【问题标题】:Meteor : updating collection fail流星:更新收集失败
【发布时间】:2015-05-04 22:41:51
【问题描述】:

我正在使用 Meteor.js 构建一个好友列表管理系统。

为此,我有一个用户列表,我可以点击它来邀请他们加入我的朋友列表。

这是我的代码。我分别在 e.target.id 和 e.target.name 中获取了另一个用户 _id 和 profile.name。

Template.talkers.events({
  "click .addTalker": function(e, tmpl){
    /* Checking if there already is a pending request */
    var bool = false;
    for(var i = 0; i < Meteor.user().profile.friends.length; i++){
      if(Meteor.user().profile.friends[i].id == id){
        bool = false;
      }else{
        bool = true;
        break;
      }
    }

    /* If there isn't */
    if(!bool){

      /* I add the other user in my friend list with a pending status */
      Meteor.users.update({_id: Meteor.userId()}, {
        $push: {'profile.friends': {
          id: e.target.id,
          status: 0
          }
        }
      });

      /* Then, I add the request on the other user profile */
      Meteor.users.update({_id: e.target.id}, {
        $set: {'profile.friends': {
          id: Meteor.userId(),
          status: 2
          }
        }
      });

      /* And I create a new notification for the other user */
      var notifId = Meteor.users.findOne({_id: e.target.id}).profile.notifications.length;
      console.log(notifId + 1);
      Meteor.users.update({_id: e.target.id}, {
        $push: {'profile.notifications': {
          id: (notifId + 1),
          type: 1,
          img: null,
          link: "/profile"},
        }
      });
      alert("An invitation has been sent to " + e.target.name)
    }
  }
  });
}

问题是,如果我在我的朋友列表中正确添加了另一个用户,并且状态为挂起,那么对于另一个用户的两次更新,我会收到两次相同的错误。目前,我将所有用户的个人资料中的_id和一些信息发布到客户端。我猜这个问题来自这样一个事实,我可能不会被允许从客户端重写另一个用户配置文件,而只是阅读它。然后,我想我应该通过方法调用在服务器端进行操作?

您能否确认我的问题,或者向我解释如何进行?

谢谢你

【问题讨论】:

    标签: mongodb meteor


    【解决方案1】:

    是的,其他用户缺乏更新权限可能是这里的问题。从那里,您有两个选择:

    1. 如您所说,使用服务器方法为您执行更新(推荐)
    2. 如果您信任您的用户(在大多数情况下,我的拙见:不信任),您可以在您希望的条件下为allow 更新Meteor.users 的权限。然后您应该能够在客户端中保留更新调用。

    【讨论】:

    • 那我会在服务器端做。但是,我很好奇:允许用户在服务器端做这件事有好处吗?程序化的东西?还是没有?例如,即使对于用户()以外的其他集合,为什么我宁愿让我的用户通过上传图像来更改我的头像集合,而不是将其传输到服务器端以更安全的方式做同样的事情呢?写下我的问题,我猜答案是:让动作客户端允许拆分工作并允许服务器“休息”,或者至少减少工作量。但这会是唯一的目的吗?
    • 我猜如果您只与可信赖的人(即:朋友)一起使用该应用程序,那么允许客户端直接更新其他用户会使代码更清晰并且不会增加复杂性:您的逻辑没有划分在服务器和客户端文件之间,您不需要仔细检查异常......另外我猜它应该表现更好,因为你只有一个异步功能......(它仍然请求当然是服务器)
    • 感谢您的帮助!
    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 2016-12-13
    • 2013-05-23
    • 1970-01-01
    • 1970-01-01
    • 2015-07-22
    • 2015-02-06
    • 1970-01-01
    相关资源
    最近更新 更多