869 lines
21 KiB
JavaScript
869 lines
21 KiB
JavaScript
/**
|
|
* Copyright (c) 2026 Niolla
|
|
* All rights reserved.
|
|
*
|
|
* This source code is proprietary and confidential.
|
|
* Unauthorized copying, modification, distribution, or use
|
|
* of this file, via any medium, is strictly prohibited.
|
|
*/
|
|
|
|
// app/controllers/permission.controller.js
|
|
|
|
|
|
// PERMISSIONS:
|
|
// 1. createPermission --> Done
|
|
// 2. getAllPermissions --> Done
|
|
// 3. getPermissionById --> Done
|
|
// 4. updatePermission --> Done
|
|
// 5. deletePermission --> Done
|
|
|
|
// ROLES:
|
|
// 1. createRole --> Done
|
|
// 2. createRolePermission --> Done
|
|
// 3. getAllRoles --> Done
|
|
// 4. getRoleById --> Done
|
|
// 5. updateRole --> Done
|
|
// 6. deleteRole --> Done
|
|
|
|
// USER PERMISSIONS:
|
|
// 1. getUserPermissions --> Done
|
|
|
|
const db = require("../models");
|
|
const User = db.User;
|
|
const Role = db.roles;
|
|
const Permission = db.permission;
|
|
const RolePermission = db.rolePermission;
|
|
const UserPermission = db.userPermission;
|
|
|
|
// Create a new permission
|
|
exports.createPermission = async (req, res) => {
|
|
try {
|
|
const { permissionName, permissionDescription, page, module, action } = req.body;
|
|
if (!permissionName || !page || !module || !action) {
|
|
return res.status(400).json({ message: "Permission name, page, module, and action are required" });
|
|
}
|
|
|
|
const permissionId = `${module}.${page}.${action}`;
|
|
|
|
// Check if permission already exists
|
|
const existingPermission = await Permission.findOne({ where: { permission_id: permissionId } });
|
|
if (existingPermission) {
|
|
return res.status(400).json({ message: "Permission already exists" });
|
|
}
|
|
|
|
// Create the new permission
|
|
const newPermission = await Permission.create({
|
|
permission_id: permissionId,
|
|
permissionName,
|
|
permissionDescription,
|
|
page,
|
|
module,
|
|
action
|
|
});
|
|
|
|
res.status(201).json({
|
|
success: true,
|
|
data: newPermission
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error creating permission:", error);
|
|
res.status(500).json({ message: "Internal server error" });
|
|
}
|
|
};
|
|
|
|
// Bulk create permissions
|
|
exports.bulkCreatePermissions = async (req, res) => {
|
|
try {
|
|
const { permissions } = req.body;
|
|
|
|
if (!permissions || !Array.isArray(permissions) || permissions.length === 0) {
|
|
return res.status(400).json({
|
|
success: false,
|
|
message: "Permissions array is required and must not be empty"
|
|
});
|
|
}
|
|
|
|
const results = {
|
|
created: [],
|
|
failed: []
|
|
};
|
|
|
|
for (const item of permissions) {
|
|
try {
|
|
const { permissionName, permissionDescription, page, module, action } = item;
|
|
|
|
if (!permissionName || !page || !module || !action) {
|
|
results.failed.push({
|
|
...item,
|
|
error: "Permission name, page, module, and action are required"
|
|
});
|
|
continue;
|
|
}
|
|
|
|
const permissionId = `${module}.${page}.${action}`;
|
|
|
|
// Check if permission already exists
|
|
const existingPermission = await Permission.findOne({ where: { permission_id: permissionId } });
|
|
if (existingPermission) {
|
|
results.failed.push({
|
|
...item,
|
|
error: "Permission already exists"
|
|
});
|
|
continue;
|
|
}
|
|
|
|
const newPermission = await Permission.create({
|
|
permission_id: permissionId,
|
|
permissionName,
|
|
permissionDescription,
|
|
page,
|
|
module,
|
|
action
|
|
});
|
|
|
|
results.created.push(newPermission);
|
|
|
|
} catch (itemError) {
|
|
results.failed.push({
|
|
...item,
|
|
error: itemError.message
|
|
});
|
|
}
|
|
}
|
|
|
|
res.status(201).json({
|
|
success: results.failed.length === 0,
|
|
data: results
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error bulk creating permissions:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while bulk creating permissions."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Get all permissions
|
|
exports.getAllPermissions = async (req, res) => {
|
|
try {
|
|
const permissions = await Permission.findAll();
|
|
|
|
res.status(200).json({
|
|
success: true,
|
|
data: permissions
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error fetching permissions:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while fetching permissions."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Get permission by ID
|
|
exports.getPermissionById = async (req, res) => {
|
|
try {
|
|
const { permissionId } = req.params;
|
|
|
|
const permission = await Permission.findByPk(permissionId);
|
|
if (!permission) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "Permission not found"
|
|
});
|
|
}
|
|
|
|
res.status(200).json({
|
|
success: true,
|
|
data: permission
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error fetching permission:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while fetching permission."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Update permission
|
|
exports.updatePermission = async (req, res) => {
|
|
try {
|
|
const { permissionId } = req.params;
|
|
const { permissionName, permissionDescription, page, module, action } = req.body;
|
|
|
|
const permission = await Permission.findByPk(permissionId);
|
|
if (!permission) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "Permission not found"
|
|
});
|
|
}
|
|
|
|
// Update permission fields
|
|
await permission.update({
|
|
permissionName: permissionName || permission.permissionName,
|
|
permissionDescription: permissionDescription || permission.permissionDescription,
|
|
page: page || permission.page,
|
|
module: module || permission.module,
|
|
action: action || permission.action
|
|
});
|
|
|
|
res.status(200).json({
|
|
success: true,
|
|
data: permission,
|
|
message: "Permission updated successfully"
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error updating permission:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while updating permission."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Delete permission
|
|
exports.deletePermission = async (req, res) => {
|
|
try {
|
|
const { permissionId } = req.params;
|
|
|
|
const permission = await Permission.findByPk(permissionId);
|
|
if (!permission) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "Permission not found"
|
|
});
|
|
}
|
|
|
|
// Delete associated user and role permissions first
|
|
await UserPermission.destroy({ where: { permission_id: permissionId } });
|
|
await RolePermission.destroy({ where: { permission_id: permissionId } });
|
|
|
|
// Delete the permission
|
|
await permission.destroy();
|
|
|
|
res.status(200).json({
|
|
success: true,
|
|
message: "Permission deleted successfully"
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error deleting permission:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while deleting permission."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Create a new role
|
|
exports.createRole = async (req, res) => {
|
|
try {
|
|
const { roleName, roleDescription } = req.body;
|
|
|
|
if (!roleName) {
|
|
return res.status(400).json({
|
|
success: false,
|
|
message: "Role name is required"
|
|
});
|
|
}
|
|
|
|
// Generate role ID
|
|
const roleId = `role_${Date.now()}`;
|
|
|
|
const newRole = await Role.create({
|
|
role_id: roleId,
|
|
roleName,
|
|
roleDescription
|
|
});
|
|
|
|
res.status(201).json({
|
|
success: true,
|
|
data: newRole
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error creating role:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while creating role."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Create role-permission assignment
|
|
exports.createRolePermission = async (req, res) => {
|
|
try {
|
|
const { role_id, permission_id } = req.body;
|
|
|
|
if (!role_id || !permission_id) {
|
|
return res.status(400).json({
|
|
success: false,
|
|
message: "Role ID and Permission ID are required"
|
|
});
|
|
}
|
|
|
|
// Verify role and permission exist
|
|
const role = await Role.findByPk(role_id);
|
|
if (!role) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "Role not found"
|
|
});
|
|
}
|
|
|
|
const permission = await Permission.findByPk(permission_id);
|
|
if (!permission) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "Permission not found"
|
|
});
|
|
}
|
|
|
|
// Check if assignment already exists
|
|
const existingAssignment = await RolePermission.findOne({
|
|
where: { role_id, permission_id }
|
|
});
|
|
if (existingAssignment) {
|
|
return res.status(400).json({
|
|
success: false,
|
|
message: "Role permission already exists"
|
|
});
|
|
}
|
|
|
|
const rpId = `rp_${Date.now()}`;
|
|
const newRolePermission = await RolePermission.create({
|
|
rp_id: rpId,
|
|
role_id,
|
|
permission_id
|
|
});
|
|
|
|
res.status(201).json({
|
|
success: true,
|
|
data: newRolePermission
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error creating role permission:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while creating role permission."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Bulk create role permissions
|
|
exports.bulkCreateRolePermissions = async (req, res) => {
|
|
try {
|
|
const { role_id, permission_ids } = req.body;
|
|
|
|
if (!role_id || !permission_ids || !Array.isArray(permission_ids) || permission_ids.length === 0) {
|
|
return res.status(400).json({
|
|
success: false,
|
|
message: "Role ID and permission_ids array are required and must not be empty"
|
|
});
|
|
}
|
|
|
|
// Verify role exists
|
|
const role = await Role.findByPk(role_id);
|
|
if (!role) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "Role not found"
|
|
});
|
|
}
|
|
|
|
const results = {
|
|
created: [],
|
|
failed: []
|
|
};
|
|
|
|
for (const permission_id of permission_ids) {
|
|
try {
|
|
if (!permission_id) {
|
|
results.failed.push({
|
|
role_id,
|
|
permission_id,
|
|
error: "Permission ID is required"
|
|
});
|
|
continue;
|
|
}
|
|
|
|
// Verify permission exists
|
|
const permission = await Permission.findByPk(permission_id);
|
|
if (!permission) {
|
|
results.failed.push({
|
|
role_id,
|
|
permission_id,
|
|
error: "Permission not found"
|
|
});
|
|
continue;
|
|
}
|
|
|
|
// Check if assignment already exists
|
|
const existingAssignment = await RolePermission.findOne({
|
|
where: { role_id, permission_id }
|
|
});
|
|
if (existingAssignment) {
|
|
results.failed.push({
|
|
role_id,
|
|
permission_id,
|
|
error: "Role permission already exists"
|
|
});
|
|
continue;
|
|
}
|
|
|
|
const rpId = `rp_${Date.now()}`;
|
|
const newRolePermission = await RolePermission.create({
|
|
rp_id: rpId,
|
|
role_id,
|
|
permission_id
|
|
});
|
|
|
|
results.created.push(newRolePermission);
|
|
|
|
} catch (itemError) {
|
|
results.failed.push({
|
|
role_id,
|
|
permission_id,
|
|
error: itemError.message
|
|
});
|
|
}
|
|
}
|
|
|
|
res.status(201).json({
|
|
success: results.failed.length === 0,
|
|
data: results
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error bulk creating role permissions:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while bulk creating role permissions."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Get all roles
|
|
exports.getAllRoles = async (req, res) => {
|
|
try {
|
|
const roles = await Role.findAll({
|
|
include: [
|
|
{
|
|
model: RolePermission,
|
|
as: "rolePermissions",
|
|
include: [
|
|
{
|
|
model: Permission,
|
|
as: "permission",
|
|
attributes: ["permission_id", "permissionName", "page", "module", "action"]
|
|
}
|
|
]
|
|
}
|
|
]
|
|
});
|
|
|
|
res.status(200).json({
|
|
success: true,
|
|
data: roles
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error fetching roles:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while fetching roles."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Get role by ID
|
|
exports.getRoleById = async (req, res) => {
|
|
try {
|
|
const { roleId } = req.params;
|
|
|
|
const role = await Role.findByPk(roleId, {
|
|
include: [
|
|
{
|
|
model: RolePermission,
|
|
as: "rolePermissions",
|
|
include: [
|
|
{
|
|
model: Permission,
|
|
as: "permission",
|
|
attributes: ["permission_id", "permissionName", "page", "module", "action"]
|
|
}
|
|
]
|
|
}
|
|
]
|
|
});
|
|
|
|
if (!role) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "Role not found"
|
|
});
|
|
}
|
|
|
|
res.status(200).json({
|
|
success: true,
|
|
data: role
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error fetching role:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while fetching role."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Update role
|
|
exports.updateRole = async (req, res) => {
|
|
try {
|
|
const { roleId } = req.params;
|
|
const { roleName, roleDescription } = req.body;
|
|
|
|
const role = await Role.findByPk(roleId);
|
|
if (!role) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "Role not found"
|
|
});
|
|
}
|
|
|
|
// Update role fields
|
|
await role.update({
|
|
roleName: roleName || role.roleName,
|
|
roleDescription: roleDescription || role.roleDescription
|
|
});
|
|
|
|
res.status(200).json({
|
|
success: true,
|
|
data: role,
|
|
message: "Role updated successfully"
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error updating role:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while updating role."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Delete role
|
|
exports.deleteRole = async (req, res) => {
|
|
try {
|
|
const { roleId } = req.params;
|
|
|
|
const role = await Role.findByPk(roleId);
|
|
if (!role) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "Role not found"
|
|
});
|
|
}
|
|
|
|
// Delete associated role permissions first
|
|
await RolePermission.destroy({ where: { role_id: roleId } });
|
|
|
|
// Delete the role
|
|
await role.destroy();
|
|
|
|
res.status(200).json({
|
|
success: true,
|
|
message: "Role deleted successfully"
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error deleting role:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while deleting role."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Get user permissions
|
|
exports.getUserPermissions = async (req, res) => {
|
|
try {
|
|
const userId = req.params.userId;
|
|
|
|
// Fetch user permissions
|
|
const userPermissions = await UserPermission.findAll({
|
|
where: { user_id: userId },
|
|
include: [
|
|
{
|
|
model: Permission,
|
|
as: "permission",
|
|
attributes: ["permission_id", "permissionName", "page", "module", "action"]
|
|
}
|
|
]
|
|
});
|
|
|
|
res.status(200).json({
|
|
success: true,
|
|
data: userPermissions
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error fetching user permissions:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while fetching user permissions."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Create user permission
|
|
exports.createUserPermission = async (req, res) => {
|
|
try {
|
|
const { user_id, permission_id } = req.body;
|
|
|
|
if (!user_id || !permission_id) {
|
|
return res.status(400).json({
|
|
success: false,
|
|
message: "User ID and Permission ID are required"
|
|
});
|
|
}
|
|
|
|
// Verify user and permission exist
|
|
const user = await User.findByPk(user_id);
|
|
if (!user) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "User not found"
|
|
});
|
|
}
|
|
|
|
const permission = await Permission.findByPk(permission_id);
|
|
if (!permission) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "Permission not found"
|
|
});
|
|
}
|
|
|
|
// Check if assignment already exists
|
|
const existingAssignment = await UserPermission.findOne({
|
|
where: { user_id, permission_id }
|
|
});
|
|
if (existingAssignment) {
|
|
return res.status(400).json({
|
|
success: false,
|
|
message: "User permission already exists"
|
|
});
|
|
}
|
|
|
|
const newUserPermission = await UserPermission.create({
|
|
user_id,
|
|
permission_id
|
|
});
|
|
|
|
res.status(201).json({
|
|
success: true,
|
|
data: newUserPermission
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error creating user permission:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while creating user permission."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Bulk create user permissions
|
|
exports.bulkCreateUserPermissions = async (req, res) => {
|
|
try {
|
|
const { user_id, permission_ids } = req.body;
|
|
|
|
if (!user_id || !permission_ids || !Array.isArray(permission_ids) || permission_ids.length === 0) {
|
|
return res.status(400).json({
|
|
success: false,
|
|
message: "User ID and permission_ids array are required and must not be empty"
|
|
});
|
|
}
|
|
|
|
// Verify user exists
|
|
const user = await User.findByPk(user_id);
|
|
if (!user) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "User not found"
|
|
});
|
|
}
|
|
|
|
const results = {
|
|
created: [],
|
|
failed: []
|
|
};
|
|
|
|
for (const permission_id of permission_ids) {
|
|
try {
|
|
if (!permission_id) {
|
|
results.failed.push({
|
|
user_id,
|
|
permission_id,
|
|
error: "Permission ID is required"
|
|
});
|
|
continue;
|
|
}
|
|
|
|
// Verify permission exists
|
|
const permission = await Permission.findByPk(permission_id);
|
|
if (!permission) {
|
|
results.failed.push({
|
|
user_id,
|
|
permission_id,
|
|
error: "Permission not found"
|
|
});
|
|
continue;
|
|
}
|
|
|
|
// Check if assignment already exists
|
|
const existingAssignment = await UserPermission.findOne({
|
|
where: { user_id, permission_id }
|
|
});
|
|
if (existingAssignment) {
|
|
results.failed.push({
|
|
user_id,
|
|
permission_id,
|
|
error: "User permission already exists"
|
|
});
|
|
continue;
|
|
}
|
|
|
|
const newUserPermission = await UserPermission.create({
|
|
user_id,
|
|
permission_id
|
|
});
|
|
|
|
results.created.push(newUserPermission);
|
|
|
|
} catch (itemError) {
|
|
results.failed.push({
|
|
user_id,
|
|
permission_id,
|
|
error: itemError.message
|
|
});
|
|
}
|
|
}
|
|
|
|
res.status(201).json({
|
|
success: results.failed.length === 0,
|
|
data: results
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error bulk creating user permissions:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while bulk creating user permissions."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Update user permission
|
|
exports.updateUserPermission = async (req, res) => {
|
|
try {
|
|
const { upId } = req.params;
|
|
const { permission_id } = req.body;
|
|
|
|
if (!permission_id) {
|
|
return res.status(400).json({
|
|
success: false,
|
|
message: "Permission ID is required"
|
|
});
|
|
}
|
|
|
|
const userPermission = await UserPermission.findByPk(upId);
|
|
if (!userPermission) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "User permission not found"
|
|
});
|
|
}
|
|
|
|
// Verify permission exists
|
|
const permission = await Permission.findByPk(permission_id);
|
|
if (!permission) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "Permission not found"
|
|
});
|
|
}
|
|
|
|
// Check if new permission assignment already exists for this user
|
|
const existingAssignment = await UserPermission.findOne({
|
|
where: {
|
|
user_id: userPermission.user_id,
|
|
permission_id
|
|
}
|
|
});
|
|
if (existingAssignment && existingAssignment.up_id !== upId) {
|
|
return res.status(400).json({
|
|
success: false,
|
|
message: "This permission is already assigned to this user"
|
|
});
|
|
}
|
|
|
|
await userPermission.update({ permission_id });
|
|
|
|
res.status(200).json({
|
|
success: true,
|
|
data: userPermission,
|
|
message: "User permission updated successfully"
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error updating user permission:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while updating user permission."
|
|
});
|
|
}
|
|
};
|
|
|
|
// Delete user permission
|
|
exports.deleteUserPermission = async (req, res) => {
|
|
try {
|
|
const { upId } = req.params;
|
|
|
|
const userPermission = await UserPermission.findByPk(upId);
|
|
if (!userPermission) {
|
|
return res.status(404).json({
|
|
success: false,
|
|
message: "User permission not found"
|
|
});
|
|
}
|
|
|
|
await userPermission.destroy();
|
|
|
|
res.status(200).json({
|
|
success: true,
|
|
message: "User permission deleted successfully"
|
|
});
|
|
|
|
} catch (error) {
|
|
console.error("Error deleting user permission:", error);
|
|
res.status(500).json({
|
|
success: false,
|
|
message: "An error occurred while deleting user permission."
|
|
});
|
|
}
|
|
};
|