Skip to content

Commit 4d83b9c

Browse files
committed
Add PATCH /crates/:crate/:version route
Signed-off-by: Rustin170506 <[email protected]>
1 parent 1a2b531 commit 4d83b9c

File tree

3 files changed

+165
-67
lines changed

3 files changed

+165
-67
lines changed

src/controllers/version/metadata.rs

Lines changed: 160 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,17 +6,43 @@
66
77
use axum::extract::Path;
88
use axum::Json;
9+
use crates_io_worker::BackgroundJob;
10+
use diesel::{
11+
BoolExpressionMethods, ExpressionMethods, PgExpressionMethods, QueryDsl, RunQueryDsl,
12+
};
913
use diesel_async::async_connection_wrapper::AsyncConnectionWrapper;
14+
use http::request::Parts;
15+
use http::StatusCode;
16+
use serde::Deserialize;
1017
use serde_json::Value;
18+
use tokio::runtime::Handle;
1119

1220
use crate::app::AppState;
13-
use crate::models::VersionOwnerAction;
21+
use crate::auth::AuthCheck;
22+
use crate::models::token::EndpointScope;
23+
use crate::models::{
24+
insert_version_owner_action, Crate, Rights, Version, VersionAction, VersionOwnerAction,
25+
};
26+
use crate::rate_limiter::LimitedAction;
27+
use crate::schema::versions;
1428
use crate::tasks::spawn_blocking;
15-
use crate::util::errors::{version_not_found, AppResult};
29+
use crate::util::diesel::Conn;
30+
use crate::util::errors::{bad_request, custom, version_not_found, AppResult};
1631
use crate::views::{EncodableDependency, EncodableVersion};
32+
use crate::worker::jobs::{self, UpdateDefaultVersion};
1733

1834
use super::version_and_crate;
1935

36+
#[derive(Deserialize)]
37+
pub struct VersionUpdate {
38+
yanked: Option<bool>,
39+
yank_message: Option<String>,
40+
}
41+
#[derive(Deserialize)]
42+
pub struct VersionUpdateRequest {
43+
version: VersionUpdate,
44+
}
45+
2046
/// Handles the `GET /crates/:crate_id/:version/dependencies` route.
2147
///
2248
/// This information can be obtained directly from the index.
@@ -84,3 +110,135 @@ pub async fn show(
84110
})
85111
.await
86112
}
113+
114+
/// Handles the `PATCH /crates/:crate/:version` route.
115+
///
116+
/// This endpoint allows updating the yanked state of a version, including a yank message.
117+
pub async fn update(
118+
state: AppState,
119+
Path((crate_name, version)): Path<(String, String)>,
120+
req: Parts,
121+
Json(update_request): Json<VersionUpdateRequest>,
122+
) -> AppResult<Json<Value>> {
123+
if semver::Version::parse(&version).is_err() {
124+
return Err(version_not_found(&crate_name, &version));
125+
}
126+
127+
let conn = state.db_write().await?;
128+
spawn_blocking(move || {
129+
let conn: &mut AsyncConnectionWrapper<_> = &mut conn.into();
130+
let (mut version, krate) = version_and_crate(conn, &crate_name, &version)?;
131+
132+
validate_yank_update(&update_request.version, &version)?;
133+
perform_version_yank_update(
134+
&state,
135+
&req,
136+
conn,
137+
&mut version,
138+
&krate,
139+
update_request.version.yanked,
140+
update_request.version.yank_message,
141+
)?;
142+
143+
let published_by = version.published_by(conn);
144+
let actions = VersionOwnerAction::by_version(conn, &version)?;
145+
let updated_version = EncodableVersion::from(version, &krate.name, published_by, actions);
146+
Ok(Json(json!({ "version": updated_version })))
147+
})
148+
.await
149+
}
150+
151+
fn validate_yank_update(update_data: &VersionUpdate, version: &Version) -> AppResult<()> {
152+
match (update_data.yanked, &update_data.yank_message) {
153+
(Some(false), Some(_)) => {
154+
return Err(bad_request("Cannot set yank message when unyanking"));
155+
}
156+
(None, Some(_)) => {
157+
if !version.yanked {
158+
return Err(bad_request(
159+
"Cannot update yank message for a version that is not yanked",
160+
));
161+
}
162+
}
163+
_ => {}
164+
}
165+
Ok(())
166+
}
167+
168+
pub fn perform_version_yank_update(
169+
state: &AppState,
170+
req: &Parts,
171+
conn: &mut impl Conn,
172+
version: &mut Version,
173+
krate: &Crate,
174+
yanked: Option<bool>,
175+
yank_message: Option<String>,
176+
) -> AppResult<()> {
177+
let auth = AuthCheck::default()
178+
.with_endpoint_scope(EndpointScope::Yank)
179+
.for_crate(&krate.name)
180+
.check(req, conn)?;
181+
182+
state
183+
.rate_limiter
184+
.check_rate_limit(auth.user_id(), LimitedAction::YankUnyank, conn)?;
185+
186+
let api_token_id = auth.api_token_id();
187+
let user = auth.user();
188+
let owners = krate.owners(conn)?;
189+
190+
if Handle::current().block_on(user.rights(state, &owners))? < Rights::Publish {
191+
if user.is_admin {
192+
let action = if version.yanked {
193+
"yanking"
194+
} else {
195+
"unyanking"
196+
};
197+
warn!(
198+
"Admin {} is {action} {}@{}",
199+
user.gh_login, krate.name, version.num
200+
);
201+
} else {
202+
return Err(custom(
203+
StatusCode::FORBIDDEN,
204+
"must already be an owner to yank or unyank",
205+
));
206+
}
207+
}
208+
209+
let yanked = yanked.unwrap_or(version.yanked);
210+
// Check if the yanked state or yank message has changed and update if necessary
211+
let updated_cnt = diesel::update(
212+
versions::table.find(version.id).filter(
213+
versions::yanked
214+
.is_distinct_from(yanked)
215+
.or(versions::yank_message.is_distinct_from(&yank_message)),
216+
),
217+
)
218+
.set((
219+
versions::yanked.eq(yanked),
220+
versions::yank_message.eq(&yank_message),
221+
))
222+
.execute(conn)?;
223+
224+
// If no rows were updated, return early
225+
if updated_cnt == 0 {
226+
return Ok(());
227+
}
228+
229+
// Apply the update to the version
230+
version.yanked = yanked;
231+
version.yank_message = yank_message;
232+
233+
let action = if version.yanked {
234+
VersionAction::Yank
235+
} else {
236+
VersionAction::Unyank
237+
};
238+
insert_version_owner_action(conn, version.id, user.id, api_token_id, action)?;
239+
240+
jobs::enqueue_sync_to_index(&krate.name, conn)?;
241+
UpdateDefaultVersion::new(krate.id).enqueue(conn)?;
242+
243+
Ok(())
244+
}

src/controllers/version/yank.rs

Lines changed: 4 additions & 64 deletions
Original file line numberDiff line numberDiff line change
@@ -1,26 +1,15 @@
11
//! Endpoints for yanking and unyanking specific versions of crates
22
3+
use super::metadata::perform_version_yank_update;
34
use super::version_and_crate;
45
use crate::app::AppState;
5-
use crate::auth::AuthCheck;
66
use crate::controllers::helpers::ok_true;
7-
use crate::models::token::EndpointScope;
8-
use crate::models::Rights;
9-
use crate::models::{insert_version_owner_action, VersionAction};
10-
use crate::rate_limiter::LimitedAction;
11-
use crate::schema::versions;
127
use crate::tasks::spawn_blocking;
13-
use crate::util::errors::{custom, version_not_found, AppResult};
14-
use crate::worker::jobs;
15-
use crate::worker::jobs::UpdateDefaultVersion;
8+
use crate::util::errors::{version_not_found, AppResult};
169
use axum::extract::Path;
1710
use axum::response::Response;
18-
use crates_io_worker::BackgroundJob;
19-
use diesel::prelude::*;
2011
use diesel_async::async_connection_wrapper::AsyncConnectionWrapper;
2112
use http::request::Parts;
22-
use http::StatusCode;
23-
use tokio::runtime::Handle;
2413

2514
/// Handles the `DELETE /crates/:crate_id/:version/yank` route.
2615
/// This does not delete a crate version, it makes the crate
@@ -66,57 +55,8 @@ async fn modify_yank(
6655
let conn = state.db_write().await?;
6756
spawn_blocking(move || {
6857
let conn: &mut AsyncConnectionWrapper<_> = &mut conn.into();
69-
70-
let auth = AuthCheck::default()
71-
.with_endpoint_scope(EndpointScope::Yank)
72-
.for_crate(&crate_name)
73-
.check(&req, conn)?;
74-
75-
state
76-
.rate_limiter
77-
.check_rate_limit(auth.user_id(), LimitedAction::YankUnyank, conn)?;
78-
79-
let (version, krate) = version_and_crate(conn, &crate_name, &version)?;
80-
let api_token_id = auth.api_token_id();
81-
let user = auth.user();
82-
let owners = krate.owners(conn)?;
83-
84-
if Handle::current().block_on(user.rights(&state, &owners))? < Rights::Publish {
85-
if user.is_admin {
86-
let action = if yanked { "yanking" } else { "unyanking" };
87-
warn!(
88-
"Admin {} is {action} {}@{}",
89-
user.gh_login, krate.name, version.num
90-
);
91-
} else {
92-
return Err(custom(
93-
StatusCode::FORBIDDEN,
94-
"must already be an owner to yank or unyank",
95-
));
96-
}
97-
}
98-
99-
if version.yanked == yanked {
100-
// The crate is already in the state requested, nothing to do
101-
return ok_true();
102-
}
103-
104-
diesel::update(&version)
105-
.set(versions::yanked.eq(yanked))
106-
.execute(conn)?;
107-
108-
let action = if yanked {
109-
VersionAction::Yank
110-
} else {
111-
VersionAction::Unyank
112-
};
113-
114-
insert_version_owner_action(conn, version.id, user.id, api_token_id, action)?;
115-
116-
jobs::enqueue_sync_to_index(&krate.name, conn)?;
117-
118-
UpdateDefaultVersion::new(krate.id).enqueue(conn)?;
119-
58+
let (mut version, krate) = version_and_crate(conn, &crate_name, &version)?;
59+
perform_version_yank_update(&state, &req, conn, &mut version, &krate, Some(yanked), None)?;
12060
ok_true()
12161
})
12262
.await

src/router.rs

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ pub fn build_axum_router(state: AppState) -> Router<()> {
4545
.route("/api/v1/crates/:crate_id", get(krate::metadata::show))
4646
.route(
4747
"/api/v1/crates/:crate_id/:version",
48-
get(version::metadata::show),
48+
get(version::metadata::show).patch(version::metadata::update),
4949
)
5050
.route(
5151
"/api/v1/crates/:crate_id/:version/readme",

0 commit comments

Comments
 (0)