update user functionality and cleanup

This commit is contained in:
2021-08-12 15:48:02 +02:00
committed by dietrich
parent 6837495eba
commit d503d49917
10 changed files with 297 additions and 80 deletions
+2 -2
View File
@@ -26,7 +26,7 @@ clap = "2.33"
dotenv = "0.15.0"
fluent-langneg = "0.13"
image = "0.23"
opentelemetry = "0.13"
opentelemetry = "0.14"
opentelemetry-jaeger = "0.12"
qrcode = "0.12"
rand = "0.8"
@@ -70,4 +70,4 @@ tokio = "0.2.25"
[dev-dependencies.reqwest]
features = ["cookies"]
version = "0.10.10"
version = "0.11.3"
+1 -1
View File
@@ -20,7 +20,7 @@ use tracing::{error, info, trace, warn};
static MIGRATOR: Migrator = sqlx::migrate!();
#[allow(clippy::clippy::too_many_lines)]
#[allow(clippy::too_many_lines)]
fn generate_cli() -> App<'static, 'static> {
app_from_crate!()
.arg(
+4
View File
@@ -374,6 +374,10 @@ pub async fn webservice(
.route(
"/create_user/",
web::post().to(views::process_create_user_json),
)
.route(
"/update_user/",
web::post().to(views::process_update_user_json),
),
)
// login to the admin area
+57 -3
View File
@@ -4,7 +4,7 @@ use enum_map::EnumMap;
use serde::Serialize;
use shared::{
apirequests::{
general::{Filter, Operation, Ordering},
general::{EditMode, Filter, Operation, Ordering},
links::{LinkOverviewColumns, LinkRequestForm},
users::{UserDelta, UserOverviewColumns, UserRequestForm},
},
@@ -310,7 +310,7 @@ pub struct Item<T> {
///
/// # Errors
/// Fails with [`ServerError`] if access to the database fails or this user does not have permissions.
#[allow(clippy::clippy::missing_panics_doc)]
#[allow(clippy::missing_panics_doc)]
#[instrument(skip(id))]
pub async fn get_user(
id: &Identity,
@@ -400,6 +400,9 @@ pub async fn create_user_json(
server_config: &ServerConfig,
) -> Result<Item<User>, ServerError> {
info!("Creating a User: {:?}", &data);
if data.edit != EditMode::Create {
return Err(ServerError::User("Wrong Request".to_string()));
}
let auth = authenticate(id, server_config).await?;
// Require a password on user creation!
@@ -440,7 +443,58 @@ pub async fn create_user_json(
///
/// # Errors
/// Fails with [`ServerError`] if access to the database fails, this user does not have permissions, or the given data is malformed.
#[allow(clippy::clippy::missing_panics_doc)]
#[instrument(skip(id))]
pub async fn update_user_json(
id: &Identity,
data: &web::Json<UserDelta>,
server_config: &ServerConfig,
) -> Result<Item<User>, ServerError> {
let auth = authenticate(id, server_config).await?;
if let Some(uid) = data.id {
let unmodified_user = User::get_user(uid, server_config).await?;
if auth.admin_or_self(uid) {
match auth {
Role::Admin { .. } | Role::Regular { .. } => {
info!("Updating userinfo: ");
let password = match &data.password {
Some(password) => NewUser::hash_password(password, &server_config.secret)?,
None => unmodified_user.password,
};
let new_user = User {
id: uid,
username: data.username.clone(),
email: data.email.clone(),
password,
role: unmodified_user.role,
language: unmodified_user.language,
};
new_user.update_user(server_config).await?;
let changed_user = User::get_user(uid, server_config).await?;
Ok(Item {
user: changed_user.clone(),
item: changed_user,
})
}
Role::NotAuthenticated | Role::Disabled => {
unreachable!("Should be unreachable because of the `admin_or_self`")
}
}
} else {
Err(ServerError::User("Not a valid UID".to_owned()))
}
} else {
Err(ServerError::User("Not a valid UID".to_owned()))
}
}
/// Take a [`actix_web::web::Form<NewUser>`] and update the corresponding entry in the database.
/// The password is only updated if a new password of at least 4 characters is provided.
/// The `user_id` is never changed.
///
/// # Errors
/// Fails with [`ServerError`] if access to the database fails, this user does not have permissions, or the given data is malformed.
#[allow(clippy::missing_panics_doc)]
#[instrument(skip(id))]
pub async fn update_user(
id: &Identity,
+15
View File
@@ -365,6 +365,21 @@ pub async fn process_create_user_json(
}
}
#[instrument(skip(id))]
pub async fn process_update_user_json(
config: web::Data<crate::ServerConfig>,
form: web::Json<UserDelta>,
id: Identity,
) -> Result<HttpResponse, ServerError> {
info!("Listing Users to Json api");
match queries::update_user_json(&id, &form, &config).await {
Ok(item) => Ok(HttpResponse::Ok().json2(&SuccessMessage {
message: format!("Successfully saved user: {}", item.item.username),
})),
Err(e) => Err(e),
}
}
#[instrument(skip(id))]
pub async fn toggle_admin(
data: web::Path<String>,
+14
View File
@@ -170,4 +170,18 @@ div.actions input {
div.editdialog {
background-color: aliceblue;
border: 5px solid rgb(90, 90, 90);
}
div.closebutton a {
display: block;
position: absolute;
top: 10px;
right: 10px;
font-size: xx-large;
}
div.message {
background-color: aliceblue;
border: 5px solid rgb(90, 90, 90);
height: auto;
}