POST /api/v1/entry/{slug}/photos/order renames an entry's image files to
photo-01..NN in the client-supplied order so the feed cover (media.images|first)
follows the drag — no stock endpoint can express this. Same R6 guard chain as the
delete route (site OWNER + direct child of the active trip's dailies), then the
shared PhotoRenumberer does the two-phase rename and the cache is cleared.
Filename safety is layered: unsafe 'order' entries (/, ..) are dropped here and
PhotoRenumberer only renames real image files, so a crafted body can never touch
the entry .md, a .gpx or a .meta.yaml. Registers behind the API route-map cache,
so a deploy cache-clear is required (same as the existing DELETE /entry/{slug}).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
70 lines
3.0 KiB
PHP
70 lines
3.0 KiB
PHP
<?php
|
|
namespace Grav\Plugin;
|
|
|
|
use Grav\Common\Plugin;
|
|
use RocketTheme\Toolbox\Event\Event;
|
|
|
|
/**
|
|
* Entry Actions — a thin, purpose-built API surface for owner-only, active-trip
|
|
* scoped journal-entry actions that the stock Grav API cannot express safely.
|
|
*
|
|
* Routes:
|
|
* - DELETE /api/v1/entry/{slug} — delete a journal entry folder
|
|
* - POST /api/v1/entry/{slug}/photos/order — reorder an entry's photos
|
|
*
|
|
* The stock DELETE /api/v1/pages<route> only checks write-permission (no trip
|
|
* scope, and any admin passes), which violates R6; and no stock endpoint can
|
|
* rename media to the photo-NN cover order at all. Both custom routes require the
|
|
* configured site OWNER and assert the target is a direct child of the active
|
|
* trip's dailies container — sharing one guard (EntryScopeGuard) with the save
|
|
* path so the R6 enforcement points cannot diverge (KTD5).
|
|
*
|
|
* Custom-in-repo (NOT GPM-managed): tracked via a `!` negation in user/.gitignore
|
|
* and deployed with the content push, like cache-on-save. Never in plugins.txt.
|
|
*/
|
|
class EntryActionsPlugin extends Plugin
|
|
{
|
|
public static function getSubscribedEvents(): array
|
|
{
|
|
return [
|
|
'onPluginsInitialized' => ['onPluginsInitialized', 0],
|
|
'onApiRegisterRoutes' => ['onApiRegisterRoutes', 0],
|
|
];
|
|
}
|
|
|
|
/**
|
|
* Register a lazy PSR-4 autoloader for this plugin's classes. The api router
|
|
* dispatches from a CACHED route map and instantiates the controller directly
|
|
* (ApiRouter::handleRoute → `new $controllerClass`) WITHOUT re-firing
|
|
* onApiRegisterRoutes, so requiring the class only there would leave it
|
|
* unloaded on cached-route requests. Lazy autoloading fires exactly when the
|
|
* router constructs the controller — by which point the api plugin's own
|
|
* autoloader (for AbstractApiController) is already registered.
|
|
*/
|
|
public function onPluginsInitialized(): void
|
|
{
|
|
spl_autoload_register(static function (string $class): void {
|
|
$prefix = 'Grav\\Plugin\\EntryActions\\';
|
|
if (strncmp($class, $prefix, strlen($prefix)) !== 0) {
|
|
return;
|
|
}
|
|
$rel = substr($class, strlen($prefix));
|
|
$file = __DIR__ . '/classes/' . str_replace('\\', '/', $rel) . '.php';
|
|
if (is_file($file)) {
|
|
require_once $file;
|
|
}
|
|
});
|
|
}
|
|
|
|
public function onApiRegisterRoutes(Event $event): void
|
|
{
|
|
$routes = $event['routes'];
|
|
$routes->delete('/entry/{slug}', [EntryActions\EntryActionsApiController::class, 'deleteEntry']);
|
|
// Reorder an entry's photos to a client-supplied order → rename to
|
|
// photo-01..NN so the feed cover (media.images|first) follows the drag.
|
|
// Nested-static-after-param, same shape as the DELETE above — it only
|
|
// registers once the API route-map cache is rebuilt (deploy must clear cache).
|
|
$routes->post('/entry/{slug}/photos/order', [EntryActions\EntryActionsApiController::class, 'reorderPhotos']);
|
|
}
|
|
}
|