From e435e457dec903fc6842690d40fbe331451d1c2e Mon Sep 17 00:00:00 2001 From: Chirag Aggarwal Date: Wed, 12 Feb 2025 09:50:13 +0000 Subject: [PATCH] chore: added check for team membership exists --- app/config/errors.php | 7 ++++++- app/controllers/api/teams.php | 8 +++++--- src/Appwrite/Extend/Exception.php | 1 + 3 files changed, 12 insertions(+), 4 deletions(-) diff --git a/app/config/errors.php b/app/config/errors.php index 461521f5e0..f552b8898d 100644 --- a/app/config/errors.php +++ b/app/config/errors.php @@ -356,9 +356,14 @@ return [ ], Exception::TEAM_INVALID_SECRET => [ 'name' => Exception::TEAM_INVALID_SECRET, - 'description' => 'The team invitation secret is invalid. Please request a new invitation and try again.', + 'description' => 'The team invitation secret is invalid. Please request a new invitation and try again.', 'code' => 401, ], + Exception::TEAM_MEMBERSHIP_ALREADY_EXISTS => [ + 'name' => Exception::TEAM_MEMBERSHIP_ALREADY_EXISTS, + 'description' => 'Team membership already exists. Please check your existing memberships and try again.', + 'code' => 409, + ], Exception::TEAM_MEMBERSHIP_MISMATCH => [ 'name' => Exception::TEAM_MEMBERSHIP_MISMATCH, 'description' => 'The membership ID does not belong to the team ID.', diff --git a/app/controllers/api/teams.php b/app/controllers/api/teams.php index 18faaeceeb..597424f861 100644 --- a/app/controllers/api/teams.php +++ b/app/controllers/api/teams.php @@ -588,9 +588,8 @@ App::post('/v1/teams/:teamId/memberships') Query::equal('teamInternalId', [$team->getInternalId()]), ]); + $secret = Auth::tokenGenerator(); if ($membership->isEmpty()) { - $secret = Auth::tokenGenerator(); - $membershipId = ID::unique(); $membership = new Document([ '$id' => $membershipId, @@ -618,7 +617,8 @@ App::post('/v1/teams/:teamId/memberships') $dbForProject->createDocument('memberships', $membership); Authorization::skip(fn () => $dbForProject->increaseDocumentAttribute('teams', $team->getId(), 'total', 1)); - } else { + } elseif ($membership->getAttribute('joined') === null) { + $membership->setAttribute('secret', Auth::hash($secret)); $membership->setAttribute('invited', DateTime::now()); if ($isPrivilegedUser || $isAppUser) { @@ -629,6 +629,8 @@ App::post('/v1/teams/:teamId/memberships') $membership = ($isPrivilegedUser || $isAppUser) ? Authorization::skip(fn () => $dbForProject->updateDocument('memberships', $membership->getId(), $membership)) : $dbForProject->updateDocument('memberships', $membership->getId(), $membership); + } else { + throw new Exception(Exception::TEAM_MEMBERSHIP_ALREADY_EXISTS); } diff --git a/src/Appwrite/Extend/Exception.php b/src/Appwrite/Extend/Exception.php index d4f47ca177..7f75d8e97b 100644 --- a/src/Appwrite/Extend/Exception.php +++ b/src/Appwrite/Extend/Exception.php @@ -114,6 +114,7 @@ class Exception extends \Exception public const TEAM_NOT_FOUND = 'team_not_found'; public const TEAM_INVITE_NOT_FOUND = 'team_invite_not_found'; public const TEAM_INVALID_SECRET = 'team_invalid_secret'; + public const TEAM_MEMBERSHIP_ALREADY_EXISTS = 'team_membership_already_exists'; public const TEAM_MEMBERSHIP_MISMATCH = 'team_membership_mismatch'; public const TEAM_INVITE_MISMATCH = 'team_invite_mismatch'; public const TEAM_ALREADY_EXISTS = 'team_already_exists';