class UserApiController extends ApiController
{
- protected $userRepo;
+ protected UserRepo $userRepo;
- protected $fieldsToExpose = [
- 'email', 'created_at', 'updated_at', 'last_activity_at', 'external_auth_id'
+ protected array $fieldsToExpose = [
+ 'email', 'created_at', 'updated_at', 'last_activity_at', 'external_auth_id',
];
public function __construct(UserRepo $userRepo)
$this->middleware(function ($request, $next) {
$this->checkPermission('users-manage');
$this->preventAccessInDemoMode();
+
return $next($request);
});
}
{
return [
'create' => [
- 'name' => ['required', 'min:2'],
+ 'name' => ['required', 'min:2', 'max:100'],
'email' => [
- 'required', 'min:2', 'email', new Unique('users', 'email')
+ 'required', 'min:2', 'email', new Unique('users', 'email'),
],
'external_auth_id' => ['string'],
- 'language' => ['string'],
- 'password' => [Password::default()],
- 'roles' => ['array'],
- 'roles.*' => ['integer'],
- 'send_invite' => ['boolean'],
+ 'language' => ['string', 'max:15', 'alpha_dash'],
+ 'password' => [Password::default()],
+ 'roles' => ['array'],
+ 'roles.*' => ['integer'],
+ 'send_invite' => ['boolean'],
],
'update' => [
- 'name' => ['min:2'],
+ 'name' => ['min:2', 'max:100'],
'email' => [
'min:2',
'email',
- (new Unique('users', 'email'))->ignore($userId ?? null)
+ (new Unique('users', 'email'))->ignore($userId ?? null),
],
'external_auth_id' => ['string'],
- 'language' => ['string'],
- 'password' => [Password::default()],
- 'roles' => ['array'],
- 'roles.*' => ['integer'],
+ 'language' => ['string', 'max:15', 'alpha_dash'],
+ 'password' => [Password::default()],
+ 'roles' => ['array'],
+ 'roles.*' => ['integer'],
],
'delete' => [
'migrate_ownership_id' => ['integer', 'exists:users,id'],
*/
public function list()
{
- $users = $this->userRepo->getApiUsersBuilder();
+ $users = User::query()->select(['*'])
+ ->scopes('withLastActivityAt')
+ ->with(['avatar']);
return $this->apiListingResponse($users, [
'id', 'name', 'slug', 'email', 'external_auth_id',
/**
* Create a new user in the system.
+ * Requires permission to manage users.
*/
public function create(Request $request)
{
/**
* Update an existing user in the system.
+ * Requires permission to manage users.
+ *
* @throws UserUpdateException
*/
public function update(Request $request, string $id)