2019-05-16 10:39:25 -04:00
|
|
|
package handlers
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
|
|
|
"net/http"
|
2019-06-24 17:36:42 -08:00
|
|
|
"strconv"
|
2019-06-25 22:31:54 -08:00
|
|
|
"strings"
|
2019-06-21 00:37:34 -04:00
|
|
|
"time"
|
2019-05-16 10:39:25 -04:00
|
|
|
|
2019-07-13 12:16:28 -08:00
|
|
|
"geeks-accelerator/oss/saas-starter-kit/internal/platform/auth"
|
|
|
|
"geeks-accelerator/oss/saas-starter-kit/internal/platform/web"
|
2019-08-04 14:48:43 -08:00
|
|
|
"geeks-accelerator/oss/saas-starter-kit/internal/platform/web/webcontext"
|
|
|
|
"geeks-accelerator/oss/saas-starter-kit/internal/platform/web/weberror"
|
2019-07-13 12:16:28 -08:00
|
|
|
"geeks-accelerator/oss/saas-starter-kit/internal/user"
|
2019-08-04 14:48:43 -08:00
|
|
|
"geeks-accelerator/oss/saas-starter-kit/internal/user_auth"
|
2019-08-17 11:03:48 +07:00
|
|
|
|
2019-08-07 23:00:12 -08:00
|
|
|
"github.com/gorilla/schema"
|
2019-05-16 10:39:25 -04:00
|
|
|
"github.com/pkg/errors"
|
2019-06-25 22:31:54 -08:00
|
|
|
"gopkg.in/go-playground/validator.v9"
|
2019-05-16 10:39:25 -04:00
|
|
|
)
|
|
|
|
|
2019-06-24 17:36:42 -08:00
|
|
|
// sessionTtl defines the auth token expiration.
|
|
|
|
var sessionTtl = time.Hour * 24
|
|
|
|
|
2019-05-16 10:39:25 -04:00
|
|
|
// User represents the User API method handler set.
|
2019-08-17 11:03:48 +07:00
|
|
|
type Users struct {
|
|
|
|
AuthRepo UserAuthRepository
|
|
|
|
UserRepo UserRepository
|
2019-05-16 10:39:25 -04:00
|
|
|
// ADD OTHER STATE LIKE THE LOGGER AND CONFIG HERE.
|
|
|
|
}
|
|
|
|
|
2019-08-17 11:03:48 +07:00
|
|
|
type UserAuthRepository interface {
|
|
|
|
SwitchAccount(ctx context.Context, claims auth.Claims, req user_auth.SwitchAccountRequest, expires time.Duration,
|
|
|
|
now time.Time, scopes ...string) (user_auth.Token, error)
|
|
|
|
Authenticate(ctx context.Context, req user_auth.AuthenticateRequest, expires time.Duration, now time.Time, scopes ...string) (user_auth.Token, error)
|
|
|
|
VirtualLogin(ctx context.Context, claims auth.Claims, req user_auth.VirtualLoginRequest,
|
|
|
|
expires time.Duration, now time.Time, scopes ...string) (user_auth.Token, error)
|
|
|
|
VirtualLogout(ctx context.Context, claims auth.Claims, expires time.Duration, now time.Time, scopes ...string) (user_auth.Token, error)
|
|
|
|
}
|
|
|
|
|
|
|
|
type UserRepository interface {
|
|
|
|
Find(ctx context.Context, claims auth.Claims, req user.UserFindRequest) (user.Users, error)
|
|
|
|
//FindByAccount(ctx context.Context, claims auth.Claims, req user.UserFindByAccountRequest) (user.Users, error)
|
|
|
|
Read(ctx context.Context, claims auth.Claims, req user.UserReadRequest) (*user.User, error)
|
|
|
|
ReadByID(ctx context.Context, claims auth.Claims, id string) (*user.User, error)
|
|
|
|
Create(ctx context.Context, claims auth.Claims, req user.UserCreateRequest, now time.Time) (*user.User, error)
|
|
|
|
Update(ctx context.Context, claims auth.Claims, req user.UserUpdateRequest, now time.Time) error
|
|
|
|
UpdatePassword(ctx context.Context, claims auth.Claims, req user.UserUpdatePasswordRequest, now time.Time) error
|
|
|
|
Archive(ctx context.Context, claims auth.Claims, req user.UserArchiveRequest, now time.Time) error
|
|
|
|
Restore(ctx context.Context, claims auth.Claims, req user.UserRestoreRequest, now time.Time) error
|
|
|
|
Delete(ctx context.Context, claims auth.Claims, req user.UserDeleteRequest) error
|
|
|
|
ResetPassword(ctx context.Context, req user.UserResetPasswordRequest, now time.Time) (string, error)
|
|
|
|
ResetConfirm(ctx context.Context, req user.UserResetConfirmRequest, now time.Time) (*user.User, error)
|
|
|
|
}
|
|
|
|
|
2019-06-25 22:31:54 -08:00
|
|
|
// Find godoc
|
2019-06-27 04:48:18 -08:00
|
|
|
// TODO: Need to implement unittests on users/find endpoint. There are none.
|
2019-06-25 22:31:54 -08:00
|
|
|
// @Summary List users
|
|
|
|
// @Description Find returns the existing users in the system.
|
|
|
|
// @Tags user
|
|
|
|
// @Accept json
|
|
|
|
// @Produce json
|
|
|
|
// @Security OAuth2Password
|
|
|
|
// @Param where query string false "Filter string, example: name = 'Company Name' and email = 'gabi.may@geeksinthewoods.com'"
|
|
|
|
// @Param order query string false "Order columns separated by comma, example: created_at desc"
|
|
|
|
// @Param limit query integer false "Limit, example: 10"
|
|
|
|
// @Param offset query integer false "Offset, example: 20"
|
2019-08-04 14:48:43 -08:00
|
|
|
// @Param include-archived query boolean false "Included Archived, example: false"
|
2019-06-25 22:31:54 -08:00
|
|
|
// @Success 200 {array} user.UserResponse
|
2019-08-05 19:49:30 -08:00
|
|
|
// @Failure 400 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 500 {object} weberror.ErrorResponse
|
2019-06-25 22:31:54 -08:00
|
|
|
// @Router /users [get]
|
2019-08-17 11:03:48 +07:00
|
|
|
func (h *Users) Find(ctx context.Context, w http.ResponseWriter, r *http.Request, params map[string]string) error {
|
2019-06-21 00:37:34 -04:00
|
|
|
claims, ok := ctx.Value(auth.Key).(auth.Claims)
|
|
|
|
if !ok {
|
|
|
|
return errors.New("claims missing from context")
|
|
|
|
}
|
|
|
|
|
|
|
|
var req user.UserFindRequest
|
2019-06-25 22:31:54 -08:00
|
|
|
|
|
|
|
// Handle where query value if set.
|
|
|
|
if v := r.URL.Query().Get("where"); v != "" {
|
|
|
|
where, args, err := web.ExtractWhereArgs(v)
|
|
|
|
if err != nil {
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusBadRequest))
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
2019-08-05 17:12:28 -08:00
|
|
|
req.Where = where
|
2019-06-25 22:31:54 -08:00
|
|
|
req.Args = args
|
|
|
|
}
|
|
|
|
|
|
|
|
// Handle order query value if set.
|
|
|
|
if v := r.URL.Query().Get("order"); v != "" {
|
|
|
|
for _, o := range strings.Split(v, ",") {
|
|
|
|
o = strings.TrimSpace(o)
|
|
|
|
if o != "" {
|
|
|
|
req.Order = append(req.Order, o)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// Handle limit query value if set.
|
|
|
|
if v := r.URL.Query().Get("limit"); v != "" {
|
|
|
|
l, err := strconv.Atoi(v)
|
|
|
|
if err != nil {
|
|
|
|
err = errors.WithMessagef(err, "unable to parse %s as int for limit param", v)
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusBadRequest))
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
|
|
|
ul := uint(l)
|
|
|
|
req.Limit = &ul
|
|
|
|
}
|
|
|
|
|
|
|
|
// Handle offset query value if set.
|
|
|
|
if v := r.URL.Query().Get("offset"); v != "" {
|
|
|
|
l, err := strconv.Atoi(v)
|
|
|
|
if err != nil {
|
|
|
|
err = errors.WithMessagef(err, "unable to parse %s as int for offset param", v)
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusBadRequest))
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
|
|
|
ul := uint(l)
|
|
|
|
req.Limit = &ul
|
|
|
|
}
|
|
|
|
|
2019-08-04 14:48:43 -08:00
|
|
|
// Handle include-archived query value if set.
|
|
|
|
if v := r.URL.Query().Get("include-archived"); v != "" {
|
2019-06-25 22:31:54 -08:00
|
|
|
b, err := strconv.ParseBool(v)
|
|
|
|
if err != nil {
|
2019-08-04 14:48:43 -08:00
|
|
|
err = errors.WithMessagef(err, "unable to parse %s as boolean for include-archived param", v)
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusBadRequest))
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
2019-08-04 14:48:43 -08:00
|
|
|
req.IncludeArchived = b
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
|
|
|
|
2019-06-26 20:21:00 -08:00
|
|
|
//if err := web.Decode(r, &req); err != nil {
|
|
|
|
// if _, ok := errors.Cause(err).(*web.Error); !ok {
|
2019-08-01 16:17:47 -08:00
|
|
|
// err = weberror.NewError(ctx, err, http.StatusBadRequest)
|
2019-06-26 20:21:00 -08:00
|
|
|
// }
|
|
|
|
// return web.RespondJsonError(ctx, w, err)
|
|
|
|
//}
|
2019-06-21 00:37:34 -04:00
|
|
|
|
2019-08-17 11:03:48 +07:00
|
|
|
res, err := h.UserRepo.Find(ctx, claims, req)
|
2019-05-16 10:39:25 -04:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2019-06-25 22:31:54 -08:00
|
|
|
var resp []*user.UserResponse
|
|
|
|
for _, m := range res {
|
|
|
|
resp = append(resp, m.Response(ctx))
|
|
|
|
}
|
|
|
|
|
|
|
|
return web.RespondJson(ctx, w, resp, http.StatusOK)
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
|
2019-06-25 02:40:29 -08:00
|
|
|
// Read godoc
|
2019-06-25 22:31:54 -08:00
|
|
|
// @Summary Get user by ID
|
|
|
|
// @Description Read returns the specified user from the system.
|
2019-06-25 02:40:29 -08:00
|
|
|
// @Tags user
|
|
|
|
// @Accept json
|
|
|
|
// @Produce json
|
2019-06-25 06:25:55 -08:00
|
|
|
// @Security OAuth2Password
|
|
|
|
// @Param id path string true "User ID"
|
2019-06-25 22:31:54 -08:00
|
|
|
// @Success 200 {object} user.UserResponse
|
2019-08-05 19:49:30 -08:00
|
|
|
// @Failure 400 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 404 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 500 {object} weberror.ErrorResponse
|
2019-06-25 02:40:29 -08:00
|
|
|
// @Router /users/{id} [get]
|
2019-08-17 11:03:48 +07:00
|
|
|
func (h *Users) Read(ctx context.Context, w http.ResponseWriter, r *http.Request, params map[string]string) error {
|
2019-05-16 10:39:25 -04:00
|
|
|
claims, ok := ctx.Value(auth.Key).(auth.Claims)
|
|
|
|
if !ok {
|
|
|
|
return errors.New("claims missing from context")
|
|
|
|
}
|
|
|
|
|
2019-08-04 14:48:43 -08:00
|
|
|
// Handle include-archived query value if set.
|
2019-06-24 17:36:42 -08:00
|
|
|
var includeArchived bool
|
2019-08-04 14:48:43 -08:00
|
|
|
if v := r.URL.Query().Get("include-archived"); v != "" {
|
2019-06-26 20:21:00 -08:00
|
|
|
b, err := strconv.ParseBool(v)
|
2019-06-24 17:36:42 -08:00
|
|
|
if err != nil {
|
2019-08-04 14:48:43 -08:00
|
|
|
err = errors.WithMessagef(err, "unable to parse %s as boolean for include-archived param", v)
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusBadRequest))
|
2019-06-24 17:36:42 -08:00
|
|
|
}
|
2019-06-26 20:21:00 -08:00
|
|
|
includeArchived = b
|
2019-06-24 17:36:42 -08:00
|
|
|
}
|
|
|
|
|
2019-08-17 11:03:48 +07:00
|
|
|
res, err := h.UserRepo.Read(ctx, claims, user.UserReadRequest{
|
2019-08-04 14:48:43 -08:00
|
|
|
ID: params["id"],
|
|
|
|
IncludeArchived: includeArchived,
|
|
|
|
})
|
2019-05-16 10:39:25 -04:00
|
|
|
if err != nil {
|
2019-06-26 20:21:00 -08:00
|
|
|
cause := errors.Cause(err)
|
|
|
|
switch cause {
|
2019-05-16 10:39:25 -04:00
|
|
|
case user.ErrNotFound:
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusNotFound))
|
2019-05-16 10:39:25 -04:00
|
|
|
default:
|
2019-06-24 17:36:42 -08:00
|
|
|
return errors.Wrapf(err, "ID: %s", params["id"])
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-06-25 22:31:54 -08:00
|
|
|
return web.RespondJson(ctx, w, res.Response(ctx), http.StatusOK)
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
|
2019-06-25 22:31:54 -08:00
|
|
|
// Create godoc
|
|
|
|
// @Summary Create new user.
|
|
|
|
// @Description Create inserts a new user into the system.
|
|
|
|
// @Tags user
|
|
|
|
// @Accept json
|
|
|
|
// @Produce json
|
|
|
|
// @Security OAuth2Password
|
|
|
|
// @Param data body user.UserCreateRequest true "User details"
|
2019-06-26 20:21:00 -08:00
|
|
|
// @Success 201 {object} user.UserResponse
|
2019-08-05 19:49:30 -08:00
|
|
|
// @Failure 400 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 403 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 500 {object} weberror.ErrorResponse
|
2019-06-25 22:31:54 -08:00
|
|
|
// @Router /users [post]
|
2019-08-17 11:03:48 +07:00
|
|
|
func (h *Users) Create(ctx context.Context, w http.ResponseWriter, r *http.Request, params map[string]string) error {
|
2019-08-01 16:17:47 -08:00
|
|
|
v, err := webcontext.ContextValues(ctx)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2019-06-24 17:36:42 -08:00
|
|
|
}
|
|
|
|
|
2019-08-01 16:17:47 -08:00
|
|
|
claims, err := auth.ClaimsFromContext(ctx)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2019-06-21 00:37:34 -04:00
|
|
|
}
|
|
|
|
|
2019-06-24 17:36:42 -08:00
|
|
|
var req user.UserCreateRequest
|
2019-08-01 16:17:47 -08:00
|
|
|
if err := web.Decode(ctx, r, &req); err != nil {
|
|
|
|
if _, ok := errors.Cause(err).(*weberror.Error); !ok {
|
|
|
|
err = weberror.NewError(ctx, err, http.StatusBadRequest)
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
2019-06-27 04:48:18 -08:00
|
|
|
return web.RespondJsonError(ctx, w, err)
|
2019-06-24 17:36:42 -08:00
|
|
|
}
|
|
|
|
|
2019-08-17 11:03:48 +07:00
|
|
|
usr, err := h.UserRepo.Create(ctx, claims, req, v.Now)
|
2019-06-24 17:36:42 -08:00
|
|
|
if err != nil {
|
2019-06-26 20:21:00 -08:00
|
|
|
cause := errors.Cause(err)
|
|
|
|
switch cause {
|
2019-06-24 17:36:42 -08:00
|
|
|
case user.ErrForbidden:
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusForbidden))
|
2019-06-24 17:36:42 -08:00
|
|
|
default:
|
2019-06-26 20:21:00 -08:00
|
|
|
_, ok := cause.(validator.ValidationErrors)
|
2019-06-25 22:31:54 -08:00
|
|
|
if ok {
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusBadRequest))
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
|
|
|
|
2019-06-24 17:36:42 -08:00
|
|
|
return errors.Wrapf(err, "User: %+v", &req)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-08-17 11:03:48 +07:00
|
|
|
return web.RespondJson(ctx, w, usr.Response(ctx), http.StatusCreated)
|
2019-06-24 17:36:42 -08:00
|
|
|
}
|
|
|
|
|
2019-06-25 22:31:54 -08:00
|
|
|
// Read godoc
|
|
|
|
// @Summary Update user by ID
|
|
|
|
// @Description Update updates the specified user in the system.
|
|
|
|
// @Tags user
|
|
|
|
// @Accept json
|
|
|
|
// @Produce json
|
|
|
|
// @Security OAuth2Password
|
|
|
|
// @Param data body user.UserUpdateRequest true "Update fields"
|
2019-06-26 20:21:00 -08:00
|
|
|
// @Success 204
|
2019-08-05 19:49:30 -08:00
|
|
|
// @Failure 400 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 403 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 500 {object} weberror.ErrorResponse
|
2019-06-25 22:31:54 -08:00
|
|
|
// @Router /users [patch]
|
2019-08-17 11:03:48 +07:00
|
|
|
func (h *Users) Update(ctx context.Context, w http.ResponseWriter, r *http.Request, params map[string]string) error {
|
2019-08-01 16:17:47 -08:00
|
|
|
v, err := webcontext.ContextValues(ctx)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
|
2019-08-01 16:17:47 -08:00
|
|
|
claims, err := auth.ClaimsFromContext(ctx)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2019-06-24 17:36:42 -08:00
|
|
|
}
|
|
|
|
|
|
|
|
var req user.UserUpdateRequest
|
2019-08-01 16:17:47 -08:00
|
|
|
if err := web.Decode(ctx, r, &req); err != nil {
|
|
|
|
if _, ok := errors.Cause(err).(*weberror.Error); !ok {
|
|
|
|
err = weberror.NewError(ctx, err, http.StatusBadRequest)
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
2019-06-27 04:48:18 -08:00
|
|
|
return web.RespondJsonError(ctx, w, err)
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
|
2019-08-17 11:03:48 +07:00
|
|
|
err = h.UserRepo.Update(ctx, claims, req, v.Now)
|
2019-05-16 10:39:25 -04:00
|
|
|
if err != nil {
|
2019-06-26 20:21:00 -08:00
|
|
|
cause := errors.Cause(err)
|
|
|
|
switch cause {
|
2019-06-24 17:36:42 -08:00
|
|
|
case user.ErrForbidden:
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusForbidden))
|
2019-06-24 17:36:42 -08:00
|
|
|
default:
|
2019-06-26 20:21:00 -08:00
|
|
|
_, ok := cause.(validator.ValidationErrors)
|
2019-06-25 22:31:54 -08:00
|
|
|
if ok {
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusBadRequest))
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
|
|
|
|
2019-06-26 20:21:00 -08:00
|
|
|
return errors.Wrapf(err, "Id: %s User: %+v", req.ID, &req)
|
2019-06-24 17:36:42 -08:00
|
|
|
}
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
|
2019-06-24 17:36:42 -08:00
|
|
|
return web.RespondJson(ctx, w, nil, http.StatusNoContent)
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
|
2019-06-25 22:31:54 -08:00
|
|
|
// Read godoc
|
|
|
|
// @Summary Update user password by ID
|
|
|
|
// @Description Update updates the password for a specified user in the system.
|
|
|
|
// @Tags user
|
|
|
|
// @Accept json
|
|
|
|
// @Produce json
|
|
|
|
// @Security OAuth2Password
|
|
|
|
// @Param data body user.UserUpdatePasswordRequest true "Update fields"
|
2019-06-26 20:21:00 -08:00
|
|
|
// @Success 204
|
2019-08-05 19:49:30 -08:00
|
|
|
// @Failure 400 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 403 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 500 {object} weberror.ErrorResponse
|
2019-06-25 22:31:54 -08:00
|
|
|
// @Router /users/password [patch]
|
2019-08-17 11:03:48 +07:00
|
|
|
func (h *Users) UpdatePassword(ctx context.Context, w http.ResponseWriter, r *http.Request, params map[string]string) error {
|
2019-08-01 16:17:47 -08:00
|
|
|
v, err := webcontext.ContextValues(ctx)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2019-06-24 17:36:42 -08:00
|
|
|
}
|
|
|
|
|
2019-08-01 16:17:47 -08:00
|
|
|
claims, err := auth.ClaimsFromContext(ctx)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2019-06-21 00:37:34 -04:00
|
|
|
}
|
|
|
|
|
2019-06-24 17:36:42 -08:00
|
|
|
var req user.UserUpdatePasswordRequest
|
2019-08-01 16:17:47 -08:00
|
|
|
if err := web.Decode(ctx, r, &req); err != nil {
|
|
|
|
if _, ok := errors.Cause(err).(*weberror.Error); !ok {
|
|
|
|
err = weberror.NewError(ctx, err, http.StatusBadRequest)
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
2019-06-27 04:48:18 -08:00
|
|
|
return web.RespondJsonError(ctx, w, err)
|
2019-06-24 17:36:42 -08:00
|
|
|
}
|
2019-06-21 00:37:34 -04:00
|
|
|
|
2019-08-17 11:03:48 +07:00
|
|
|
err = h.UserRepo.UpdatePassword(ctx, claims, req, v.Now)
|
2019-06-24 17:36:42 -08:00
|
|
|
if err != nil {
|
2019-06-26 20:21:00 -08:00
|
|
|
cause := errors.Cause(err)
|
|
|
|
switch cause {
|
2019-06-24 17:36:42 -08:00
|
|
|
case user.ErrNotFound:
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusNotFound))
|
2019-06-24 17:36:42 -08:00
|
|
|
case user.ErrForbidden:
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusForbidden))
|
2019-06-24 17:36:42 -08:00
|
|
|
default:
|
2019-06-26 20:21:00 -08:00
|
|
|
_, ok := cause.(validator.ValidationErrors)
|
2019-06-25 22:31:54 -08:00
|
|
|
if ok {
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusBadRequest))
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
|
|
|
|
|
|
|
return errors.Wrapf(err, "Id: %s User: %+v", req.ID, &req)
|
2019-06-24 17:36:42 -08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return web.RespondJson(ctx, w, nil, http.StatusNoContent)
|
|
|
|
}
|
|
|
|
|
2019-06-25 22:31:54 -08:00
|
|
|
// Read godoc
|
|
|
|
// @Summary Archive user by ID
|
|
|
|
// @Description Archive soft-deletes the specified user from the system.
|
|
|
|
// @Tags user
|
|
|
|
// @Accept json
|
|
|
|
// @Produce json
|
|
|
|
// @Security OAuth2Password
|
|
|
|
// @Param data body user.UserArchiveRequest true "Update fields"
|
2019-06-26 20:21:00 -08:00
|
|
|
// @Success 204
|
2019-08-05 19:49:30 -08:00
|
|
|
// @Failure 400 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 403 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 500 {object} weberror.ErrorResponse
|
2019-06-25 22:31:54 -08:00
|
|
|
// @Router /users/archive [patch]
|
2019-08-17 11:03:48 +07:00
|
|
|
func (h *Users) Archive(ctx context.Context, w http.ResponseWriter, r *http.Request, params map[string]string) error {
|
2019-08-01 16:17:47 -08:00
|
|
|
v, err := webcontext.ContextValues(ctx)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
|
2019-08-01 16:17:47 -08:00
|
|
|
claims, err := auth.ClaimsFromContext(ctx)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
|
2019-06-25 22:31:54 -08:00
|
|
|
var req user.UserArchiveRequest
|
2019-08-01 16:17:47 -08:00
|
|
|
if err := web.Decode(ctx, r, &req); err != nil {
|
|
|
|
if _, ok := errors.Cause(err).(*weberror.Error); !ok {
|
|
|
|
err = weberror.NewError(ctx, err, http.StatusBadRequest)
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
2019-06-27 04:48:18 -08:00
|
|
|
return web.RespondJsonError(ctx, w, err)
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
|
|
|
|
2019-08-17 11:03:48 +07:00
|
|
|
err = h.UserRepo.Archive(ctx, claims, req, v.Now)
|
2019-05-16 10:39:25 -04:00
|
|
|
if err != nil {
|
2019-06-26 20:21:00 -08:00
|
|
|
cause := errors.Cause(err)
|
|
|
|
switch cause {
|
2019-05-16 10:39:25 -04:00
|
|
|
case user.ErrForbidden:
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusForbidden))
|
2019-05-16 10:39:25 -04:00
|
|
|
default:
|
2019-06-26 20:21:00 -08:00
|
|
|
_, ok := cause.(validator.ValidationErrors)
|
2019-06-25 22:31:54 -08:00
|
|
|
if ok {
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusBadRequest))
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
|
|
|
|
|
|
|
return errors.Wrapf(err, "Id: %s", req.ID)
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-05-23 14:32:24 -05:00
|
|
|
return web.RespondJson(ctx, w, nil, http.StatusNoContent)
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
|
2019-06-25 22:31:54 -08:00
|
|
|
// Delete godoc
|
|
|
|
// @Summary Delete user by ID
|
|
|
|
// @Description Delete removes the specified user from the system.
|
|
|
|
// @Tags user
|
|
|
|
// @Accept json
|
|
|
|
// @Produce json
|
|
|
|
// @Security OAuth2Password
|
|
|
|
// @Param id path string true "User ID"
|
2019-06-26 20:21:00 -08:00
|
|
|
// @Success 204
|
2019-08-05 19:49:30 -08:00
|
|
|
// @Failure 400 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 403 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 500 {object} weberror.ErrorResponse
|
2019-06-25 22:31:54 -08:00
|
|
|
// @Router /users/{id} [delete]
|
2019-08-17 11:03:48 +07:00
|
|
|
func (h *Users) Delete(ctx context.Context, w http.ResponseWriter, r *http.Request, params map[string]string) error {
|
2019-08-01 16:17:47 -08:00
|
|
|
claims, err := auth.ClaimsFromContext(ctx)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2019-06-21 00:37:34 -04:00
|
|
|
}
|
|
|
|
|
2019-08-17 11:03:48 +07:00
|
|
|
err = h.UserRepo.Delete(ctx, claims,
|
2019-08-04 14:48:43 -08:00
|
|
|
user.UserDeleteRequest{ID: params["id"]})
|
2019-05-16 10:39:25 -04:00
|
|
|
if err != nil {
|
2019-06-26 20:21:00 -08:00
|
|
|
cause := errors.Cause(err)
|
|
|
|
switch cause {
|
2019-05-16 10:39:25 -04:00
|
|
|
case user.ErrForbidden:
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusForbidden))
|
2019-05-16 10:39:25 -04:00
|
|
|
default:
|
2019-06-27 04:48:18 -08:00
|
|
|
_, ok := cause.(validator.ValidationErrors)
|
|
|
|
if ok {
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusBadRequest))
|
2019-06-27 04:48:18 -08:00
|
|
|
}
|
|
|
|
|
|
|
|
return errors.Wrapf(err, "Id: %s", params["id"])
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-05-23 14:32:24 -05:00
|
|
|
return web.RespondJson(ctx, w, nil, http.StatusNoContent)
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
|
2019-06-25 22:31:54 -08:00
|
|
|
// SwitchAccount godoc
|
|
|
|
// @Summary Switch account.
|
|
|
|
// @Description SwitchAccount updates the auth claims to a new account.
|
|
|
|
// @Tags user
|
|
|
|
// @Accept json
|
|
|
|
// @Produce json
|
|
|
|
// @Security OAuth2Password
|
|
|
|
// @Param account_id path int true "Account ID"
|
2019-06-27 04:48:18 -08:00
|
|
|
// @Success 200
|
2019-08-05 19:49:30 -08:00
|
|
|
// @Failure 400 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 401 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 500 {object} weberror.ErrorResponse
|
2019-06-25 22:31:54 -08:00
|
|
|
// @Router /users/switch-account/{account_id} [patch]
|
2019-08-17 11:03:48 +07:00
|
|
|
func (h *Users) SwitchAccount(ctx context.Context, w http.ResponseWriter, r *http.Request, params map[string]string) error {
|
2019-08-01 16:17:47 -08:00
|
|
|
v, err := webcontext.ContextValues(ctx)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2019-06-24 17:36:42 -08:00
|
|
|
}
|
|
|
|
|
2019-08-01 16:17:47 -08:00
|
|
|
claims, err := auth.ClaimsFromContext(ctx)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2019-06-24 17:36:42 -08:00
|
|
|
}
|
|
|
|
|
2019-08-17 11:03:48 +07:00
|
|
|
tkn, err := h.AuthRepo.SwitchAccount(ctx, claims, user_auth.SwitchAccountRequest{
|
2019-08-05 17:12:28 -08:00
|
|
|
AccountID: params["account_id"],
|
|
|
|
}, sessionTtl, v.Now)
|
2019-06-24 17:36:42 -08:00
|
|
|
if err != nil {
|
2019-06-26 20:21:00 -08:00
|
|
|
cause := errors.Cause(err)
|
|
|
|
switch cause {
|
2019-08-04 14:48:43 -08:00
|
|
|
case user_auth.ErrAuthenticationFailure:
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusUnauthorized))
|
2019-06-24 17:36:42 -08:00
|
|
|
default:
|
2019-06-26 20:21:00 -08:00
|
|
|
_, ok := cause.(validator.ValidationErrors)
|
2019-06-25 22:31:54 -08:00
|
|
|
if ok {
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusBadRequest))
|
2019-06-25 22:31:54 -08:00
|
|
|
}
|
|
|
|
|
2019-06-24 17:36:42 -08:00
|
|
|
return errors.Wrap(err, "switch account")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-06-27 04:48:18 -08:00
|
|
|
return web.RespondJson(ctx, w, tkn, http.StatusOK)
|
2019-06-24 17:36:42 -08:00
|
|
|
}
|
|
|
|
|
2019-06-25 06:25:55 -08:00
|
|
|
// Token godoc
|
|
|
|
// @Summary Token handles a request to authenticate a user.
|
|
|
|
// @Description Token generates an oauth2 accessToken using Basic Auth with a user's email and password.
|
|
|
|
// @Tags user
|
2019-08-07 23:00:12 -08:00
|
|
|
// @Accept x-www-form-urlencoded
|
2019-06-25 06:25:55 -08:00
|
|
|
// @Produce json
|
2019-08-07 23:00:12 -08:00
|
|
|
// @Param username formData string true "Email"
|
|
|
|
// @Param password formData string true "Password"
|
|
|
|
// @Param account_id formData string false "Account ID"
|
2019-08-08 01:12:04 -08:00
|
|
|
// @Param scope formData string false "Scope" Enums(user, admin)
|
2019-06-27 04:48:18 -08:00
|
|
|
// @Success 200
|
2019-08-05 19:49:30 -08:00
|
|
|
// @Failure 400 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 401 {object} weberror.ErrorResponse
|
|
|
|
// @Failure 500 {object} weberror.ErrorResponse
|
2019-06-25 06:25:55 -08:00
|
|
|
// @Router /oauth/token [post]
|
2019-08-17 11:03:48 +07:00
|
|
|
func (h *Users) Token(ctx context.Context, w http.ResponseWriter, r *http.Request, params map[string]string) error {
|
2019-08-01 16:17:47 -08:00
|
|
|
v, err := webcontext.ContextValues(ctx)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
|
2019-08-07 23:00:12 -08:00
|
|
|
var authReq user_auth.AuthenticateRequest
|
|
|
|
var scopes []string
|
|
|
|
|
2019-05-16 10:39:25 -04:00
|
|
|
email, pass, ok := r.BasicAuth()
|
2019-08-07 23:00:12 -08:00
|
|
|
if !ok || email == "" {
|
|
|
|
if r.Method == http.MethodPost {
|
|
|
|
err := r.ParseForm()
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
decoder := schema.NewDecoder()
|
|
|
|
decoder.IgnoreUnknownKeys(true)
|
|
|
|
|
|
|
|
var req user_auth.OAuth2PasswordRequest
|
|
|
|
if err := decoder.Decode(&req, r.PostForm); err != nil {
|
|
|
|
if _, ok := errors.Cause(err).(*weberror.Error); !ok {
|
|
|
|
err = weberror.NewError(ctx, err, http.StatusBadRequest)
|
|
|
|
}
|
|
|
|
return web.RespondJsonError(ctx, w, err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Validate the request.
|
|
|
|
err = webcontext.Validator().StructCtx(ctx, req)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
authReq.Email = req.Username
|
|
|
|
authReq.Password = req.Password
|
|
|
|
scopes = req.Scope
|
|
|
|
} else {
|
|
|
|
err := errors.New("must provide email and password in Basic auth")
|
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusUnauthorized))
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
authReq.Email = email
|
|
|
|
authReq.Password = pass
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|
|
|
|
|
2019-08-07 23:00:12 -08:00
|
|
|
if qv := r.URL.Query().Get("account_id"); qv != "" {
|
|
|
|
authReq.AccountID = qv
|
|
|
|
}
|
2019-08-05 17:12:28 -08:00
|
|
|
|
2019-06-25 22:31:54 -08:00
|
|
|
// Optional to include scope.
|
2019-08-07 23:00:12 -08:00
|
|
|
if qv := r.URL.Query().Get("scope"); qv != "" {
|
|
|
|
scopes = strings.Split(qv, ",")
|
|
|
|
}
|
2019-06-25 22:31:54 -08:00
|
|
|
|
2019-08-17 11:03:48 +07:00
|
|
|
tkn, err := h.AuthRepo.Authenticate(ctx, authReq, sessionTtl, v.Now, scopes...)
|
2019-05-16 10:39:25 -04:00
|
|
|
if err != nil {
|
2019-06-26 20:21:00 -08:00
|
|
|
cause := errors.Cause(err)
|
|
|
|
switch cause {
|
2019-08-04 14:48:43 -08:00
|
|
|
case user_auth.ErrAuthenticationFailure:
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusUnauthorized))
|
2019-05-16 10:39:25 -04:00
|
|
|
default:
|
2019-06-27 04:48:18 -08:00
|
|
|
_, ok := cause.(validator.ValidationErrors)
|
|
|
|
if ok {
|
2019-08-01 16:17:47 -08:00
|
|
|
return web.RespondJsonError(ctx, w, weberror.NewError(ctx, err, http.StatusBadRequest))
|
2019-06-27 04:48:18 -08:00
|
|
|
}
|
|
|
|
|
2019-05-16 10:39:25 -04:00
|
|
|
return errors.Wrap(err, "authenticating")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-05-23 14:32:24 -05:00
|
|
|
return web.RespondJson(ctx, w, tkn, http.StatusOK)
|
2019-05-16 10:39:25 -04:00
|
|
|
}
|