api_user.go 5.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173
  1. package httpd
  2. import (
  3. "errors"
  4. "net/http"
  5. "strconv"
  6. "github.com/drakkan/sftpgo/dataprovider"
  7. "github.com/drakkan/sftpgo/utils"
  8. "github.com/go-chi/chi"
  9. "github.com/go-chi/render"
  10. )
  11. func getUsers(w http.ResponseWriter, r *http.Request) {
  12. limit := 100
  13. offset := 0
  14. order := "ASC"
  15. username := ""
  16. var err error
  17. if _, ok := r.URL.Query()["limit"]; ok {
  18. limit, err = strconv.Atoi(r.URL.Query().Get("limit"))
  19. if err != nil {
  20. err = errors.New("Invalid limit")
  21. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  22. return
  23. }
  24. if limit > 500 {
  25. limit = 500
  26. }
  27. }
  28. if _, ok := r.URL.Query()["offset"]; ok {
  29. offset, err = strconv.Atoi(r.URL.Query().Get("offset"))
  30. if err != nil {
  31. err = errors.New("Invalid offset")
  32. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  33. return
  34. }
  35. }
  36. if _, ok := r.URL.Query()["order"]; ok {
  37. order = r.URL.Query().Get("order")
  38. if order != "ASC" && order != "DESC" {
  39. err = errors.New("Invalid order")
  40. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  41. return
  42. }
  43. }
  44. if _, ok := r.URL.Query()["username"]; ok {
  45. username = r.URL.Query().Get("username")
  46. }
  47. users, err := dataprovider.GetUsers(dataProvider, limit, offset, order, username)
  48. if err == nil {
  49. render.JSON(w, r, users)
  50. } else {
  51. sendAPIResponse(w, r, err, "", http.StatusInternalServerError)
  52. }
  53. }
  54. func getUserByID(w http.ResponseWriter, r *http.Request) {
  55. userID, err := strconv.ParseInt(chi.URLParam(r, "userID"), 10, 64)
  56. if err != nil {
  57. err = errors.New("Invalid userID")
  58. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  59. return
  60. }
  61. user, err := dataprovider.GetUserByID(dataProvider, userID)
  62. if err == nil {
  63. render.JSON(w, r, dataprovider.HideUserSensitiveData(&user))
  64. } else if _, ok := err.(*dataprovider.RecordNotFoundError); ok {
  65. sendAPIResponse(w, r, err, "", http.StatusNotFound)
  66. } else {
  67. sendAPIResponse(w, r, err, "", http.StatusInternalServerError)
  68. }
  69. }
  70. func addUser(w http.ResponseWriter, r *http.Request) {
  71. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  72. var user dataprovider.User
  73. err := render.DecodeJSON(r.Body, &user)
  74. if err != nil {
  75. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  76. return
  77. }
  78. err = dataprovider.AddUser(dataProvider, user)
  79. if err == nil {
  80. user, err = dataprovider.UserExists(dataProvider, user.Username)
  81. if err == nil {
  82. render.JSON(w, r, dataprovider.HideUserSensitiveData(&user))
  83. } else {
  84. sendAPIResponse(w, r, err, "", http.StatusInternalServerError)
  85. }
  86. } else {
  87. sendAPIResponse(w, r, err, "", getRespStatus(err))
  88. }
  89. }
  90. func updateUser(w http.ResponseWriter, r *http.Request) {
  91. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  92. userID, err := strconv.ParseInt(chi.URLParam(r, "userID"), 10, 64)
  93. if err != nil {
  94. err = errors.New("Invalid userID")
  95. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  96. return
  97. }
  98. user, err := dataprovider.GetUserByID(dataProvider, userID)
  99. currentPermissions := user.Permissions
  100. currentFileExtensions := user.Filters.FileExtensions
  101. currentS3AccessSecret := ""
  102. if user.FsConfig.Provider == 1 {
  103. currentS3AccessSecret = user.FsConfig.S3Config.AccessSecret
  104. }
  105. user.Permissions = make(map[string][]string)
  106. user.Filters.FileExtensions = []dataprovider.ExtensionsFilter{}
  107. if _, ok := err.(*dataprovider.RecordNotFoundError); ok {
  108. sendAPIResponse(w, r, err, "", http.StatusNotFound)
  109. return
  110. } else if err != nil {
  111. sendAPIResponse(w, r, err, "", http.StatusInternalServerError)
  112. return
  113. }
  114. err = render.DecodeJSON(r.Body, &user)
  115. if err != nil {
  116. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  117. return
  118. }
  119. // we use new Permissions if passed otherwise the old ones
  120. if len(user.Permissions) == 0 {
  121. user.Permissions = currentPermissions
  122. }
  123. // we use new file extensions if passed otherwise the old ones
  124. if len(user.Filters.FileExtensions) == 0 {
  125. user.Filters.FileExtensions = currentFileExtensions
  126. }
  127. // we use the new access secret if different from the old one and not empty
  128. if user.FsConfig.Provider == 1 {
  129. if utils.RemoveDecryptionKey(currentS3AccessSecret) == user.FsConfig.S3Config.AccessSecret ||
  130. (len(user.FsConfig.S3Config.AccessSecret) == 0 && len(user.FsConfig.S3Config.AccessKey) > 0) {
  131. user.FsConfig.S3Config.AccessSecret = currentS3AccessSecret
  132. }
  133. }
  134. if user.ID != userID {
  135. sendAPIResponse(w, r, err, "user ID in request body does not match user ID in path parameter", http.StatusBadRequest)
  136. return
  137. }
  138. err = dataprovider.UpdateUser(dataProvider, user)
  139. if err != nil {
  140. sendAPIResponse(w, r, err, "", getRespStatus(err))
  141. } else {
  142. sendAPIResponse(w, r, err, "User updated", http.StatusOK)
  143. }
  144. }
  145. func deleteUser(w http.ResponseWriter, r *http.Request) {
  146. userID, err := strconv.ParseInt(chi.URLParam(r, "userID"), 10, 64)
  147. if err != nil {
  148. err = errors.New("Invalid userID")
  149. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  150. return
  151. }
  152. user, err := dataprovider.GetUserByID(dataProvider, userID)
  153. if _, ok := err.(*dataprovider.RecordNotFoundError); ok {
  154. sendAPIResponse(w, r, err, "", http.StatusNotFound)
  155. return
  156. } else if err != nil {
  157. sendAPIResponse(w, r, err, "", http.StatusInternalServerError)
  158. return
  159. }
  160. err = dataprovider.DeleteUser(dataProvider, user)
  161. if err != nil {
  162. sendAPIResponse(w, r, err, "", http.StatusInternalServerError)
  163. } else {
  164. sendAPIResponse(w, r, err, "User deleted", http.StatusOK)
  165. }
  166. }