2020-11-21 17:38:58 +01:00
|
|
|
// Vikunja is a to-do list application to facilitate your life.
|
2021-02-02 20:19:13 +01:00
|
|
|
// Copyright 2018-2021 Vikunja and contributors. All rights reserved.
|
2020-11-21 17:38:58 +01:00
|
|
|
//
|
|
|
|
// This program is free software: you can redistribute it and/or modify
|
2020-12-23 16:41:52 +01:00
|
|
|
// it under the terms of the GNU Affero General Public Licensee as published by
|
2020-11-21 17:38:58 +01:00
|
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
|
|
// (at your option) any later version.
|
|
|
|
//
|
|
|
|
// This program is distributed in the hope that it will be useful,
|
|
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
2020-12-23 16:41:52 +01:00
|
|
|
// GNU Affero General Public Licensee for more details.
|
2020-11-21 17:38:58 +01:00
|
|
|
//
|
2020-12-23 16:41:52 +01:00
|
|
|
// You should have received a copy of the GNU Affero General Public Licensee
|
2020-11-21 17:38:58 +01:00
|
|
|
// along with this program. If not, see <https://www.gnu.org/licenses/>.
|
|
|
|
|
|
|
|
package user
|
|
|
|
|
|
|
|
import (
|
|
|
|
"code.vikunja.io/api/pkg/config"
|
2021-02-02 23:48:37 +01:00
|
|
|
"code.vikunja.io/api/pkg/events"
|
2021-02-07 22:05:09 +01:00
|
|
|
"code.vikunja.io/api/pkg/notifications"
|
2020-11-21 17:38:58 +01:00
|
|
|
"golang.org/x/crypto/bcrypt"
|
2020-12-23 16:32:28 +01:00
|
|
|
"xorm.io/xorm"
|
2020-11-21 17:38:58 +01:00
|
|
|
)
|
|
|
|
|
2021-10-31 12:37:08 +01:00
|
|
|
const IssuerLocal = `local`
|
2020-11-21 17:38:58 +01:00
|
|
|
|
|
|
|
// CreateUser creates a new user and inserts it into the database
|
2020-12-23 16:32:28 +01:00
|
|
|
func CreateUser(s *xorm.Session, user *User) (newUser *User, err error) {
|
2020-11-21 17:38:58 +01:00
|
|
|
|
|
|
|
if user.Issuer == "" {
|
2021-10-31 12:37:08 +01:00
|
|
|
user.Issuer = IssuerLocal
|
2020-11-21 17:38:58 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// Check if we have all needed information
|
|
|
|
err = checkIfUserIsValid(user)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
// Check if the user already exists with that username
|
2020-12-23 16:32:28 +01:00
|
|
|
err = checkIfUserExists(s, user)
|
2020-11-21 17:38:58 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2021-10-31 12:37:08 +01:00
|
|
|
if user.Issuer == IssuerLocal {
|
2020-11-21 17:38:58 +01:00
|
|
|
// Hash the password
|
2021-04-11 15:17:50 +02:00
|
|
|
user.Password, err = HashPassword(user.Password)
|
2020-11-21 17:38:58 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-07-13 22:56:02 +02:00
|
|
|
user.Status = StatusActive
|
2020-11-21 17:38:58 +01:00
|
|
|
user.AvatarProvider = "initials"
|
|
|
|
|
|
|
|
// Insert it
|
2020-12-23 16:32:28 +01:00
|
|
|
_, err = s.Insert(user)
|
2020-11-21 17:38:58 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
// Get the full new User
|
2020-12-23 16:32:28 +01:00
|
|
|
newUserOut, err := GetUserByID(s, user.ID)
|
2020-11-21 17:38:58 +01:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2021-02-02 23:48:37 +01:00
|
|
|
err = events.Dispatch(&CreatedEvent{
|
|
|
|
User: newUserOut,
|
|
|
|
})
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2021-02-07 22:05:09 +01:00
|
|
|
// Dont send a mail if no mailer is configured
|
2021-10-31 12:37:08 +01:00
|
|
|
if !config.MailerEnabled.GetBool() || user.Issuer != IssuerLocal {
|
2021-02-07 22:05:09 +01:00
|
|
|
return newUserOut, err
|
|
|
|
}
|
2020-11-21 17:38:58 +01:00
|
|
|
|
2021-07-13 22:56:02 +02:00
|
|
|
user.Status = StatusEmailConfirmationRequired
|
2022-03-30 20:25:56 +02:00
|
|
|
token, err := generateToken(s, user, TokenEmailConfirm)
|
2021-07-13 22:56:02 +02:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
_, err = s.
|
|
|
|
Where("id = ?", user.ID).
|
|
|
|
Cols("email", "is_active").
|
|
|
|
Update(user)
|
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2021-02-07 22:05:09 +01:00
|
|
|
n := &EmailConfirmNotification{
|
2021-07-13 22:56:02 +02:00
|
|
|
User: user,
|
|
|
|
IsNew: true,
|
|
|
|
ConfirmToken: token.Token,
|
2021-02-07 22:05:09 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
err = notifications.Notify(user, n)
|
2020-11-21 17:38:58 +01:00
|
|
|
return newUserOut, err
|
|
|
|
}
|
|
|
|
|
|
|
|
// HashPassword hashes a password
|
2021-04-11 15:17:50 +02:00
|
|
|
func HashPassword(password string) (string, error) {
|
2020-11-21 17:38:58 +01:00
|
|
|
bytes, err := bcrypt.GenerateFromPassword([]byte(password), 11)
|
|
|
|
return string(bytes), err
|
|
|
|
}
|
|
|
|
|
|
|
|
func checkIfUserIsValid(user *User) error {
|
|
|
|
if user.Email == "" ||
|
2021-10-31 12:37:08 +01:00
|
|
|
(user.Issuer != IssuerLocal && user.Subject == "") ||
|
|
|
|
(user.Issuer == IssuerLocal && (user.Password == "" ||
|
2020-11-21 17:38:58 +01:00
|
|
|
user.Username == "")) {
|
|
|
|
return ErrNoUsernamePassword{}
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2020-12-23 16:32:28 +01:00
|
|
|
func checkIfUserExists(s *xorm.Session, user *User) (err error) {
|
2020-11-21 17:38:58 +01:00
|
|
|
exists := true
|
2020-12-23 16:32:28 +01:00
|
|
|
_, err = GetUserByUsername(s, user.Username)
|
2020-11-21 17:38:58 +01:00
|
|
|
if err != nil {
|
|
|
|
if IsErrUserDoesNotExist(err) {
|
|
|
|
exists = false
|
|
|
|
} else {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if exists {
|
|
|
|
return ErrUsernameExists{user.ID, user.Username}
|
|
|
|
}
|
|
|
|
|
|
|
|
// Check if the user already existst with that email
|
|
|
|
exists = true
|
|
|
|
userToCheck := &User{
|
|
|
|
Email: user.Email,
|
|
|
|
Issuer: user.Issuer,
|
|
|
|
Subject: user.Subject,
|
|
|
|
}
|
|
|
|
|
2021-10-31 12:37:08 +01:00
|
|
|
if user.Issuer != IssuerLocal {
|
2020-11-21 17:38:58 +01:00
|
|
|
userToCheck.Email = ""
|
|
|
|
}
|
|
|
|
|
2020-12-23 16:32:28 +01:00
|
|
|
_, err = getUser(s, userToCheck, false)
|
2020-11-21 17:38:58 +01:00
|
|
|
if err != nil {
|
|
|
|
if IsErrUserDoesNotExist(err) {
|
|
|
|
exists = false
|
|
|
|
} else {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
2021-10-31 12:37:08 +01:00
|
|
|
if exists && user.Issuer == IssuerLocal {
|
2020-11-21 17:38:58 +01:00
|
|
|
return ErrUserEmailExists{user.ID, user.Email}
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|