Skip to content

API MSN Events v1.5.0 Release Notes

Latest

Choose a tag to compare

@Xoriax Xoriax released this 31 Oct 13:12

Permissions and Access Improvements

New Features

Extended Permissions System

  • Album access: Creators, event organizers, and group administrators can now access and manage albums
  • Photo management: Extended access to photo authors, album creators, organizers, and group administrators
  • Poll voting: Poll creators, organizers, and group administrators can now vote on their own polls
  • Ticket purchasing: Event organizers and group administrators can purchase tickets for their events

Enhanced Group Management

  • New endpoint: POST /groups/:id/promote/:userId to promote members to administrators
  • Flexible group leaving: Administrators can leave groups after promoting other administrators
  • Smart validation: Protection against removing the last administrator

Technical Improvements

Authentication Middleware Updates

  • Multi-parameter support: Middlewares now handle id, groupId, and eventId parameters
  • Hierarchical permissions: Organizers and administrators automatically inherit participant/member rights
  • Debug logging: Added detailed logs for permission troubleshooting

Controller Updates

  • Albums: Added GroupModel support for extended access permissions
  • Photos: Updated checkPhotoAccess middleware with 4 parameters (added GroupModel)
  • Polls: Inclusive voting logic for creators and administrators
  • Tickets: Purchase authorization for organizers and group administrators

Architecture Enhancements

  • GroupSchema imports added to all necessary controllers
  • Updated constructors with this.GroupModel
  • Populated groupId relations in event queries
  • Full ESLint compliance (100 character limit, consistent indentation)

Documentation

Updated README

  • Simplified API documentation with Postman collection link
  • Removed detailed endpoint listings in favor of Postman collection
  • Focus on architecture and concepts

Improved Error Messages

  • More descriptive permission error messages
  • Clear indication of authorized roles for each action
  • Consistent HTTP status codes

Migration and Compatibility

This version is fully backward compatible. Existing endpoints continue to work normally with extended permissions for improved user experience.

Technical Details

Files Modified:

  • src/controllers/albums.controller.mjs
  • src/controllers/photos.controller.mjs
  • src/controllers/polls.controller.mjs
  • src/controllers/tickets.controller.mjs
  • src/controllers/groups.controller.mjs
  • src/controllers/discussions.controller.mjs
  • src/middleware/auth.mjs
  • README.md

Key Changes:

  • Enhanced middleware functions for better parameter handling
  • Extended permission checks to include creators and administrators
  • Improved group management with promotion capabilities
  • Streamlined documentation approach

This release significantly improves user experience by allowing creators, organizers, and administrators to naturally interact with their own content while maintaining API security.