user.go 3.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164
  1. // Copyright 2017 Frédéric Guillot. All rights reserved.
  2. // Use of this source code is governed by the Apache 2.0
  3. // license that can be found in the LICENSE file.
  4. package api
  5. import (
  6. "errors"
  7. "github.com/miniflux/miniflux/server/api/payload"
  8. "github.com/miniflux/miniflux/server/core"
  9. )
  10. // CreateUser is the API handler to create a new user.
  11. func (c *Controller) CreateUser(ctx *core.Context, request *core.Request, response *core.Response) {
  12. if !ctx.IsAdminUser() {
  13. response.JSON().Forbidden()
  14. return
  15. }
  16. user, err := payload.DecodeUserPayload(request.Body())
  17. if err != nil {
  18. response.JSON().BadRequest(err)
  19. return
  20. }
  21. if err := user.ValidateUserCreation(); err != nil {
  22. response.JSON().BadRequest(err)
  23. return
  24. }
  25. if c.store.UserExists(user.Username) {
  26. response.JSON().BadRequest(errors.New("This user already exists"))
  27. return
  28. }
  29. err = c.store.CreateUser(user)
  30. if err != nil {
  31. response.JSON().ServerError(errors.New("Unable to create this user"))
  32. return
  33. }
  34. user.Password = ""
  35. response.JSON().Created(user)
  36. }
  37. // UpdateUser is the API handler to update the given user.
  38. func (c *Controller) UpdateUser(ctx *core.Context, request *core.Request, response *core.Response) {
  39. if !ctx.IsAdminUser() {
  40. response.JSON().Forbidden()
  41. return
  42. }
  43. userID, err := request.IntegerParam("userID")
  44. if err != nil {
  45. response.JSON().BadRequest(err)
  46. return
  47. }
  48. user, err := payload.DecodeUserPayload(request.Body())
  49. if err != nil {
  50. response.JSON().BadRequest(err)
  51. return
  52. }
  53. if err := user.ValidateUserModification(); err != nil {
  54. response.JSON().BadRequest(err)
  55. return
  56. }
  57. originalUser, err := c.store.UserByID(userID)
  58. if err != nil {
  59. response.JSON().BadRequest(errors.New("Unable to fetch this user from the database"))
  60. return
  61. }
  62. if originalUser == nil {
  63. response.JSON().NotFound(errors.New("User not found"))
  64. return
  65. }
  66. originalUser.Merge(user)
  67. if err = c.store.UpdateUser(originalUser); err != nil {
  68. response.JSON().ServerError(errors.New("Unable to update this user"))
  69. return
  70. }
  71. response.JSON().Created(originalUser)
  72. }
  73. // GetUsers is the API handler to get the list of users.
  74. func (c *Controller) GetUsers(ctx *core.Context, request *core.Request, response *core.Response) {
  75. if !ctx.IsAdminUser() {
  76. response.JSON().Forbidden()
  77. return
  78. }
  79. users, err := c.store.Users()
  80. if err != nil {
  81. response.JSON().ServerError(errors.New("Unable to fetch the list of users"))
  82. return
  83. }
  84. response.JSON().Standard(users)
  85. }
  86. // GetUser is the API handler to fetch the given user.
  87. func (c *Controller) GetUser(ctx *core.Context, request *core.Request, response *core.Response) {
  88. if !ctx.IsAdminUser() {
  89. response.JSON().Forbidden()
  90. return
  91. }
  92. userID, err := request.IntegerParam("userID")
  93. if err != nil {
  94. response.JSON().BadRequest(err)
  95. return
  96. }
  97. user, err := c.store.UserByID(userID)
  98. if err != nil {
  99. response.JSON().BadRequest(errors.New("Unable to fetch this user from the database"))
  100. return
  101. }
  102. if user == nil {
  103. response.JSON().NotFound(errors.New("User not found"))
  104. return
  105. }
  106. response.JSON().Standard(user)
  107. }
  108. // RemoveUser is the API handler to remove an existing user.
  109. func (c *Controller) RemoveUser(ctx *core.Context, request *core.Request, response *core.Response) {
  110. if !ctx.IsAdminUser() {
  111. response.JSON().Forbidden()
  112. return
  113. }
  114. userID, err := request.IntegerParam("userID")
  115. if err != nil {
  116. response.JSON().BadRequest(err)
  117. return
  118. }
  119. user, err := c.store.UserByID(userID)
  120. if err != nil {
  121. response.JSON().ServerError(errors.New("Unable to fetch this user from the database"))
  122. return
  123. }
  124. if user == nil {
  125. response.JSON().NotFound(errors.New("User not found"))
  126. return
  127. }
  128. if err := c.store.RemoveUser(user.ID); err != nil {
  129. response.JSON().BadRequest(errors.New("Unable to remove this user from the database"))
  130. return
  131. }
  132. response.JSON().NoContent()
  133. }