xssbook2/db/rest/comment/api_comment_update.sql

51 lines
975 B
MySQL
Raw Normal View History

CREATE FUNCTION _api.comment_update()
RETURNS TRIGGER
LANGUAGE plpgsql VOLATILE
AS $BODY$
DECLARE
_user_id INTEGER;
_changed BOOLEAN;
BEGIN
_user_id = _api.get_user_id();
_changed = FALSE;
IF OLD.user_id <> _user_id THEN
PERFORM _api.raise_deny();
END IF;
NEW.content = COALESCE(NEW.content, OLD.content);
NEW.content := _api.trim(NEW.content);
PERFORM _api.validate_text(
_text => NEW.content,
_column => 'content',
_min => 1,
_max => 1024
);
IF NEW.content IS DISTINCT FROM OLD.content THEN
_changed = TRUE;
END IF;
IF _changed THEN
UPDATE admin.comment
SET content = NEW.content
WHERE id = OLD.id;
END IF;
RETURN NEW;
END
$BODY$;
GRANT EXECUTE ON FUNCTION _api.comment_update()
TO rest_user;
GRANT UPDATE ON TABLE api.comment
TO rest_user;
GRANT UPDATE ON TABLE admin.comment
TO rest_user;
CREATE TRIGGER api_comment_update_trgr
INSTEAD OF UPDATE
ON api.comment
FOR EACH ROW
EXECUTE PROCEDURE _api.comment_update();