DeleteAttendanceItem.js 2.8 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394
  1. const API = require("../../lib/API");
  2. const { BaseStdResponse } = require("../../BaseStdResponse");
  3. const db = require("../../plugin/DataBase/db");
  4. const AccessControl = require("../../lib/AccessControl");
  5. class DeleteAttendanceItem extends API {
  6. constructor() {
  7. super();
  8. this.setPath('/Attendance');
  9. this.setMethod('DELETE');
  10. }
  11. async onRequest(req, res) {
  12. let {
  13. uuid,
  14. session,
  15. project_id
  16. } = req.body;
  17. // 检查必需的参数是否缺失
  18. if ([uuid, session, project_id].some(value => value === '' || value === null || value === undefined)) {
  19. res.json({
  20. ...BaseStdResponse.MISSING_PARAMETER,
  21. endpoint: 1513123
  22. });
  23. return;
  24. }
  25. // 检查 session 是否有效
  26. if (!await AccessControl.checkSession(uuid, session)) {
  27. res.json({
  28. ...BaseStdResponse.ACCESS_DENIED,
  29. endpoint: 48153145
  30. });
  31. return;
  32. }
  33. // 获取考勤项目
  34. const sqlGetProject = 'SELECT createUser, admin FROM kq_items WHERE id = ?';
  35. let projectResult = await db.query(sqlGetProject, [project_id]);
  36. if (!projectResult || projectResult.length === 0) {
  37. res.json({
  38. ...BaseStdResponse.DATABASE_ERR,
  39. endpoint: 154754511
  40. });
  41. return;
  42. }
  43. let projectData = projectResult[0];
  44. // 检查用户权限
  45. let permission = await AccessControl.getPermission(uuid);
  46. if (projectData.createUser !== uuid && !permission.includes('admin') && !projectData.admin.includes(uuid)) {
  47. return res.json({
  48. ...BaseStdResponse.PERMISSION_DENIED,
  49. endpoint: 481454,
  50. msg: '你不是该考勤项目管理员,无操作权限'
  51. });
  52. }
  53. // 删除考勤项目
  54. const sqlDeleteProject = 'DELETE FROM kq_items WHERE id = ?';
  55. let deleteResult = await db.query(sqlDeleteProject, [project_id]);
  56. if (!deleteResult || deleteResult.affectedRows !== 1) {
  57. res.json({
  58. ...BaseStdResponse.DATABASE_ERR,
  59. endpoint: 513513
  60. });
  61. return;
  62. }
  63. // 删除考勤记录
  64. const sqlDeleteRecords = 'DELETE FROM kq_records WHERE project_id = ?';
  65. let deleteRecordsResult = await db.query(sqlDeleteRecords, [project_id]);
  66. if (!deleteRecordsResult) {
  67. res.json({
  68. ...BaseStdResponse.DATABASE_ERR,
  69. endpoint: 513513
  70. });
  71. return;
  72. }
  73. res.json({
  74. ...BaseStdResponse.OK
  75. });
  76. }
  77. }
  78. module.exports.DeleteAttendanceItem = DeleteAttendanceItem;