Files
alfresco-community-repo/source/java/org/alfresco/repo/invitation/script/ScriptNominatedInvitation.java
Andrei Rebegea cc9876de74 MNT-17427 : api/invite/cancel deletes records in the database with a GET: CSRF/XSS attack
- delete the script/org/alfresco/repository/invite/invite.get
   - use the alternatives: script/org/alfresco/repository/site/invitation/invitation.post and script/org/alfresco/repository/site/invitation/invitation.delete
   - updating the tests
   - updating the controller for the invitation.delete to a java controller
   - fix test fallout (SiteServiceTest testInviteDisabledUser - expected error status code)
   - improve security by allowing only invitationIDs that belong the the site passed as parameter to be canceled
   - be consistent and return 404 when an invitationID can not be found

git-svn-id: https://svn.alfresco.com/repos/alfresco-enterprise/alfresco/BRANCHES/DEV/5.2.N/root@135255 c4b6b30b-aa2e-2d43-bbcb-ca4b014f7261
2017-02-20 09:04:45 +00:00

99 lines
2.9 KiB
Java

/*
* #%L
* Alfresco Repository
* %%
* Copyright (C) 2005 - 2016 Alfresco Software Limited
* %%
* This file is part of the Alfresco software.
* If the software was purchased under a paid Alfresco license, the terms of
* the paid license agreement will prevail. Otherwise, the software is
* provided under the following open source license terms:
*
* Alfresco is free software: you can redistribute it and/or modify
* it under the terms of the GNU Lesser General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* Alfresco is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Lesser General Public License for more details.
*
* You should have received a copy of the GNU Lesser General Public License
* along with Alfresco. If not, see <http://www.gnu.org/licenses/>.
* #L%
*/
package org.alfresco.repo.invitation.script;
import java.util.Date;
import org.alfresco.service.cmr.invitation.InvitationService;
import org.alfresco.service.cmr.invitation.NominatedInvitation;
import org.springframework.extensions.surf.util.ISO8601DateFormat;
/**
* Java script moderated invitation for the Java Script API
*
* @author mrogers
*/
public class ScriptNominatedInvitation extends ScriptInvitation<NominatedInvitation> implements java.io.Serializable
{
private static final long serialVersionUID = 6079656007339750930L;
public ScriptNominatedInvitation(NominatedInvitation invitation, InvitationService invitationService)
{
super(invitation, invitationService);
}
/**
* @see org.alfresco.service.cmr.invitation.NominatedInvitation#getInviteeEmail()
*/
@Override
public String getInviteeEmail()
{
return getInvitation().getInviteeEmail();
}
/**
* @see org.alfresco.service.cmr.invitation.NominatedInvitation#getInviteeFirstName()
*/
@Override
public String getInviteeFirstName()
{
return getInvitation().getInviteeFirstName();
}
/**
* @see org.alfresco.service.cmr.invitation.NominatedInvitation#getInviteeLastName()
*/
@Override
public String getInviteeLastName()
{
return getInvitation().getInviteeLastName();
}
public void accept(String reason)
{
getInvitationService().accept(getInviteId(), reason);
}
/**
* Which role to be added with
* @return the roleName
*/
public Date getSentInviteDate()
{
return getInvitation().getSentInviteDate();
}
public String getSentInviteDateAsISO8601()
{
return ISO8601DateFormat.format(getSentInviteDate());
}
public String getInviteTicket()
{
return getInvitation().getTicket();
}
}