Files
backend/src/comments/comments.controller.ts
T
Ali Reza bb59d5e9ba Initial commit: Meshkee CMS API
NestJS backend with Prisma, Docker Compose for Postgres/Redis, and deploy docs for the production VM.
2026-07-21 17:52:36 +03:30

76 lines
2.1 KiB
TypeScript

import {
Body,
Controller,
Delete,
Get,
Param,
Patch,
Post,
Query,
UseGuards,
} from '@nestjs/common';
import { AuthUser } from '../auth/auth.types';
import { CurrentUser } from '../auth/decorators/current-user.decorator';
import { RequireBusinessPermission } from '../auth/decorators/require-business-permission.decorator';
import { BusinessPermissionGuard } from '../auth/guards/business-permission.guard';
import { JwtAuthGuard } from '../auth/guards/jwt-auth.guard';
import { CommentsService } from './comments.service';
import {
CreatePublicCommentDto,
ListCommentsDto,
ListPublicCommentsDto,
UpdateCommentApprovalDto,
} from './dto/comment.dto';
@Controller('tenants/:host/comments')
export class PublicCommentsController {
constructor(private readonly service: CommentsService) {}
@Post()
create(@Param('host') host: string, @Body() dto: CreatePublicCommentDto) {
return this.service.createPublic(host, dto);
}
@Get()
list(@Param('host') host: string, @Query() query: ListPublicCommentsDto) {
return this.service.listPublic(host, query);
}
}
@Controller('businesses/:businessId/comments')
@UseGuards(JwtAuthGuard, BusinessPermissionGuard)
export class CommentsController {
constructor(private readonly service: CommentsService) {}
@Get()
@RequireBusinessPermission('comments.read')
list(
@Param('businessId') businessId: string,
@Query() query: ListCommentsDto,
@CurrentUser() user: AuthUser,
) {
return this.service.listAdmin(businessId, query, user);
}
@Patch(':commentId')
@RequireBusinessPermission('comments.approve')
updateApproval(
@Param('businessId') businessId: string,
@Param('commentId') commentId: string,
@Body() dto: UpdateCommentApprovalDto,
@CurrentUser() user: AuthUser,
) {
return this.service.updateApproval(businessId, commentId, dto, user);
}
@Delete(':commentId')
@RequireBusinessPermission('comments.delete')
remove(
@Param('businessId') businessId: string,
@Param('commentId') commentId: string,
@CurrentUser() user: AuthUser,
) {
return this.service.remove(businessId, commentId, user);
}
}