make privileges more defining for UI

This commit is contained in:
2021-08-12 15:48:02 +02:00
committed by dietrich
parent eee0a8dba2
commit f361a13c91
9 changed files with 150 additions and 87 deletions
+2 -1
View File
@@ -207,7 +207,7 @@ pub async fn webservice(
) -> Result<actix_web::dev::Server, std::io::Error> {
let host_port = format!("{}:{}", &server_config.internal_ip, &server_config.port);
info!(
"Running on: {}://{}/admin/login/",
"Running on: {}://{}/apps/",
&server_config.protocol, host_port
);
info!(
@@ -265,6 +265,7 @@ pub async fn webservice(
"/update_user/",
web::post().to(views::process_update_user_json),
)
.route("/update_privileges/", web::post().to(views::toggle_admin))
.route(
"/get_logged_user/",
web::post().to(views::get_logged_user_json),
+7 -3
View File
@@ -255,6 +255,10 @@ pub async fn list_users(
Ok(ListWithOwner { user, list: users })
}
RoleGuard::Regular { user } => Ok(ListWithOwner {
user: user.clone(),
list: vec![user],
}),
_ => Err(ServerError::User(
"Administrator permissions required".to_owned(),
)),
@@ -559,14 +563,14 @@ pub async fn update_user(
#[instrument(skip(id))]
pub async fn toggle_admin(
id: &Identity,
user_id: &str,
user_id: Option<i64>,
server_config: &ServerConfig,
) -> Result<Item<User>, ServerError> {
if let Ok(uid) = user_id.parse::<i64>() {
if let Some(uid) = user_id {
let auth = authenticate(id, server_config).await?;
match auth {
RoleGuard::Admin { .. } => {
info!("Changing administrator priviledges: ");
info!("Changing administrator privileges: ");
let unchanged_user = User::get_user(uid, server_config).await?;
+8 -6
View File
@@ -207,15 +207,17 @@ pub async fn process_update_user_json(
#[instrument(skip(id))]
pub async fn toggle_admin(
data: web::Path<String>,
user: web::Json<UserDelta>,
config: web::Data<crate::ServerConfig>,
id: Identity,
) -> Result<HttpResponse, ServerError> {
let update = queries::toggle_admin(&id, &data.0, &config).await?;
Ok(redirect_builder(&format!(
"/admin/view/profile/{}",
update.item.id
)))
let update = queries::toggle_admin(&id, user.id, &config).await?;
Ok(HttpResponse::Ok().json2(&Status::Success(Message {
message: format!(
"Successfully changed privileges or user: {}",
update.item.username
),
})))
}
#[instrument(skip(id))]