| 37597 |
amit |
1 |
-- Register /agedAppleImeis for the partner (FOFO) role.
|
|
|
2 |
--
|
|
|
3 |
-- RoleInterceptor -> RoleManager.isAuthorizedURI() authorises every non-admin request by
|
|
|
4 |
-- regex-matching the URI against dtr.api rows reachable through dtr.role_api. A URI with no
|
|
|
5 |
-- matching row throws GE_1004, so a new partner-facing endpoint is denied until it is registered
|
|
|
6 |
-- here — the Java change alone is not enough.
|
|
|
7 |
--
|
|
|
8 |
-- Mirrors how the sibling banner endpoints are registered:
|
|
|
9 |
-- id 215 /activatedImeis GET FOFO
|
|
|
10 |
-- id 285 /activated-imeis-grn-pending GET FOFO
|
|
|
11 |
--
|
|
|
12 |
-- FOFO_ADMIN needs no row: isAdmin() short-circuits before the api lookup.
|
|
|
13 |
--
|
|
|
14 |
-- Safe to re-run.
|
|
|
15 |
|
|
|
16 |
INSERT INTO dtr.api (name, uri, method, create_timestamp, update_timestamp)
|
|
|
17 |
SELECT 'Aged Apple Stock IMEIs', '/agedAppleImeis', 'GET', NOW(), NOW()
|
|
|
18 |
WHERE NOT EXISTS (SELECT 1 FROM dtr.api WHERE uri = '/agedAppleImeis' AND method = 'GET');
|
|
|
19 |
|
|
|
20 |
INSERT INTO dtr.role_api (role_id, api_id)
|
|
|
21 |
SELECT r.id, a.id
|
|
|
22 |
FROM dtr.role r
|
|
|
23 |
JOIN dtr.api a ON a.uri = '/agedAppleImeis' AND a.method = 'GET'
|
|
|
24 |
WHERE r.name = 'FOFO'
|
|
|
25 |
AND NOT EXISTS (SELECT 1 FROM dtr.role_api ra WHERE ra.role_id = r.id AND ra.api_id = a.id);
|