diff --git a/app/Http/Controllers/API/GroupController.php b/app/Http/Controllers/API/GroupController.php index d2e6941bf..41a3f23ec 100644 --- a/app/Http/Controllers/API/GroupController.php +++ b/app/Http/Controllers/API/GroupController.php @@ -1074,10 +1074,15 @@ public function updateGroupv2(Request $request, $idGroup): JsonResponse { 'email' => $email, ]; + // Hosts can edit the postcode (area stays admin/coordinator only, below). Only touch it when sent, so a + // partial update doesn't blank it. + if ($request->has('postcode')) { + $data['postcode'] = $postcode; + } + if ($user->hasRole('Administrator') || ($user->hasRole('NetworkCoordinator') && $isCoordinatorForGroup)) { // Got permission to update these. $data['area'] = $area; - $data['postcode'] = $postcode; $data['archived_at'] = $archived_at; } @@ -1212,6 +1217,7 @@ private function validateGroupParams(Request $request, $create, ?Group $existing 'location' => ['required', 'max:255'], 'description' => ['required'], 'website' => ['nullable', 'url', 'max:255'], + 'postcode' => ['nullable', 'max:32'], ]); } else { $request->validate([ @@ -1219,6 +1225,7 @@ private function validateGroupParams(Request $request, $create, ?Group $existing 'location' => ['max:255'], 'website' => ['nullable', 'url', 'max:255'], 'archived_at' => ['nullable', 'date'], + 'postcode' => ['nullable', 'max:32'], ]); } diff --git a/resources/js/components/GroupAddEdit.vue b/resources/js/components/GroupAddEdit.vue index 686b33de5..fa87ffbda 100644 --- a/resources/js/components/GroupAddEdit.vue +++ b/resources/js/components/GroupAddEdit.vue @@ -53,7 +53,6 @@ :lat.sync="lat" :lng.sync="lng" :postcode.sync="postcode" - :can-edit-postcode="canApprove" class="group-location" :has-error="$v.location.$error" ref="location" diff --git a/resources/js/components/GroupLocation.vue b/resources/js/components/GroupLocation.vue index 5d94e467b..9ddaa199e 100644 --- a/resources/js/components/GroupLocation.vue +++ b/resources/js/components/GroupLocation.vue @@ -24,7 +24,7 @@ - + {{ __('groups.groups_postcode_small') }} @@ -77,11 +77,6 @@ export default { type: Boolean, required: false, default: false - }, - canEditPostcode: { - type: Boolean, - required: false, - default: false } }, components: { diff --git a/tests/Feature/Groups/GroupEditTest.php b/tests/Feature/Groups/GroupEditTest.php index 7534a6d6f..f02bc3d60 100644 --- a/tests/Feature/Groups/GroupEditTest.php +++ b/tests/Feature/Groups/GroupEditTest.php @@ -92,6 +92,39 @@ public function invalid_location(): void ]); } + /** @test */ + public function host_can_edit_postcode_but_not_area(): void { + $group = Group::factory()->create(['postcode' => 'SW9 7QD', 'area' => 'London']); + + $host = User::factory()->host()->create(); + $group->addVolunteer($host); + $group->makeMemberAHost($host); + $this->actingAs($host); + + $response = $this->patch('/api/v2/groups/' . $group->idgroups, [ + 'postcode' => 'E8 1AA', + 'area' => 'Elsewhere', + ]); + $response->assertSuccessful(); + + $group->refresh(); + $this->assertEquals('E8 1AA', $group->postcode); + $this->assertEquals('London', $group->area); + + // A partial update that doesn't send the postcode leaves it alone. + $response = $this->patch('/api/v2/groups/' . $group->idgroups, [ + 'network_data' => ['foo' => 'bar'], + ]); + $response->assertSuccessful(); + $this->assertEquals('E8 1AA', $group->refresh()->postcode); + + // Longer than the column. + $this->expectException(\Illuminate\Validation\ValidationException::class); + $this->patch('/api/v2/groups/' . $group->idgroups, [ + 'postcode' => str_repeat('X', 33), + ]); + } + /** @test */ public function image_upload(): void { Storage::fake('avatars');