Skip to content

Commit 4f590c3

Browse files
committed
let editors read a draft page
1 parent 288699e commit 4f590c3

2 files changed

Lines changed: 39 additions & 0 deletions

File tree

‎apps/api/src/routes/pages.test.ts‎

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -154,6 +154,30 @@ describe("page routes", () => {
154154
await app.close()
155155
})
156156

157+
it("lets an editor read a draft the public cannot see", async () => {
158+
await app.inject({
159+
method: "POST",
160+
url: "/api/pages/wip",
161+
headers: { ...origin, cookie },
162+
payload: { content: validPage },
163+
})
164+
// Public sees nothing (it is a draft).
165+
const pub = await app.inject({ method: "GET", url: "/api/pages/wip" })
166+
expect(pub.statusCode).toBe(404)
167+
// The editor can read it.
168+
const draft = await app.inject({
169+
method: "GET",
170+
url: "/api/pages/wip/draft",
171+
headers: { cookie },
172+
})
173+
expect(draft.statusCode).toBe(200)
174+
expect((draft.json() as { status: string }).status).toBe("draft")
175+
// Without editor rights it is refused.
176+
const anon = await app.inject({ method: "GET", url: "/api/pages/wip/draft" })
177+
expect(anon.statusCode).toBe(401)
178+
await app.close()
179+
})
180+
157181
it("rejects a page with an unsafe url", async () => {
158182
const res = await app.inject({
159183
method: "POST",

‎apps/api/src/routes/pages.ts‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -57,6 +57,21 @@ export async function registerPageRoutes(app: FastifyInstance, deps: PageDeps) {
5757
return { slug: page.slug, version: page.version, content: page.content }
5858
})
5959

60+
// Editor: read the current page including a draft, so an editor can reload
61+
// work in progress that the public endpoint hides.
62+
app.get("/api/pages/:slug/draft", async (req, reply) => {
63+
if (!(await requireEditor(req, reply))) return
64+
const { slug } = req.params as { slug: string }
65+
const page = deps.pages.get(slug)
66+
if (!page) return reply.code(404).send({ error: "not found" })
67+
return {
68+
slug: page.slug,
69+
version: page.version,
70+
status: page.status,
71+
content: page.content,
72+
}
73+
})
74+
6075
// Editor: create or update a page. The content is validated against the page
6176
// schema, so a stored page can never carry an unknown component or an unsafe
6277
// url no matter what the client or an AI generator sends.

0 commit comments

Comments
 (0)