main.go 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217
  1. package main
  2. import (
  3. "github.com/kataras/iris"
  4. "github.com/kataras/go-template/html"
  5. "fmt"
  6. "git.mmnx.de/Moe/databaseutils"
  7. "git.mmnx.de/Moe/usermanager"
  8. "git.mmnx.de/Moe/configutils"
  9. "golang.org/x/crypto/bcrypt"
  10. "errors"
  11. )
  12. type pageUserParams struct{
  13. HasError string
  14. Error string
  15. ReqDir string
  16. Username string
  17. Email string
  18. Admin string
  19. } // {Error: ""}
  20. func main() {
  21. conf := configutils.ReadConfig("config.json") // read config
  22. configutils.Conf = &conf // store conf globally accessible
  23. databaseutils.DBUtil = &databaseutils.DBUtils{configutils.Conf.DBUser, configutils.Conf.DBPass, configutils.Conf.DBHost, configutils.Conf.DBName, nil} // init dbutils
  24. databaseutils.DBUtil.Connect() // connect to db
  25. users := make([]usermanager.User, 0) // users list
  26. usermanager.Users = &users // store globally accessible
  27. fmt.Print("") // for not needing to remove fmt ...
  28. iris.Config.IsDevelopment = true
  29. //iris.Config.Render.Template.Gzip = true
  30. /** HELPER FUNCTION EXAMPLE **/
  31. /*config := html.DefaultConfig()
  32. config.Layout = "layouts/main.html"
  33. config.Helpers["boldme"] = func(input string) raymond.SafeString {
  34. return raymond.SafeString("<b> " + input + "</b>")
  35. }*/
  36. /** ROUTING **/
  37. iris.UseTemplate(html.New(html.Config{
  38. Layout: "layouts/main.html",
  39. }))
  40. iris.Static("/js", "./static/js", 1)
  41. iris.Static("/css", "./static/css", 1)
  42. iris.Static("/img", "./static/img", 1)
  43. iris.Static("/static", "./static/static", 1)
  44. iris.Post("/login", loginHandler) // login form handler
  45. iris.Post("/account", usermanager.AuthHandler, accountUpdateHandler)
  46. iris.Post("/admin", usermanager.AuthHandler, usermanager.AdminHandler, adminPostHandler)
  47. iris.Get("/login", templateHandler)
  48. iris.Get("/", usermanager.AuthHandler, templateHandler)
  49. iris.Get("/account", usermanager.AuthHandler, templateHandler)
  50. iris.Get("/help", usermanager.AuthHandler, templateHandler)
  51. iris.Get("/admin", usermanager.AuthHandler, usermanager.AdminHandler, func(ctx *iris.Context) { // TODO integrate in outsource (templateHandler)
  52. userID := ctx.GetString("userID")
  53. user, err := usermanager.GetUser(userID)
  54. tokens, err := databaseutils.DBUtil.GetRows("*", "tokens", "used", "0") // get unused tokens
  55. if err != nil {
  56. fmt.Println(err.Error()) // TODO: nicer
  57. }
  58. message := "" // string for textarea output in /admin
  59. for i, _ := range tokens {
  60. message += tokens[i][1] + "\n"
  61. }
  62. params := usermanager.PageUserParamsMessage{"0", "", "admin", user.Username, "", user.Admin, message}
  63. if err := ctx.Render("admin_box.html", params); err != nil {
  64. println(err.Error())
  65. }
  66. })
  67. /** OTHER **/
  68. iris.Listen(":8080")
  69. }
  70. func loginHandler(ctx *iris.Context) {
  71. username := ctx.FormValueString("username") // POST values from login form
  72. password := ctx.FormValueString("password")
  73. user := usermanager.User{} // new user
  74. tokenString, err := user.Login(username, password) // try to login
  75. if err != nil {
  76. ctx.Render("login_box.html", usermanager.PageParams{"1", err.Error(), "login", "0"})
  77. } else {
  78. ctx.SetCookieKV("token", tokenString)
  79. ctx.Redirect("/")
  80. // TODO: error-alternative success (main.html)
  81. }
  82. }
  83. func accountUpdateHandler(ctx *iris.Context) { // TODO tidy up?
  84. err := errors.New(""); err = nil
  85. username := ctx.FormValueString("username") // POST values
  86. password := ctx.FormValueString("password")
  87. userID := ctx.GetString("userID")
  88. usersArrayID := usermanager.SearchUser(userID)
  89. user := (*usermanager.Users)[usersArrayID] // user must be logged in to do this -> get from users list
  90. if username != "" && usermanager.SearchUserByUsername(username) != -1 && username != user.Username { // username can't be changed as there already exists a user with that name or it's the old name
  91. ctx.Render("account_box.html", usermanager.PageUserParams{"1", errors.New("Username already taken").Error(), "account", user.Username, user.Mail, user.Admin})
  92. return
  93. }
  94. needQuery := false
  95. if username != "" { // if not left empty (-> change)
  96. needQuery = true
  97. } else {
  98. username = user.Username // keep
  99. }
  100. hashedPassword := user.Password // we assumpt the user's not changing his password
  101. if password != "" { // if not left empty we change it
  102. needQuery = true
  103. hashedPassword, err = func (hashedPassword []byte, err error) (string, error) { // hash password, we use an anonymous function to convert it to string
  104. if err != nil { // should never happen
  105. ctx.Render("account_box.html", usermanager.PageUserParams{"1", err.Error(), "account", user.Username, user.Mail, user.Admin})
  106. return "", err
  107. }
  108. return string(hashedPassword), nil
  109. }(bcrypt.GenerateFromPassword([]byte(password), 15)) // this is the actual hashing call
  110. if err != nil { // should never happen
  111. ctx.Render("account_box.html", usermanager.PageUserParams{"1", err.Error(), "account", user.Username, user.Mail, user.Admin})
  112. return
  113. }
  114. }
  115. if !needQuery { // we don't need to update anything
  116. ctx.Render("account_box.html", usermanager.PageUserParams{"1", errors.New("nothing to update").Error(), "account", user.Username, user.Mail, user.Admin})
  117. return
  118. }
  119. (*usermanager.Users)[usermanager.SearchUser(userID)].Username = username // update values in runtime users list
  120. (*usermanager.Users)[usermanager.SearchUser(userID)].Password = hashedPassword
  121. err = (*usermanager.Users)[usermanager.SearchUser(userID)].Update() // try to update in db
  122. if err != nil { // failed to update
  123. ctx.Render("account_box.html", usermanager.PageUserParams{"1", err.Error(), "account", user.Username, user.Mail, user.Admin})
  124. return
  125. }
  126. // TODO success notifications
  127. if err != nil {
  128. ctx.Render("account_box.html", usermanager.PageUserParams{"1", err.Error(), "account", user.Username, user.Mail, user.Admin}) // TODO dynamic
  129. } else {
  130. ctx.Render("account_box.html", usermanager.PageUserParams{"0", "", "account", user.Username, user.Mail, user.Admin}) // TODO dynamic
  131. }
  132. }
  133. func adminPostHandler(ctx *iris.Context) {
  134. err := errors.New(""); err = nil
  135. userID := ctx.GetString("userID")
  136. usersArrayID := usermanager.SearchUser(userID)
  137. err = usermanager.GenerateTokens(5) // tokens
  138. if err != nil {
  139. ctx.Render("admin_box.html", usermanager.PageUserParams{"1", err.Error(), "admin", user.Username, user.Mail, user.Admin}) // TODO dynamic
  140. fmt.Println(err.Error())
  141. return
  142. }
  143. ctx.Redirect("/admin") // just redirect so that we see old+new tokens
  144. // TODO success notifications
  145. }
  146. func templateHandler(ctx *iris.Context) {
  147. template := ""
  148. switch ctx.RequestPath(false) {
  149. case "/":
  150. template = "home"
  151. case "/account":
  152. template = "account"
  153. case "/help":
  154. template = "help"
  155. case "/admin":
  156. template = "admin"
  157. case "/login":
  158. template = "login"
  159. }
  160. // fmt.Println(ctx.RequestPath(false))
  161. // fmt.Println(template)
  162. userID := ctx.GetString("userID")
  163. user, err := usermanager.GetUser(userID)
  164. if err != nil { // user is apparently not logged in -> login
  165. ctx.MustRender("login_box.html", pageUserParams{"1", err.Error(), template, "", "", "0"})
  166. return
  167. }
  168. params := usermanager.PageUserParams{"0", "", template, user.Username, "", user.Admin}
  169. ctx.MustRender(template + "_box.html", params);
  170. }