event.locals.pb.send("/integration/komoot/login", {
|
||||
method: "GET",
|
||||
});
|
||||
return json(r);
|
||||
|
||||
@@ -1,16 +1,15 @@
|
||||
import { ListShareCreateSchema } from '$lib/models/api/list_share_schema';
|
||||
import type { ListShare } from '$lib/models/list_share';
|
||||
import type { User } from '$lib/models/user';
|
||||
import { pb } from '$lib/pocketbase';
|
||||
import { Collection, create, handleError, list } from '$lib/util/api_util';
|
||||
import { error, json, type RequestEvent } from '@sveltejs/kit';
|
||||
import { json, type RequestEvent } from '@sveltejs/kit';
|
||||
|
||||
export async function GET(event: RequestEvent) {
|
||||
try {
|
||||
const r = await list<ListShare>(event, Collection.list_share);
|
||||
|
||||
for (const share of r.items) {
|
||||
const anonymous_user = await pb.collection('users_anonymous').getOne<User>(share.user)
|
||||
const anonymous_user = await event.locals.pb.collection('users_anonymous').getOne<User>(share.user)
|
||||
share.expand = {
|
||||
user: anonymous_user
|
||||
}
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
import { ListCreateSchema } from '$lib/models/api/list_schema';
|
||||
import type { List } from '$lib/models/list';
|
||||
import { pb } from '$lib/pocketbase';
|
||||
import { Collection, create, handleError, list } from '$lib/util/api_util';
|
||||
import { json, type RequestEvent } from '@sveltejs/kit';
|
||||
|
||||
@@ -8,13 +7,13 @@ export async function GET(event: RequestEvent) {
|
||||
try {
|
||||
const r = await list<List>(event, Collection.lists);
|
||||
for (const t of r.items) {
|
||||
if (!t.author || !pb.authStore.record) {
|
||||
if (!t.author || !event.locals.pb.authStore.record) {
|
||||
continue;
|
||||
}
|
||||
if (!t.expand) {
|
||||
t.expand = {}
|
||||
}
|
||||
t.expand!.author = await pb.collection("users_anonymous").getOne(t.author);
|
||||
t.expand!.author = await event.locals.pb.collection("users_anonymous").getOne(t.author);
|
||||
}
|
||||
return json(r)
|
||||
} catch (e) {
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
import { ListUpdateSchema } from "$lib/models/api/list_schema";
|
||||
import type { List } from "$lib/models/list";
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { Collection, handleError, remove, show, update } from "$lib/util/api_util";
|
||||
import { json, type RequestEvent } from "@sveltejs/kit";
|
||||
|
||||
@@ -10,7 +9,7 @@ export async function GET(event: RequestEvent) {
|
||||
if (!r.expand) {
|
||||
r.expand = {} as any
|
||||
}
|
||||
r.expand!.author = await pb.collection('users_anonymous').getOne(r.author!)
|
||||
r.expand!.author = await event.locals.pb.collection('users_anonymous').getOne(r.author!)
|
||||
|
||||
return json(r)
|
||||
} catch (e: any) {
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { Collection, handleError, upload } from "$lib/util/api_util";
|
||||
import { json, type RequestEvent } from "@sveltejs/kit";
|
||||
import type { List } from "postcss/lib/list";
|
||||
|
||||
@@ -1,16 +1,15 @@
|
||||
import type { Notification } from '$lib/models/notification';
|
||||
import type { UserAnonymous } from '$lib/models/user';
|
||||
import { pb } from '$lib/pocketbase';
|
||||
import { Collection, handleError, list } from '$lib/util/api_util';
|
||||
import { error, json, type RequestEvent } from '@sveltejs/kit';
|
||||
import { json, type RequestEvent } from '@sveltejs/kit';
|
||||
|
||||
export async function GET(event: RequestEvent) {
|
||||
try {
|
||||
const r = await list<Notification>(event, Collection.notifications);
|
||||
|
||||
for (const notification of r.items) {
|
||||
const recipient = await pb.collection('users_anonymous').getOne<UserAnonymous>(notification.recipient, { requestKey: null })
|
||||
const author = await pb.collection('users_anonymous').getOne<UserAnonymous>(notification.author, { requestKey: null })
|
||||
const recipient = await event.locals.pb.collection('users_anonymous').getOne<UserAnonymous>(notification.recipient, { requestKey: null })
|
||||
const author = await event.locals.pb.collection('users_anonymous').getOne<UserAnonymous>(notification.author, { requestKey: null })
|
||||
notification.expand = {
|
||||
recipient, author
|
||||
}
|
||||
|
||||
@@ -1,8 +1,7 @@
|
||||
import { SettingsCreateSchema } from '$lib/models/api/settings_schema';
|
||||
import type { Settings } from "$lib/models/settings";
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { Collection, handleError, remove, show, update } from "$lib/util/api_util";
|
||||
import { error, json, type RequestEvent } from "@sveltejs/kit";
|
||||
import { json, type RequestEvent } from "@sveltejs/kit";
|
||||
|
||||
|
||||
export async function GET(event: RequestEvent) {
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
import { SummitLogUpdateSchema } from "$lib/models/api/summit_log_schema";
|
||||
import type { SummitLog } from "$lib/models/summit_log";
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { Collection, handleError, remove, show, update } from "$lib/util/api_util";
|
||||
import { error, json, type RequestEvent } from "@sveltejs/kit";
|
||||
|
||||
@@ -12,7 +11,7 @@ export async function GET(event: RequestEvent) {
|
||||
if (!r.expand) {
|
||||
r.expand = {} as any
|
||||
}
|
||||
r.expand!.author = await pb.collection("users_anonymous").getOne(r.author!);
|
||||
r.expand!.author = await event.locals.pb.collection("users_anonymous").getOne(r.author!);
|
||||
|
||||
return json(r)
|
||||
} catch (e: any) {
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
import { TrailShareCreateSchema } from '$lib/models/api/trail_share_schema';
|
||||
import type { TrailShare } from '$lib/models/trail_share';
|
||||
import type { UserAnonymous } from '$lib/models/user';
|
||||
import { pb } from '$lib/pocketbase';
|
||||
import { Collection, handleError, list, create } from '$lib/util/api_util';
|
||||
import { json, type RequestEvent } from '@sveltejs/kit';
|
||||
|
||||
@@ -9,7 +8,7 @@ export async function GET(event: RequestEvent) {
|
||||
try {
|
||||
const r = await list<TrailShare>(event, Collection.trail_share);
|
||||
for (const share of r.items) {
|
||||
const anonymous_user = await pb.collection('users_anonymous').getOne<UserAnonymous>(share.user)
|
||||
const anonymous_user = await event.locals.pb.collection('users_anonymous').getOne<UserAnonymous>(share.user)
|
||||
share.expand = {
|
||||
user: anonymous_user
|
||||
}
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
import { TrailCreateSchema } from '$lib/models/api/trail_schema';
|
||||
import type { Trail } from '$lib/models/trail';
|
||||
import { pb } from '$lib/pocketbase';
|
||||
import { Collection, create, handleError, list } from '$lib/util/api_util';
|
||||
import { json, type RequestEvent } from '@sveltejs/kit';
|
||||
|
||||
@@ -9,14 +8,13 @@ export async function GET(event: RequestEvent) {
|
||||
const r = await list<Trail>(event, Collection.trails);
|
||||
|
||||
for (const t of r.items) {
|
||||
if (!t.author || !pb.authStore.record) {
|
||||
if (!t.author || !event.locals.pb.authStore.record) {
|
||||
continue;
|
||||
}
|
||||
if (!t.expand) {
|
||||
t.expand = {} as any
|
||||
}
|
||||
|
||||
// t.expand!.author = await pb.collection("users_anonymous").getOne(t.author);
|
||||
t.expand?.waypoints?.sort((a, b) => (a.distance_from_start ?? 0) - (b.distance_from_start ?? 0))
|
||||
}
|
||||
return json(r)
|
||||
|
||||
@@ -1,22 +1,22 @@
|
||||
import type { Trail } from "$lib/models/trail";
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { Collection, handleError, remove, show, update } from "$lib/util/api_util";
|
||||
import { error, json, type RequestEvent } from "@sveltejs/kit";
|
||||
import { TrailUpdateSchema } from '$lib/models/api/trail_schema';
|
||||
import type PocketBase from "pocketbase";
|
||||
|
||||
export async function GET(event: RequestEvent) {
|
||||
try {
|
||||
const r = await show<Trail>(event, Collection.trails)
|
||||
|
||||
if (pb.authStore.record) {
|
||||
if (event.locals.pb.authStore.record) {
|
||||
if (!r.expand) {
|
||||
r.expand = {} as any
|
||||
}
|
||||
r.expand!.author = await pb.collection("users_anonymous").getOne(r.author!);
|
||||
r.expand!.author = await event.locals.pb.collection("users_anonymous").getOne(r.author!);
|
||||
}
|
||||
|
||||
// remove time from dates
|
||||
await enrichRecord(r);
|
||||
await enrichRecord(event.locals.pb, r);
|
||||
|
||||
// sort waypoints by distance
|
||||
r.expand?.waypoints?.sort((a, b) => (a.distance_from_start ?? 0) - (b.distance_from_start ?? 0))
|
||||
@@ -29,7 +29,7 @@ export async function GET(event: RequestEvent) {
|
||||
export async function POST(event: RequestEvent) {
|
||||
try {
|
||||
const r = await update<Trail>(event, TrailUpdateSchema, Collection.trails)
|
||||
await enrichRecord(r)
|
||||
await enrichRecord(event.locals.pb, r)
|
||||
return json(r);
|
||||
} catch (e: any) {
|
||||
throw handleError(e)
|
||||
@@ -47,7 +47,7 @@ export async function DELETE(event: RequestEvent) {
|
||||
|
||||
|
||||
|
||||
async function enrichRecord(r: Trail) {
|
||||
async function enrichRecord(pb: PocketBase, r: Trail) {
|
||||
r.date = r.date?.substring(0, 10) ?? "";
|
||||
for (const log of r.expand?.summit_logs ?? []) {
|
||||
log.date = log.date.substring(0, 10);
|
||||
|
||||
@@ -1,10 +1,9 @@
|
||||
import { type TrailBoundingBox, type TrailFilterValues } from '$lib/models/trail';
|
||||
import { pb } from '$lib/pocketbase';
|
||||
import { handleError } from '$lib/util/api_util';
|
||||
import { error, json, type RequestEvent } from '@sveltejs/kit';
|
||||
|
||||
export async function GET(event: RequestEvent) {
|
||||
if (!pb.authStore.record) {
|
||||
if (!event.locals.pb.authStore.record) {
|
||||
return json({
|
||||
max_lat: 0,
|
||||
min_lat: 0,
|
||||
@@ -13,7 +12,7 @@ export async function GET(event: RequestEvent) {
|
||||
});
|
||||
}
|
||||
try {
|
||||
const r = await pb.collection('trails_bounding_box').getOne<TrailBoundingBox>(pb.authStore.record!.id)
|
||||
const r = await event.locals.pb.collection('trails_bounding_box').getOne<TrailBoundingBox>(event.locals.pb.authStore.record!.id)
|
||||
return json(r)
|
||||
} catch (e: any) {
|
||||
throw handleError(e);
|
||||
|
||||
@@ -1,10 +1,9 @@
|
||||
import { type TrailFilterValues } from '$lib/models/trail';
|
||||
import { pb } from '$lib/pocketbase';
|
||||
import { handleError } from '$lib/util/api_util';
|
||||
import { error, json, type RequestEvent } from '@sveltejs/kit';
|
||||
import { json, type RequestEvent } from '@sveltejs/kit';
|
||||
|
||||
export async function GET(event: RequestEvent) {
|
||||
if (!pb.authStore.record) {
|
||||
if (!event.locals.pb.authStore.record) {
|
||||
return json({
|
||||
min_distance: 0,
|
||||
max_distance: 20000,
|
||||
@@ -15,7 +14,7 @@ export async function GET(event: RequestEvent) {
|
||||
});
|
||||
}
|
||||
try {
|
||||
const r = await pb.collection('trails_filter').getOne<TrailFilterValues>(pb.authStore.record!.id)
|
||||
const r = await event.locals.pb.collection('trails_filter').getOne<TrailFilterValues>(event.locals.pb.authStore.record!.id)
|
||||
return json(r)
|
||||
} catch (e: any) {
|
||||
throw handleError(e);
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
import { TrailRecommendSchema } from '$lib/models/api/trail_schema';
|
||||
import type { Trail } from '$lib/models/trail';
|
||||
import { pb } from '$lib/pocketbase';
|
||||
import { handleError } from '$lib/util/api_util';
|
||||
import { json, type RequestEvent } from '@sveltejs/kit';
|
||||
|
||||
@@ -9,7 +8,7 @@ export async function GET(event: RequestEvent) {
|
||||
const searchParams = Object.fromEntries(event.url.searchParams);
|
||||
const safeSearchParams = TrailRecommendSchema.parse(searchParams);
|
||||
|
||||
const r = await pb.send("/trail/recommend?" + new URLSearchParams({
|
||||
const r = await event.locals.pb.send("/trail/recommend?" + new URLSearchParams({
|
||||
size: safeSearchParams.size?.toString() ?? ""
|
||||
}), {
|
||||
method: "GET",
|
||||
@@ -18,13 +17,13 @@ export async function GET(event: RequestEvent) {
|
||||
const result: Trail[] = r;
|
||||
|
||||
for (const t of result) {
|
||||
if (!t.author || !pb.authStore.record) {
|
||||
if (!t.author || !event.locals.pb.authStore.record) {
|
||||
continue;
|
||||
}
|
||||
if (!t.expand) {
|
||||
t.expand = {} as any
|
||||
}
|
||||
t.expand!.author = await pb.collection("users_anonymous").getOne(t.author);
|
||||
t.expand!.author = await event.locals.pb.collection("users_anonymous").getOne(t.author);
|
||||
}
|
||||
|
||||
return json(result)
|
||||
|
||||
@@ -1,13 +1,12 @@
|
||||
import GPX from "$lib/models/gpx/gpx";
|
||||
import { haversineDistance } from "$lib/models/gpx/utils";
|
||||
import { SummitLog } from "$lib/models/summit_log";
|
||||
import type { Trail } from "$lib/models/trail";
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { fetchGPX, trails_create } from "$lib/stores/trail_store";
|
||||
import { trails_create } from "$lib/stores/trail_store";
|
||||
import { handleError } from "$lib/util/api_util";
|
||||
import { fromFile, gpx2trail } from "$lib/util/gpx_util";
|
||||
import { json, type RequestEvent } from "@sveltejs/kit";
|
||||
import { ClientResponseError } from "pocketbase";
|
||||
import type PocketBase from 'pocketbase';
|
||||
|
||||
export async function PUT(event: RequestEvent) {
|
||||
try {
|
||||
@@ -31,7 +30,7 @@ export async function PUT(event: RequestEvent) {
|
||||
if (!ignoreDuplicates) {
|
||||
let duplicate: Trail | null = null;
|
||||
try {
|
||||
duplicate = await findDuplicate(trail)
|
||||
duplicate = await findDuplicate(event.locals.pb, trail)
|
||||
} catch (e: any) {
|
||||
throw new ClientResponseError({ status: 500, response: { message: "Error checking for duplicates" } })
|
||||
}
|
||||
@@ -66,7 +65,7 @@ export async function PUT(event: RequestEvent) {
|
||||
}
|
||||
}
|
||||
|
||||
async function findDuplicate(t1: Trail) {
|
||||
async function findDuplicate(pb: PocketBase, t1: Trail) {
|
||||
const trails: Trail[] = await pb.collection('trails').getFullList({ requestKey: null });
|
||||
|
||||
const distanceThreshold = 100;
|
||||
|
||||
@@ -1,8 +1,7 @@
|
||||
import { env } from '$env/dynamic/public';
|
||||
import { UserCreateSchema } from '$lib/models/api/user_schema';
|
||||
import type { User } from '$lib/models/user';
|
||||
import { pb } from '$lib/pocketbase';
|
||||
import { Collection, create, handleError } from '$lib/util/api_util';
|
||||
import { Collection, handleError } from '$lib/util/api_util';
|
||||
import { json, type RequestEvent } from '@sveltejs/kit';
|
||||
import { ClientResponseError } from 'pocketbase';
|
||||
|
||||
@@ -16,9 +15,9 @@ export async function PUT(event: RequestEvent) {
|
||||
const data = await event.request.json();
|
||||
const safeData = UserCreateSchema.parse(data);
|
||||
|
||||
const r = await pb.collection(Collection.users).create<User>(safeData)
|
||||
const r = await event.locals.pb.collection(Collection.users).create<User>(safeData)
|
||||
|
||||
await pb.collection('users').requestVerification(safeData.email);
|
||||
await event.locals.pb.collection('users').requestVerification(safeData.email);
|
||||
|
||||
return json(r);
|
||||
} catch (e: any) {
|
||||
|
||||
@@ -1,9 +1,8 @@
|
||||
import { RecordIdSchema } from '$lib/models/api/base_schema';
|
||||
import { UserUpdateSchema } from '$lib/models/api/user_schema';
|
||||
import type { User } from '$lib/models/user';
|
||||
import { pb } from '$lib/pocketbase';
|
||||
import { Collection, handleError, remove, show } from '$lib/util/api_util';
|
||||
import { error, json, type RequestEvent } from '@sveltejs/kit'
|
||||
import { json, type RequestEvent } from '@sveltejs/kit';
|
||||
|
||||
export async function GET(event: RequestEvent) {
|
||||
try {
|
||||
@@ -23,13 +22,13 @@ export async function POST(event: RequestEvent) {
|
||||
|
||||
const safeData = UserUpdateSchema.parse(data);
|
||||
|
||||
if (safeData.email && safeData.email != pb.authStore.record!.email) {
|
||||
const r = await pb.collection('users').requestEmailChange(safeData.email);
|
||||
pb.authStore.record!.email = safeData.email;
|
||||
if (safeData.email && safeData.email != event.locals.pb.authStore.record!.email) {
|
||||
const r = await event.locals.pb.collection('users').requestEmailChange(safeData.email);
|
||||
event.locals.pb.authStore.record!.email = safeData.email;
|
||||
}
|
||||
const r = await pb.collection('users').update<User>(safeParams.id, safeData)
|
||||
const r = await event.locals.pb.collection('users').update<User>(safeParams.id, safeData)
|
||||
if (safeData.password) {
|
||||
const r = await pb.collection('users').authWithPassword(safeData.email ?? safeData.username!, safeData.password);
|
||||
const r = await event.locals.pb.collection('users').authWithPassword(safeData.email ?? safeData.username!, safeData.password);
|
||||
return json(r.record)
|
||||
} else {
|
||||
return json(r);
|
||||
|
||||
@@ -1,5 +1,4 @@
|
||||
import type { UserAnonymous } from '$lib/models/user';
|
||||
import { pb } from '$lib/pocketbase';
|
||||
import { Collection, handleError, list } from '$lib/util/api_util';
|
||||
import { json, type RequestEvent } from '@sveltejs/kit';
|
||||
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { Collection } from "$lib/util/api_util";
|
||||
import { error, type ServerLoad } from "@sveltejs/kit";
|
||||
import { ClientResponseError } from "pocketbase";
|
||||
@@ -9,7 +8,7 @@ export const load: ServerLoad = async ({ params, locals, url, fetch }) => {
|
||||
}
|
||||
|
||||
try {
|
||||
await pb.collection(Collection.users).confirmVerification(params.token)
|
||||
await locals.pb.collection(Collection.users).confirmVerification(params.token)
|
||||
} catch (e) {
|
||||
if (e instanceof ClientResponseError) {
|
||||
error(400, e.message);
|
||||
|
||||
@@ -5,11 +5,9 @@
|
||||
import StravaSettingsModal from "$lib/components/settings/integrations/strava_settings_modal.svelte";
|
||||
import {
|
||||
Integration,
|
||||
type BaseIntegration,
|
||||
type KomootIntegration,
|
||||
type StravaIntegration,
|
||||
type StravaIntegration
|
||||
} from "$lib/models/integration.js";
|
||||
import { pb } from "$lib/pocketbase.js";
|
||||
import {
|
||||
integrations_create,
|
||||
integrations_update,
|
||||
|
||||
@@ -1,9 +1,7 @@
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { integrations_index, integrations_update } from "$lib/stores/integration_store";
|
||||
import { error, redirect, type RequestEvent, type ServerLoad } from "@sveltejs/kit";
|
||||
import { error, redirect, type ServerLoad } from "@sveltejs/kit";
|
||||
import { ClientResponseError } from "pocketbase";
|
||||
|
||||
export const load: ServerLoad = async ({ url, fetch }) => {
|
||||
export const load: ServerLoad = async ({ url, fetch, locals }) => {
|
||||
const oauthError = url.searchParams.get('error');
|
||||
if (oauthError) {
|
||||
// user cancelled
|
||||
@@ -22,7 +20,7 @@ export const load: ServerLoad = async ({ url, fetch }) => {
|
||||
}
|
||||
|
||||
try {
|
||||
await pb.send("/integration/strava/token", {
|
||||
await locals.pb.send("/integration/strava/token", {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({
|
||||
|
||||
@@ -1,18 +1,21 @@
|
||||
import { ExpandType } from "$lib/models/list";
|
||||
import { Trail } from "$lib/models/trail";
|
||||
import { pb } from "$lib/pocketbase";
|
||||
import { categories_index } from "$lib/stores/category_store";
|
||||
import { lists_index } from "$lib/stores/list_store";
|
||||
import { trails_show } from "$lib/stores/trail_store";
|
||||
import { currentUser } from "$lib/stores/user_store";
|
||||
import { error, type Load } from "@sveltejs/kit";
|
||||
import { get } from "svelte/store";
|
||||
|
||||
export const load: Load = async ({ params, fetch }) => {
|
||||
const user = get(currentUser)
|
||||
|
||||
if (!params.id) {
|
||||
return error(400, "Bad Request")
|
||||
}
|
||||
const categories = await categories_index(fetch)
|
||||
const lists = await lists_index({ q: "", author: pb.authStore.record?.id ?? "" }, 1, -1, fetch, ExpandType.None)
|
||||
|
||||
const lists = await lists_index({ q: "", author: user?.id ?? "" }, 1, -1, fetch, ExpandType.None)
|
||||
|
||||
let trail: Trail;
|
||||
if (params.id === "new") {
|
||||
trail = new Trail("", { category: categories[0] });
|
||||
|
||||
Reference in New Issue
Block a user