2016-04-02 14:40:07 +02:00
package projects
import (
2016-04-09 21:09:57 +02:00
"database/sql"
2020-12-03 14:51:15 +01:00
"github.com/ansible-semaphore/semaphore/api/helpers"
2020-12-01 20:06:49 +01:00
"github.com/ansible-semaphore/semaphore/models"
2017-02-23 00:21:49 +01:00
"net/http"
2016-04-17 12:41:36 +02:00
"strconv"
2016-04-09 21:09:57 +02:00
2020-12-01 20:06:49 +01:00
log "github.com/Sirupsen/logrus"
2017-02-23 00:21:49 +01:00
"github.com/gorilla/context"
2016-04-02 14:40:07 +02:00
"github.com/masterminds/squirrel"
)
2018-03-27 22:12:47 +02:00
// UserMiddleware ensures a user exists and loads it to the context
2019-07-09 18:14:06 +02:00
func UserMiddleware ( next http . Handler ) http . Handler {
return http . HandlerFunc ( func ( w http . ResponseWriter , r * http . Request ) {
2020-12-01 20:06:49 +01:00
project := context . Get ( r , "project" ) . ( models . Project )
2020-12-03 14:51:15 +01:00
userID , err := helpers . GetIntParam ( "user_id" , w , r )
2019-07-09 18:14:06 +02:00
if err != nil {
2016-04-09 21:09:57 +02:00
return
}
2020-12-01 20:06:49 +01:00
var user models . User
2020-12-03 14:51:15 +01:00
if err := helpers . Store ( r ) . Sql ( ) . SelectOne ( & user , "select u.* from project__user as pu join `user` as u on pu.user_id=u.id where pu.user_id=? and pu.project_id=?" , userID , project . ID ) ; err != nil {
2019-07-09 18:14:06 +02:00
if err == sql . ErrNoRows {
w . WriteHeader ( http . StatusNotFound )
return
}
panic ( err )
}
2016-04-09 21:09:57 +02:00
2019-07-09 18:14:06 +02:00
context . Set ( r , "projectUser" , user )
next . ServeHTTP ( w , r )
} )
2016-04-04 15:44:34 +02:00
}
2018-03-27 22:12:47 +02:00
// GetUsers returns all users in a project
2019-07-09 18:11:01 +02:00
func GetUsers ( w http . ResponseWriter , r * http . Request ) {
2020-11-03 21:56:22 +01:00
if user := context . Get ( r , "projectUser" ) ; user != nil {
2020-12-03 14:51:15 +01:00
helpers . WriteJSON ( w , http . StatusOK , user . ( models . User ) )
2020-11-03 21:56:22 +01:00
return
}
2020-12-01 20:06:49 +01:00
project := context . Get ( r , "project" ) . ( models . Project )
var users [ ] models . User
2019-07-09 18:11:01 +02:00
sort := r . URL . Query ( ) . Get ( "sort" )
order := r . URL . Query ( ) . Get ( "order" )
if order != asc && order != desc {
order = asc
}
q := squirrel . Select ( "u.*" ) . Column ( "pu.admin" ) .
From ( "project__user as pu" ) .
LeftJoin ( "user as u on pu.user_id=u.id" ) .
Where ( "pu.project_id=?" , project . ID )
switch sort {
case "name" , "username" , "email" :
q = q . OrderBy ( "u." + sort + " " + order )
case "admin" :
q = q . OrderBy ( "pu." + sort + " " + order )
default :
q = q . OrderBy ( "u.name " + order )
}
query , args , _ := q . ToSql ( )
2020-12-03 14:51:15 +01:00
if _ , err := helpers . Store ( r ) . Sql ( ) . Select ( & users , query , args ... ) ; err != nil {
2019-07-09 18:11:01 +02:00
panic ( err )
}
2020-12-03 14:51:15 +01:00
helpers . WriteJSON ( w , http . StatusOK , users )
2016-04-02 14:40:07 +02:00
}
2018-03-27 22:12:47 +02:00
// AddUser adds a user to a projects team in the database
2019-07-09 18:11:01 +02:00
func AddUser ( w http . ResponseWriter , r * http . Request ) {
2020-12-01 20:06:49 +01:00
project := context . Get ( r , "project" ) . ( models . Project )
2019-07-09 18:11:01 +02:00
var user struct {
UserID int ` json:"user_id" binding:"required" `
Admin bool ` json:"admin" `
}
2020-12-03 14:51:15 +01:00
if ! helpers . Bind ( w , r , & user ) {
2019-07-09 18:11:01 +02:00
return
}
2020-12-03 14:51:15 +01:00
_ , err := helpers . Store ( r ) . CreateProjectUser ( models . ProjectUser { ProjectID : project . ID , UserID : user . UserID , Admin : user . Admin } )
2020-12-01 20:06:49 +01:00
if err != nil {
w . WriteHeader ( http . StatusConflict )
return
2019-07-09 18:11:01 +02:00
}
objType := "user"
desc := "User ID " + strconv . Itoa ( user . UserID ) + " added to team"
2020-12-01 20:06:49 +01:00
2020-12-03 14:51:15 +01:00
_ , err = helpers . Store ( r ) . CreateEvent ( models . Event {
2019-07-09 18:11:01 +02:00
ProjectID : & project . ID ,
ObjectType : & objType ,
ObjectID : & user . UserID ,
Description : & desc ,
2020-12-01 20:06:49 +01:00
} )
if err != nil {
log . Error ( err )
w . WriteHeader ( http . StatusInternalServerError )
return
2019-07-09 18:11:01 +02:00
}
w . WriteHeader ( http . StatusNoContent )
2016-04-02 14:40:07 +02:00
}
2018-03-27 22:12:47 +02:00
// RemoveUser removes a user from a project team
2019-07-09 18:11:01 +02:00
func RemoveUser ( w http . ResponseWriter , r * http . Request ) {
2020-12-01 20:06:49 +01:00
project := context . Get ( r , "project" ) . ( models . Project )
user := context . Get ( r , "projectUser" ) . ( models . User )
2019-07-09 18:11:01 +02:00
2020-12-03 14:51:15 +01:00
err := helpers . Store ( r ) . DeleteProjectUser ( project . ID , user . ID )
2020-12-01 20:06:49 +01:00
if err != nil {
log . Error ( err )
w . WriteHeader ( http . StatusInternalServerError )
return
2019-07-09 18:11:01 +02:00
}
objType := "user"
desc := "User ID " + strconv . Itoa ( user . ID ) + " removed from team"
2020-12-01 20:06:49 +01:00
2020-12-03 14:51:15 +01:00
_ , err = helpers . Store ( r ) . CreateEvent ( models . Event {
2019-07-09 18:11:01 +02:00
ProjectID : & project . ID ,
ObjectType : & objType ,
ObjectID : & user . ID ,
Description : & desc ,
2020-12-01 20:06:49 +01:00
} )
if err != nil {
log . Error ( err )
w . WriteHeader ( http . StatusInternalServerError )
return
2019-07-09 18:11:01 +02:00
}
w . WriteHeader ( http . StatusNoContent )
2016-04-02 14:40:07 +02:00
}
2016-04-04 15:44:34 +02:00
2018-03-27 22:12:47 +02:00
// MakeUserAdmin writes the admin flag to the users account
2019-07-09 18:11:01 +02:00
func MakeUserAdmin ( w http . ResponseWriter , r * http . Request ) {
2020-12-01 20:06:49 +01:00
project := context . Get ( r , "project" ) . ( models . Project )
user := context . Get ( r , "projectUser" ) . ( models . User )
2019-07-09 18:11:01 +02:00
admin := 1
2016-04-09 21:09:57 +02:00
2019-07-09 18:11:01 +02:00
if r . Method == "DELETE" {
// strip admin
admin = 0
}
2016-04-04 15:44:34 +02:00
2020-12-03 14:51:15 +01:00
if _ , err := helpers . Store ( r ) . Sql ( ) . Exec ( "update project__user set `admin`=? where user_id=? and project_id=?" , admin , user . ID , project . ID ) ; err != nil {
2019-07-09 18:11:01 +02:00
panic ( err )
}
2016-04-09 21:09:57 +02:00
2019-07-09 18:11:01 +02:00
w . WriteHeader ( http . StatusNoContent )
2016-04-04 15:44:34 +02:00
}