2016-02-01 12:59:10 +01:00
|
|
|
/*
|
|
|
|
Copyright (c) 2016 VMware, Inc. All Rights Reserved.
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
you may not use this file except in compliance with the License.
|
|
|
|
You may obtain a copy of the License at
|
|
|
|
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
See the License for the specific language governing permissions and
|
|
|
|
limitations under the License.
|
|
|
|
*/
|
|
|
|
package controllers
|
|
|
|
|
|
|
|
import (
|
|
|
|
"bytes"
|
2016-02-24 07:31:52 +01:00
|
|
|
"net/http"
|
2016-02-01 12:59:10 +01:00
|
|
|
"os"
|
|
|
|
"regexp"
|
|
|
|
"text/template"
|
|
|
|
|
|
|
|
"github.com/vmware/harbor/dao"
|
|
|
|
"github.com/vmware/harbor/models"
|
|
|
|
"github.com/vmware/harbor/utils"
|
|
|
|
|
|
|
|
"github.com/astaxie/beego"
|
|
|
|
)
|
|
|
|
|
|
|
|
type ChangePasswordController struct {
|
|
|
|
BaseController
|
|
|
|
}
|
|
|
|
|
|
|
|
func (cpc *ChangePasswordController) Get() {
|
|
|
|
sessionUserId := cpc.GetSession("userId")
|
|
|
|
if sessionUserId == nil {
|
2016-02-24 07:31:52 +01:00
|
|
|
cpc.Redirect("/signIn", http.StatusFound)
|
2016-02-25 04:48:22 +01:00
|
|
|
return
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
cpc.Data["Username"] = cpc.GetSession("username")
|
|
|
|
cpc.ForwardTo("page_title_change_password", "change-password")
|
|
|
|
}
|
|
|
|
|
|
|
|
func (cpc *CommonController) UpdatePassword() {
|
|
|
|
|
|
|
|
sessionUserId := cpc.GetSession("userId")
|
|
|
|
|
2016-02-23 21:02:08 +01:00
|
|
|
if sessionUserId == nil {
|
2016-02-01 12:59:10 +01:00
|
|
|
beego.Warning("User does not login.")
|
2016-02-24 07:31:52 +01:00
|
|
|
cpc.CustomAbort(http.StatusUnauthorized, "please_login_first")
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
oldPassword := cpc.GetString("old_password")
|
2016-02-23 21:02:08 +01:00
|
|
|
if oldPassword == "" {
|
|
|
|
beego.Error("Old password is blank")
|
2016-02-24 07:31:52 +01:00
|
|
|
cpc.CustomAbort(http.StatusBadRequest, "Old password is blank")
|
2016-02-23 21:02:08 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
queryUser := models.User{UserId: sessionUserId.(int), Password: oldPassword}
|
2016-02-01 12:59:10 +01:00
|
|
|
user, err := dao.CheckUserPassword(queryUser)
|
|
|
|
if err != nil {
|
|
|
|
beego.Error("Error occurred in CheckUserPassword:", err)
|
2016-02-24 07:31:52 +01:00
|
|
|
cpc.CustomAbort(http.StatusInternalServerError, "Internal error.")
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
if user == nil {
|
|
|
|
beego.Warning("Password input is not correct")
|
2016-02-24 07:31:52 +01:00
|
|
|
cpc.CustomAbort(http.StatusForbidden, "old_password_is_not_correct")
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
password := cpc.GetString("password")
|
|
|
|
if password != "" {
|
2016-02-23 21:02:08 +01:00
|
|
|
updateUser := models.User{UserId: sessionUserId.(int), Password: password, Salt: user.Salt}
|
|
|
|
err = dao.ChangeUserPassword(updateUser, oldPassword)
|
|
|
|
if err != nil {
|
|
|
|
beego.Error("Error occurred in ChangeUserPassword:", err)
|
2016-02-24 07:31:52 +01:00
|
|
|
cpc.CustomAbort(http.StatusInternalServerError, "Internal error.")
|
2016-02-23 21:02:08 +01:00
|
|
|
}
|
2016-02-01 12:59:10 +01:00
|
|
|
} else {
|
2016-02-24 07:31:52 +01:00
|
|
|
cpc.CustomAbort(http.StatusBadRequest, "please_input_new_password")
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
type ForgotPasswordController struct {
|
|
|
|
BaseController
|
|
|
|
}
|
|
|
|
|
|
|
|
type MessageDetail struct {
|
|
|
|
Hint string
|
|
|
|
Url string
|
|
|
|
Uuid string
|
|
|
|
}
|
|
|
|
|
|
|
|
func (fpc *ForgotPasswordController) Get() {
|
|
|
|
fpc.ForwardTo("page_title_forgot_password", "forgot-password")
|
|
|
|
}
|
|
|
|
|
|
|
|
func (fpc *CommonController) SendEmail() {
|
|
|
|
|
|
|
|
email := fpc.GetString("email")
|
|
|
|
|
2016-02-23 21:02:08 +01:00
|
|
|
pass, _ := regexp.MatchString(`^(([^<>()[\]\\.,;:\s@\"]+(\.[^<>()[\]\\.,;:\s@\"]+)*)|(\".+\"))@((\[[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\])|(([a-zA-Z\-0-9]+\.)+[a-zA-Z]{2,}))$`, email)
|
|
|
|
|
|
|
|
if !pass {
|
2016-02-24 07:31:52 +01:00
|
|
|
fpc.CustomAbort(http.StatusBadRequest, "email_content_illegal")
|
2016-02-23 21:02:08 +01:00
|
|
|
} else {
|
2016-02-01 12:59:10 +01:00
|
|
|
|
|
|
|
queryUser := models.User{Email: email}
|
|
|
|
exist, err := dao.UserExists(queryUser, "email")
|
|
|
|
if err != nil {
|
|
|
|
beego.Error("Error occurred in UserExists:", err)
|
2016-02-24 07:31:52 +01:00
|
|
|
fpc.CustomAbort(http.StatusInternalServerError, "Internal error.")
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
if !exist {
|
2016-02-24 07:31:52 +01:00
|
|
|
fpc.CustomAbort(http.StatusNotFound, "email_does_not_exist")
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
messageTemplate, err := template.ParseFiles("views/reset-password-mail.tpl")
|
|
|
|
if err != nil {
|
|
|
|
beego.Error("Parse email template file failed:", err)
|
2016-02-24 07:31:52 +01:00
|
|
|
fpc.CustomAbort(http.StatusInternalServerError, err.Error())
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
message := new(bytes.Buffer)
|
|
|
|
|
|
|
|
harborUrl := os.Getenv("HARBOR_URL")
|
|
|
|
if harborUrl == "" {
|
|
|
|
harborUrl = "localhost"
|
|
|
|
}
|
|
|
|
uuid, err := dao.GenerateRandomString()
|
|
|
|
if err != nil {
|
|
|
|
beego.Error("Error occurred in GenerateRandomString:", err)
|
2016-02-24 07:31:52 +01:00
|
|
|
fpc.CustomAbort(http.StatusInternalServerError, "Internal error.")
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
err = messageTemplate.Execute(message, MessageDetail{
|
|
|
|
Hint: fpc.Tr("reset_email_hint"),
|
|
|
|
Url: harborUrl,
|
|
|
|
Uuid: uuid,
|
|
|
|
})
|
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
beego.Error("message template error:", err)
|
2016-02-24 07:31:52 +01:00
|
|
|
fpc.CustomAbort(http.StatusInternalServerError, "internal_error")
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
config, err := beego.AppConfig.GetSection("mail")
|
|
|
|
if err != nil {
|
|
|
|
beego.Error("Can not load app.conf:", err)
|
2016-02-24 07:31:52 +01:00
|
|
|
fpc.CustomAbort(http.StatusInternalServerError, "internal_error")
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
mail := utils.Mail{
|
|
|
|
From: config["from"],
|
|
|
|
To: []string{email},
|
|
|
|
Subject: fpc.Tr("reset_email_subject"),
|
|
|
|
Message: message.String()}
|
|
|
|
|
|
|
|
err = mail.SendMail()
|
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
beego.Error("send email failed:", err)
|
2016-02-24 07:31:52 +01:00
|
|
|
fpc.CustomAbort(http.StatusInternalServerError, "send_email_failed")
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
user := models.User{ResetUuid: uuid, Email: email}
|
|
|
|
dao.UpdateUserResetUuid(user)
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
type ResetPasswordController struct {
|
|
|
|
BaseController
|
|
|
|
}
|
|
|
|
|
|
|
|
func (rpc *ResetPasswordController) Get() {
|
|
|
|
|
2016-02-23 21:02:08 +01:00
|
|
|
resetUuid := rpc.GetString("reset_uuid")
|
|
|
|
if resetUuid == "" {
|
|
|
|
beego.Error("Reset uuid is blank.")
|
2016-02-24 07:31:52 +01:00
|
|
|
rpc.Redirect("/", http.StatusFound)
|
2016-02-25 04:48:22 +01:00
|
|
|
return
|
2016-02-23 21:02:08 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
queryUser := models.User{ResetUuid: resetUuid}
|
2016-02-01 12:59:10 +01:00
|
|
|
user, err := dao.GetUser(queryUser)
|
|
|
|
if err != nil {
|
|
|
|
beego.Error("Error occurred in GetUser:", err)
|
2016-02-24 07:31:52 +01:00
|
|
|
rpc.CustomAbort(http.StatusInternalServerError, "Internal error.")
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
if user != nil {
|
|
|
|
rpc.Data["ResetUuid"] = user.ResetUuid
|
|
|
|
rpc.ForwardTo("page_title_reset_password", "reset-password")
|
|
|
|
} else {
|
2016-02-24 07:31:52 +01:00
|
|
|
rpc.Redirect("/", http.StatusFound)
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (rpc *CommonController) ResetPassword() {
|
|
|
|
|
|
|
|
resetUuid := rpc.GetString("reset_uuid")
|
2016-02-23 21:02:08 +01:00
|
|
|
if resetUuid == "" {
|
2016-02-24 07:31:52 +01:00
|
|
|
rpc.CustomAbort(http.StatusBadRequest, "Reset uuid is blank.")
|
2016-02-23 21:02:08 +01:00
|
|
|
}
|
2016-02-01 12:59:10 +01:00
|
|
|
|
|
|
|
queryUser := models.User{ResetUuid: resetUuid}
|
|
|
|
user, err := dao.GetUser(queryUser)
|
|
|
|
if err != nil {
|
|
|
|
beego.Error("Error occurred in GetUser:", err)
|
2016-02-24 07:31:52 +01:00
|
|
|
rpc.CustomAbort(http.StatusInternalServerError, "Internal error.")
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
2016-02-23 21:02:08 +01:00
|
|
|
if user == nil {
|
|
|
|
beego.Error("User does not exist")
|
2016-02-24 07:31:52 +01:00
|
|
|
rpc.CustomAbort(http.StatusBadRequest, "User does not exist")
|
2016-02-23 21:02:08 +01:00
|
|
|
}
|
2016-02-01 12:59:10 +01:00
|
|
|
|
|
|
|
password := rpc.GetString("password")
|
|
|
|
|
|
|
|
if password != "" {
|
|
|
|
user.Password = password
|
2016-02-24 13:44:46 +01:00
|
|
|
err = dao.ResetUserPassword(*user)
|
|
|
|
if err != nil {
|
|
|
|
beego.Error("Error occurred in ResetUserPassword:", err)
|
2016-02-24 07:31:52 +01:00
|
|
|
rpc.CustomAbort(http.StatusInternalServerError, "Internal error.")
|
2016-02-24 13:44:46 +01:00
|
|
|
}
|
2016-02-01 12:59:10 +01:00
|
|
|
} else {
|
2016-02-24 07:31:52 +01:00
|
|
|
rpc.CustomAbort(http.StatusBadRequest, "password_is_required")
|
2016-02-01 12:59:10 +01:00
|
|
|
}
|
|
|
|
}
|