users.go 3.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138
  1. package main
  2. import (
  3. "errors"
  4. "fmt"
  5. "net/http"
  6. "strconv"
  7. "github.com/asaskevich/govalidator"
  8. "github.com/knadh/listmonk/models"
  9. "github.com/labstack/echo"
  10. )
  11. // handleGetUsers handles retrieval of users.
  12. func handleGetUsers(c echo.Context) error {
  13. var (
  14. app = c.Get("app").(*App)
  15. out []models.User
  16. id, _ = strconv.Atoi(c.Param("id"))
  17. single = false
  18. )
  19. // Fetch one list.
  20. if id > 0 {
  21. single = true
  22. }
  23. err := app.Queries.GetUsers.Select(&out, id)
  24. if err != nil {
  25. return echo.NewHTTPError(http.StatusInternalServerError,
  26. fmt.Sprintf("Error fetching users: %s", pqErrMsg(err)))
  27. } else if single && len(out) == 0 {
  28. return echo.NewHTTPError(http.StatusBadRequest, "User not found.")
  29. } else if len(out) == 0 {
  30. return c.JSON(http.StatusOK, okResp{[]struct{}{}})
  31. }
  32. if single {
  33. return c.JSON(http.StatusOK, okResp{out[0]})
  34. }
  35. return c.JSON(http.StatusOK, okResp{out})
  36. }
  37. // handleCreateUser handles user creation.
  38. func handleCreateUser(c echo.Context) error {
  39. var (
  40. app = c.Get("app").(*App)
  41. o = models.User{}
  42. )
  43. if err := c.Bind(&o); err != nil {
  44. return err
  45. }
  46. if !govalidator.IsEmail(o.Email) {
  47. return errors.New("invalid `email`")
  48. }
  49. if !govalidator.IsByteLength(o.Name, 1, stdInputMaxLen) {
  50. return errors.New("invalid length for `name`")
  51. }
  52. // Insert and read ID.
  53. var newID int
  54. if err := app.Queries.CreateUser.Get(&newID,
  55. o.Email,
  56. o.Name,
  57. o.Password,
  58. o.Type,
  59. o.Status); err != nil {
  60. return echo.NewHTTPError(http.StatusInternalServerError,
  61. fmt.Sprintf("Error creating user: %v", pqErrMsg(err)))
  62. }
  63. // Hand over to the GET handler to return the last insertion.
  64. c.SetParamNames("id")
  65. c.SetParamValues(fmt.Sprintf("%d", newID))
  66. return c.JSON(http.StatusOK, handleGetLists(c))
  67. }
  68. // handleUpdateUser handles user modification.
  69. func handleUpdateUser(c echo.Context) error {
  70. var (
  71. app = c.Get("app").(*App)
  72. id, _ = strconv.Atoi(c.Param("id"))
  73. )
  74. if id < 1 {
  75. return echo.NewHTTPError(http.StatusBadRequest, "Invalid ID.")
  76. } else if id == 1 {
  77. return echo.NewHTTPError(http.StatusBadRequest,
  78. "The primordial super admin cannot be deleted.")
  79. }
  80. var o models.User
  81. if err := c.Bind(&o); err != nil {
  82. return err
  83. }
  84. if !govalidator.IsEmail(o.Email) {
  85. return errors.New("invalid `email`")
  86. }
  87. if !govalidator.IsByteLength(o.Name, 1, stdInputMaxLen) {
  88. return errors.New("invalid length for `name`")
  89. }
  90. // TODO: PASSWORD HASHING.
  91. res, err := app.Queries.UpdateUser.Exec(o.ID,
  92. o.Email,
  93. o.Name,
  94. o.Password,
  95. o.Type,
  96. o.Status)
  97. if err != nil {
  98. return echo.NewHTTPError(http.StatusInternalServerError,
  99. fmt.Sprintf("Error updating user: %s", pqErrMsg(err)))
  100. }
  101. if n, _ := res.RowsAffected(); n == 0 {
  102. return echo.NewHTTPError(http.StatusBadRequest, "User not found.")
  103. }
  104. return handleGetUsers(c)
  105. }
  106. // handleDeleteUser handles user deletion.
  107. func handleDeleteUser(c echo.Context) error {
  108. var (
  109. id, _ = strconv.Atoi(c.Param("id"))
  110. )
  111. if id < 1 {
  112. return echo.NewHTTPError(http.StatusBadRequest, "Invalid ID.")
  113. }
  114. return c.JSON(http.StatusOK, okResp{true})
  115. }