*/
@Override
protected Response internalExecute(HttpServletRequest request, Session databaseSession) {
Response response = null;
User oldUser = null;
HttpSession httpSession = request.getSession();
// if user is not a manager, he can't continue
if( ! ((Boolean) httpSession.getAttribute("manager")) ) {
return new Response(ResponseStatus.FAIL, "No authorization");
}
try {
Role newRoleObject = (Role) databaseSession.createCriteria(Role.class).add(Restrictions.eq("id", this.role)).uniqueResult();
if (null == newRoleObject) {
return new Response(ResponseStatus.FAIL, "User role does not exist, database failure.");
}
oldUser = (User) databaseSession.createCriteria(User.class)
.add(Restrictions.eq("id", id))
.uniqueResult();
if (null == oldUser) {
throw new IllegalArgumentException("The user you are editing was not found.");
}
Transaction transaction = databaseSession.beginTransaction();
oldUser.setUsername(this.username);
oldUser.setPassword(this.password);
oldUser.setFullname(this.fullname);
oldUser.setRole(newRoleObject);
databaseSession.update(oldUser);
transaction.commit();
response = new Response(ResponseStatus.OK);
}