const Errors = { NOT_ENOUGH_RIGHTS: { notEnoughRights: 'Not enough rights', }, ATTACHMENT_NOT_FOUND: { attachmentNotFound: 'Attachment not found', }, }; module.exports = { inputs: { id: { type: 'string', regex: /^[0-9]+$/, required: true, }, }, exits: { notEnoughRights: { responseType: 'forbidden', }, attachmentNotFound: { responseType: 'notFound', }, }, async fn(inputs) { const { currentUser } = this.req; const path = await sails.helpers.attachments .getProjectPath(inputs.id) .intercept('pathNotFound', () => Errors.ATTACHMENT_NOT_FOUND); let { attachment } = path; const { card, board } = path; const boardMembership = await BoardMembership.findOne({ boardId: board.id, userId: currentUser.id, }); if (!boardMembership) { throw Errors.ATTACHMENT_NOT_FOUND; // Forbidden } if (boardMembership.role !== BoardMembership.Roles.EDITOR) { throw Errors.NOT_ENOUGH_RIGHTS; } attachment = await sails.helpers.attachments.deleteOne(attachment, board, card, this.req); if (!attachment) { throw Errors.ATTACHMENT_NOT_FOUND; } return { item: attachment, }; }, };