Subversion Repositories SmartDukaan

Rev

Blame | Last modification | View Log | RSS feed

-- Register /agedAppleImeis for the partner (FOFO) role.
--
-- RoleInterceptor -> RoleManager.isAuthorizedURI() authorises every non-admin request by
-- regex-matching the URI against dtr.api rows reachable through dtr.role_api. A URI with no
-- matching row throws GE_1004, so a new partner-facing endpoint is denied until it is registered
-- here — the Java change alone is not enough.
--
-- Mirrors how the sibling banner endpoints are registered:
--   id 215  /activatedImeis               GET  FOFO
--   id 285  /activated-imeis-grn-pending  GET  FOFO
--
-- FOFO_ADMIN needs no row: isAdmin() short-circuits before the api lookup.
--
-- Safe to re-run.

INSERT INTO dtr.api (name, uri, method, create_timestamp, update_timestamp)
SELECT 'Aged Apple Stock IMEIs', '/agedAppleImeis', 'GET', NOW(), NOW()
WHERE NOT EXISTS (SELECT 1 FROM dtr.api WHERE uri = '/agedAppleImeis' AND method = 'GET');

INSERT INTO dtr.role_api (role_id, api_id)
SELECT r.id, a.id
FROM dtr.role r
JOIN dtr.api a ON a.uri = '/agedAppleImeis' AND a.method = 'GET'
WHERE r.name = 'FOFO'
  AND NOT EXISTS (SELECT 1 FROM dtr.role_api ra WHERE ra.role_id = r.id AND ra.api_id = a.id);