fix: memberikan akses ke mentor untuk /project/{id_project} route

This commit is contained in:
Rafi Athallah
2026-07-10 15:57:57 +07:00
parent 54ad32137f
commit bbfa152fc2
3 changed files with 307 additions and 5 deletions
@@ -221,10 +221,21 @@ class CertificateService {
async getProjectCertificates(id_project, actor) {
try {
if (!actor?.id) {
return error(new BadRequestError('Admin ID is required'));
return error(new BadRequestError('User ID is required'));
}
if (actor.role !== 'admin') {
const project = await certificateRepository.findProjectById(id_project);
if (!project) {
return error(new NotFoundError('Project not found'));
}
if (actor.role === 'mentor') {
if (project.id_admin !== parseInt(actor.id)) {
return error(
new ForbiddenError('Access denied: you are not the mentor of this project'),
);
}
} else if (actor.role !== 'admin') {
return error(
new ForbiddenError('Access denied: only admins/mentors can view project certificates'),
);
+3 -3
View File
@@ -287,7 +287,7 @@ router.get('/detail/:id', verifyJWT, certificateController.getCertificateDetail)
* @swagger
* /certificate-api/project/{id_project}:
* get:
* summary: Get certificates issued for a specific project (Admin only)
* summary: Get certificates issued for a specific project (Admin/Mentor only)
* description: Admin/Mentor can retrieve all certificates issued to interns for a specific project.
* tags: [Certificate]
* security:
@@ -324,11 +324,11 @@ router.get('/detail/:id', verifyJWT, certificateController.getCertificateDetail)
* 401:
* description: Unauthorized
* 403:
* description: Forbidden (Admin only)
* description: Forbidden (Admin/Mentor only)
* 500:
* description: Internal server error
*/
router.get('/project/:id_project', verifyJWT, isAdmin, certificateController.getProjectCertificates);
router.get('/project/:id_project', verifyJWT, isMentorOrAdmin, certificateController.getProjectCertificates);
/**
* @swagger
* /certificate-api/verify-uuid/{uuid}: