Ensure completed request view is readonly
This commit is contained in:
@@ -563,6 +563,10 @@ export const app = new Elysia()
|
||||
params: t.Object({ id: t.String() })
|
||||
})
|
||||
.post("/:id/request-action", async ({ params: { id }, body: { reviewerNotes, activityVerifications } }) => {
|
||||
const verification = await s.Verifications.get(id);
|
||||
if (!verification) throw new NotFoundError("Verification not found");
|
||||
if (verification.status === "completed") throw status(409, { error: "Cannot modify a completed verification" });
|
||||
|
||||
const updated = await s.Verifications.requestAction(id, reviewerNotes ?? null, activityVerifications);
|
||||
if (!updated) throw new NotFoundError("Verification not found");
|
||||
}, {
|
||||
@@ -573,6 +577,10 @@ export const app = new Elysia()
|
||||
})
|
||||
})
|
||||
.post("/:id/complete", async ({ params: { id }, body: { activityVerifications }, accountId }) => {
|
||||
const verification = await s.Verifications.get(id);
|
||||
if (!verification) throw new NotFoundError("Verification not found");
|
||||
if (verification.status === "completed") throw status(409, { error: "Cannot modify a completed verification" });
|
||||
|
||||
const updated = await s.Verifications.complete(id, accountId, activityVerifications);
|
||||
if (!updated) throw new NotFoundError("Verification not found");
|
||||
}, {
|
||||
|
||||
Reference in New Issue
Block a user