user_remove.go 1.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051
  1. // Copyright 2018 Frédéric Guillot. All rights reserved.
  2. // Use of this source code is governed by the Apache 2.0
  3. // license that can be found in the LICENSE file.
  4. package ui // import "miniflux.app/ui"
  5. import (
  6. "errors"
  7. "net/http"
  8. "miniflux.app/http/request"
  9. "miniflux.app/http/response/html"
  10. "miniflux.app/http/route"
  11. )
  12. func (h *handler) removeUser(w http.ResponseWriter, r *http.Request) {
  13. loggedUser, err := h.store.UserByID(request.UserID(r))
  14. if err != nil {
  15. html.ServerError(w, r, err)
  16. return
  17. }
  18. if !loggedUser.IsAdmin {
  19. html.Forbidden(w, r)
  20. return
  21. }
  22. selectedUserID := request.RouteInt64Param(r, "userID")
  23. selectedUser, err := h.store.UserByID(selectedUserID)
  24. if err != nil {
  25. html.ServerError(w, r, err)
  26. return
  27. }
  28. if selectedUser == nil {
  29. html.NotFound(w, r)
  30. return
  31. }
  32. if selectedUser.ID == loggedUser.ID {
  33. html.BadRequest(w, r, errors.New("You cannot remove yourself"))
  34. return
  35. }
  36. if err := h.store.RemoveUser(selectedUser.ID); err != nil {
  37. html.ServerError(w, r, err)
  38. return
  39. }
  40. html.Redirect(w, r, route.Path(h.router, "users"))
  41. }