feat: add branches feature, security audit, and multi-branch support
This commit is contained in:
@@ -1002,6 +1002,18 @@ app.delete('/api/groups/:id/photos/:photoId', requireAdmin, async (req, res) =>
|
||||
res.json({ ok: true });
|
||||
});
|
||||
|
||||
app.put('/api/groups/:id/photos/:photoId/cover', requireAdmin, async (req, res) => {
|
||||
const { rows } = await pool.query(
|
||||
'SELECT photo_path FROM group_photos WHERE id = $1 AND group_id = $2',
|
||||
[req.params.photoId, req.params.id]
|
||||
);
|
||||
if (!rows.length) return res.status(404).json({ error: 'Не найдено' });
|
||||
await pool.query('UPDATE groups SET cover_path = $1 WHERE id = $2', [rows[0].photo_path, req.params.id]);
|
||||
await logAudit(req, 'group.photo.set_cover', { group_id: req.params.id, photo_id: req.params.photoId });
|
||||
const { rows: gRows } = await pool.query('SELECT * FROM groups WHERE id = $1', [req.params.id]);
|
||||
res.json(gRows[0]);
|
||||
});
|
||||
|
||||
// --- Students CRUD ---
|
||||
app.get('/api/students', apiLimiter, async (_, res) => {
|
||||
const { rows } = await pool.query(
|
||||
|
||||
Reference in New Issue
Block a user