Files
gh-christianlouis-docuelevate/frontend/static/js/sharing.js
T
copilot-swe-agent[bot] c7d3ec57c3 fix: restore all code deleted/truncated by d2217531 Jules SSRF commit
Commit d2217531 (google-labs-jules SSRF fix) catastrophically deleted
11,500+ lines across 100+ files while fixing an unrelated IMAP issue.

Restored from d2217531^ (pre-bad-commit state):

Deleted files (fully restored):
- app/api/{automation,classification_rules,comments,sharing}.py
- app/middleware/upload_rate_limit.py
- app/tasks/{automation_tasks,classify_document}.py
- app/utils/{automation_hooks,classification_rules}.py
- docs/AppleAppStoreCompliance.md
- frontend/input.css, package.json, package-lock.json, tailwind.config.js
- frontend/static/js/{annotations,claim,comments,sharing}.js
- frontend/templates/{admin_connections,file_annotations,file_summary}.html
- tests/{test_api_files_comprehensive,test_auth_extended,test_sharing,
         test_comments,test_connections,test_imap_profiles,test_api_sessions,
         test_automation,test_classification_rules,test_api_advanced_filters,
         test_api_classification_rules,test_upload_rate_limit,test_api_dropbox,
         test_classify_document,test_comments_ui,test_upload_to_icloud,
         test_api_onedrive_comprehensive,test_frontend_build,test_sentry,
         test_diagnostic,test_database,test_views_dropbox,test_local_auth}.py

Truncated files (content restored):
- app/{auth,config,main,models,celery_worker,database}.py
- app/api/{__init__,api_tokens,diagnostic,dropbox,files,google_drive,
           integrations,local_auth,mobile,onedrive,pipelines,qr_auth,
           settings,url_upload}.py
- app/middleware/upload_rate_limit.py
- app/tasks/upload_to_nextcloud.py
- app/utils/{allowed_types,settings_service,settings_sync,user_scope,webhook}.py
- app/views/{base,dropbox,files,google_drive,onedrive,settings}.py
- docs/{API,AuthenticationSetup,ConfigurationGuide,DatabaseConfiguration,
        DeploymentGuide,DropboxSetup,GoogleDriveSetup,KubernetesDeployment,
        MobileApp,OneDriveSetup,ProductionReadiness,SentrySetup,
        SocialLoginSetup,UserGuide}.md
- frontend/static/{js/upload.js,styles.css}
- frontend/templates/{api_tokens,base,devices,dropbox,dropbox_callback,
                      file_view,files,google_drive,onedrive,onedrive_callback,
                      signup}.html
- frontend/translations/en.json
- migrations/env.py
- tests/{conftest,test_api_integrations,test_api_mobile,test_api_settings,
         test_api_tokens,test_audit_logs,test_duplicates,test_imap_tasks,
         test_setup_wizard,test_views_files_comprehensive}.py

Security fixes kept from post-d2217531 commits:
- app/utils/network.py: DNS SSRF fail-secure fix (06b0fced)
- app/utils/file_operations.py: path traversal fix (1018ea17)
- tests/test_imap_tasks.py: re-applied 4 is_private_ip mock patches

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
Agent-Logs-Url: https://github.com/christianlouis/DocuElevate/sessions/51133dd8-9bec-41ab-aa10-3de753634187
2026-03-23 23:52:39 +00:00

225 lines
7.7 KiB
JavaScript
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
/**
* sharing.js File sharing management UI.
*
* Renders the current shares for a document and lets the file owner
* add new shares, change roles, or revoke access.
*
* Usage:
* initSharing(fileId, i18n)
*
* The i18n object is expected to contain all keys used below.
*/
/* global fetch */
(function () {
'use strict';
var _fileId = null;
var _i18n = {};
// ── DOM helpers ──────────────────────────────────────────────────────────
function _el(id) {
return document.getElementById(id);
}
function _esc(str) {
return String(str)
.replace(/&/g, '&amp;')
.replace(/</g, '&lt;')
.replace(/>/g, '&gt;')
.replace(/"/g, '&quot;')
.replace(/'/g, '&#039;');
}
function _t(key) {
return _i18n[key] || key;
}
// ── API helpers ──────────────────────────────────────────────────────────
function _apiUrl(suffix) {
return '/api/files/' + _fileId + suffix;
}
function _fetchShares() {
return fetch(_apiUrl('/shares'), { credentials: 'same-origin' })
.then(function (r) { return r.json(); });
}
function _addShare(userId, role) {
return fetch(_apiUrl('/shares'), {
method: 'POST',
credentials: 'same-origin',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ shared_with_user_id: userId, role: role }),
}).then(function (r) {
return r.json().then(function (body) {
if (!r.ok) throw new Error((body && body.detail) || r.statusText);
return body;
});
});
}
function _updateRole(shareId, role) {
return fetch(_apiUrl('/shares/' + shareId), {
method: 'PUT',
credentials: 'same-origin',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ role: role }),
}).then(function (r) {
return r.json().then(function (body) {
if (!r.ok) throw new Error((body && body.detail) || r.statusText);
return body;
});
});
}
function _revokeShare(shareId) {
return fetch(_apiUrl('/shares/' + shareId), {
method: 'DELETE',
credentials: 'same-origin',
}).then(function (r) {
return r.json().then(function (body) {
if (!r.ok) throw new Error((body && body.detail) || r.statusText);
return body;
});
});
}
// ── Render ───────────────────────────────────────────────────────────────
function _renderShares(shares) {
var list = _el('sharing-list');
if (!list) return;
if (!shares || shares.length === 0) {
list.innerHTML = '<p style="color:#64748b;font-size:0.875rem;">' + _esc(_t('no_shares')) + '</p>';
return;
}
var rows = shares.map(function (s) {
var roleLabel = s.role === 'editor' ? _t('role_editor') : _t('role_viewer');
return (
'<div style="display:flex;align-items:center;justify-content:space-between;gap:0.5rem;padding:0.5rem 0;border-bottom:1px solid #f1f5f9;">' +
'<span style="font-size:0.875rem;color:#334155;overflow:hidden;text-overflow:ellipsis;white-space:nowrap;flex:1;" ' +
'aria-label="' + _esc(_t('user_id_label') + ': ' + (s.display_name || s.user_id)) + '" ' +
'title="' + _esc(s.user_id) + '">' +
_esc(s.display_name || s.user_id) +
'</span>' +
'<select' +
' data-share-id="' + _esc(s.share_id) + '"' +
' class="sharing-role-select"' +
' aria-label="' + _esc(_t('change_role')) + '"' +
' style="padding:0.25rem 0.5rem;border:1px solid #cbd5e1;border-radius:0.25rem;font-size:0.8rem;background:#fff;"' +
'>' +
'<option value="viewer"' + (s.role === 'viewer' ? ' selected' : '') + '>' + _esc(_t('role_viewer')) + '</option>' +
'<option value="editor"' + (s.role === 'editor' ? ' selected' : '') + '>' + _esc(_t('role_editor')) + '</option>' +
'</select>' +
'<button' +
' data-share-id="' + _esc(s.share_id) + '"' +
' class="sharing-revoke-btn"' +
' aria-label="' + _esc(_t('revoke')) + '"' +
' title="' + _esc(_t('revoke')) + '"' +
' style="padding:0.25rem 0.5rem;background:#fee2e2;color:#b91c1c;border:1px solid #fca5a5;border-radius:0.25rem;font-size:0.8rem;cursor:pointer;"' +
'>' +
'<i class="fas fa-user-minus" aria-hidden="true"></i>' +
'</button>' +
'</div>'
);
});
list.innerHTML = rows.join('');
// Role change handlers
list.querySelectorAll('.sharing-role-select').forEach(function (sel) {
sel.addEventListener('change', function () {
var shareId = sel.getAttribute('data-share-id');
var newRole = sel.value;
_updateRole(shareId, newRole)
.then(function () { _loadAndRender(); })
.catch(function (err) { _showError(err.message); });
});
});
// Revoke handlers
list.querySelectorAll('.sharing-revoke-btn').forEach(function (btn) {
btn.addEventListener('click', function () {
if (!window.confirm(_t('revoke_confirm'))) return;
var shareId = btn.getAttribute('data-share-id');
_revokeShare(shareId)
.then(function () { _loadAndRender(); })
.catch(function (err) { _showError(err.message); });
});
});
}
function _loadAndRender() {
var list = _el('sharing-list');
if (!list) return;
list.innerHTML = '<p style="color:#64748b;font-size:0.875rem;">' + _esc(_t('loading')) + '</p>';
_fetchShares()
.then(function (data) {
// GET /files/{id}/shares returns an array; /files/{id}/shared-with also returns array
var shares = Array.isArray(data) ? data : (data.shares || []);
// Normalise keys: shares list uses share_id, but the shares endpoint returns id
shares = shares.map(function (s) {
return {
share_id: s.share_id || s.id,
user_id: s.user_id || s.shared_with_user_id,
display_name: s.display_name || s.shared_with_user_id || s.user_id,
role: s.role,
};
});
_renderShares(shares);
})
.catch(function (err) {
if (list) list.innerHTML = '<p style="color:#ef4444;font-size:0.875rem;">' + _esc(err.message) + '</p>';
});
}
function _showError(msg) {
var el = _el('sharing-form-error');
if (!el) return;
el.textContent = msg;
el.style.display = 'block';
setTimeout(function () { el.style.display = 'none'; }, 5000);
}
// ── Init ─────────────────────────────────────────────────────────────────
function initSharing(fileId, i18n) {
_fileId = fileId;
_i18n = i18n || {};
_loadAndRender();
var form = _el('sharing-form');
if (!form) return;
form.addEventListener('submit', function (e) {
e.preventDefault();
var userInput = _el('share-user-input');
var roleInput = _el('share-role-input');
var userId = userInput ? userInput.value.trim() : '';
var role = roleInput ? roleInput.value : 'viewer';
if (!userId) {
_showError(_t('error_empty_user'));
return;
}
_addShare(userId, role)
.then(function () {
if (userInput) userInput.value = '';
_loadAndRender();
})
.catch(function (err) { _showError(err.message); });
});
}
// Expose
window.initSharing = initSharing;
})();