|
|
@@ -26,7 +26,9 @@ const CLASS_SYSTEM_FIELDS = {
|
|
|
Node: new Set(['nodeId','parentId','depth','child','orderId','zstatus','sourceKey','cuser','cuname','editDate']),
|
|
|
Special: new Set(['specId','pid','orderId','sourceKey','cuser','editDate']),
|
|
|
Model: new Set(['modelId','modelType','tableName','sourceKey','nodeId','fromModel','multiFlag','sysModel']),
|
|
|
- ModelField: new Set(['fieldId','modelId','fieldName','fieldType','sourceKey','sysType','orderId'])
|
|
|
+ ModelField: new Set(['fieldId','modelId','fieldName','fieldType','sourceKey','sysType','orderId']),
|
|
|
+ Guestbook: new Set(['gid','parentid','cateid','userid','status','sourceKey','gdate','ip']),
|
|
|
+ Guestcate: new Set(['cateid','parentId','gtype','sourceKey','orderId'])
|
|
|
};
|
|
|
|
|
|
function inputOf(request) {
|
|
|
@@ -544,6 +546,65 @@ async function handler(request, response) {
|
|
|
for (const target of targets) await audit(context, 'order-model-field', 'ModelField', target.id);
|
|
|
return response.json({ success: true, data: { updated: targets.length, modelId: modelIds[0], results: targets.map(serializeObject) } });
|
|
|
}
|
|
|
+ if (operation === 'saveGuestbook') {
|
|
|
+ const objectId = String(input.objectId || '');
|
|
|
+ if (!objectId) fail(400, '普通留言新增必须走前台留言云函数;后台只能通过专用回复流程新增');
|
|
|
+ const fields = await schemaFor('Guestbook');
|
|
|
+ const query = new Parse.Query('Guestbook'); applyTenant(query, fields, context, input.companyId); const target = await query.get(objectId, { useMasterKey: true });
|
|
|
+ const payload = input.fields && typeof input.fields === 'object' ? input.fields : {};
|
|
|
+ const title = String(payload.title == null ? target.get('title') || '' : payload.title).trim();
|
|
|
+ const content = String(payload.tcontent == null ? target.get('tcontent') || '' : payload.tcontent);
|
|
|
+ if (!title || title.length > 200) fail(400, '留言标题长度应为 1 至 200 位');
|
|
|
+ if (content.length > 200000) fail(400, '留言内容过长');
|
|
|
+ target.set('title', title); target.set('tcontent', content);
|
|
|
+ await target.save(null, { useMasterKey: true }); await audit(context, 'update-guestbook', 'Guestbook', objectId);
|
|
|
+ return response.json({ success: true, data: serializeObject(target) });
|
|
|
+ }
|
|
|
+ if (operation === 'guestbookReply') {
|
|
|
+ const parentObjectId = String(input.parentObjectId || '');
|
|
|
+ const title = String(input.title || '').trim() || '[管理员回复]';
|
|
|
+ const content = String(input.content || '');
|
|
|
+ if (!parentObjectId) fail(400, '缺少原留言');
|
|
|
+ if (title.length > 200 || !content.trim() || content.length > 200000) fail(400, '回复标题或内容无效');
|
|
|
+ const fields = await schemaFor('Guestbook');
|
|
|
+ const query = new Parse.Query('Guestbook'); applyTenant(query, fields, context, input.companyId); const parent = await query.get(parentObjectId, { useMasterKey: true });
|
|
|
+ const company = parent.get('company') || context.company; const companyId = pointerId(company); const parentGid = Number(parent.get('gid')) || 0; const cateid = Number(parent.get('cateid')) || 0;
|
|
|
+ if (!companyId || !parentGid) fail(409, '原留言缺少帐套或旧系统编号');
|
|
|
+ const reply = new Parse.Object('Guestbook');
|
|
|
+ reply.set('sourceKey', 'cloud:admin-guestbook-reply:' + companyId + ':' + Date.now() + ':' + Math.random().toString(36).slice(2,10)); reply.set('company', company); reply.set('parentid', parentGid); reply.set('cateid', cateid); reply.set('userid', Number(context.current.get('legacyUserId')) || 0); reply.set('title', title); reply.set('tcontent', content); reply.set('status', 99); reply.set('gdate', new Date()); reply.set('ip', 'admin-cloud');
|
|
|
+ try { await reply.save(null, { useMasterKey: true }); }
|
|
|
+ catch (error) { fail(422, '管理员回复初始写入失败: ' + String(error && error.message || error)); }
|
|
|
+ try {
|
|
|
+ const rows = await Psql.query('WITH lock_row AS MATERIALIZED (SELECT pg_advisory_xact_lock(hashtext(\'xiaoshu-guestbook-gid:\'||$1))), next_id AS MATERIALIZED (SELECT COALESCE(MAX("gid"),0)+1 AS id FROM "Guestbook",lock_row WHERE "company"=$1 AND COALESCE("gid",0)>0) UPDATE "Guestbook" SET "gid"=next_id.id,"sourceKey"=\'[["Gid",\'||next_id.id::text||\']]\',"updatedAt"=NOW() FROM next_id WHERE "objectId"=$2 RETURNING next_id.id', [companyId, reply.id]);
|
|
|
+ if (!Number(rows[0] && rows[0].id)) throw new Error('无法分配回复编号');
|
|
|
+ } catch (error) { await reply.destroy({ useMasterKey: true }).catch(() => undefined); fail(422, '管理员回复结构写入失败: ' + String(error && error.message || error)); }
|
|
|
+ await reply.fetch({ useMasterKey: true }); await audit({ ...context, company }, 'reply-guestbook', 'Guestbook', reply.id);
|
|
|
+ return response.json({ success: true, data: serializeObject(reply) });
|
|
|
+ }
|
|
|
+ if (operation === 'guestbookBatch') {
|
|
|
+ const action = String(input.action || '');
|
|
|
+ if (!['audit','unaudit','recycle','recover','purge'].includes(action)) fail(400, '不支持的留言批量操作');
|
|
|
+ const requestedIds = Array.isArray(input.objectIds) ? input.objectIds : [input.objectId];
|
|
|
+ const objectIds = [...new Set(requestedIds.map((value) => String(value || '').trim()).filter(Boolean))];
|
|
|
+ if (!objectIds.length || objectIds.length > 100) fail(400, '每次请选择 1 至 100 条留言');
|
|
|
+ const fields = await schemaFor('Guestbook');
|
|
|
+ const query = new Parse.Query('Guestbook'); applyTenant(query, fields, context, input.companyId); query.containedIn('objectId', objectIds); query.limit(objectIds.length);
|
|
|
+ const targets = await query.find({ useMasterKey: true });
|
|
|
+ if (targets.length !== objectIds.length) fail(404, '部分留言不存在或不属于当前帐套');
|
|
|
+ if (action === 'purge') {
|
|
|
+ const companyIds = [...new Set(targets.map((target) => pointerId(target.get('company'))).filter(Boolean))]; const gids = targets.map((target) => Number(target.get('gid')) || 0);
|
|
|
+ if (companyIds.length !== 1 || gids.some((gid) => gid < 1)) fail(409, '留言缺少有效帐套或编号');
|
|
|
+ const children = await Psql.one('SELECT COUNT(*)::int AS count FROM "Guestbook" WHERE "company"=$1 AND "parentid"=ANY($2::numeric[]) AND NOT ("gid"=ANY($2::numeric[]))', [companyIds[0], gids]);
|
|
|
+ if (Number(children.count) > 0) fail(409, '留言仍有回复,不能永久删除');
|
|
|
+ await Parse.Object.destroyAll(targets, { useMasterKey: true });
|
|
|
+ } else {
|
|
|
+ const status = action === 'recycle' ? -2 : action === 'unaudit' ? 0 : 99;
|
|
|
+ for (const target of targets) target.set('status', status);
|
|
|
+ await Parse.Object.saveAll(targets, { useMasterKey: true });
|
|
|
+ }
|
|
|
+ for (const target of targets) await audit({ ...context, company: target.get('company') || context.company }, 'guestbook-' + action, 'Guestbook', target.id);
|
|
|
+ return response.json({ success: true, data: { action, updated: targets.length, results: action === 'purge' ? [] : targets.map(serializeObject) } });
|
|
|
+ }
|
|
|
if (operation === 'contentBatch') {
|
|
|
const action = String(input.action || '');
|
|
|
if (!['status','recycle','recover','move'].includes(action)) fail(400, '不支持的内容批量操作');
|
|
|
@@ -583,7 +644,7 @@ async function handler(request, response) {
|
|
|
const classWritable = !READ_ONLY_CLASSES.has(className);
|
|
|
if (operation === 'schema') {
|
|
|
const fieldList = Object.entries(fields).filter(([name]) => !HIDDEN_FIELDS.has(name) && !/(?:password|secret|sessiontoken|masterkey|privatekey)/i.test(name)).map(([name, field]) => ({ name, type: field.type, targetClass: field.targetClass, required: field.required === true, writable: classWritable && !isSystemField(className, name) && GENERIC_WRITE_TYPES.has(field.type) }));
|
|
|
- return response.json({ success: true, data: { className, label: CLASS_LABELS[className] || className, fields: fieldList, writable: classWritable, creatable: classWritable && !['CommonModel','Model','ModelField'].includes(className), supportsSoftDelete: Boolean(fields.isDeleted) } });
|
|
|
+ return response.json({ success: true, data: { className, label: CLASS_LABELS[className] || className, fields: fieldList, writable: classWritable, creatable: classWritable && !['CommonModel','Model','ModelField','Guestbook','Guestcate'].includes(className), supportsSoftDelete: Boolean(fields.isDeleted) } });
|
|
|
}
|
|
|
if (operation === 'list') {
|
|
|
const page = Math.max(1, Number(input.page) || 1); const pageSize = Math.min(100, Math.max(1, Number(input.pageSize) || 20));
|
|
|
@@ -607,6 +668,8 @@ async function handler(request, response) {
|
|
|
if (className === 'Node') fail(400, '栏目必须走专用保存流程');
|
|
|
if (className === 'Special') fail(400, '专题必须走专用保存流程');
|
|
|
if (className === 'Model' || className === 'ModelField') fail(400, '模型结构必须走专用元数据流程');
|
|
|
+ if (className === 'Guestbook') fail(400, '留言必须走专用编辑或回复流程');
|
|
|
+ if (className === 'Guestcate') fail(501, 'migration_blocked: 留言/贴吧分类需要专用原子分类编号、类型与父子引用流程,通用保存已禁用');
|
|
|
if (className === 'CommonModel' && !objectId) fail(400, '内容新增必须同时写入模型附表,不能走通用保存');
|
|
|
let object;
|
|
|
if (objectId) { const query = new Parse.Query(className); applyTenant(query, fields, context, input.companyId); object = await query.get(objectId, { useMasterKey: true }); } else object = new Parse.Object(className);
|
|
|
@@ -619,11 +682,13 @@ async function handler(request, response) {
|
|
|
if (operation === 'delete') {
|
|
|
if (!classWritable || !objectId) fail(400, '该记录不允许删除'); const query = new Parse.Query(className); applyTenant(query, fields, context, input.companyId); const object = await query.get(objectId, { useMasterKey: true });
|
|
|
if (className === 'Model' || className === 'ModelField') fail(501, 'migration_blocked: 删除模型或字段需要同步删除 PostgreSQL 物理表/列并验证历史数据,托管云函数中未开放此 DDL 流程');
|
|
|
+ if (className === 'Guestcate') fail(501, 'migration_blocked: 分类删除前需要同时核验留言、帖子、权限与下级分类引用,通用删除已禁用');
|
|
|
if (className === '_User') assertCanManageUser(context, object, 'lock');
|
|
|
if (className === 'Group') { const groupId = Number(object.get('groupId')) || 0; const companyId = pointerId(object.get('company')); const users = await Psql.one('SELECT COUNT(*)::int AS count FROM "_User" WHERE "company"=$1 AND COALESCE("legacyGroupId",0)=$2 AND ("isDeleted" IS NULL OR "isDeleted"=FALSE)', [companyId, groupId]); const children = await Psql.one('SELECT COUNT(*)::int AS count FROM "Group" WHERE "company"=$1 AND COALESCE("parentGroupId",0)=$2', [companyId, groupId]); if (Number(users.count) > 0) fail(409, '该用户组仍有用户,不能删除'); if (Number(children.count) > 0) fail(409, '该用户组仍有下级组,不能删除'); }
|
|
|
if (className === 'CommonModel') { object.set('status', -2); await object.save(null, { useMasterKey: true }); await audit(context, 'content-recycle', className, objectId); return response.json({ success: true, data: { objectId, softDeleted: true, status: -2 } }); }
|
|
|
if (className === 'Node') { object.set('zstatus', -2); if (fields.editDate) object.set('editDate', new Date()); await object.save(null, { useMasterKey: true }); await audit(context, 'node-recycle', className, objectId); return response.json({ success: true, data: { objectId, softDeleted: true, zstatus: -2 } }); }
|
|
|
if (className === 'Special') { const specId = Number(object.get('specId')) || 0; const companyId = pointerId(object.get('company')); const children = await Psql.one('SELECT COUNT(*)::int AS count FROM "Special" WHERE "company"=$1 AND COALESCE("pid",0)=$2', [companyId, specId]); if (Number(children.count) > 0) fail(409, '该专题仍有下级专题,不能删除'); await object.destroy({ useMasterKey: true }); await audit(context, 'delete-special', className, objectId); return response.json({ success: true, data: { objectId, softDeleted: false } }); }
|
|
|
+ if (className === 'Guestbook') { object.set('status', -2); await object.save(null, { useMasterKey: true }); await audit(context, 'guestbook-recycle', className, objectId); return response.json({ success: true, data: { objectId, softDeleted: true, status: -2 } }); }
|
|
|
if (fields.isDeleted) { object.set('isDeleted', true); await object.save(null, { useMasterKey: true }); } else await object.destroy({ useMasterKey: true });
|
|
|
if (className === '_User') await revokeSessions([object]);
|
|
|
await audit(context, 'delete', className, objectId); return response.json({ success: true, data: { objectId, softDeleted: Boolean(fields.isDeleted) } });
|