Semaphore/api/projects/users.go

155 lines
3.6 KiB
Go
Raw Normal View History

2016-04-02 14:40:07 +02:00
package projects
import (
"github.com/ansible-semaphore/semaphore/api/helpers"
"github.com/ansible-semaphore/semaphore/db"
2017-02-23 00:21:49 +01:00
"net/http"
2016-04-17 12:41:36 +02:00
"strconv"
log "github.com/Sirupsen/logrus"
2017-02-23 00:21:49 +01:00
"github.com/gorilla/context"
2016-04-02 14:40:07 +02:00
)
// UserMiddleware ensures a user exists and loads it to the context
func UserMiddleware(next http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
project := context.Get(r, "project").(db.Project)
userID, err := helpers.GetIntParam("user_id", w, r)
if err != nil {
return
}
2020-12-17 15:00:05 +01:00
_, err = helpers.Store(r).GetProjectUser(project.ID, userID)
2020-12-17 15:00:05 +01:00
if err != nil {
helpers.WriteError(w, err)
return
}
user, err := helpers.Store(r).GetUser(userID)
if err != nil {
helpers.WriteError(w, err)
return
}
context.Set(r, "projectUser", user)
next.ServeHTTP(w, r)
})
2016-04-04 15:44:34 +02:00
}
// GetUsers returns all users in a project
func GetUsers(w http.ResponseWriter, r *http.Request) {
2020-12-04 23:22:05 +01:00
// get single user if user ID specified in the request
2020-11-03 21:56:22 +01:00
if user := context.Get(r, "projectUser"); user != nil {
helpers.WriteJSON(w, http.StatusOK, user.(db.User))
2020-11-03 21:56:22 +01:00
return
}
project := context.Get(r, "project").(db.Project)
2020-12-17 15:00:05 +01:00
params := db.RetrieveQueryParams{
SortBy: r.URL.Query().Get("sort"),
SortInverted: r.URL.Query().Get("order") == desc,
}
2020-12-17 15:00:05 +01:00
users, err := helpers.Store(r).GetProjectUsers(project.ID, params)
2020-12-17 15:00:05 +01:00
if err != nil {
helpers.WriteError(w, err)
return
}
helpers.WriteJSON(w, http.StatusOK, users)
2016-04-02 14:40:07 +02:00
}
// AddUser adds a user to a projects team in the database
func AddUser(w http.ResponseWriter, r *http.Request) {
project := context.Get(r, "project").(db.Project)
2021-08-20 08:28:50 +02:00
var projectUser struct {
UserID int `json:"user_id" binding:"required"`
Admin bool `json:"admin"`
}
2021-08-20 08:28:50 +02:00
if !helpers.Bind(w, r, &projectUser) {
return
}
2021-08-20 08:28:50 +02:00
_, err := helpers.Store(r).CreateProjectUser(db.ProjectUser{ProjectID: project.ID, UserID: projectUser.UserID, Admin: projectUser.Admin})
if err != nil {
w.WriteHeader(http.StatusConflict)
return
}
2021-08-20 08:28:50 +02:00
user := context.Get(r, "user").(*db.User)
objType := "user"
2021-08-20 08:28:50 +02:00
desc := "User ID " + strconv.Itoa(projectUser.UserID) + " added to team"
_, err = helpers.Store(r).CreateEvent(db.Event{
2021-08-20 08:28:50 +02:00
UserID: &user.ID,
ProjectID: &project.ID,
ObjectType: &objType,
2021-08-20 08:28:50 +02:00
ObjectID: &projectUser.UserID,
Description: &desc,
})
if err != nil {
log.Error(err)
}
w.WriteHeader(http.StatusNoContent)
2016-04-02 14:40:07 +02:00
}
// RemoveUser removes a user from a project team
func RemoveUser(w http.ResponseWriter, r *http.Request) {
project := context.Get(r, "project").(db.Project)
2021-08-20 08:28:50 +02:00
projectUser := context.Get(r, "projectUser").(db.User)
2021-08-20 08:28:50 +02:00
err := helpers.Store(r).DeleteProjectUser(project.ID, projectUser.ID)
if err != nil {
2020-12-17 15:00:05 +01:00
helpers.WriteError(w, err)
return
}
2021-08-20 08:28:50 +02:00
user := context.Get(r, "user").(*db.User)
objType := "user"
2021-08-20 08:28:50 +02:00
desc := "User ID " + strconv.Itoa(projectUser.ID) + " removed from team"
_, err = helpers.Store(r).CreateEvent(db.Event{
2021-08-20 08:28:50 +02:00
UserID: &user.ID,
ProjectID: &project.ID,
ObjectType: &objType,
2021-08-20 08:28:50 +02:00
ObjectID: &projectUser.ID,
Description: &desc,
})
if err != nil {
log.Error(err)
}
w.WriteHeader(http.StatusNoContent)
2016-04-02 14:40:07 +02:00
}
2016-04-04 15:44:34 +02:00
// MakeUserAdmin writes the admin flag to the users account
func MakeUserAdmin(w http.ResponseWriter, r *http.Request) {
project := context.Get(r, "project").(db.Project)
user := context.Get(r, "projectUser").(db.User)
2020-12-17 15:00:05 +01:00
admin := true
if r.Method == "DELETE" {
// strip admin
2020-12-17 15:00:05 +01:00
admin = false
}
2016-04-04 15:44:34 +02:00
2020-12-17 15:00:05 +01:00
err := helpers.Store(r).UpdateProjectUser(db.ProjectUser{UserID: user.ID, ProjectID: project.ID, Admin: admin})
if err != nil {
helpers.WriteError(w, err)
return
}
w.WriteHeader(http.StatusNoContent)
2016-04-04 15:44:34 +02:00
}