9 "github.com/dchest/passwordreset"
10 "github.com/gin-gonic/gin"
12 "git.immae.eu/Cryptoportfolio/Front.git/db"
16 VALID_EMAIL_REGEX = `(?i)^[A-Z0-9._%+-]+@[A-Z0-9.-]+\.[A-Z]{2,4}$`
19 func UserConfirmed(c *gin.Context) *Error {
20 user, exists := c.Get("user")
23 return &Error{NotAuthorized, "not authorized", fmt.Errorf("no user key in context")}
26 if user.(db.User).Status != db.Confirmed {
27 return &Error{UserNotConfirmed, "user awaiting admin validation", fmt.Errorf("user '%v' not confirmed", user)}
33 func UserIsAdmin(c *gin.Context) *Error {
34 user, exists := c.Get("user")
37 return &Error{NotAuthorized, "not authorized", fmt.Errorf("no user key in context")}
40 if user.(db.User).Role != db.RoleAdmin {
41 return &Error{NotAuthorized, "not authorized", fmt.Errorf("user '%v' is not admin", user)}
47 func GetUser(c *gin.Context) db.User {
48 user, _ := c.Get("user")
53 func IsValidEmailAddress(email string) bool {
54 r := regexp.MustCompile(VALID_EMAIL_REGEX)
56 return r.MatchString(email)
59 type SignParams struct {
64 type SignResult struct {
65 Token string `json:"token"`
66 IsAdmin bool `json:"isAdmin"`
69 func (s SignParams) Validate() *Error {
70 if !IsValidEmailAddress(s.Email) {
71 return &Error{InvalidEmail, "invalid email", fmt.Errorf("'%v' is not a valid email", s.Email)}
75 return &Error{InvalidPassword, "invalid password", fmt.Errorf("invalid password")}
81 type SignupQuery struct {
85 func (q SignupQuery) ValidateParams() *Error {
86 return q.In.Validate()
89 func (q SignupQuery) Run() (interface{}, *Error) {
90 user, err := db.GetUserByEmail(q.In.Email)
92 return nil, NewInternalError(err)
96 return nil, &Error{EmailExists, "email already taken", fmt.Errorf("'%v' is already registered '%v'", q.In.Email, user)}
99 newUser := db.User{Email: q.In.Email, Status: db.AwaitingConfirmation}
100 newUser.PasswordHash, err = db.HashPassword(q.In.Password)
102 return nil, NewInternalError(err)
105 err = db.InsertUser(&newUser)
107 return nil, NewInternalError(err)
110 token, err := CreateJwtToken(newUser.Id)
112 return nil, NewInternalError(fmt.Errorf("cannot create jwt token %v", err))
115 if CONFIG.FreeSMSUser != "" {
116 err := SendSMS(CONFIG.FreeSMSUser, CONFIG.FreeSMSPass, fmt.Sprintf("New user signup '%v'", q.In.Email))
118 return nil, NewInternalError(err)
122 configMap := make(map[string]string)
123 configMap["key"] = ""
124 configMap["secret"] = ""
126 _, err = db.SetUserMarketConfig(newUser.Id, "poloniex", configMap)
128 return nil, NewInternalError(err)
131 if MAIL_CONFIG.IsEnabled {
132 mailConfirmationToken := passwordreset.NewToken(q.In.Email, time.Hour*24*1, []byte(strconv.FormatUint(uint64(newUser.Status), 10)), PASSWORD_RESET_SECRET)
133 err = SendConfirmationMail(q.In.Email, mailConfirmationToken)
135 return nil, NewInternalError(err)
139 return SignResult{token, newUser.Role == db.RoleAdmin}, nil
142 type SigninQuery struct {
146 func (q SigninQuery) ValidateParams() *Error {
147 return q.In.Validate()
150 func (q SigninQuery) Run() (interface{}, *Error) {
151 user, err := db.GetUserByEmail(q.In.Email)
153 return nil, NewInternalError(err)
157 return nil, &Error{InvalidCredentials, "invalid credentials", fmt.Errorf("no email '%v' found", q.In.Email)}
160 err = db.ValidatePassword(q.In.Password, user.PasswordHash)
162 return nil, &Error{InvalidCredentials, "invalid credentials", err}
165 token, err := CreateJwtToken(user.Id)
167 return nil, NewInternalError(err)
170 return SignResult{token, user.Role == db.RoleAdmin}, nil
173 type ConfirmEmailQuery struct {
179 func (q ConfirmEmailQuery) ValidateParams() *Error {
181 if q.In.Token == "" {
182 return &Error{BadRequest, "invalid token", fmt.Errorf("invalid token")}
188 func (q ConfirmEmailQuery) Run() (interface{}, *Error) {
191 email, err := passwordreset.VerifyToken(q.In.Token, func(email string) ([]byte, error) {
193 user, err = db.GetUserByEmail(email)
199 return nil, fmt.Errorf("'%v' is not registered", email)
202 return []byte(strconv.FormatUint(uint64(user.Status), 10)), nil
204 }, PASSWORD_RESET_SECRET)
206 if err != nil && (err == passwordreset.ErrExpiredToken) {
207 return nil, &Error{BadRequest, "expired token", fmt.Errorf("expired token")}
208 } else if err != nil && (err == passwordreset.ErrMalformedToken || err == passwordreset.ErrWrongSignature) {
209 return nil, &Error{BadRequest, "wrong token", fmt.Errorf("wrong token")}
210 } else if err != nil {
211 return nil, NewInternalError(err)
215 return nil, &Error{BadRequest, "bad request", fmt.Errorf("no user found for email '%v'", email)}
218 err = db.SetUserStatus(user, db.Confirmed)
220 return nil, NewInternalError(err)
226 type UserAccountQuery struct {
231 Email string `json:"email"`
235 func (q UserAccountQuery) ValidateParams() *Error {
239 func (q UserAccountQuery) Run() (interface{}, *Error) {
240 q.Out.Email = q.In.User.Email