Semaphore/api/projects/inventory.go

224 lines
4.9 KiB
Go
Raw Normal View History

2016-04-02 14:40:07 +02:00
package projects
2016-04-04 15:44:34 +02:00
import (
log "github.com/Sirupsen/logrus"
"github.com/ansible-semaphore/semaphore/api/helpers"
"github.com/ansible-semaphore/semaphore/db"
2017-02-23 00:21:49 +01:00
"net/http"
"os"
"path/filepath"
"strings"
2017-02-23 00:21:49 +01:00
"github.com/gorilla/context"
2016-04-04 15:44:34 +02:00
)
2016-04-02 14:40:07 +02:00
const (
asc = "asc"
desc = "desc"
)
// InventoryMiddleware ensures an inventory exists and loads it to the context
func InventoryMiddleware(next http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
project := context.Get(r, "project").(db.Project)
inventoryID, err := helpers.GetIntParam("inventory_id", w, r)
if err != nil {
return
}
2020-12-07 13:13:59 +01:00
inventory, err := helpers.Store(r).GetInventory(project.ID, inventoryID)
if err != nil {
helpers.WriteError(w, err)
}
context.Set(r, "inventory", inventory)
next.ServeHTTP(w, r)
})
2016-04-02 14:40:07 +02:00
}
// GetInventory returns an inventory from the database
func GetInventory(w http.ResponseWriter, r *http.Request) {
2020-11-03 19:09:09 +01:00
if inventory := context.Get(r, "inventory"); inventory != nil {
helpers.WriteJSON(w, http.StatusOK, inventory.(db.Inventory))
2020-11-03 19:09:09 +01:00
return
}
2020-11-22 01:32:49 +01:00
project := context.Get(r, "project").(db.Project)
2020-11-03 19:09:09 +01:00
2020-12-07 13:13:59 +01:00
params := db.RetrieveQueryParams{
SortBy: r.URL.Query().Get("sort"),
SortInverted: r.URL.Query().Get("order") == desc,
}
2020-12-07 13:13:59 +01:00
inventories, err := helpers.Store(r).GetInventories(project.ID, params)
2020-12-07 13:13:59 +01:00
if err != nil {
helpers.WriteError(w, err)
return
}
2016-04-04 15:44:34 +02:00
2020-12-07 13:13:59 +01:00
helpers.WriteJSON(w, http.StatusOK, inventories)
2016-04-04 15:44:34 +02:00
}
// AddInventory creates an inventory in the database
func AddInventory(w http.ResponseWriter, r *http.Request) {
project := context.Get(r, "project").(db.Project)
2020-12-07 13:13:59 +01:00
var inventory db.Inventory
2016-04-04 15:44:34 +02:00
if !helpers.Bind(w, r, &inventory) {
return
}
2016-04-04 15:44:34 +02:00
2020-12-07 13:13:59 +01:00
if inventory.ProjectID != project.ID {
helpers.WriteJSON(w, http.StatusBadRequest, map[string]string{
"error": "Project ID in body and URL must be the same",
})
return
}
switch inventory.Type {
case "static", "file":
break
default:
2020-12-07 13:13:59 +01:00
helpers.WriteJSON(w, http.StatusBadRequest, map[string]string{
"error": "Not supported inventory type",
})
return
}
2016-04-17 02:20:23 +02:00
2020-12-07 13:13:59 +01:00
newInventory, err := helpers.Store(r).CreateInventory(inventory)
if err != nil {
2020-12-07 13:13:59 +01:00
helpers.WriteError(w, err)
return
}
2016-04-04 15:44:34 +02:00
objType := "inventory"
desc := "Inventory " + inventory.Name + " created"
_, err = helpers.Store(r).CreateEvent(db.Event{
ProjectID: &project.ID,
ObjectType: &objType,
2020-12-07 13:13:59 +01:00
ObjectID: &newInventory.ID,
Description: &desc,
})
if err != nil {
2020-12-07 13:13:59 +01:00
// Write error to log but return ok to user, because inventory created
log.Error(err)
}
2020-12-07 13:13:59 +01:00
helpers.WriteJSON(w, http.StatusCreated, newInventory)
2016-04-04 15:44:34 +02:00
}
// IsValidInventoryPath tests a path to ensure it is below the cwd
2018-03-08 12:37:38 +01:00
func IsValidInventoryPath(path string) bool {
currentPath, err := os.Getwd()
if err != nil {
2018-03-08 10:04:34 +01:00
return false
}
absPath, err := filepath.Abs(path)
if err != nil {
2018-03-08 10:04:34 +01:00
return false
}
relPath, err := filepath.Rel(currentPath, absPath)
if err != nil {
2018-03-08 10:04:34 +01:00
return false
}
return !strings.HasPrefix(relPath, "..")
2018-03-08 10:04:34 +01:00
}
// UpdateInventory writes updated values to an existing inventory item in the database
func UpdateInventory(w http.ResponseWriter, r *http.Request) {
oldInventory := context.Get(r, "inventory").(db.Inventory)
2020-12-07 13:13:59 +01:00
var inventory db.Inventory
if !helpers.Bind(w, r, &inventory) {
return
}
2020-12-07 13:13:59 +01:00
if inventory.ID != oldInventory.ID {
helpers.WriteJSON(w, http.StatusBadRequest, map[string]string{
"error": "Inventory ID in body and URL must be the same",
})
return
}
if inventory.ProjectID != oldInventory.ProjectID {
helpers.WriteJSON(w, http.StatusBadRequest, map[string]string{
"error": "Project ID in body and URL must be the same",
})
return
}
switch inventory.Type {
case "static":
break
case "file":
if !IsValidInventoryPath(inventory.Inventory) {
2020-11-22 01:32:49 +01:00
w.WriteHeader(http.StatusBadRequest)
return
}
default:
w.WriteHeader(http.StatusBadRequest)
return
}
2020-12-07 13:13:59 +01:00
err := helpers.Store(r).UpdateInventory(inventory)
if err != nil {
2020-12-07 13:13:59 +01:00
helpers.WriteError(w, err)
return
}
w.WriteHeader(http.StatusNoContent)
2016-04-02 14:40:07 +02:00
}
// RemoveInventory deletes an inventory from the database
func RemoveInventory(w http.ResponseWriter, r *http.Request) {
inventory := context.Get(r, "inventory").(db.Inventory)
var err error
softDeletion := len(r.URL.Query().Get("setRemoved")) == 0
if softDeletion {
err = helpers.Store(r).DeleteInventorySoft(inventory.ProjectID, inventory.ID)
} else {
err = helpers.Store(r).DeleteInventory(inventory.ProjectID, inventory.ID)
if err == db.ErrInvalidOperation {
helpers.WriteJSON(w, http.StatusBadRequest, map[string]interface{}{
"error": "Inventory is in use by one or more templates",
"inUse": true,
})
return
}
}
if err != nil {
helpers.WriteError(w, err)
return
}
desc := "Inventory " + inventory.Name + " deleted"
_, err = helpers.Store(r).CreateEvent(db.Event{
ProjectID: &inventory.ProjectID,
Description: &desc,
})
if err != nil {
log.Error(err)
return
}
2016-04-17 02:20:23 +02:00
w.WriteHeader(http.StatusNoContent)
2016-04-02 14:40:07 +02:00
}