Semaphore/api/projects/keys.go

227 lines
4.7 KiB
Go
Raw Normal View History

2016-04-02 14:40:07 +02:00
package projects
2016-04-04 01:10:12 +02:00
import (
log "github.com/Sirupsen/logrus"
"github.com/ansible-semaphore/semaphore/api/helpers"
"github.com/ansible-semaphore/semaphore/db"
"net/http"
2017-02-23 00:21:49 +01:00
"github.com/gorilla/context"
2016-04-04 01:10:12 +02:00
)
2016-04-02 14:40:07 +02:00
// KeyMiddleware ensures a key exists and loads it to the context
func KeyMiddleware(next http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
project := context.Get(r, "project").(db.Project)
keyID, err := helpers.GetIntParam("key_id", w, r)
if err != nil {
return
}
2020-12-08 08:23:33 +01:00
key, err := helpers.Store(r).GetAccessKey(project.ID, keyID)
2020-12-08 08:23:33 +01:00
if err != nil {
helpers.WriteError(w, err)
return
}
context.Set(r, "accessKey", key)
next.ServeHTTP(w, r)
})
2016-04-04 15:44:34 +02:00
}
// GetKeys retrieves sorted keys from the database
func GetKeys(w http.ResponseWriter, r *http.Request) {
2020-11-04 20:30:36 +01:00
if key := context.Get(r, "accessKey"); key != nil {
k := key.(db.AccessKey)
k.Secret = nil
helpers.WriteJSON(w, http.StatusOK, k)
2020-11-04 20:30:36 +01:00
return
}
project := context.Get(r, "project").(db.Project)
var keys []db.AccessKey
2020-12-08 08:23:33 +01:00
params := db.RetrieveQueryParams{
SortBy: r.URL.Query().Get("sort"),
SortInverted: r.URL.Query().Get("order") == desc,
}
2020-12-08 08:23:33 +01:00
keys, err := helpers.Store(r).GetAccessKeys(project.ID, params)
for _, k := range keys {
k.Secret = nil
}
2020-12-08 08:23:33 +01:00
if err != nil {
helpers.WriteError(w, err)
return
}
helpers.WriteJSON(w, http.StatusOK, keys)
2016-04-02 14:40:07 +02:00
}
// AddKey adds a new key to the database
func AddKey(w http.ResponseWriter, r *http.Request) {
project := context.Get(r, "project").(db.Project)
var key db.AccessKey
if !helpers.Bind(w, r, &key) {
return
}
2020-12-08 08:23:33 +01:00
if key.ProjectID == nil || *key.ProjectID != project.ID {
helpers.WriteJSON(w, http.StatusBadRequest, map[string]string{
"error": "Project ID in body and URL must be the same",
2020-12-08 08:23:33 +01:00
})
return
}
switch key.Type {
2021-08-30 16:24:20 +02:00
case db.AccessKeyNone:
break
2021-08-30 16:24:20 +02:00
case db.AccessKeySSH:
if key.Secret == nil || len(*key.Secret) == 0 {
helpers.WriteJSON(w, http.StatusBadRequest, map[string]string{
"error": "SSH Secret empty",
})
return
}
default:
helpers.WriteJSON(w, http.StatusBadRequest, map[string]string{
"error": "Invalid key type",
})
return
}
2021-08-30 16:24:20 +02:00
if key.Secret != nil {
*key.Secret += "\n"
}
2020-12-08 08:23:33 +01:00
newKey, err := helpers.Store(r).CreateAccessKey(key)
if err != nil {
2020-12-08 08:23:33 +01:00
helpers.WriteError(w, err)
return
}
2021-08-20 08:28:50 +02:00
user := context.Get(r, "user").(*db.User)
objType := "key"
desc := "Access Key " + key.Name + " created"
_, err = helpers.Store(r).CreateEvent(db.Event{
2021-08-20 08:28:50 +02:00
UserID: &user.ID,
2020-12-08 08:23:33 +01:00
ProjectID: newKey.ProjectID,
ObjectType: &objType,
2020-12-08 08:23:33 +01:00
ObjectID: &newKey.ID,
Description: &desc,
})
if err != nil {
log.Error(err)
}
w.WriteHeader(http.StatusNoContent)
2016-04-04 01:10:12 +02:00
}
// UpdateKey updates key in database
// nolint: gocyclo
func UpdateKey(w http.ResponseWriter, r *http.Request) {
var key db.AccessKey
oldKey := context.Get(r, "accessKey").(db.AccessKey)
if !helpers.Bind(w, r, &key) {
return
}
switch key.Type {
2021-08-30 16:24:20 +02:00
case db.AccessKeyNone:
case db.AccessKeySSH:
default:
helpers.WriteJSON(w, http.StatusBadRequest, map[string]string{
"error": "Invalid key type",
})
return
}
if key.Type == db.AccessKeyNone {
key.Key = nil
key.Secret = nil
} else if key.Secret == nil || len(*key.Secret) == 0 {
// override secret
key.Secret = oldKey.Secret
} else {
secret := *key.Secret + "\n"
key.Secret = &secret
}
2020-12-08 08:23:33 +01:00
if err := helpers.Store(r).UpdateAccessKey(key); err != nil {
helpers.WriteError(w, err)
return
}
2021-08-20 08:28:50 +02:00
user := context.Get(r, "user").(*db.User)
desc := "Access Key " + key.Name + " updated"
objType := "key"
_, err := helpers.Store(r).CreateEvent(db.Event{
2021-08-20 08:28:50 +02:00
UserID: &user.ID,
ProjectID: oldKey.ProjectID,
Description: &desc,
ObjectID: &oldKey.ID,
ObjectType: &objType,
})
if err != nil {
log.Error(err)
return
}
w.WriteHeader(http.StatusNoContent)
2016-04-02 14:40:07 +02:00
}
// RemoveKey deletes a key from the database
func RemoveKey(w http.ResponseWriter, r *http.Request) {
key := context.Get(r, "accessKey").(db.AccessKey)
2020-12-08 08:23:33 +01:00
var err error
2021-05-16 23:44:42 +02:00
softDeletion := r.URL.Query().Get("setRemoved") == "1"
2020-12-08 08:23:33 +01:00
if softDeletion {
err = helpers.Store(r).DeleteAccessKeySoft(*key.ProjectID, key.ID)
} else {
err = helpers.Store(r).DeleteAccessKey(*key.ProjectID, key.ID)
if err == db.ErrInvalidOperation {
helpers.WriteJSON(w, http.StatusBadRequest, map[string]interface{}{
2020-12-08 08:23:33 +01:00
"error": "Inventory is in use by one or more templates",
"inUse": true,
})
return
}
}
2020-12-08 08:23:33 +01:00
if err != nil {
helpers.WriteError(w, err)
return
}
2021-08-20 08:28:50 +02:00
user := context.Get(r, "user").(*db.User)
desc := "Access Key " + key.Name + " deleted"
_, err = helpers.Store(r).CreateEvent(db.Event{
2021-08-20 08:28:50 +02:00
UserID: &user.ID,
ProjectID: key.ProjectID,
Description: &desc,
})
if err != nil {
log.Error(err)
}
w.WriteHeader(http.StatusNoContent)
2016-04-02 14:40:07 +02:00
}