main.go 7.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238
  1. package main
  2. import (
  3. "github.com/kataras/iris"
  4. "github.com/kataras/go-template/html"
  5. "fmt"
  6. "git.mmnx.de/Moe/usermanager"
  7. "git.mmnx.de/Moe/databaseutils"
  8. "git.mmnx.de/Moe/configutils"
  9. "git.mmnx.de/Moe/templatehelpers"
  10. "golang.org/x/crypto/bcrypt"
  11. // "errors"
  12. "strconv"
  13. )
  14. type pageUserParams struct{
  15. HasError string
  16. Error string
  17. ReqDir string
  18. Username string
  19. Email string
  20. Admin string
  21. } // {Error: ""}
  22. func main() {
  23. conf := configutils.ReadConfig("config.json") // read config
  24. configutils.Conf = &conf // store conf globally accessible
  25. databaseutils.DBUtil = &databaseutils.DBUtils{configutils.Conf.DBUser, configutils.Conf.DBPass, configutils.Conf.DBHost, configutils.Conf.DBName, nil} // init dbutils
  26. databaseutils.DBUtil.Connect() // connect to db
  27. users := make([]usermanager.User, 0) // users list
  28. usermanager.Users = &users // store globally accessible
  29. fmt.Print("") // for not needing to remove fmt ...
  30. iris.Config.IsDevelopment = true
  31. //iris.Config.Render.Template.Gzip = true
  32. /** HELPER FUNCTION EXAMPLE **/
  33. /*config := html.DefaultConfig()
  34. config.Layout = "layouts/main.html"
  35. config.Helpers["boldme"] = func(input string) raymond.SafeString {
  36. return raymond.SafeString("<b> " + input + "</b>")
  37. }*/
  38. /** ROUTING **/
  39. iris.UseTemplate(html.New(html.Config{
  40. Layout: "layouts/main.html",
  41. }))
  42. iris.Static("/js", "./static/js", 1)
  43. iris.Static("/css", "./static/css", 1)
  44. iris.Static("/img", "./static/img", 1)
  45. iris.Static("/static", "./static/static", 1)
  46. iris.Post("/login", loginHandler) // login form handler // TODO: outsource ?
  47. iris.Post("/register", registerHandler, usermanager.LogoutHandler) // TODO outsource ?
  48. iris.Post("/account", usermanager.AuthHandler, accountUpdateHandler, usermanager.LogoutHandler)
  49. iris.Post("/admin", usermanager.AuthHandler, usermanager.AdminHandler, adminPostHandler)
  50. iris.Get("/login", templateHandler) // TODO not when logged in
  51. iris.Get("/logout", usermanager.AuthHandler, usermanager.LogoutHandler)
  52. iris.Get("/register", templateHandler) // TODO not when logged in
  53. iris.Get("/", usermanager.AuthHandler, templateHandler)
  54. iris.Get("/account", usermanager.AuthHandler, templateHandler)
  55. iris.Get("/help", usermanager.AuthHandler, templateHandler)
  56. iris.Get("/admin", usermanager.AuthHandler, usermanager.AdminHandler, templateHandler)
  57. /** OTHER **/
  58. iris.Listen(":8080")
  59. }
  60. func loginHandler(ctx *iris.Context) {
  61. username := ctx.FormValueString("username") // POST values from login form
  62. password := ctx.FormValueString("password")
  63. user := usermanager.User{} // new user
  64. tokenString, err := user.Login(username, password) // try to login
  65. if err != nil {
  66. ctx.Render("login_box.html", usermanager.PageParams{"1", err.Error(), "login", "0"})
  67. } else {
  68. ctx.SetCookieKV("token", tokenString)
  69. ctx.Redirect("/")
  70. // TODO: error-alternative success (main.html)
  71. }
  72. }
  73. func registerHandler(ctx *iris.Context) {
  74. token := ctx.FormValueString("token") // POST values from login form
  75. username := ctx.FormValueString("username")
  76. password := ctx.FormValueString("password")
  77. user := usermanager.User{} // new user
  78. tokenUserID, err := usermanager.SearchUserByTokenInDB(token) // user, we're going to change
  79. if err != nil {
  80. templatehelpers.ShowError(err.Error(), ctx, "register")
  81. return
  82. }
  83. tokenUserIDStr := strconv.FormatInt(int64(tokenUserID), 10)
  84. if err != nil {
  85. templatehelpers.ShowError(err.Error(), ctx, "register")
  86. return
  87. }
  88. tokenUser, err := usermanager.GetUserFromDB(tokenUserIDStr)
  89. if err != nil {
  90. templatehelpers.ShowError(err.Error(), ctx, "register")
  91. return
  92. }
  93. tokens := usermanager.GetTokens(false) // get all unused tokens, // TODO when v outsourced, use GetToken()
  94. unusedToken := false // TODO: outsource this (GetToken())
  95. for i, _ := range tokens {
  96. if token == tokens[i] {
  97. unusedToken = true
  98. break
  99. }
  100. }
  101. tokens = usermanager.GetTokens(true) // get all used tokens, // TODO when v outsourced, use GetToken()
  102. usedToken := false // TODO: outsource this (GetToken())
  103. for i, _ := range tokens {
  104. if token == tokens[i] {
  105. usedToken = true
  106. break
  107. }
  108. }
  109. if !unusedToken && !usedToken { // token doesnt exist
  110. templatehelpers.ShowError(usermanager.ERR_INVALID_TOKEN, ctx, "register")
  111. }
  112. userID := usermanager.SearchUserByUsernameInDB(username) // check if a user with that name already exists
  113. if userID != -1 {
  114. tokenUserIDInt, err := strconv.Atoi(tokenUser.ID) // convert userID to int ...
  115. if err != nil {
  116. templatehelpers.ShowError(err.Error(), ctx, "register")
  117. return
  118. }
  119. if userID != tokenUserIDInt { // tries to steal another users identity
  120. templatehelpers.ShowError(usermanager.ERR_USERNAME_TAKEN, ctx, "register")
  121. return
  122. } // if it's his own name, that's "taken" he can change
  123. }
  124. if unusedToken {
  125. passwordBin, _ := bcrypt.GenerateFromPassword([]byte(password), 15) // hash password
  126. err := usermanager.RegisterUserWithToken(username, string(passwordBin), token) // register user
  127. if err != nil {
  128. templatehelpers.ShowError(err.Error(), ctx, "register")
  129. return
  130. }
  131. tokenString, err := user.Login(username, password) // try to login
  132. if err != nil {
  133. templatehelpers.ShowError(err.Error(), ctx, "login")
  134. } else {
  135. ctx.SetCookieKV("token", tokenString)
  136. ctx.Redirect("/")
  137. // TODO: error-alternative success (main.html)
  138. }
  139. } else {
  140. // TODO maybe check whether to login or logout
  141. if err := usermanager.UserUpdateProcessor(username, password, tokenUserIDStr); err != nil {
  142. templatehelpers.ShowError(err.Error(), ctx, "register")
  143. return
  144. }
  145. }
  146. }
  147. func accountUpdateHandler(ctx *iris.Context) {
  148. username := ctx.FormValueString("username") // POST values
  149. password := ctx.FormValueString("password")
  150. userID := ctx.GetString("userID")
  151. if err := usermanager.UserUpdateProcessor(username, password, userID); err != nil {
  152. templatehelpers.ShowError(err.Error(), ctx, "account")
  153. return
  154. }
  155. }
  156. func adminPostHandler(ctx *iris.Context) {
  157. _ = usermanager.GenerateTokens(5) // generate tokens and store in db, we don't need them now
  158. ctx.Redirect("/admin") // just redirect so that we see old+new tokens
  159. // TODO success notifications
  160. }
  161. func templateHandler(ctx *iris.Context) {
  162. var params usermanager.PageUserParams
  163. userID := ctx.GetString("userID")
  164. user, err := usermanager.GetUser(userID)
  165. if err != nil {
  166. if err.Error() != "User not logged in" {
  167. fmt.Println(err.Error())
  168. }
  169. }
  170. template := ""
  171. switch ctx.RequestPath(false) {
  172. default:
  173. template = "home"
  174. params = usermanager.PageUserParams{"0", "", template, user.Username, user.Admin, []string{}}
  175. case "/":
  176. template = "home"
  177. params = usermanager.PageUserParams{"0", "", template, user.Username, user.Admin, []string{}}
  178. case "/account":
  179. template = "account"
  180. params = usermanager.PageUserParams{"0", "", template, user.Username, user.Admin, []string{}}
  181. case "/help":
  182. template = "help"
  183. params = usermanager.PageUserParams{"0", "", template, user.Username, user.Admin, []string{}}
  184. case "/admin":
  185. template = "admin"
  186. tokens := usermanager.GetTokens(false)
  187. params = usermanager.PageUserParams{"0", "", template, user.Username, user.Admin, tokens}
  188. case "/login":
  189. template = "login"
  190. params = usermanager.PageUserParams{"0", "", template, "", "0", []string{}}
  191. case "/register":
  192. template = "register"
  193. params = usermanager.PageUserParams{"0", "", template, "", "0", []string{}}
  194. }
  195. ctx.MustRender(template + "_box.html", params);
  196. }