api_group.go 4.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134
  1. package httpd
  2. import (
  3. "context"
  4. "net/http"
  5. "github.com/go-chi/render"
  6. "github.com/drakkan/sftpgo/v2/dataprovider"
  7. "github.com/drakkan/sftpgo/v2/util"
  8. "github.com/drakkan/sftpgo/v2/vfs"
  9. )
  10. func getGroups(w http.ResponseWriter, r *http.Request) {
  11. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  12. limit, offset, order, err := getSearchFilters(w, r)
  13. if err != nil {
  14. return
  15. }
  16. groups, err := dataprovider.GetGroups(limit, offset, order, false)
  17. if err != nil {
  18. sendAPIResponse(w, r, err, "", http.StatusInternalServerError)
  19. return
  20. }
  21. render.JSON(w, r, groups)
  22. }
  23. func addGroup(w http.ResponseWriter, r *http.Request) {
  24. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  25. claims, err := getTokenClaims(r)
  26. if err != nil || claims.Username == "" {
  27. sendAPIResponse(w, r, err, "Invalid token claims", http.StatusBadRequest)
  28. return
  29. }
  30. var group dataprovider.Group
  31. err = render.DecodeJSON(r.Body, &group)
  32. if err != nil {
  33. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  34. return
  35. }
  36. err = dataprovider.AddGroup(&group, claims.Username, util.GetIPFromRemoteAddress(r.RemoteAddr))
  37. if err != nil {
  38. sendAPIResponse(w, r, err, "", getRespStatus(err))
  39. return
  40. }
  41. renderGroup(w, r, group.Name, http.StatusCreated)
  42. }
  43. func updateGroup(w http.ResponseWriter, r *http.Request) {
  44. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  45. claims, err := getTokenClaims(r)
  46. if err != nil || claims.Username == "" {
  47. sendAPIResponse(w, r, err, "Invalid token claims", http.StatusBadRequest)
  48. return
  49. }
  50. name := getURLParam(r, "name")
  51. group, err := dataprovider.GroupExists(name)
  52. if err != nil {
  53. sendAPIResponse(w, r, err, "", getRespStatus(err))
  54. return
  55. }
  56. users := group.Users
  57. groupID := group.ID
  58. name = group.Name
  59. currentS3AccessSecret := group.UserSettings.FsConfig.S3Config.AccessSecret
  60. currentAzAccountKey := group.UserSettings.FsConfig.AzBlobConfig.AccountKey
  61. currentAzSASUrl := group.UserSettings.FsConfig.AzBlobConfig.SASURL
  62. currentGCSCredentials := group.UserSettings.FsConfig.GCSConfig.Credentials
  63. currentCryptoPassphrase := group.UserSettings.FsConfig.CryptConfig.Passphrase
  64. currentSFTPPassword := group.UserSettings.FsConfig.SFTPConfig.Password
  65. currentSFTPKey := group.UserSettings.FsConfig.SFTPConfig.PrivateKey
  66. group.UserSettings.FsConfig.S3Config = vfs.S3FsConfig{}
  67. group.UserSettings.FsConfig.AzBlobConfig = vfs.AzBlobFsConfig{}
  68. group.UserSettings.FsConfig.GCSConfig = vfs.GCSFsConfig{}
  69. group.UserSettings.FsConfig.CryptConfig = vfs.CryptFsConfig{}
  70. group.UserSettings.FsConfig.SFTPConfig = vfs.SFTPFsConfig{}
  71. err = render.DecodeJSON(r.Body, &group)
  72. if err != nil {
  73. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  74. return
  75. }
  76. group.ID = groupID
  77. group.Name = name
  78. group.UserSettings.FsConfig.SetEmptySecretsIfNil()
  79. updateEncryptedSecrets(&group.UserSettings.FsConfig, currentS3AccessSecret, currentAzAccountKey, currentAzSASUrl,
  80. currentGCSCredentials, currentCryptoPassphrase, currentSFTPPassword, currentSFTPKey)
  81. err = dataprovider.UpdateGroup(&group, users, claims.Username, util.GetIPFromRemoteAddress(r.RemoteAddr))
  82. if err != nil {
  83. sendAPIResponse(w, r, err, "", getRespStatus(err))
  84. return
  85. }
  86. sendAPIResponse(w, r, nil, "Group updated", http.StatusOK)
  87. }
  88. func renderGroup(w http.ResponseWriter, r *http.Request, name string, status int) {
  89. group, err := dataprovider.GroupExists(name)
  90. if err != nil {
  91. sendAPIResponse(w, r, err, "", getRespStatus(err))
  92. return
  93. }
  94. group.PrepareForRendering()
  95. if status != http.StatusOK {
  96. ctx := context.WithValue(r.Context(), render.StatusCtxKey, status)
  97. render.JSON(w, r.WithContext(ctx), group)
  98. } else {
  99. render.JSON(w, r, group)
  100. }
  101. }
  102. func getGroupByName(w http.ResponseWriter, r *http.Request) {
  103. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  104. name := getURLParam(r, "name")
  105. renderGroup(w, r, name, http.StatusOK)
  106. }
  107. func deleteGroup(w http.ResponseWriter, r *http.Request) {
  108. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  109. claims, err := getTokenClaims(r)
  110. if err != nil || claims.Username == "" {
  111. sendAPIResponse(w, r, err, "Invalid token claims", http.StatusBadRequest)
  112. return
  113. }
  114. name := getURLParam(r, "name")
  115. err = dataprovider.DeleteGroup(name, claims.Username, util.GetIPFromRemoteAddress(r.RemoteAddr))
  116. if err != nil {
  117. sendAPIResponse(w, r, err, "", getRespStatus(err))
  118. return
  119. }
  120. sendAPIResponse(w, r, err, "Group deleted", http.StatusOK)
  121. }