signup.go 3.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135
  1. package api
  2. import (
  3. "github.com/grafana/grafana/pkg/api/dtos"
  4. "github.com/grafana/grafana/pkg/bus"
  5. "github.com/grafana/grafana/pkg/events"
  6. "github.com/grafana/grafana/pkg/metrics"
  7. "github.com/grafana/grafana/pkg/middleware"
  8. m "github.com/grafana/grafana/pkg/models"
  9. "github.com/grafana/grafana/pkg/setting"
  10. "github.com/grafana/grafana/pkg/util"
  11. )
  12. // GET /api/user/signup/options
  13. func GetSignUpOptions(c *middleware.Context) Response {
  14. return Json(200, util.DynMap{
  15. "verifyEmailEnabled": setting.VerifyEmailEnabled,
  16. "autoAssignOrg": setting.AutoAssignOrg,
  17. })
  18. }
  19. // POST /api/user/signup
  20. func SignUp(c *middleware.Context, form dtos.SignUpForm) Response {
  21. if !setting.AllowUserSignUp {
  22. return ApiError(401, "User signup is disabled", nil)
  23. }
  24. existing := m.GetUserByLoginQuery{LoginOrEmail: form.Email}
  25. if err := bus.Dispatch(&existing); err == nil {
  26. return ApiError(422, "User with same email address already exists", nil)
  27. }
  28. cmd := m.CreateTempUserCommand{}
  29. cmd.OrgId = -1
  30. cmd.Email = form.Email
  31. cmd.Status = m.TmpUserSignUpStarted
  32. cmd.InvitedByUserId = c.UserId
  33. cmd.Code = util.GetRandomString(20)
  34. cmd.RemoteAddr = c.Req.RemoteAddr
  35. if err := bus.Dispatch(&cmd); err != nil {
  36. return ApiError(500, "Failed to create signup", err)
  37. }
  38. bus.Publish(&events.SignUpStarted{
  39. Email: form.Email,
  40. Code: cmd.Code,
  41. })
  42. metrics.M_Api_User_SignUpStarted.Inc()
  43. return Json(200, util.DynMap{"status": "SignUpCreated"})
  44. }
  45. func SignUpStep2(c *middleware.Context, form dtos.SignUpStep2Form) Response {
  46. if !setting.AllowUserSignUp {
  47. return ApiError(401, "User signup is disabled", nil)
  48. }
  49. createUserCmd := m.CreateUserCommand{
  50. Email: form.Email,
  51. Login: form.Username,
  52. Name: form.Name,
  53. Password: form.Password,
  54. OrgName: form.OrgName,
  55. }
  56. // verify email
  57. if setting.VerifyEmailEnabled {
  58. if ok, rsp := verifyUserSignUpEmail(form.Email, form.Code); !ok {
  59. return rsp
  60. }
  61. createUserCmd.EmailVerified = true
  62. }
  63. // check if user exists
  64. existing := m.GetUserByLoginQuery{LoginOrEmail: form.Email}
  65. if err := bus.Dispatch(&existing); err == nil {
  66. return ApiError(401, "User with same email address already exists", nil)
  67. }
  68. // dispatch create command
  69. if err := bus.Dispatch(&createUserCmd); err != nil {
  70. return ApiError(500, "Failed to create user", err)
  71. }
  72. // publish signup event
  73. user := &createUserCmd.Result
  74. bus.Publish(&events.SignUpCompleted{
  75. Email: user.Email,
  76. Name: user.NameOrFallback(),
  77. })
  78. // mark temp user as completed
  79. if ok, rsp := updateTempUserStatus(form.Code, m.TmpUserCompleted); !ok {
  80. return rsp
  81. }
  82. // check for pending invites
  83. invitesQuery := m.GetTempUsersQuery{Email: form.Email, Status: m.TmpUserInvitePending}
  84. if err := bus.Dispatch(&invitesQuery); err != nil {
  85. return ApiError(500, "Failed to query database for invites", err)
  86. }
  87. apiResponse := util.DynMap{"message": "User sign up completed successfully", "code": "redirect-to-landing-page"}
  88. for _, invite := range invitesQuery.Result {
  89. if ok, rsp := applyUserInvite(user, invite, false); !ok {
  90. return rsp
  91. }
  92. apiResponse["code"] = "redirect-to-select-org"
  93. }
  94. loginUserWithUser(user, c)
  95. metrics.M_Api_User_SignUpCompleted.Inc()
  96. return Json(200, apiResponse)
  97. }
  98. func verifyUserSignUpEmail(email string, code string) (bool, Response) {
  99. query := m.GetTempUserByCodeQuery{Code: code}
  100. if err := bus.Dispatch(&query); err != nil {
  101. if err == m.ErrTempUserNotFound {
  102. return false, ApiError(404, "Invalid email verification code", nil)
  103. }
  104. return false, ApiError(500, "Failed to read temp user", err)
  105. }
  106. tempUser := query.Result
  107. if tempUser.Email != email {
  108. return false, ApiError(404, "Email verification code does not match email", nil)
  109. }
  110. return true, nil
  111. }