oauth2_unlink.go 1.9 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071
  1. // SPDX-FileCopyrightText: Copyright The Miniflux Authors. All rights reserved.
  2. // SPDX-License-Identifier: Apache-2.0
  3. package ui // import "miniflux.app/v2/internal/ui"
  4. import (
  5. "log/slog"
  6. "net/http"
  7. "miniflux.app/v2/internal/config"
  8. "miniflux.app/v2/internal/http/request"
  9. "miniflux.app/v2/internal/http/response"
  10. "miniflux.app/v2/internal/locale"
  11. "miniflux.app/v2/internal/ui/session"
  12. )
  13. func (h *handler) oauth2Unlink(w http.ResponseWriter, r *http.Request) {
  14. if config.Opts.DisableLocalAuth() {
  15. slog.Warn("blocking oauth2 unlink attempt, local auth is disabled",
  16. slog.String("user_agent", r.UserAgent()),
  17. )
  18. response.HTMLRedirect(w, r, h.routePath("/"))
  19. return
  20. }
  21. provider := request.RouteStringParam(r, "provider")
  22. if provider == "" {
  23. slog.Warn("Invalid or missing OAuth2 provider")
  24. response.HTMLRedirect(w, r, h.routePath("/"))
  25. return
  26. }
  27. authProvider, err := getOAuth2Manager(r.Context()).FindProvider(provider)
  28. if err != nil {
  29. slog.Error("Unable to initialize OAuth2 provider",
  30. slog.String("provider", provider),
  31. slog.Any("error", err),
  32. )
  33. response.HTMLRedirect(w, r, h.routePath("/settings"))
  34. return
  35. }
  36. user, err := h.store.UserByID(request.UserID(r))
  37. if err != nil {
  38. response.HTMLServerError(w, r, err)
  39. return
  40. }
  41. hasPassword, err := h.store.HasPassword(request.UserID(r))
  42. if err != nil {
  43. response.HTMLServerError(w, r, err)
  44. return
  45. }
  46. sess := session.New(h.store, request.SessionID(r))
  47. printer := locale.NewPrinter(request.UserLanguage(r))
  48. if !hasPassword {
  49. sess.NewFlashErrorMessage(printer.Print("error.unlink_account_without_password"))
  50. response.HTMLRedirect(w, r, h.routePath("/settings"))
  51. return
  52. }
  53. authProvider.UnsetUserProfileID(user)
  54. if err := h.store.UpdateUser(user); err != nil {
  55. response.HTMLServerError(w, r, err)
  56. return
  57. }
  58. sess.NewFlashMessage(printer.Print("alert.account_unlinked"))
  59. response.HTMLRedirect(w, r, h.routePath("/settings"))
  60. }