[CORL-409] Prevent users from ignoring staff members (#2355)

* Throw error if user tries to ignore a staff member

Throws a UserCannotBeIgnoredError if a user tries to ignore
a user who is a staff member. A staff member in this case is
considered anyone who has a role of staff, moderator, or admin.

CORL-409

* Prevent users from ignoring staff in the user info popover

Creates the staff roles in a constant next to the user model.
Uses this to add a computed property to the user resolver.

CORL-409

* Remove unnecessary async declaration from userIsStaff helper function

CORL-409

* Specify ignoreable on users in client test fixtures

Allows the tests to pass for the required computed property
of ignoreable that is computed by whether a user is a staff
member or not.

CORL-409

* Update more fixtures with ignoreable property on mocked users/commenters

CORL-409

* Consolidate ignore-able calculation into re-usable helper methods

Re-use the logic for whether a role is a staff member to
clearly define when a user is ignore-able or not across the
business logic.

CORL-409

* Set the ignoreable optimisticResponse on comment mutations

We have set the ignoreable value in the graphQL schema, so now
the optimisticResponses are looking for a default value to use
until the data result arrives. Put to false since the ignoreable
value is set on our author, we likely don't want to ignore ourselves.

CORL-409
This commit is contained in:
Nick Funk
2019-06-13 17:24:50 +00:00
committed by Wyatt Johnson
parent 3947b143cb
commit 662f5ce314
14 changed files with 78 additions and 6 deletions
@@ -6,6 +6,7 @@ import {
GQLUserTypeResolver,
} from "coral-server/graph/tenant/schema/__generated__/types";
import * as user from "coral-server/models/user";
import { roleIsStaff } from "coral-server/models/user/helpers";
import { UserStatusInput } from "./UserStatus";
import { getRequestedFields } from "./util";
@@ -41,4 +42,5 @@ export const User: GQLUserTypeResolver<user.User> = {
}),
ignoredUsers: ({ ignoredUsers }, input, ctx, info) =>
maybeLoadOnlyIgnoredUserID(ctx, info, ignoredUsers),
ignoreable: ({ role }) => !roleIsStaff(role),
};
@@ -1456,6 +1456,13 @@ type User {
permit: [SUSPENDED, BANNED]
)
"""
ignoreable is a computed property based on the
user's role. Typically, users with elevated privileges
aren't allowed to be ignored.
"""
ignoreable: Boolean!
"""
comments are the comments written by the User.
"""