// Player · Teams — the caller's own Teams and their own access on one. // // Mounted at /api/v1/player/teams by player/index.js, which already applied // `noindex, requireAuth`. No extra gate: both handlers are self-scoped to // req.user.id and neither takes a user id from the caller. // // **Staff are a superset of players.** This group is open to any authenticated // account, not just role 'player' — a moderator is in guilds too, and gating on // the role would 403 them off their own Teams. That mistake has been made here // once already (see player/index.js). // // Leader-exercised actions — granting forum access — land in phase 4 and will // live under this same prefix rather than under /admin: a leader is a player, and // the /admin tier gate is requireRole('admin','editor','moderator'), so putting a // leader endpoint behind it would mean widening that gate. const express = require('express') const ctrl = require('./teams.controller') const teamsRouter = express.Router() teamsRouter.get( '/', // #swagger.tags = ['Player · Teams'] // #swagger.summary = 'List the caller’s Teams, with the reason for each' // #swagger.description = 'Membership and forum grants are separate authority paths, so each Team carries `reason`: membership | grant | both. A Team hidden from public surfaces is still listed here — suppression is a public-surface rule, and a member is not a member of the public.' // #swagger.security = [{ "cookieAuth": [] }, { "bearerAuth": [] }] /* #swagger.responses[200] = { description: 'The caller’s Teams', content: { "application/json": { schema: { $ref: "#/components/schemas/PlayerTeamList" } } } } */ /* #swagger.responses[403] = { description: 'Account not active (disabled/banned)', content: { "application/json": { schema: { $ref: "#/components/schemas/Error" } } } } */ ctrl.listMine, ) teamsRouter.get( '/:slug/access', // #swagger.tags = ['Player · Teams'] // #swagger.summary = 'The caller’s own resolved access on one Team' // #swagger.description = 'Reports viaMembership and viaGrant separately, and keeps both when both hold: the UI presents membership as the current reason while the grant survives as audit history.' // #swagger.parameters['slug'] = { in: 'path', required: true, schema: { type: 'string' }, description: 'The Team slug.' } // #swagger.security = [{ "cookieAuth": [] }, { "bearerAuth": [] }] /* #swagger.responses[200] = { description: 'The caller’s access', content: { "application/json": { schema: { $ref: "#/components/schemas/PlayerTeamAccess" } } } } */ /* #swagger.responses[404] = { description: 'No such Team', content: { "application/json": { schema: { $ref: "#/components/schemas/Error" } } } } */ ctrl.getMyAccess, ) module.exports = teamsRouter