fix: do not send channel's secret to frontend

This commit is contained in:
JustSong
2023-05-15 23:30:29 +08:00
parent 8ead1f76cd
commit e495960d0e
2 changed files with 9 additions and 4 deletions
+2 -2
View File
@@ -83,7 +83,7 @@ func GetChannel(c *gin.Context) {
}) })
return return
} }
channel_, err := model.GetChannelById(id, userId) channel_, err := model.GetChannelById(id, userId, false)
if err != nil { if err != nil {
c.JSON(http.StatusOK, gin.H{ c.JSON(http.StatusOK, gin.H{
"success": false, "success": false,
@@ -183,7 +183,7 @@ func UpdateChannel(c *gin.Context) {
}) })
return return
} }
oldChannel, err := model.GetChannelById(channel_.Id, userId) oldChannel, err := model.GetChannelById(channel_.Id, userId, true)
if err != nil { if err != nil {
c.JSON(http.StatusOK, gin.H{ c.JSON(http.StatusOK, gin.H{
"success": false, "success": false,
+7 -2
View File
@@ -45,12 +45,17 @@ type BriefChannel struct {
Description string `json:"description"` Description string `json:"description"`
} }
func GetChannelById(id int, userId int) (*Channel, error) { func GetChannelById(id int, userId int, selectAll bool) (*Channel, error) {
if id == 0 || userId == 0 { if id == 0 || userId == 0 {
return nil, errors.New("id 或 userId 为空!") return nil, errors.New("id 或 userId 为空!")
} }
c := Channel{Id: id, UserId: userId} c := Channel{Id: id, UserId: userId}
err := DB.Where(c).First(&c).Error var err error
if selectAll {
err = DB.Where(c).First(&c).Error
} else {
err = DB.Omit("secret").Where(c).First(&c).Error
}
return &c, err return &c, err
} }