| 12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849 |
- <?php
- /**
- * Admin JSON API for putting one image into a topic (or back into none).
- *
- * Creating, renaming, reordering and deleting topics are plain form posts on
- * gallery-edit.php — they change the page anyway. Assignment is the exception:
- * dragging a photo from one section to another has to happen without a reload,
- * or organising a few hundred images would be a few hundred page loads.
- *
- * Fields: slug, action (assign), key (the image's S3 key), topic (a topic id,
- * or empty for no topic).
- */
- require dirname(__DIR__) . '/app/bootstrap.php';
- if (!auth_check()) {
- json_response(['error' => 'Not authenticated'], 401);
- }
- if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
- json_response(['error' => 'POST only'], 405);
- }
- csrf_verify();
- // Nothing here is slow, but a drag over many images fires these back to back
- // and PHP holds the session file exclusively for the whole request.
- session_write_close();
- $slug = (string)($_POST['slug'] ?? '');
- $gallery = gallery_load($slug);
- if ($gallery === null) {
- json_response(['error' => 'Unknown gallery'], 404);
- }
- if (($_POST['action'] ?? '') !== 'assign') {
- json_response(['error' => 'Unknown action'], 400);
- }
- $topic = (string)($_POST['topic'] ?? '');
- // Checked against this gallery's topics, so a stale page cannot write a
- // reference to one that has since been deleted. gallery_assign_topic() checks
- // again under its lock, where the answer is authoritative.
- if ($topic !== '' && !isset(gallery_topic_map($gallery)[$topic])) {
- json_response(['error' => 'Unknown topic'], 400);
- }
- if (!gallery_assign_topic($slug, (string)($_POST['key'] ?? ''), $topic)) {
- json_response(['error' => 'Unknown image'], 404);
- }
- json_response(['ok' => true]);
|