user.go 3.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146
  1. package api
  2. import (
  3. "github.com/grafana/grafana/pkg/bus"
  4. "github.com/grafana/grafana/pkg/middleware"
  5. m "github.com/grafana/grafana/pkg/models"
  6. "github.com/grafana/grafana/pkg/util"
  7. )
  8. // GET /api/user (current authenticated user)
  9. func GetSignedInUser(c *middleware.Context) Response {
  10. return getUserUserProfile(c.UserId)
  11. }
  12. // GET /api/user/:id
  13. func GetUserById(c *middleware.Context) Response {
  14. return getUserUserProfile(c.ParamsInt64(":id"))
  15. }
  16. func getUserUserProfile(userId int64) Response {
  17. query := m.GetUserProfileQuery{UserId: userId}
  18. if err := bus.Dispatch(&query); err != nil {
  19. return ApiError(500, "Failed to get user", err)
  20. }
  21. return Json(200, query.Result)
  22. }
  23. // POST /api/user
  24. func UpdateSignedInUser(c *middleware.Context, cmd m.UpdateUserCommand) Response {
  25. cmd.UserId = c.UserId
  26. return handleUpdateUser(cmd)
  27. }
  28. // POST /api/users/:id
  29. func UpdateUser(c *middleware.Context, cmd m.UpdateUserCommand) Response {
  30. cmd.UserId = c.ParamsInt64(":id")
  31. return handleUpdateUser(cmd)
  32. }
  33. func handleUpdateUser(cmd m.UpdateUserCommand) Response {
  34. if len(cmd.Login) == 0 {
  35. cmd.Login = cmd.Email
  36. if len(cmd.Login) == 0 {
  37. return ApiError(400, "Validation error, need specify either username or email", nil)
  38. }
  39. }
  40. if err := bus.Dispatch(&cmd); err != nil {
  41. return ApiError(500, "failed to update user", err)
  42. }
  43. return ApiSuccess("User updated")
  44. }
  45. // GET /api/user/orgs
  46. func GetSignedInUserOrgList(c *middleware.Context) Response {
  47. return getUserOrgList(c.UserId)
  48. }
  49. // GET /api/user/:id/orgs
  50. func GetUserOrgList(c *middleware.Context) Response {
  51. return getUserOrgList(c.ParamsInt64(":id"))
  52. }
  53. func getUserOrgList(userId int64) Response {
  54. query := m.GetUserOrgListQuery{UserId: userId}
  55. if err := bus.Dispatch(&query); err != nil {
  56. return ApiError(500, "Faile to get user organziations", err)
  57. }
  58. return Json(200, query.Result)
  59. }
  60. func validateUsingOrg(userId int64, orgId int64) bool {
  61. query := m.GetUserOrgListQuery{UserId: userId}
  62. if err := bus.Dispatch(&query); err != nil {
  63. return false
  64. }
  65. // validate that the org id in the list
  66. valid := false
  67. for _, other := range query.Result {
  68. if other.OrgId == orgId {
  69. valid = true
  70. }
  71. }
  72. return valid
  73. }
  74. // POST /api/user/using/:id
  75. func UserSetUsingOrg(c *middleware.Context) Response {
  76. orgId := c.ParamsInt64(":id")
  77. if !validateUsingOrg(c.UserId, orgId) {
  78. return ApiError(401, "Not a valid organization", nil)
  79. }
  80. cmd := m.SetUsingOrgCommand{UserId: c.UserId, OrgId: orgId}
  81. if err := bus.Dispatch(&cmd); err != nil {
  82. return ApiError(500, "Failed change active organization", err)
  83. }
  84. return ApiSuccess("Active organization changed")
  85. }
  86. func ChangeUserPassword(c *middleware.Context, cmd m.ChangeUserPasswordCommand) Response {
  87. userQuery := m.GetUserByIdQuery{Id: c.UserId}
  88. if err := bus.Dispatch(&userQuery); err != nil {
  89. return ApiError(500, "Could not read user from database", err)
  90. }
  91. passwordHashed := util.EncodePassword(cmd.OldPassword, userQuery.Result.Salt)
  92. if passwordHashed != userQuery.Result.Password {
  93. return ApiError(401, "Invalid old password", nil)
  94. }
  95. if len(cmd.NewPassword) < 4 {
  96. return ApiError(400, "New password too short", nil)
  97. }
  98. cmd.UserId = c.UserId
  99. cmd.NewPassword = util.EncodePassword(cmd.NewPassword, userQuery.Result.Salt)
  100. if err := bus.Dispatch(&cmd); err != nil {
  101. return ApiError(500, "Failed to change user password", err)
  102. }
  103. return ApiSuccess("User password changed")
  104. }
  105. // GET /api/users
  106. func SearchUsers(c *middleware.Context) Response {
  107. query := m.SearchUsersQuery{Query: "", Page: 0, Limit: 1000}
  108. if err := bus.Dispatch(&query); err != nil {
  109. return ApiError(500, "Failed to fetch users", err)
  110. }
  111. return Json(200, query.Result)
  112. }