user.go 2.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128
  1. package api
  2. import (
  3. "github.com/grafana/grafana/pkg/bus"
  4. "github.com/grafana/grafana/pkg/middleware"
  5. m "github.com/grafana/grafana/pkg/models"
  6. "github.com/grafana/grafana/pkg/util"
  7. )
  8. // GET /api/user (current authenticated user)
  9. func GetSignedInUser(c *middleware.Context) Response {
  10. return getUserUserProfile(c.UserId)
  11. }
  12. // GET /api/user/:id
  13. func GetUserById(c *middleware.Context) Response {
  14. return getUserUserProfile(c.ParamsInt64(":id"))
  15. }
  16. func getUserUserProfile(userId int64) Response {
  17. query := m.GetUserProfileQuery{UserId: userId}
  18. if err := bus.Dispatch(&query); err != nil {
  19. return ApiError(500, "Failed to get user", err)
  20. }
  21. return Json(200, query.Result)
  22. }
  23. func UpdateUser(c *middleware.Context, cmd m.UpdateUserCommand) {
  24. cmd.UserId = c.UserId
  25. if err := bus.Dispatch(&cmd); err != nil {
  26. c.JsonApiErr(400, "Failed to update user", err)
  27. return
  28. }
  29. c.JsonOK("User updated")
  30. }
  31. // GET /api/user/orgs
  32. func GetSignedInUserOrgList(c *middleware.Context) Response {
  33. return getUserOrgList(c.UserId)
  34. }
  35. // GET /api/user/:id/orgs
  36. func GetUserOrgList(c *middleware.Context) Response {
  37. return getUserOrgList(c.ParamsInt64(":id"))
  38. }
  39. func getUserOrgList(userId int64) Response {
  40. query := m.GetUserOrgListQuery{UserId: userId}
  41. if err := bus.Dispatch(&query); err != nil {
  42. return ApiError(500, "Faile to get user organziations", err)
  43. }
  44. return Json(200, query.Result)
  45. }
  46. func validateUsingOrg(userId int64, orgId int64) bool {
  47. query := m.GetUserOrgListQuery{UserId: userId}
  48. if err := bus.Dispatch(&query); err != nil {
  49. return false
  50. }
  51. // validate that the org id in the list
  52. valid := false
  53. for _, other := range query.Result {
  54. if other.OrgId == orgId {
  55. valid = true
  56. }
  57. }
  58. return valid
  59. }
  60. func UserSetUsingOrg(c *middleware.Context) {
  61. orgId := c.ParamsInt64(":id")
  62. if !validateUsingOrg(c.UserId, orgId) {
  63. c.JsonApiErr(401, "Not a valid organization", nil)
  64. return
  65. }
  66. cmd := m.SetUsingOrgCommand{
  67. UserId: c.UserId,
  68. OrgId: orgId,
  69. }
  70. if err := bus.Dispatch(&cmd); err != nil {
  71. c.JsonApiErr(500, "Failed change active organization", err)
  72. return
  73. }
  74. c.JsonOK("Active organization changed")
  75. }
  76. func ChangeUserPassword(c *middleware.Context, cmd m.ChangeUserPasswordCommand) {
  77. userQuery := m.GetUserByIdQuery{Id: c.UserId}
  78. if err := bus.Dispatch(&userQuery); err != nil {
  79. c.JsonApiErr(500, "Could not read user from database", err)
  80. return
  81. }
  82. passwordHashed := util.EncodePassword(cmd.OldPassword, userQuery.Result.Salt)
  83. if passwordHashed != userQuery.Result.Password {
  84. c.JsonApiErr(401, "Invalid old password", nil)
  85. return
  86. }
  87. if len(cmd.NewPassword) < 4 {
  88. c.JsonApiErr(400, "New password too short", nil)
  89. return
  90. }
  91. cmd.UserId = c.UserId
  92. cmd.NewPassword = util.EncodePassword(cmd.NewPassword, userQuery.Result.Salt)
  93. if err := bus.Dispatch(&cmd); err != nil {
  94. c.JsonApiErr(500, "Failed to change user password", err)
  95. return
  96. }
  97. c.JsonOK("User password changed")
  98. }