From 689343845bf9a7a8b546b0bbcf7475310bb9b401 Mon Sep 17 00:00:00 2001 From: "Noah Hanford (spaced)" Date: Sat, 3 Oct 2026 11:04:15 -0400 Subject: [PATCH 1/2] feat: add ability hide votes if you cannot vote --- api.go | 58 ++++++++++++++++++++++++++++--------- database/poll.go | 25 ++++++++-------- templates/create.tmpl | 9 ++++++ templates/unauthorized.tmpl | 2 +- 4 files changed, 67 insertions(+), 27 deletions(-) diff --git a/api.go b/api.go index 1a11815..fbd9209 100644 --- a/api.go +++ b/api.go @@ -38,15 +38,31 @@ func GetHomepage(c *gin.Context) { // A user may be unable to vote but should still be able to see a list of polls user := GetUserData(c) - polls, err := database.GetOpenPolls(c) + pollResults, err := database.GetOpenPolls(c) if err != nil { c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()}) return } - sort.Slice(polls, func(i, j int) bool { - return polls[i].Id > polls[j].Id + sort.Slice(pollResults, func(i, j int) bool { + return pollResults[i].Id > pollResults[j].Id }) + polls := []*database.Poll{} + + for i := range pollResults { + poll := pollResults[i] + + if poll.HideForIneligible { + canVoteResult := canVote(user, *poll, poll.AllowedUsers) + + if canVoteResult != 0 && canVoteResult != 9 { + continue + } + } + + polls = append(polls, pollResults[i]) + } + c.HTML(http.StatusOK, "index.tmpl", gin.H{ "Polls": polls, "Username": user.Username, @@ -151,17 +167,18 @@ func CreatePoll(c *gin.Context) { quorum = quorum / 100 poll := &database.Poll{ - Id: "", - CreatedBy: user.Username, - Title: c.PostForm("title"), - Description: c.PostForm("description"), - VoteType: database.POLL_TYPE_SIMPLE, - OpenedTime: time.Now(), - Open: true, - QuorumType: quorum, - Gatekeep: c.PostForm("gatekeep") == "true", - AllowWriteIns: c.PostForm("allowWriteIn") == "true", - Hidden: c.PostForm("hidden") == "true", + Id: "", + CreatedBy: user.Username, + Title: c.PostForm("title"), + Description: c.PostForm("description"), + VoteType: database.POLL_TYPE_SIMPLE, + OpenedTime: time.Now(), + Open: true, + QuorumType: quorum, + Gatekeep: c.PostForm("gatekeep") == "true", + AllowWriteIns: c.PostForm("allowWriteIn") == "true", + Hidden: c.PostForm("hidden") == "true", + HideForIneligible: c.PostForm("hideIneligible") == "true", } if c.PostForm("rankedChoice") == "true" { poll.VoteType = database.POLL_TYPE_RANKED @@ -253,6 +270,19 @@ func GetPollResults(c *gin.Context) { canModify := IsActiveRTP(user) || IsEboard(user) || ownsPoll(poll, user) + if poll.HideForIneligible { + canVoteResult := canVote(user, *poll, poll.AllowedUsers) + + if canVoteResult != 0 && canVoteResult != 9 { + c.HTML(http.StatusForbidden, "unauthorized.tmpl", gin.H{ + "Username": user.Username, + "FullName": user.FullName, + "EBoard": IsEboard(user), + }) + return + } + } + if poll.Hidden && poll.Open { c.HTML(http.StatusUnauthorized, "hidden.tmpl", gin.H{ "Id": poll.Id, diff --git a/database/poll.go b/database/poll.go index 7df45fc..77b9f2b 100644 --- a/database/poll.go +++ b/database/poll.go @@ -16,18 +16,19 @@ import ( ) type Poll struct { - Id string `bson:"_id,omitempty"` - CreatedBy string `bson:"createdBy"` - Title string `bson:"title"` - Description string `bson:"description"` - VoteType string `bson:"voteType"` - Options []string `bson:"options"` - OpenedTime time.Time `bson:"openedTime"` - Open bool `bson:"open"` - Gatekeep bool `bson:"gatekeep"` - QuorumType float64 `bson:"quorumType"` - AllowedUsers []string `bson:"allowedUsers"` - AllowWriteIns bool `bson:"writeins"` + Id string `bson:"_id,omitempty"` + CreatedBy string `bson:"createdBy"` + Title string `bson:"title"` + Description string `bson:"description"` + VoteType string `bson:"voteType"` + Options []string `bson:"options"` + OpenedTime time.Time `bson:"openedTime"` + Open bool `bson:"open"` + Gatekeep bool `bson:"gatekeep"` + HideForIneligible bool `bson:"hideIneligible"` + QuorumType float64 `bson:"quorumType"` + AllowedUsers []string `bson:"allowedUsers"` + AllowWriteIns bool `bson:"writeins"` // Prevent this poll from having progress displayed // This is important for events like elections where the results shouldn't be visible mid vote diff --git a/templates/create.tmpl b/templates/create.tmpl index d1bc7f2..65aead6 100644 --- a/templates/create.tmpl +++ b/templates/create.tmpl @@ -110,6 +110,15 @@ placeholder="Comma separated list of usernames" > +
+ + +
{{ end }} diff --git a/templates/unauthorized.tmpl b/templates/unauthorized.tmpl index b84ade8..708ac2e 100644 --- a/templates/unauthorized.tmpl +++ b/templates/unauthorized.tmpl @@ -2,7 +2,7 @@
Attention! -

You're not authorized to vote!

+

You're not authorized to vote or view this poll!

It looks like you're either not marked as active, or you're on co-op right now From bab0f41fd51dcc358b6f7c8381a4483d7e4c63df Mon Sep 17 00:00:00 2001 From: "Noah Hanford (spaced)" Date: Sat, 3 Oct 2026 11:23:51 -0400 Subject: [PATCH 2/2] fix: better for loop --- api.go | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/api.go b/api.go index fbd9209..8fe6c7c 100644 --- a/api.go +++ b/api.go @@ -49,9 +49,7 @@ func GetHomepage(c *gin.Context) { polls := []*database.Poll{} - for i := range pollResults { - poll := pollResults[i] - + for _, poll := range pollResults { if poll.HideForIneligible { canVoteResult := canVote(user, *poll, poll.AllowedUsers) @@ -60,7 +58,7 @@ func GetHomepage(c *gin.Context) { } } - polls = append(polls, pollResults[i]) + polls = append(polls, poll) } c.HTML(http.StatusOK, "index.tmpl", gin.H{