|
@@ -7,6 +7,7 @@ import (
|
|
|
"git.mmnx.de/Moe/databaseutils"
|
|
"git.mmnx.de/Moe/databaseutils"
|
|
|
"git.mmnx.de/Moe/usermanager"
|
|
"git.mmnx.de/Moe/usermanager"
|
|
|
"git.mmnx.de/Moe/configutils"
|
|
"git.mmnx.de/Moe/configutils"
|
|
|
|
|
+ "git.mmnx.de/Moe/templatehelpers"
|
|
|
"golang.org/x/crypto/bcrypt"
|
|
"golang.org/x/crypto/bcrypt"
|
|
|
"errors"
|
|
"errors"
|
|
|
)
|
|
)
|
|
@@ -54,11 +55,13 @@ func main() {
|
|
|
iris.Static("/img", "./static/img", 1)
|
|
iris.Static("/img", "./static/img", 1)
|
|
|
iris.Static("/static", "./static/static", 1)
|
|
iris.Static("/static", "./static/static", 1)
|
|
|
|
|
|
|
|
- iris.Post("/login", loginHandler) // login form handler
|
|
|
|
|
|
|
+ iris.Post("/login", loginHandler) // login form handler // TODO: outsource ?
|
|
|
|
|
+ iris.Post("/register", registerHandler) // TODO outsource ?
|
|
|
iris.Post("/account", usermanager.AuthHandler, accountUpdateHandler)
|
|
iris.Post("/account", usermanager.AuthHandler, accountUpdateHandler)
|
|
|
iris.Post("/admin", usermanager.AuthHandler, usermanager.AdminHandler, adminPostHandler)
|
|
iris.Post("/admin", usermanager.AuthHandler, usermanager.AdminHandler, adminPostHandler)
|
|
|
|
|
|
|
|
- iris.Get("/login", templateHandler)
|
|
|
|
|
|
|
+ iris.Get("/login", templateHandler) // TODO not when logged in
|
|
|
|
|
+ iris.Get("/register", templateHandler) // TODO not when logged in
|
|
|
iris.Get("/", usermanager.AuthHandler, templateHandler)
|
|
iris.Get("/", usermanager.AuthHandler, templateHandler)
|
|
|
iris.Get("/account", usermanager.AuthHandler, templateHandler)
|
|
iris.Get("/account", usermanager.AuthHandler, templateHandler)
|
|
|
iris.Get("/help", usermanager.AuthHandler, templateHandler)
|
|
iris.Get("/help", usermanager.AuthHandler, templateHandler)
|
|
@@ -85,6 +88,49 @@ func loginHandler(ctx *iris.Context) {
|
|
|
}
|
|
}
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
|
|
+func registerHandler(ctx *iris.Context) {
|
|
|
|
|
+ token := ctx.FormValueString("token") // POST values from login form
|
|
|
|
|
+ username := ctx.FormValueString("username")
|
|
|
|
|
+ password := ctx.FormValueString("password")
|
|
|
|
|
+
|
|
|
|
|
+ user := usermanager.User{} // new user
|
|
|
|
|
+
|
|
|
|
|
+ tokens := usermanager.GetTokens(false) // get all unused tokens
|
|
|
|
|
+ validToken := false
|
|
|
|
|
+ for i, _ := range tokens {
|
|
|
|
|
+ if token == tokens[i] {
|
|
|
|
|
+ validToken = true
|
|
|
|
|
+ break
|
|
|
|
|
+ }
|
|
|
|
|
+ }
|
|
|
|
|
+ if !validToken { // token not valid
|
|
|
|
|
+ templatehelpers.ShowError(usermanager.ERR_INVALID_TOKEN, ctx, "register")
|
|
|
|
|
+ }
|
|
|
|
|
+
|
|
|
|
|
+ userID := usermanager.SearchUserByUsernameInDB(username) // check if a user with that name already exists
|
|
|
|
|
+ if userID != -1 {
|
|
|
|
|
+ templatehelpers.ShowError(usermanager.ERR_USERNAME_TAKEN, ctx, "register")
|
|
|
|
|
+ }
|
|
|
|
|
+
|
|
|
|
|
+ passwordBin, _ := bcrypt.GenerateFromPassword([]byte(password), 15) // hash password
|
|
|
|
|
+
|
|
|
|
|
+ err := usermanager.RegisterUserWithToken(username, string(passwordBin), token) // register user
|
|
|
|
|
+ if err != nil {
|
|
|
|
|
+ templatehelpers.ShowError(err.Error(), ctx, "register")
|
|
|
|
|
+ return
|
|
|
|
|
+ }
|
|
|
|
|
+
|
|
|
|
|
+ tokenString, err := user.Login(username, password) // try to login
|
|
|
|
|
+
|
|
|
|
|
+ if err != nil {
|
|
|
|
|
+ templatehelpers.ShowError(err.Error(), ctx, "login")
|
|
|
|
|
+ } else {
|
|
|
|
|
+ ctx.SetCookieKV("token", tokenString)
|
|
|
|
|
+ ctx.Redirect("/")
|
|
|
|
|
+ // TODO: error-alternative success (main.html)
|
|
|
|
|
+ }
|
|
|
|
|
+}
|
|
|
|
|
+
|
|
|
func accountUpdateHandler(ctx *iris.Context) { // TODO tidy up?
|
|
func accountUpdateHandler(ctx *iris.Context) { // TODO tidy up?
|
|
|
err := errors.New(""); err = nil
|
|
err := errors.New(""); err = nil
|
|
|
username := ctx.FormValueString("username") // POST values
|
|
username := ctx.FormValueString("username") // POST values
|
|
@@ -94,7 +140,7 @@ func accountUpdateHandler(ctx *iris.Context) { // TODO tidy up?
|
|
|
user := (*usermanager.Users)[usersArrayID] // user must be logged in to do this -> get from users list
|
|
user := (*usermanager.Users)[usersArrayID] // user must be logged in to do this -> get from users list
|
|
|
|
|
|
|
|
if username != "" && usermanager.SearchUserByUsername(username) != -1 && username != user.Username { // username can't be changed as there already exists a user with that name or it's the old name
|
|
if username != "" && usermanager.SearchUserByUsername(username) != -1 && username != user.Username { // username can't be changed as there already exists a user with that name or it's the old name
|
|
|
- ctx.Render("account_box.html", usermanager.PageUserParams{"1", errors.New("Username already taken").Error(), "account", user.Username, user.Mail, user.Admin, []string{"ayy", "lmao"}})
|
|
|
|
|
|
|
+ ctx.Render("account_box.html", usermanager.PageUserParams{"1", errors.New("Username already taken").Error(), "account", user.Username, user.Admin, []string{"ayy", "lmao"}})
|
|
|
return
|
|
return
|
|
|
}
|
|
}
|
|
|
|
|
|
|
@@ -112,19 +158,19 @@ func accountUpdateHandler(ctx *iris.Context) { // TODO tidy up?
|
|
|
needQuery = true
|
|
needQuery = true
|
|
|
hashedPassword, err = func (hashedPassword []byte, err error) (string, error) { // hash password, we use an anonymous function to convert it to string
|
|
hashedPassword, err = func (hashedPassword []byte, err error) (string, error) { // hash password, we use an anonymous function to convert it to string
|
|
|
if err != nil { // should never happen
|
|
if err != nil { // should never happen
|
|
|
- ctx.Render("account_box.html", usermanager.PageUserParams{"1", err.Error(), "account", user.Username, user.Mail, user.Admin, []string{"ayy", "lmao"}})
|
|
|
|
|
|
|
+ ctx.Render("account_box.html", usermanager.PageUserParams{"1", err.Error(), "account", user.Username, user.Admin, []string{"ayy", "lmao"}})
|
|
|
return "", err
|
|
return "", err
|
|
|
}
|
|
}
|
|
|
return string(hashedPassword), nil
|
|
return string(hashedPassword), nil
|
|
|
}(bcrypt.GenerateFromPassword([]byte(password), 15)) // this is the actual hashing call
|
|
}(bcrypt.GenerateFromPassword([]byte(password), 15)) // this is the actual hashing call
|
|
|
if err != nil { // should never happen
|
|
if err != nil { // should never happen
|
|
|
- ctx.Render("account_box.html", usermanager.PageUserParams{"1", err.Error(), "account", user.Username, user.Mail, user.Admin, []string{"ayy", "lmao"}})
|
|
|
|
|
|
|
+ ctx.Render("account_box.html", usermanager.PageUserParams{"1", err.Error(), "account", user.Username, user.Admin, []string{"ayy", "lmao"}})
|
|
|
return
|
|
return
|
|
|
}
|
|
}
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
if !needQuery { // we don't need to update anything
|
|
if !needQuery { // we don't need to update anything
|
|
|
- ctx.Render("account_box.html", usermanager.PageUserParams{"1", errors.New("nothing to update").Error(), "account", user.Username, user.Mail, user.Admin, []string{"ayy", "lmao"}})
|
|
|
|
|
|
|
+ ctx.Render("account_box.html", usermanager.PageUserParams{"1", errors.New("nothing to update").Error(), "account", user.Username, user.Admin, []string{"ayy", "lmao"}})
|
|
|
return
|
|
return
|
|
|
}
|
|
}
|
|
|
|
|
|
|
@@ -133,16 +179,16 @@ func accountUpdateHandler(ctx *iris.Context) { // TODO tidy up?
|
|
|
|
|
|
|
|
err = (*usermanager.Users)[usermanager.SearchUser(userID)].Update() // try to update in db
|
|
err = (*usermanager.Users)[usermanager.SearchUser(userID)].Update() // try to update in db
|
|
|
if err != nil { // failed to update
|
|
if err != nil { // failed to update
|
|
|
- ctx.Render("account_box.html", usermanager.PageUserParams{"1", err.Error(), "account", user.Username, user.Mail, user.Admin, []string{"ayy", "lmao"}})
|
|
|
|
|
|
|
+ ctx.Render("account_box.html", usermanager.PageUserParams{"1", err.Error(), "account", user.Username, user.Admin, []string{"ayy", "lmao"}})
|
|
|
return
|
|
return
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
// TODO success notifications
|
|
// TODO success notifications
|
|
|
|
|
|
|
|
if err != nil {
|
|
if err != nil {
|
|
|
- ctx.Render("account_box.html", usermanager.PageUserParams{"1", err.Error(), "account", user.Username, user.Mail, user.Admin, []string{"ayy", "lmao"}}) // TODO dynamic
|
|
|
|
|
|
|
+ ctx.Render("account_box.html", usermanager.PageUserParams{"1", err.Error(), "account", user.Username, user.Admin, []string{"ayy", "lmao"}}) // TODO dynamic
|
|
|
} else {
|
|
} else {
|
|
|
- ctx.Render("account_box.html", usermanager.PageUserParams{"0", "", "account", user.Username, user.Mail, user.Admin, []string{"ayy", "lmao"}}) // TODO dynamic
|
|
|
|
|
|
|
+ ctx.Render("account_box.html", usermanager.PageUserParams{"0", "", "account", user.Username, user.Admin, []string{"ayy", "lmao"}}) // TODO dynamic
|
|
|
}
|
|
}
|
|
|
}
|
|
}
|
|
|
|
|
|
|
@@ -159,42 +205,36 @@ func templateHandler(ctx *iris.Context) {
|
|
|
var params usermanager.PageUserParams
|
|
var params usermanager.PageUserParams
|
|
|
userID := ctx.GetString("userID")
|
|
userID := ctx.GetString("userID")
|
|
|
user, err := usermanager.GetUser(userID)
|
|
user, err := usermanager.GetUser(userID)
|
|
|
-
|
|
|
|
|
- if err != nil { // user is apparently not logged in -> login
|
|
|
|
|
- ctx.MustRender("login_box.html", pageUserParams{"1", err.Error(), "login", "", "", "0"})
|
|
|
|
|
- return
|
|
|
|
|
|
|
+ if err != nil {
|
|
|
|
|
+ if err.Error() != "User not logged in" {
|
|
|
|
|
+ fmt.Println(err.Error())
|
|
|
|
|
+ }
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
template := ""
|
|
template := ""
|
|
|
switch ctx.RequestPath(false) {
|
|
switch ctx.RequestPath(false) {
|
|
|
default:
|
|
default:
|
|
|
template = "home"
|
|
template = "home"
|
|
|
- params = usermanager.PageUserParams{"0", "", template, user.Username, "", user.Admin, []string{}}
|
|
|
|
|
|
|
+ params = usermanager.PageUserParams{"0", "", template, user.Username, user.Admin, []string{}}
|
|
|
case "/":
|
|
case "/":
|
|
|
template = "home"
|
|
template = "home"
|
|
|
- params = usermanager.PageUserParams{"0", "", template, user.Username, "", user.Admin, []string{}}
|
|
|
|
|
|
|
+ params = usermanager.PageUserParams{"0", "", template, user.Username, user.Admin, []string{}}
|
|
|
case "/account":
|
|
case "/account":
|
|
|
template = "account"
|
|
template = "account"
|
|
|
- params = usermanager.PageUserParams{"0", "", template, user.Username, "", user.Admin, []string{}}
|
|
|
|
|
|
|
+ params = usermanager.PageUserParams{"0", "", template, user.Username, user.Admin, []string{}}
|
|
|
case "/help":
|
|
case "/help":
|
|
|
template = "help"
|
|
template = "help"
|
|
|
- params = usermanager.PageUserParams{"0", "", template, user.Username, "", user.Admin, []string{}}
|
|
|
|
|
|
|
+ params = usermanager.PageUserParams{"0", "", template, user.Username, user.Admin, []string{}}
|
|
|
case "/admin":
|
|
case "/admin":
|
|
|
template = "admin"
|
|
template = "admin"
|
|
|
- tokens, err := databaseutils.DBUtil.GetRows("*", "tokens", "used", "0") // get unused tokens // TODO: outsource in function GetTokens()
|
|
|
|
|
- if err != nil {
|
|
|
|
|
- fmt.Println(err.Error()) // TODO: nicer / outsource
|
|
|
|
|
- }
|
|
|
|
|
-
|
|
|
|
|
- message := "" // string for textarea output in /admin
|
|
|
|
|
- for i, _ := range tokens { // TODO outsource
|
|
|
|
|
- message += tokens[i][1] + "\n"
|
|
|
|
|
- } // TODO outsource function until here
|
|
|
|
|
-
|
|
|
|
|
- params = usermanager.PageUserParams{"0", "", template, user.Username, "", user.Admin, []string{message}}
|
|
|
|
|
|
|
+ tokens := usermanager.GetTokens(false)
|
|
|
|
|
+ params = usermanager.PageUserParams{"0", "", template, user.Username, user.Admin, tokens}
|
|
|
case "/login":
|
|
case "/login":
|
|
|
template = "login"
|
|
template = "login"
|
|
|
- params = usermanager.PageUserParams{"0", "", template, "", "", "0", []string{"ayy", "lmao"}}
|
|
|
|
|
|
|
+ params = usermanager.PageUserParams{"0", "", template, "", "0", []string{"ayy", "lmao"}}
|
|
|
|
|
+ case "/register":
|
|
|
|
|
+ template = "register"
|
|
|
|
|
+ params = usermanager.PageUserParams{"0", "", template, "", "0", []string{}}
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
|
|
|