2021-07-17 18:45:52 +00:00
|
|
|
extern crate log;
|
2021-07-23 13:48:57 +00:00
|
|
|
use crate::file_io::*;
|
2021-07-22 21:17:55 +00:00
|
|
|
use rocket::http::{Cookie, Cookies};
|
2021-07-22 21:31:18 +00:00
|
|
|
use crate::user::*;
|
2021-07-18 20:36:23 +00:00
|
|
|
use rocket_contrib::json::{Json, JsonValue};
|
2021-07-18 18:11:54 +00:00
|
|
|
use random_string::generate;
|
2021-07-17 15:40:05 +00:00
|
|
|
extern crate sha1;
|
2021-07-18 20:36:23 +00:00
|
|
|
use serde::Deserialize;
|
2021-07-18 00:32:57 +00:00
|
|
|
|
2021-07-17 15:40:05 +00:00
|
|
|
// Post request to register a user and pin
|
2021-07-18 17:16:00 +00:00
|
|
|
#[post("/register/<name>/<pin>/<pronouns>")]
|
2021-07-18 16:06:05 +00:00
|
|
|
pub fn register_user(name: String, pin: i32, pronouns: String) -> JsonValue {
|
2021-07-23 13:42:33 +00:00
|
|
|
// check if the user exists
|
|
|
|
if let Some(user) = db_read_user(&name).ok().flatten() {
|
|
|
|
warn!("Cannot create user {}! User is already in system.", name);
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "user already exists",
|
|
|
|
});
|
|
|
|
} else {
|
|
|
|
let pin_hashed = sha1::Sha1::from(&pin.to_string()).digest().to_string(); // hash the pin
|
2021-07-22 21:17:55 +00:00
|
|
|
|
2021-07-23 13:42:33 +00:00
|
|
|
let new_user: User = User {
|
|
|
|
name: name.to_string().to_lowercase(),
|
|
|
|
pin_hashed,
|
|
|
|
pronouns: pronouns.to_string().to_lowercase(),
|
|
|
|
session_token: "NULL".to_string(),
|
|
|
|
role: UserType::Normal,
|
|
|
|
};
|
2021-07-17 19:53:10 +00:00
|
|
|
|
2021-07-22 15:01:07 +00:00
|
|
|
db_add(&new_user);
|
2021-07-17 18:45:52 +00:00
|
|
|
|
2021-07-18 00:33:22 +00:00
|
|
|
info!(
|
|
|
|
"succesfully created user {} with pin hash {}",
|
2021-07-22 15:01:07 +00:00
|
|
|
new_user.name.to_string(),
|
|
|
|
new_user.pin_hashed
|
2021-07-18 00:33:22 +00:00
|
|
|
);
|
2021-07-18 16:06:05 +00:00
|
|
|
return json!({
|
|
|
|
"status": "ok",
|
2021-07-18 20:36:23 +00:00
|
|
|
"reason": format!("user {} registered", new_user.name.to_string().to_lowercase()),
|
2021-07-18 16:06:05 +00:00
|
|
|
});
|
2021-07-23 13:42:33 +00:00
|
|
|
}
|
2021-07-17 15:40:05 +00:00
|
|
|
}
|
|
|
|
|
2021-07-23 13:42:33 +00:00
|
|
|
fn create_token(name: String, mut user: User) -> String {
|
2021-07-18 18:11:54 +00:00
|
|
|
let charset = "1234567890abcdefghijklmnopqrstuvwxyz";
|
|
|
|
|
2021-07-23 13:42:33 +00:00
|
|
|
if user.name == name {
|
|
|
|
user.session_token = generate(12, charset);
|
|
|
|
db_add(&user);
|
|
|
|
info!("succesfully created token for user {}", name);
|
|
|
|
let token = user.session_token.clone();
|
|
|
|
return token;
|
2021-07-18 17:16:00 +00:00
|
|
|
};
|
2021-07-23 13:42:33 +00:00
|
|
|
|
2021-07-18 17:26:26 +00:00
|
|
|
warn!("something bad happened while creating a token and idk what");
|
2021-07-18 17:16:00 +00:00
|
|
|
return "NULL".to_string();
|
|
|
|
}
|
|
|
|
|
2021-07-22 17:01:30 +00:00
|
|
|
// Check if user is properly logged in
|
|
|
|
#[get("/token/<name>")]
|
|
|
|
pub fn check_token(name: String, mut cookies: Cookies) -> JsonValue {
|
2021-07-23 13:42:33 +00:00
|
|
|
// check if the user is in the system
|
|
|
|
if let Some(user) = db_read_user(&name).ok().flatten() {
|
|
|
|
// get the token from the cookie
|
|
|
|
let token = match cookies.get_private("token") {
|
|
|
|
None => {
|
|
|
|
warn!("couldn't get token cookie!");
|
2021-07-22 17:01:30 +00:00
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
2021-07-23 13:42:33 +00:00
|
|
|
"reason": "could not read cookie",
|
2021-07-22 17:01:30 +00:00
|
|
|
});
|
2021-07-23 13:42:33 +00:00
|
|
|
},
|
|
|
|
Some(token) => token,
|
|
|
|
};
|
|
|
|
|
|
|
|
// check the token value
|
|
|
|
if token.value() == "NULL" {
|
|
|
|
warn!("NULL token!");
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "NULL token",
|
|
|
|
});
|
|
|
|
} else if token.value() == user.session_token {
|
|
|
|
info!("user {} has correct session token", name);
|
|
|
|
return json!({
|
|
|
|
"status": "ok",
|
|
|
|
"reason": "correct token",
|
|
|
|
});
|
|
|
|
} else {
|
|
|
|
info!("user {} has incorrect token!", name);
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "incorrect token",
|
|
|
|
});
|
2021-07-22 17:01:30 +00:00
|
|
|
}
|
2021-07-23 13:42:33 +00:00
|
|
|
} else {
|
2021-07-22 17:01:30 +00:00
|
|
|
warn!("user {} not found", name);
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "user not found",
|
|
|
|
});
|
2021-07-23 13:42:33 +00:00
|
|
|
}
|
2021-07-22 17:01:30 +00:00
|
|
|
}
|
|
|
|
|
2021-07-22 18:23:59 +00:00
|
|
|
// Logout API
|
|
|
|
#[post("/logout", format = "json", data = "<info>")]
|
|
|
|
pub fn logout(info: Json<LogoutEvent>, mut cookies: Cookies) -> JsonValue {
|
2021-07-23 13:42:33 +00:00
|
|
|
if let Some(mut user) = db_read_user(&info.name.to_lowercase()).ok().flatten() {
|
|
|
|
let token = match cookies.get_private("token") {
|
|
|
|
None => {
|
|
|
|
warn!("couldn't get token cookie!");
|
2021-07-22 18:23:59 +00:00
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
2021-07-23 13:42:33 +00:00
|
|
|
"reason": "could not read cookie",
|
2021-07-22 18:23:59 +00:00
|
|
|
});
|
2021-07-23 13:42:33 +00:00
|
|
|
},
|
|
|
|
Some(token) => token,
|
|
|
|
};
|
|
|
|
if token.value() == "NULL" {
|
|
|
|
warn!("NULL token!");
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "NULL token",
|
|
|
|
});
|
|
|
|
} else if token.value() == user.session_token {
|
|
|
|
cookies.remove_private(Cookie::named("token"));
|
|
|
|
user.session_token = "NULL".to_string();
|
|
|
|
db_add(&user);
|
|
|
|
info!("logged out user {}", info.name);
|
|
|
|
return json!({
|
|
|
|
"status": "ok",
|
|
|
|
"reason": "logged out",
|
|
|
|
});
|
|
|
|
} else {
|
|
|
|
warn!("token does not match! cannot logout");
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "token does not match",
|
|
|
|
});
|
2021-07-22 18:23:59 +00:00
|
|
|
}
|
2021-07-23 13:42:33 +00:00
|
|
|
} else {
|
|
|
|
warn!("failed to log out user {}, user not found", info.name);
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "user not found",
|
|
|
|
});
|
2021-07-22 18:23:59 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-07-17 15:40:05 +00:00
|
|
|
// Check if pin matches user
|
2021-07-18 17:16:00 +00:00
|
|
|
#[get("/users/<name>/<pin>")]
|
2021-07-23 13:48:57 +00:00
|
|
|
pub fn login(mut cookies: Cookies, name: String, pin: i32) -> JsonValue {
|
2021-07-23 13:42:33 +00:00
|
|
|
if let Some(user) = db_read_user(&name.to_lowercase()).ok().flatten() {
|
|
|
|
let hashed_pin_input = sha1::Sha1::from(&pin.to_string()).digest().to_string();
|
2021-07-22 15:44:31 +00:00
|
|
|
|
2021-07-23 13:42:33 +00:00
|
|
|
if user.pin_hashed == hashed_pin_input { // check if pin hash matches
|
|
|
|
info!("pin correct for user {}", &user.name);
|
2021-07-18 17:26:26 +00:00
|
|
|
|
2021-07-23 13:42:33 +00:00
|
|
|
// Create token for user & set a cookie
|
|
|
|
let token = create_token(user.name.clone(), user);
|
|
|
|
let cookie = Cookie::build("token", token)
|
|
|
|
.path("/")
|
|
|
|
.finish();
|
|
|
|
cookies.remove_private(Cookie::named("token"));
|
|
|
|
cookies.add_private(cookie);
|
|
|
|
info!("set the token cookie");
|
|
|
|
|
|
|
|
return json!({
|
|
|
|
"status": "ok",
|
|
|
|
"reason": "pin matches",
|
|
|
|
});
|
|
|
|
} else {
|
|
|
|
cookies.remove_private(Cookie::named("token"));
|
|
|
|
info!("removed private cookie");
|
|
|
|
warn!("pin incorrect for user {}", user.name);
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "incorrect pin",
|
|
|
|
});
|
2021-07-17 15:40:05 +00:00
|
|
|
};
|
2021-07-23 13:42:33 +00:00
|
|
|
} else {
|
|
|
|
cookies.remove_private(Cookie::named("token"));
|
|
|
|
info!("removed private cookie");
|
|
|
|
warn!(
|
|
|
|
"cannot check pin for user {} as they do not exist",
|
|
|
|
name.to_string().to_lowercase()
|
|
|
|
);
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": format!("user {} doesn't exist", name.to_string().to_lowercase()),
|
|
|
|
});
|
2021-07-18 00:33:22 +00:00
|
|
|
}
|
2021-07-17 15:40:05 +00:00
|
|
|
}
|
|
|
|
|
2021-07-18 20:36:23 +00:00
|
|
|
// Change info about a user
|
|
|
|
#[post("/users/change", format = "json", data = "<input>")]
|
2021-07-22 18:23:59 +00:00
|
|
|
pub fn change_info(input: Json<ChangeEvent>, mut cookies: Cookies) -> JsonValue {
|
2021-07-18 20:36:23 +00:00
|
|
|
// read in the users & hash the pin
|
2021-07-22 15:01:07 +00:00
|
|
|
let mut users: Vec<User> = db_read();
|
2021-07-22 17:01:30 +00:00
|
|
|
|
|
|
|
// get token from cookie
|
|
|
|
let token = match cookies.get_private("token") {
|
|
|
|
None => {
|
|
|
|
warn!("couldn't get token cookie!");
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "could not read cookie",
|
|
|
|
});
|
|
|
|
},
|
|
|
|
Some(token) => token,
|
|
|
|
};
|
|
|
|
if token.value() == "NULL" {
|
|
|
|
warn!("NULL token!");
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "NULL token",
|
|
|
|
});
|
|
|
|
}
|
2021-07-18 20:36:23 +00:00
|
|
|
|
2021-07-23 13:42:33 +00:00
|
|
|
// find the user
|
|
|
|
if let Some(mut user) = db_read_user(&input.name).ok().flatten() {
|
|
|
|
if token.value() == user.session_token { // & if token matches:
|
|
|
|
if input.changed_event == "name" {
|
|
|
|
// remove the user first
|
|
|
|
db_remove(&user);
|
|
|
|
// change the name
|
|
|
|
user.name = input.new_event.clone();
|
|
|
|
info!("changed name of {} to {}", input.name, input.new_event);
|
|
|
|
db_add(&user);
|
2021-07-18 20:36:23 +00:00
|
|
|
return json!({
|
2021-07-23 13:42:33 +00:00
|
|
|
"status": "ok",
|
|
|
|
"reason": format!("changed name of {} to {}", input.name, input.new_event),
|
|
|
|
});
|
|
|
|
} else if input.changed_event == "pin" {
|
|
|
|
// change the pin
|
|
|
|
let new_hashed_pin = sha1::Sha1::from(&input.new_event).digest().to_string();
|
|
|
|
user.pin_hashed = new_hashed_pin.clone();
|
|
|
|
db_add(&user);
|
|
|
|
info!("changed pin of {}", input.name);
|
|
|
|
return json!({
|
|
|
|
"status": "ok",
|
|
|
|
"reason": "changed pin",
|
|
|
|
});
|
|
|
|
} else if input.changed_event == "pronouns" {
|
|
|
|
// change the pronouns
|
|
|
|
user.pronouns = input.new_event.clone();
|
|
|
|
info!("changed pronouns of {} to {}", input.name, input.new_event);
|
|
|
|
db_add(&user);
|
|
|
|
return json!({
|
|
|
|
"status": "ok",
|
|
|
|
"reason": "successfully changed pronouns",
|
2021-07-18 20:36:23 +00:00
|
|
|
});
|
|
|
|
};
|
2021-07-23 13:42:33 +00:00
|
|
|
} else {
|
|
|
|
warn!("incorrect pin for user {}", input.name);
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "incorrect pin",
|
|
|
|
});
|
|
|
|
};
|
|
|
|
} else {
|
|
|
|
warn!("couldn't change users info, user does not exist");
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "user doesn't exist",
|
|
|
|
});
|
|
|
|
}
|
2021-07-18 20:36:23 +00:00
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
2021-07-23 13:42:33 +00:00
|
|
|
"reason": "idk",
|
2021-07-18 20:36:23 +00:00
|
|
|
});
|
|
|
|
}
|
|
|
|
|
2021-07-18 17:16:00 +00:00
|
|
|
#[get("/users/<name>")]
|
2021-07-18 16:06:05 +00:00
|
|
|
pub fn get_user(name: String) -> JsonValue {
|
2021-07-22 15:01:07 +00:00
|
|
|
let users: Vec<User> = db_read();
|
2021-07-18 00:33:22 +00:00
|
|
|
let found_user = users
|
|
|
|
.iter()
|
|
|
|
.filter(|u| u.name == name.to_lowercase())
|
|
|
|
.next();
|
2021-07-17 19:53:10 +00:00
|
|
|
|
|
|
|
match found_user {
|
2021-07-18 16:06:05 +00:00
|
|
|
Some(user) => json!({
|
|
|
|
"status":"ok",
|
|
|
|
"user": {
|
|
|
|
"name": user.name,
|
|
|
|
"pronouns": user.pronouns,
|
2021-07-22 21:17:55 +00:00
|
|
|
"role": user.role,
|
2021-07-18 16:06:05 +00:00
|
|
|
},
|
|
|
|
}),
|
|
|
|
None => json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": format!("user {} not found", name),
|
|
|
|
}),
|
2021-07-17 19:53:10 +00:00
|
|
|
}
|
|
|
|
}
|
2021-07-23 11:55:24 +00:00
|
|
|
|
2021-07-22 21:17:55 +00:00
|
|
|
/* User Management */
|
|
|
|
#[post("/mod", format = "json", data = "<data>")]
|
2021-07-23 11:55:24 +00:00
|
|
|
pub fn moderation_actions(data: Json<ModerationAction>, mut cookies: Cookies) -> JsonValue {
|
2021-07-22 21:31:18 +00:00
|
|
|
let token = match cookies.get_private("token") {
|
|
|
|
None => {
|
|
|
|
warn!("couldn't get token cookie!");
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "could not read cookie",
|
|
|
|
});
|
|
|
|
},
|
|
|
|
Some(token) => token,
|
|
|
|
};
|
2021-07-23 13:42:33 +00:00
|
|
|
if let Some(user) = db_read_user(&data.name.to_lowercase()).ok().flatten() {
|
|
|
|
if token.value() == "NULL" { // fail if token is NULL
|
|
|
|
warn!("NULL token!");
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "NULL token",
|
|
|
|
});
|
|
|
|
} else if user.session_token == token.value() { // if token matches
|
|
|
|
if user.role == UserType::Normal {
|
|
|
|
match data.action {
|
|
|
|
ModActions::Kick => {
|
|
|
|
info!("kicked user {}", data.target)
|
|
|
|
},
|
|
|
|
ModActions::Ban => info!("banned user {}", data.target),
|
|
|
|
_ => info!("F"),
|
|
|
|
};
|
2021-07-23 11:55:24 +00:00
|
|
|
return json!({
|
2021-07-23 13:42:33 +00:00
|
|
|
"status": "ok",
|
|
|
|
"reason": "completed action",
|
2021-07-23 11:55:24 +00:00
|
|
|
});
|
|
|
|
} else {
|
2021-07-23 13:42:33 +00:00
|
|
|
warn!("user does not have sufficient permissions to perform that action!");
|
2021-07-23 11:55:24 +00:00
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
2021-07-23 13:42:33 +00:00
|
|
|
"reason": "insufficient permissions",
|
|
|
|
});
|
2021-07-23 11:55:24 +00:00
|
|
|
};
|
2021-07-23 13:42:33 +00:00
|
|
|
} else {
|
|
|
|
warn!("token does not match!");
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "token does not match",
|
|
|
|
})
|
2021-07-23 11:55:24 +00:00
|
|
|
};
|
2021-07-23 13:42:33 +00:00
|
|
|
} else {
|
|
|
|
warn!("user not found");
|
|
|
|
return json!({
|
|
|
|
"status": "fail",
|
|
|
|
"reason": "user not found"
|
|
|
|
});
|
|
|
|
}
|
2021-07-23 11:55:24 +00:00
|
|
|
}
|