2016-04-02 14:40:07 +02:00
package projects
import (
2016-04-09 21:09:57 +02:00
"database/sql"
2017-02-23 00:21:49 +01:00
"net/http"
2016-04-17 12:41:36 +02:00
"strconv"
2016-04-09 21:09:57 +02:00
2017-02-23 06:12:16 +01:00
"github.com/ansible-semaphore/semaphore/db"
2016-04-04 01:10:12 +02:00
"github.com/ansible-semaphore/semaphore/util"
2017-02-23 00:21:49 +01:00
"github.com/castawaylabs/mulekick"
"github.com/gorilla/context"
2016-04-02 14:40:07 +02:00
"github.com/masterminds/squirrel"
)
2017-02-22 23:17:36 +01:00
func UserMiddleware ( w http . ResponseWriter , r * http . Request ) {
2017-02-23 06:12:16 +01:00
project := context . Get ( r , "project" ) . ( db . Project )
2017-02-23 00:21:49 +01:00
userID , err := util . GetIntParam ( "user_id" , w , r )
2016-04-09 21:09:57 +02:00
if err != nil {
return
}
2017-02-23 06:12:16 +01:00
var user db . User
if err := db . Mysql . SelectOne ( & user , "select u.* from project__user as pu join user as u on pu.user_id=u.id where pu.user_id=? and pu.project_id=?" , userID , project . ID ) ; err != nil {
2016-04-09 21:09:57 +02:00
if err == sql . ErrNoRows {
2017-02-22 23:17:36 +01:00
w . WriteHeader ( http . StatusNotFound )
2016-04-09 21:09:57 +02:00
return
}
panic ( err )
}
2017-02-23 00:21:49 +01:00
context . Set ( r , "projectUser" , user )
2016-04-04 15:44:34 +02:00
}
2017-02-22 23:17:36 +01:00
func GetUsers ( w http . ResponseWriter , r * http . Request ) {
2017-02-23 06:12:16 +01:00
project := context . Get ( r , "project" ) . ( db . Project )
2016-06-17 22:16:46 +02:00
var users [ ] struct {
2017-02-23 06:12:16 +01:00
db . User
2016-06-17 22:16:46 +02:00
Admin bool ` db:"admin" json:"admin" `
}
2016-04-02 14:40:07 +02:00
2016-06-17 22:16:46 +02:00
query , args , _ := squirrel . Select ( "u.*" ) . Column ( "pu.admin" ) .
2016-04-02 14:40:07 +02:00
From ( "project__user as pu" ) .
Join ( "user as u on pu.user_id=u.id" ) .
Where ( "pu.project_id=?" , project . ID ) .
2017-03-14 16:04:48 +01:00
OrderBy ( "name asc" ) .
2016-04-02 14:40:07 +02:00
ToSql ( )
2017-02-23 06:12:16 +01:00
if _ , err := db . Mysql . Select ( & users , query , args ... ) ; err != nil {
2016-04-02 14:40:07 +02:00
panic ( err )
}
2017-02-23 00:21:49 +01:00
mulekick . WriteJSON ( w , http . StatusOK , users )
2016-04-02 14:40:07 +02:00
}
2017-02-22 23:17:36 +01:00
func AddUser ( w http . ResponseWriter , r * http . Request ) {
2017-02-23 06:12:16 +01:00
project := context . Get ( r , "project" ) . ( db . Project )
2016-04-04 01:10:12 +02:00
var user struct {
UserID int ` json:"user_id" binding:"required" `
Admin bool ` json:"admin" `
}
2017-02-22 23:21:52 +01:00
if err := mulekick . Bind ( w , r , & user ) ; err != nil {
2016-04-04 01:10:12 +02:00
return
}
2017-02-23 06:12:16 +01:00
if _ , err := db . Mysql . Exec ( "insert into project__user set user_id=?, project_id=?, admin=?" , user . UserID , project . ID , user . Admin ) ; err != nil {
2016-04-04 01:10:12 +02:00
panic ( err )
}
2016-04-17 12:41:36 +02:00
objType := "user"
desc := "User ID " + strconv . Itoa ( user . UserID ) + " added to team"
2017-02-23 06:12:16 +01:00
if err := ( db . Event {
2016-04-17 12:41:36 +02:00
ProjectID : & project . ID ,
ObjectType : & objType ,
ObjectID : & user . UserID ,
Description : & desc ,
} . Insert ( ) ) ; err != nil {
panic ( err )
}
2017-02-22 23:17:36 +01:00
w . WriteHeader ( http . StatusNoContent )
2016-04-02 14:40:07 +02:00
}
2017-02-22 23:17:36 +01:00
func RemoveUser ( w http . ResponseWriter , r * http . Request ) {
2017-02-23 06:12:16 +01:00
project := context . Get ( r , "project" ) . ( db . Project )
user := context . Get ( r , "projectUser" ) . ( db . User )
2016-04-04 01:10:12 +02:00
2017-02-23 06:12:16 +01:00
if _ , err := db . Mysql . Exec ( "delete from project__user where user_id=? and project_id=?" , user . ID , project . ID ) ; err != nil {
2016-04-04 01:10:12 +02:00
panic ( err )
}
2016-04-17 12:41:36 +02:00
objType := "user"
desc := "User ID " + strconv . Itoa ( user . ID ) + " removed from team"
2017-02-23 06:12:16 +01:00
if err := ( db . Event {
2016-04-17 12:41:36 +02:00
ProjectID : & project . ID ,
ObjectType : & objType ,
ObjectID : & user . ID ,
Description : & desc ,
} . Insert ( ) ) ; err != nil {
panic ( err )
}
2017-02-22 23:17:36 +01:00
w . WriteHeader ( http . StatusNoContent )
2016-04-02 14:40:07 +02:00
}
2016-04-04 15:44:34 +02:00
2017-02-22 23:17:36 +01:00
func MakeUserAdmin ( w http . ResponseWriter , r * http . Request ) {
2017-02-23 06:12:16 +01:00
project := context . Get ( r , "project" ) . ( db . Project )
user := context . Get ( r , "projectUser" ) . ( db . User )
2016-04-09 21:09:57 +02:00
admin := 1
2017-02-22 23:17:36 +01:00
if r . Method == "DELETE" {
2016-04-04 15:44:34 +02:00
// strip admin
2016-04-09 21:09:57 +02:00
admin = 0
2016-04-04 15:44:34 +02:00
}
2017-02-23 06:12:16 +01:00
if _ , err := db . Mysql . Exec ( "update project__user set admin=? where user_id=? and project_id=?" , admin , user . ID , project . ID ) ; err != nil {
2016-04-09 21:09:57 +02:00
panic ( err )
}
2017-02-22 23:17:36 +01:00
w . WriteHeader ( http . StatusNoContent )
2016-04-04 15:44:34 +02:00
}