aboutsummaryrefslogtreecommitdiff
path: root/lib/classes/JsonApi/Routes/Courseware/UserDataFieldOfBlocksShow.php
blob: 51b60c1fe75c63aeef1c934dc3258bad42618973 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
<?php

namespace JsonApi\Routes\Courseware;

use Courseware\Block;
use Courseware\UserDataField;
use JsonApi\Errors\AuthorizationFailedException;
use JsonApi\Errors\RecordNotFoundException;
use JsonApi\JsonApiController;
use Psr\Http\Message\ResponseInterface as Response;
use Psr\Http\Message\ServerRequestInterface as Request;

/**
 * Displays the user data field of a block.
 */
class UserDataFieldOfBlocksShow extends JsonApiController
{
    protected $allowedIncludePaths = ['block', 'user'];

    /**
     * @SuppressWarnings(PHPMD.UnusedFormalParameter)
     */
    public function __invoke(Request $request, Response $response, $args)
    {
        if (!($block = Block::find($args['id']))) {
            throw new RecordNotFoundException();
        }
        // this is automatically scoped to the requesting user
        // so we don't need to worry about the accessing the user data fields.
        $resource = UserDataField::getUserDataField($user = $this->getUser($request), $block);

        if (!Authority::canShowUserDataField($user, $resource)) {
            throw new AuthorizationFailedException();
        }

        // however, as it is intended to list all user data fields of the block, we get it here and return it back.
        $resources = UserDataField::findBySql('block_id = ?', [$block->id]);

        return $this->getContentResponse($resources);
    }
}