updated admin page with more functionality, simplified burger menu and added many-to-many parent-child relationship
This commit is contained in:
@@ -17,6 +17,7 @@ from baby_monitor.repositories.child.sqlite_child import SQLiteChildRepository
|
||||
from baby_monitor.repositories.dependencies.get_child_repository import (
|
||||
get_child_repository,
|
||||
)
|
||||
from baby_monitor.utils.access_control import verify_child_access
|
||||
|
||||
router = APIRouter(prefix="/api/sleep", tags=["sleep"])
|
||||
|
||||
@@ -30,12 +31,7 @@ def create_sleep(
|
||||
) -> SleepResponse:
|
||||
"""Create a new sleep log entry."""
|
||||
# Verify the child belongs to the authenticated user
|
||||
child = child_repo.get_by_id(request.child_id)
|
||||
if not child:
|
||||
raise HTTPException(status_code=404, detail="Child not found")
|
||||
|
||||
if child["user_id"] != user_id:
|
||||
raise HTTPException(status_code=403, detail="Access denied to this child")
|
||||
verify_child_access(child_repo, request.child_id, user_id)
|
||||
|
||||
sleep = sleep_repo.create(
|
||||
child_id=request.child_id,
|
||||
@@ -91,9 +87,7 @@ def get_sleep(
|
||||
raise HTTPException(status_code=404, detail="Sleep log not found")
|
||||
|
||||
# Verify the sleep belongs to user's child
|
||||
child = child_repo.get_by_id(sleep["child_id"])
|
||||
if not child or child["user_id"] != user_id:
|
||||
raise HTTPException(status_code=403, detail="Access denied")
|
||||
verify_child_access(child_repo, sleep["child_id"], user_id)
|
||||
|
||||
return SleepResponse(**sleep)
|
||||
|
||||
@@ -113,9 +107,7 @@ def update_sleep(
|
||||
raise HTTPException(status_code=404, detail="Sleep log not found")
|
||||
|
||||
# Verify the sleep belongs to user's child
|
||||
child = child_repo.get_by_id(sleep["child_id"])
|
||||
if not child or child["user_id"] != user_id:
|
||||
raise HTTPException(status_code=403, detail="Access denied")
|
||||
verify_child_access(child_repo, sleep["child_id"], user_id)
|
||||
|
||||
updated = sleep_repo.update(
|
||||
sleep_id=sleep_id,
|
||||
@@ -142,9 +134,7 @@ def delete_sleep(
|
||||
raise HTTPException(status_code=404, detail="Sleep log not found")
|
||||
|
||||
# Verify the sleep belongs to user's child
|
||||
child = child_repo.get_by_id(sleep["child_id"])
|
||||
if not child or child["user_id"] != user_id:
|
||||
raise HTTPException(status_code=403, detail="Access denied")
|
||||
verify_child_access(child_repo, sleep["child_id"], user_id)
|
||||
|
||||
success = sleep_repo.delete(sleep_id)
|
||||
if not success:
|
||||
|
||||
Reference in New Issue
Block a user