oauth2_unlink.go 1.8 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970
  1. // SPDX-FileCopyrightText: Copyright The Miniflux Authors. All rights reserved.
  2. // SPDX-License-Identifier: Apache-2.0
  3. package ui // import "miniflux.app/v2/internal/ui"
  4. import (
  5. "log/slog"
  6. "net/http"
  7. "miniflux.app/v2/internal/config"
  8. "miniflux.app/v2/internal/http/request"
  9. "miniflux.app/v2/internal/http/response"
  10. "miniflux.app/v2/internal/locale"
  11. )
  12. func (h *handler) oauth2Unlink(w http.ResponseWriter, r *http.Request) {
  13. if config.Opts.DisableLocalAuth() {
  14. slog.Warn("blocking oauth2 unlink attempt, local auth is disabled",
  15. slog.String("user_agent", r.UserAgent()),
  16. )
  17. response.HTMLRedirect(w, r, h.routePath("/"))
  18. return
  19. }
  20. provider := request.RouteStringParam(r, "provider")
  21. if provider == "" {
  22. slog.Warn("Invalid or missing OAuth2 provider")
  23. response.HTMLRedirect(w, r, h.routePath("/"))
  24. return
  25. }
  26. authProvider, err := getOAuth2Manager(r.Context()).FindProvider(provider)
  27. if err != nil {
  28. slog.Error("Unable to initialize OAuth2 provider",
  29. slog.String("provider", provider),
  30. slog.Any("error", err),
  31. )
  32. response.HTMLRedirect(w, r, h.routePath("/settings"))
  33. return
  34. }
  35. user, err := h.store.UserByID(request.UserID(r))
  36. if err != nil {
  37. response.HTMLServerError(w, r, err)
  38. return
  39. }
  40. hasPassword, err := h.store.HasPassword(request.UserID(r))
  41. if err != nil {
  42. response.HTMLServerError(w, r, err)
  43. return
  44. }
  45. sess := request.WebSession(r)
  46. printer := locale.NewPrinter(sess.Language())
  47. if !hasPassword {
  48. sess.SetErrorMessage(printer.Print("error.unlink_account_without_password"))
  49. response.HTMLRedirect(w, r, h.routePath("/settings"))
  50. return
  51. }
  52. authProvider.UnsetUserProfileID(user)
  53. if err := h.store.UpdateUser(user); err != nil {
  54. response.HTMLServerError(w, r, err)
  55. return
  56. }
  57. sess.SetSuccessMessage(printer.Print("alert.account_unlinked"))
  58. response.HTMLRedirect(w, r, h.routePath("/settings"))
  59. }