The hard rule on POST /api/v1/blogacl is: a 500 is never acceptable,
regardless of the payload shape. The prod 500 logged on 2026-08-21 on
mercure was caused by the PostIt client sending { circleId } only, which
the server deserialised into CircleAuthorizationToBlogPost with
BlogPostId = default(long) = 0; EF Core refused the INSERT with
InvalidOperationException: The value of
'CircleAuthorizationToBlogPost.BlogPostId' is unknown. The PostIt fix
lives in f557630a (enrich the payload with blogPostId). The server-side
guard lives in this commit:
- BlogAclApiController.CheckOwner is now async and uses FirstOrDefaultAsync
instead of First, so it does not deadlock the request thread and
returns false on a missing circle (which the controller already maps
to ChallengeResult).
- BlogsWebServerFixture now seeds Alice, her Circle and her BlogPost
in ConfigurePipelineAsync, once at host startup, against the shared
SqliteConnection (Cache=Shared). EnsureCreated is idempotent and
runs against the connection that every DbContext resolves through,
so the test theory can POST payloads with real FK ids against a
schema that actually has the Circle / BlogSpot tables.
- BlogAclApiTests:
- PostCircleAuthorization_returns_201_when_payload_mirrors_PostIt_shape
is the regression sentinel for the prod fix.
- PostCircleAuthorization_never_returns_500 is a [Theory] over
several payload shapes; any future commit that reintroduces a
500 path turns it red. CleanupAcl at the start of each insert-
bearing test isolates against xUnit's no-guarantee-of-order
execution: a successful POST in test N would otherwise conflict
with test N+1 against the same (CircleId, BlogPostId) pair.
181 lines
6.2 KiB
C#
181 lines
6.2 KiB
C#
|
|
using System.Security.Claims;
|
|
using Microsoft.AspNetCore.Mvc;
|
|
using Microsoft.EntityFrameworkCore;
|
|
using Yavsc.Abstract.BlogSpot;
|
|
using Yavsc.Models;
|
|
using Yavsc.Models.Access;
|
|
using Yavsc.Server.Helpers;
|
|
using static Yavsc.Constants;
|
|
|
|
namespace Yavsc.Blogs.Controllers
|
|
{
|
|
[Produces("application/json")]
|
|
[Route(APIPrefix+"/blogacl")]
|
|
public class BlogAclApiController : Controller
|
|
{
|
|
private readonly ApplicationDbContext _context;
|
|
|
|
public BlogAclApiController(ApplicationDbContext context)
|
|
{
|
|
_context = context;
|
|
}
|
|
|
|
/// <summary>
|
|
/// Returns the ACL entries for the caller's own blog posts.
|
|
/// Blog posts (and therefore their ACLs) are private to their
|
|
/// author — the API never exposes another user's ACL.
|
|
/// </summary>
|
|
// GET: api/v1/blogacl
|
|
[HttpGet]
|
|
public IEnumerable<CircleAuthorizationToBlogPost> GetBlogACL()
|
|
{
|
|
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
|
|
return _context.CircleAuthorizationToBlogPost
|
|
.Include(a => a.Allowed)
|
|
.Where(a => a.Allowed.OwnerId == uid);
|
|
}
|
|
|
|
// GET: api/BlogAclApi/5
|
|
[HttpGet("{id}", Name = "GetCircleAuthorizationToBlogPost")]
|
|
public async Task<IActionResult> GetCircleAuthorizationToBlogPost([FromRoute] long id)
|
|
{
|
|
if (!ModelState.IsValid)
|
|
{
|
|
return BadRequest(ModelState);
|
|
}
|
|
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
|
|
CircleAuthorizationToBlogPost circleAuthorizationToBlogPost = await _context.CircleAuthorizationToBlogPost.SingleAsync(
|
|
m => m.CircleId == id && m.Allowed.OwnerId == uid );
|
|
|
|
if (circleAuthorizationToBlogPost == null)
|
|
{
|
|
return NotFound();
|
|
}
|
|
|
|
return Ok(circleAuthorizationToBlogPost);
|
|
}
|
|
|
|
// PUT: api/BlogAclApi/5
|
|
[HttpPut("{id}")]
|
|
public async Task<IActionResult> PutCircleAuthorizationToBlogPost([FromRoute] long id, [FromBody] CircleAuthorizationToBlogPost circleAuthorizationToBlogPost)
|
|
{
|
|
if (!ModelState.IsValid)
|
|
{
|
|
return BadRequest(ModelState);
|
|
}
|
|
|
|
if (id != circleAuthorizationToBlogPost.CircleId)
|
|
{
|
|
return BadRequest();
|
|
}
|
|
|
|
if (!await CheckOwnerAsync(circleAuthorizationToBlogPost.CircleId))
|
|
{
|
|
return new ChallengeResult();
|
|
}
|
|
_context.Entry(circleAuthorizationToBlogPost).State = EntityState.Modified;
|
|
|
|
try
|
|
{
|
|
await _context.SaveChangesAsync(User.GetUserId());
|
|
}
|
|
catch (DbUpdateConcurrencyException)
|
|
{
|
|
if (!CircleAuthorizationToBlogPostExists(id))
|
|
{
|
|
return NotFound();
|
|
}
|
|
else
|
|
{
|
|
throw;
|
|
}
|
|
}
|
|
|
|
return new StatusCodeResult(StatusCodes.Status204NoContent);
|
|
}
|
|
private async Task<bool> CheckOwnerAsync (long circleId)
|
|
{
|
|
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
|
|
if (uid==null) return false;
|
|
var circle = await _context.Circle.FirstOrDefaultAsync(c=>c.Id==circleId);
|
|
if (circle == null) return false;
|
|
return circle.OwnerId == uid;
|
|
}
|
|
// POST: api/BlogAclApi
|
|
[HttpPost]
|
|
public async Task<IActionResult> PostCircleAuthorizationToBlogPost(
|
|
[FromBody] PostAccessControlRulePayload circleAuthorizationToBlogPost)
|
|
{
|
|
if (!ModelState.IsValid)
|
|
{
|
|
return BadRequest(ModelState);
|
|
}
|
|
if (!await CheckOwnerAsync(circleAuthorizationToBlogPost.CircleId))
|
|
{
|
|
return new ChallengeResult();
|
|
}
|
|
CircleAuthorizationToBlogPost entity = new CircleAuthorizationToBlogPost
|
|
{
|
|
BlogPostId = circleAuthorizationToBlogPost.BlogPostId,
|
|
CircleId = circleAuthorizationToBlogPost.CircleId
|
|
};
|
|
_context.CircleAuthorizationToBlogPost.Add(entity);
|
|
try
|
|
{
|
|
await _context.SaveChangesAsync(User.GetUserId());
|
|
}
|
|
catch (DbUpdateException)
|
|
{
|
|
if (CircleAuthorizationToBlogPostExists(circleAuthorizationToBlogPost.CircleId))
|
|
{
|
|
return new StatusCodeResult(StatusCodes.Status409Conflict);
|
|
}
|
|
else
|
|
{
|
|
throw;
|
|
}
|
|
}
|
|
|
|
return CreatedAtRoute("GetCircleAuthorizationToBlogPost", new { id = circleAuthorizationToBlogPost.CircleId }, circleAuthorizationToBlogPost);
|
|
}
|
|
|
|
// DELETE: api/BlogAclApi/5
|
|
[HttpDelete("{id}")]
|
|
public async Task<IActionResult> DeleteCircleAuthorizationToBlogPost([FromRoute] long id)
|
|
{
|
|
if (!ModelState.IsValid)
|
|
{
|
|
return BadRequest(ModelState);
|
|
}
|
|
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
|
|
|
|
CircleAuthorizationToBlogPost circleAuthorizationToBlogPost = await _context.CircleAuthorizationToBlogPost.Include(
|
|
a=>a.Allowed
|
|
).SingleAsync(m => m.CircleId == id
|
|
&& m.Allowed.OwnerId == uid);
|
|
if (circleAuthorizationToBlogPost == null)
|
|
{
|
|
return NotFound();
|
|
}
|
|
_context.CircleAuthorizationToBlogPost.Remove(circleAuthorizationToBlogPost);
|
|
await _context.SaveChangesAsync(User.GetUserId());
|
|
|
|
return Ok(circleAuthorizationToBlogPost);
|
|
}
|
|
|
|
protected override void Dispose(bool disposing)
|
|
{
|
|
if (disposing)
|
|
{
|
|
_context.Dispose();
|
|
}
|
|
base.Dispose(disposing);
|
|
}
|
|
|
|
private bool CircleAuthorizationToBlogPostExists(long id)
|
|
{
|
|
return _context.CircleAuthorizationToBlogPost.Count(e => e.CircleId == id) > 0;
|
|
}
|
|
}
|
|
}
|