Semaphore/api/projects/keys.go

228 lines
5.3 KiB
Go
Raw Normal View History

2016-04-02 14:40:07 +02:00
package projects
2016-04-04 01:10:12 +02:00
import (
"database/sql"
2017-02-23 00:21:49 +01:00
"net/http"
2017-02-23 06:12:16 +01:00
"github.com/ansible-semaphore/semaphore/db"
2016-04-04 01:10:12 +02:00
"github.com/ansible-semaphore/semaphore/util"
2019-07-09 04:36:20 +02:00
"github.com/ansible-semaphore/mulekick"
2017-02-23 00:21:49 +01:00
"github.com/gorilla/context"
2016-04-04 01:10:12 +02:00
"github.com/masterminds/squirrel"
)
2016-04-02 14:40:07 +02:00
// KeyMiddleware ensures a key exists and loads it to the context
2017-02-22 23:17:36 +01:00
func KeyMiddleware(w http.ResponseWriter, r *http.Request) {
2017-02-23 06:12:16 +01:00
project := context.Get(r, "project").(db.Project)
2017-02-23 00:21:49 +01:00
keyID, err := util.GetIntParam("key_id", w, r)
if err != nil {
return
}
2017-02-23 06:12:16 +01:00
var key db.AccessKey
if err := db.Mysql.SelectOne(&key, "select * from access_key where project_id=? and id=?", project.ID, keyID); err != nil {
if err == sql.ErrNoRows {
2017-02-22 23:17:36 +01:00
w.WriteHeader(http.StatusNotFound)
return
}
panic(err)
}
2017-02-23 00:21:49 +01:00
context.Set(r, "accessKey", key)
2016-04-04 15:44:34 +02:00
}
// GetKeys retrieves sorted keys from the database
2017-02-22 23:17:36 +01:00
func GetKeys(w http.ResponseWriter, r *http.Request) {
2017-02-23 06:12:16 +01:00
project := context.Get(r, "project").(db.Project)
var keys []db.AccessKey
2016-04-04 01:10:12 +02:00
sort := r.URL.Query().Get("sort")
order := r.URL.Query().Get("order")
if order != "asc" && order != "desc" {
order = "asc"
}
q := squirrel.Select("ak.id",
"ak.name",
"ak.type",
"ak.project_id",
"ak.key",
"ak.removed").
From("access_key ak")
2016-04-04 15:44:34 +02:00
2017-02-23 00:21:49 +01:00
if t := r.URL.Query().Get("type"); len(t) > 0 {
q = q.Where("type=?", t)
2016-04-04 15:44:34 +02:00
}
switch sort {
case "name", "type":
q = q.Where("ak.project_id=?", project.ID).
OrderBy("ak." + sort + " " + order)
default:
q = q.Where("ak.project_id=?", project.ID).
OrderBy("ak.name " + order)
}
query, args, err := q.ToSql()
util.LogWarning(err)
2017-02-23 06:12:16 +01:00
if _, err := db.Mysql.Select(&keys, query, args...); err != nil {
2016-04-04 01:10:12 +02:00
panic(err)
}
2017-02-23 00:21:49 +01:00
mulekick.WriteJSON(w, http.StatusOK, keys)
2016-04-02 14:40:07 +02:00
}
// AddKey adds a new key to the database
2017-02-22 23:17:36 +01:00
func AddKey(w http.ResponseWriter, r *http.Request) {
2017-02-23 06:12:16 +01:00
project := context.Get(r, "project").(db.Project)
var key db.AccessKey
2016-04-04 01:10:12 +02:00
if err := mulekick.Bind(w, r, &key); err != nil {
2016-04-04 01:10:12 +02:00
return
}
switch key.Type {
case "aws", "gcloud", "do":
2016-04-04 01:10:12 +02:00
break
case "ssh":
if key.Secret == nil || len(*key.Secret) == 0 {
2017-02-23 00:21:49 +01:00
mulekick.WriteJSON(w, http.StatusBadRequest, map[string]string{
"error": "SSH Secret empty",
})
return
}
2016-04-04 01:10:12 +02:00
default:
2017-02-23 00:21:49 +01:00
mulekick.WriteJSON(w, http.StatusBadRequest, map[string]string{
"error": "Invalid key type",
})
2016-04-04 01:10:12 +02:00
return
}
2016-12-21 09:56:38 +01:00
secret := *key.Secret + "\n"
2017-02-23 06:12:16 +01:00
res, err := db.Mysql.Exec("insert into access_key set name=?, type=?, project_id=?, `key`=?, secret=?", key.Name, key.Type, project.ID, key.Key, secret)
2016-04-17 12:41:36 +02:00
if err != nil {
panic(err)
}
insertID, err := res.LastInsertId()
util.LogWarning(err)
2016-04-17 12:41:36 +02:00
insertIDInt := int(insertID)
objType := "key"
desc := "Access Key " + key.Name + " created"
2017-02-23 06:12:16 +01:00
if err := (db.Event{
2016-04-17 12:41:36 +02:00
ProjectID: &project.ID,
ObjectType: &objType,
ObjectID: &insertIDInt,
Description: &desc,
}.Insert()); err != nil {
2016-04-04 01:10:12 +02:00
panic(err)
}
2017-02-22 23:17:36 +01:00
w.WriteHeader(http.StatusNoContent)
2016-04-04 01:10:12 +02:00
}
// UpdateKey updates key in database
// nolint: gocyclo
2017-02-22 23:17:36 +01:00
func UpdateKey(w http.ResponseWriter, r *http.Request) {
2017-02-23 06:12:16 +01:00
var key db.AccessKey
oldKey := context.Get(r, "accessKey").(db.AccessKey)
if err := mulekick.Bind(w, r, &key); err != nil {
return
}
switch key.Type {
case "aws", "gcloud", "do":
break
case "ssh":
if key.Secret == nil || len(*key.Secret) == 0 {
2017-02-23 00:21:49 +01:00
mulekick.WriteJSON(w, http.StatusBadRequest, map[string]string{
"error": "SSH Secret empty",
})
return
}
default:
2017-02-23 00:21:49 +01:00
mulekick.WriteJSON(w, http.StatusBadRequest, map[string]string{
"error": "Invalid key type",
})
return
}
if key.Secret == nil || len(*key.Secret) == 0 {
// override secret
key.Secret = oldKey.Secret
2016-12-21 09:56:38 +01:00
} else {
secret := *key.Secret + "\n"
key.Secret = &secret
}
2017-02-23 06:12:16 +01:00
if _, err := db.Mysql.Exec("update access_key set name=?, type=?, `key`=?, secret=? where id=?", key.Name, key.Type, key.Key, key.Secret, oldKey.ID); err != nil {
panic(err)
}
2016-04-17 12:41:36 +02:00
desc := "Access Key " + key.Name + " updated"
objType := "key"
2017-02-23 06:12:16 +01:00
if err := (db.Event{
2016-04-17 12:41:36 +02:00
ProjectID: oldKey.ProjectID,
Description: &desc,
ObjectID: &oldKey.ID,
ObjectType: &objType,
}.Insert()); err != nil {
panic(err)
}
2017-02-22 23:17:36 +01:00
w.WriteHeader(http.StatusNoContent)
2016-04-02 14:40:07 +02:00
}
// RemoveKey deletes a key from the database
2017-02-22 23:17:36 +01:00
func RemoveKey(w http.ResponseWriter, r *http.Request) {
2017-02-23 06:12:16 +01:00
key := context.Get(r, "accessKey").(db.AccessKey)
2016-04-04 01:10:12 +02:00
2017-02-23 06:12:16 +01:00
templatesC, err := db.Mysql.SelectInt("select count(1) from project__template where project_id=? and ssh_key_id=?", *key.ProjectID, key.ID)
if err != nil {
panic(err)
}
2017-02-23 06:12:16 +01:00
inventoryC, err := db.Mysql.SelectInt("select count(1) from project__inventory where project_id=? and ssh_key_id=?", *key.ProjectID, key.ID)
if err != nil {
panic(err)
}
if templatesC > 0 || inventoryC > 0 {
2017-02-23 00:21:49 +01:00
if len(r.URL.Query().Get("setRemoved")) == 0 {
mulekick.WriteJSON(w, http.StatusBadRequest, map[string]interface{}{
"error": "Key is in use by one or more templates / inventory",
"inUse": true,
})
return
}
2017-02-23 06:12:16 +01:00
if _, err := db.Mysql.Exec("update access_key set removed=1 where id=?", key.ID); err != nil {
panic(err)
}
2017-02-22 23:17:36 +01:00
w.WriteHeader(http.StatusNoContent)
return
}
2017-02-23 06:12:16 +01:00
if _, err := db.Mysql.Exec("delete from access_key where id=?", key.ID); err != nil {
2016-04-04 01:10:12 +02:00
panic(err)
}
2016-04-17 12:41:36 +02:00
desc := "Access Key " + key.Name + " deleted"
2017-02-23 06:12:16 +01:00
if err := (db.Event{
2016-04-17 12:41:36 +02:00
ProjectID: key.ProjectID,
Description: &desc,
}.Insert()); err != nil {
panic(err)
}
2017-02-22 23:17:36 +01:00
w.WriteHeader(http.StatusNoContent)
2016-04-02 14:40:07 +02:00
}