Update project config and documentation, add admin invite script,
implement membersOnly event visibility
This commit is contained in:
parent
96470a604a
commit
9e18560ebf
9 changed files with 387 additions and 50 deletions
|
|
@ -1,4 +1,6 @@
|
|||
import { loadPublicEvent } from '../../utils/loadEvent.js'
|
||||
import { getOptionalMember } from '../../utils/auth.js'
|
||||
import { hasMemberAccess } from '../../utils/tickets.js'
|
||||
|
||||
export default defineEventHandler(async (event) => {
|
||||
try {
|
||||
|
|
@ -8,6 +10,17 @@ export default defineEventHandler(async (event) => {
|
|||
select: '-registrations.email'
|
||||
})
|
||||
|
||||
// Members-only events are hidden from non-members (parallel to isVisible).
|
||||
// Registration/ticket endpoints still surface a "members only" error so an
|
||||
// authenticated guest sees actionable copy when posting; here we just 404.
|
||||
if (eventData.membersOnly) {
|
||||
const requester = await getOptionalMember(event)
|
||||
const canSee = requester?.role === 'admin' || hasMemberAccess(requester)
|
||||
if (!canSee) {
|
||||
throw createError({ statusCode: 404, statusMessage: 'Event not found' })
|
||||
}
|
||||
}
|
||||
|
||||
return {
|
||||
...eventData,
|
||||
id: eventData._id.toString(),
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue