diff --git a/CMakeLists.txt b/CMakeLists.txt index 6ba8e16..f9128ee 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -9,7 +9,15 @@ find_package(jwt-cpp REQUIRED) add_executable( auth_service src/auth_service.cpp - src/auth/auth.cpp - src/users/users.cpp + + src/auth/auth.cpp + src/auth/verify_auth.cpp + + src/users/access_request.cpp + src/users/change_password.cpp + src/users/delete_user.cpp + src/users/add_user.cpp + src/users/get_all_users.cpp + src/users/get_user.cpp ) target_link_libraries(auth_service jwt-cpp::jwt-cpp) diff --git a/src/auth/auth.cpp b/src/auth/auth.cpp index 7c37de7..2874ecd 100644 --- a/src/auth/auth.cpp +++ b/src/auth/auth.cpp @@ -35,25 +35,25 @@ void auth(const httplib::Request& request, httplib::Response& response) { response.set_content(response_json.str(), "application/json"); } -// function for verify tokens -bool verify_auth(const std::string token) { - try { - // parse token - const auto decoded = jwt::decode(token); +// // function for verify tokens +// bool verify_auth(const std::string token) { +// try { +// // parse token +// const auto decoded = jwt::decode(token); - // validate token - const auto verifier = jwt::verify() - .allow_algorithm(jwt::algorithm::hs256{JWT_SECRET_KEY}) - .with_issuer("auth0"); +// // validate token +// const auto verifier = jwt::verify() +// .allow_algorithm(jwt::algorithm::hs256{JWT_SECRET_KEY}) +// .with_issuer("auth0"); - verifier.verify(decoded); - return true; - } - catch (const std::system_error& e) { - std::cout << "Verification error: " << e.what() << std::endl; - return false; - } - catch (...) { - return false; - } -} +// verifier.verify(decoded); +// return true; +// } +// catch (const std::system_error& e) { +// std::cout << "Verification error: " << e.what() << std::endl; +// return false; +// } +// catch (...) { +// return false; +// } +// } diff --git a/src/auth/verify_auth.cpp b/src/auth/verify_auth.cpp new file mode 100644 index 0000000..bb35510 --- /dev/null +++ b/src/auth/verify_auth.cpp @@ -0,0 +1,24 @@ +#include "auth.hpp" + +// function for verify tokens +bool verify_auth(const std::string token) { + try { + // parse token + const auto decoded = jwt::decode(token); + + // validate token + const auto verifier = jwt::verify() + .allow_algorithm(jwt::algorithm::hs256{JWT_SECRET_KEY}) + .with_issuer("auth0"); + + verifier.verify(decoded); + return true; + } + catch (const std::system_error& e) { + std::cout << "Verification error: " << e.what() << std::endl; + return false; + } + catch (...) { + return false; + } +} \ No newline at end of file diff --git a/src/auth_service.cpp b/src/auth_service.cpp index 1b67592..6a8bf91 100644 --- a/src/auth_service.cpp +++ b/src/auth_service.cpp @@ -15,7 +15,7 @@ int main() { srv.Post("/api/users/all", get_all_users); srv.Post("/api/users/add", add_user); srv.Post("/api/users/user/password/change", change_password); - srv.Post("/api/users/del", del_user); + srv.Post("/api/users/del", delete_user); srv.Post("/api/access", user_access); srv.set_mount_point("/admin", "../src/web"); diff --git a/src/users/access_request.cpp b/src/users/access_request.cpp new file mode 100644 index 0000000..29a0b90 --- /dev/null +++ b/src/users/access_request.cpp @@ -0,0 +1,11 @@ +#include "users.hpp" + +// function for access or reject authorization +void user_access(const httplib::Request& request, httplib::Response& response) { + if (request.body == "") {response.set_content("{\"required\":\"[token]\"}", "application/json");return;} + nlohmann::json json_body = nlohmann::json::parse(request.body); + + if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token]\"}", "application/json");return;} + if (!verify_auth(json_body["token"])) {response.set_content("{\"access\":\"reject\"}", "application/json");return;} + response.set_content("{\"access\":\"success\"}", "application/json"); +} diff --git a/src/users/add_user.cpp b/src/users/add_user.cpp new file mode 100644 index 0000000..3566e9c --- /dev/null +++ b/src/users/add_user.cpp @@ -0,0 +1,71 @@ +#include "users.hpp" + +#define ALPHABET "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789" + +// function for generate random string +std::string get_random_string(const char *alphabet, int quantity) { + srand(time(NULL)); + std::string str; + for (int i = 0; i < quantity; i++) { + str += alphabet[0 + rand() % strlen(alphabet)]; + } + return str; +} + +// function for add user +void add_user(const httplib::Request& request, httplib::Response& response) { + if (request.body == "") {response.set_content("{\"required\":\"[token,username,password]\",\"optional\":\"[group,is_superuser]\"}", "application/json");return;} + nlohmann::json json_body = nlohmann::json::parse(request.body); + + if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token,username,password]\",\"optional\":\"[group,is_superuser]\"}", "application/json");return;} + if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + if (json_body["username"] == nullptr) {response.set_content("{\"required\":\"[token,username,password]\",\"optional\":\"[group,is_superuser]\"}", "application/json");return;} + if (json_body["password"] == nullptr) {response.set_content("{\"required\":\"[token,username,password]\",\"optional\":\"[group,is_superuser]\"}", "application/json");return;} + + auto decoded_token = jwt::decode(json_body["token"]); + std::string userid = ""; + for (auto& e : decoded_token.get_payload_json()) { + if (e.first == "userId") { + userid = e.second.to_str(); + break; + } + } + if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + + std::ifstream usersfile("users.json"); + nlohmann::json all_users = nlohmann::json::parse(usersfile); + usersfile.close(); + + nlohmann::json response_user_data = nullptr; + for (auto& user : all_users) { + if (user["id"] == userid) { + response_user_data = user; + } + } + if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + + const std::string username = json_body["username"]; + const std::string password = json_body["password"]; + + for (auto& user : all_users) { + if ((user["username"] == username)) { + response.set_content("{\"status\":\"user already exists\"}", "application/json");return; + } + } + + std::stringstream new_user_data; + + new_user_data << "{\"id\":\"" << get_random_string(ALPHABET, 50) << "\",\"username\":\"" << username << "\",\"password\":\"" << password << "\",\"group\":"; + (json_body["group"] != nullptr) ? new_user_data << json_body["group"] : new_user_data << "\"users\""; + new_user_data << ",\"is_superuser\":"; + (json_body["is_superuser"] != nullptr) ? new_user_data << json_body["is_superuser"] : new_user_data << "\"0\""; + new_user_data << "}"; + all_users.push_back(nlohmann::json::parse(new_user_data)); + + std::ofstream usersfilew("users.json"); + usersfilew << all_users.dump(4); + usersfilew.close(); + + response.set_content("{\"status\":\"ok\"}", "application/json"); +} diff --git a/src/users/change_password.cpp b/src/users/change_password.cpp new file mode 100644 index 0000000..82af660 --- /dev/null +++ b/src/users/change_password.cpp @@ -0,0 +1,77 @@ +#include "users.hpp" + +// functtion for change password for user +void change_password(const httplib::Request& request, httplib::Response& response) { + if (request.body == "") {response.set_content( + "{\"required\":\"[token,old_password,new_password] or if you superuser [token,userid,new_password]\"}", + "application/json" + );return;} + nlohmann::json json_body = nlohmann::json::parse(request.body); + + if (json_body["token"] == nullptr) {response.set_content( + "{\"required\":\"[token,old_password,new_password] or if you superuser [token,userid,new_password]\"}", + "application/json" + );return;} + if ((json_body["userid"] == nullptr) && (json_body["old_password"] == nullptr)) { + response.set_content("{\"required\":\"[token,old_password,new_password] or if you superuser [token,userid,new_password]\"}", "application/json"); + return; + } + if (json_body["new_password"] == nullptr) {response.set_content("{\"required\":\"[token] or if you superuser [token,userid]\"}", "application/json");return;} + if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + + std::string old_password = ""; + const std::string new_password = json_body["new_password"]; + + if (json_body["userid"] == nullptr) {old_password = json_body["old_password"];} + + auto decoded_token = jwt::decode(json_body["token"]); + std::string userid = ""; + for (auto& e : decoded_token.get_payload_json()) { + if (e.first == "userId") { + userid = e.second.to_str(); + break; + } + } + if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + + std::ifstream usersfile("users.json"); + nlohmann::json all_users = nlohmann::json::parse(usersfile); + usersfile.close(); + + std::string changepassuserid = userid; + if (json_body["userid"] != nullptr) { + changepassuserid = json_body["userid"]; + nlohmann::json response_user_data = nullptr; + for (auto& user : all_users) { + if (user["id"] == userid) { + response_user_data = user; + } + } + if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + } + + bool found = false; + if (json_body["userid"] != nullptr) { + for (int i = 0; i < all_users.size(); i++) { + if ((all_users[i]["id"] == changepassuserid)) { + all_users[i]["password"] = new_password; + found = true; + break; + } + } + } else { + for (int i = 0; i < all_users.size(); i++) { + if ((all_users[i]["id"] == changepassuserid) && (all_users[i]["password"] == old_password)) { + all_users[i]["password"] = new_password; + found = true; + break; + } + } + } + if (!found) {response.set_content("{\"status\":\"can't find this user\"}", "application/json");return;} + std::ofstream usersfilew("users.json"); + usersfilew << all_users.dump(4); + usersfilew.close(); + response.set_content("{\"status\":\"ok\"}", "application/json"); +} diff --git a/src/users/delete_user.cpp b/src/users/delete_user.cpp new file mode 100644 index 0000000..83ff2d3 --- /dev/null +++ b/src/users/delete_user.cpp @@ -0,0 +1,51 @@ +#include "users.hpp" + +// function for delete user +void delete_user(const httplib::Request& request, httplib::Response& response) { + if (request.body == "") {response.set_content("{\"required\":\"[token] or if you superuser [token,userid]\"}", "application/json");return;} + nlohmann::json json_body = nlohmann::json::parse(request.body); + + if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token] or if you superuser [token,userid]\"}", "application/json");return;} + if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + + auto decoded_token = jwt::decode(json_body["token"]); + std::string userid = ""; + for (auto& e : decoded_token.get_payload_json()) { + if (e.first == "userId") { + userid = e.second.to_str(); + break; + } + } + if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + + std::ifstream usersfile("users.json"); + nlohmann::json all_users = nlohmann::json::parse(usersfile); + usersfile.close(); + + std::string deluserid = userid; + if (json_body["userid"] != nullptr) { + deluserid = json_body["userid"]; + nlohmann::json response_user_data = nullptr; + for (auto& user : all_users) { + if (user["id"] == userid) { + response_user_data = user; + } + } + if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + } + + bool found = false; + for (int i = 0; i < all_users.size(); i++) { + if (all_users[i]["id"] == deluserid) { + all_users.erase(i); + found = true; + break; + } + } + if (!found) {response.set_content("{\"status\":\"can't find this user\"}", "application/json");return;} + std::ofstream usersfilew("users.json"); + usersfilew << all_users.dump(4); + usersfilew.close(); + response.set_content("{\"status\":\"ok\"}", "application/json"); +} diff --git a/src/users/get_all_users.cpp b/src/users/get_all_users.cpp new file mode 100644 index 0000000..cbf4391 --- /dev/null +++ b/src/users/get_all_users.cpp @@ -0,0 +1,32 @@ +#include "users.hpp" + +// function for get all users data without password +void get_all_users(const httplib::Request& request, httplib::Response& response) { + if (request.body == "") {response.set_content("{\"required\":\"[token]\"}", "application/json");return;} + nlohmann::json json_body = nlohmann::json::parse(request.body); + + if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token]\"}", "application/json");return;} + if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + auto decoded_token = jwt::decode(json_body["token"]); + std::string userid = ""; + for (auto& e : decoded_token.get_payload_json()) { + if (e.first == "userId") { + userid = e.second.to_str(); + break; + } + } + if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + std::ifstream usersfile("users.json"); + nlohmann::json all_users = nlohmann::json::parse(usersfile); + usersfile.close(); + nlohmann::json response_user_data = nullptr; + for (auto& user : all_users) { + if (user["id"] == userid) { + response_user_data = user; + } + user.erase("password"); + } + if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + response.set_content(all_users.dump(), "application/json"); +} diff --git a/src/users/get_user.cpp b/src/users/get_user.cpp new file mode 100644 index 0000000..cc086e3 --- /dev/null +++ b/src/users/get_user.cpp @@ -0,0 +1,32 @@ +#include "users.hpp" + +// function for get user data without password +void get_user(const httplib::Request& request, httplib::Response& response) { + if (request.body == "") {response.set_content("{\"required\":\"[token]\"}", "application/json");return;} + nlohmann::json json_body = nlohmann::json::parse(request.body); + + if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token]\"}", "application/json");return;} + if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + auto decoded_token = jwt::decode(json_body["token"]); + std::string userid = ""; + for (auto& e : decoded_token.get_payload_json()) { + if (e.first == "userId") { + userid = e.second.to_str(); + break; + } + } + if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + std::ifstream usersfile("users.json"); + nlohmann::json all_users = nlohmann::json::parse(usersfile); + usersfile.close(); + nlohmann::json response_user_data = nullptr; + for (auto& user : all_users) { + if (user["id"] == userid) { + response_user_data = user; + break; + } + } + if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + response_user_data.erase("password"); + response.set_content(response_user_data.dump(), "application/json"); +} diff --git a/src/users/users.cpp b/src/users/users.cpp deleted file mode 100644 index bb1b794..0000000 --- a/src/users/users.cpp +++ /dev/null @@ -1,268 +0,0 @@ -#include "users.hpp" -#include "sstream" - -#define ALPHABET "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789" - -std::string get_random_string(const char *alphabet, int quantity) { - srand(time(NULL)); - std::string str; - for (int i = 0; i < quantity; i++) { - str += alphabet[0 + rand() % strlen(alphabet)]; - } - return str; -} - -// function for get user data without password -void get_user(const httplib::Request& request, httplib::Response& response) { - if (request.body == "") {response.set_content("{\"required\":\"[token]\"}", "application/json");return;} - nlohmann::json json_body = nlohmann::json::parse(request.body); - - if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token]\"}", "application/json");return;} - if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;} - auto decoded_token = jwt::decode(json_body["token"]); - std::string userid = ""; - for (auto& e : decoded_token.get_payload_json()) { - if (e.first == "userId") { - userid = e.second.to_str(); - break; - } - } - if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} - std::ifstream usersfile("users.json"); - nlohmann::json all_users = nlohmann::json::parse(usersfile); - usersfile.close(); - nlohmann::json response_user_data = nullptr; - for (auto& user : all_users) { - if (user["id"] == userid) { - response_user_data = user; - break; - } - } - if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;} - response_user_data.erase("password"); - response.set_content(response_user_data.dump(), "application/json"); -} - -// function for get all users data without password -void get_all_users(const httplib::Request& request, httplib::Response& response) { - if (request.body == "") {response.set_content("{\"required\":\"[token]\"}", "application/json");return;} - nlohmann::json json_body = nlohmann::json::parse(request.body); - - if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token]\"}", "application/json");return;} - if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;} - auto decoded_token = jwt::decode(json_body["token"]); - std::string userid = ""; - for (auto& e : decoded_token.get_payload_json()) { - if (e.first == "userId") { - userid = e.second.to_str(); - break; - } - } - if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} - std::ifstream usersfile("users.json"); - nlohmann::json all_users = nlohmann::json::parse(usersfile); - usersfile.close(); - nlohmann::json response_user_data = nullptr; - for (auto& user : all_users) { - if (user["id"] == userid) { - response_user_data = user; - } - user.erase("password"); - } - if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;} - if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;} - response.set_content(all_users.dump(), "application/json"); -} - -// function for add user -void add_user(const httplib::Request& request, httplib::Response& response) { - if (request.body == "") {response.set_content("{\"required\":\"[token,username,password]\",\"optional\":\"[group,is_superuser]\"}", "application/json");return;} - nlohmann::json json_body = nlohmann::json::parse(request.body); - - if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token,username,password]\",\"optional\":\"[group,is_superuser]\"}", "application/json");return;} - if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;} - if (json_body["username"] == nullptr) {response.set_content("{\"required\":\"[token,username,password]\",\"optional\":\"[group,is_superuser]\"}", "application/json");return;} - if (json_body["password"] == nullptr) {response.set_content("{\"required\":\"[token,username,password]\",\"optional\":\"[group,is_superuser]\"}", "application/json");return;} - - auto decoded_token = jwt::decode(json_body["token"]); - std::string userid = ""; - for (auto& e : decoded_token.get_payload_json()) { - if (e.first == "userId") { - userid = e.second.to_str(); - break; - } - } - if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} - - std::ifstream usersfile("users.json"); - nlohmann::json all_users = nlohmann::json::parse(usersfile); - usersfile.close(); - - nlohmann::json response_user_data = nullptr; - for (auto& user : all_users) { - if (user["id"] == userid) { - response_user_data = user; - } - } - if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;} - if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;} - - const std::string username = json_body["username"]; - const std::string password = json_body["password"]; - - for (auto& user : all_users) { - if ((user["username"] == username)) { - response.set_content("{\"status\":\"user already exists\"}", "application/json");return; - } - } - - std::stringstream new_user_data; - - new_user_data << "{\"id\":\"" << get_random_string(ALPHABET, 50) << "\",\"username\":\"" << username << "\",\"password\":\"" << password << "\",\"group\":"; - (json_body["group"] != nullptr) ? new_user_data << json_body["group"] : new_user_data << "\"users\""; - new_user_data << ",\"is_superuser\":"; - (json_body["is_superuser"] != nullptr) ? new_user_data << json_body["is_superuser"] : new_user_data << "\"0\""; - new_user_data << "}"; - all_users.push_back(nlohmann::json::parse(new_user_data)); - - std::ofstream usersfilew("users.json"); - usersfilew << all_users.dump(4); - usersfilew.close(); - - response.set_content("{\"status\":\"ok\"}", "application/json"); -} - -void del_user(const httplib::Request& request, httplib::Response& response) { - if (request.body == "") {response.set_content("{\"required\":\"[token] or if you superuser [token,userid]\"}", "application/json");return;} - nlohmann::json json_body = nlohmann::json::parse(request.body); - - if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token] or if you superuser [token,userid]\"}", "application/json");return;} - if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;} - - auto decoded_token = jwt::decode(json_body["token"]); - std::string userid = ""; - for (auto& e : decoded_token.get_payload_json()) { - if (e.first == "userId") { - userid = e.second.to_str(); - break; - } - } - if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} - - std::ifstream usersfile("users.json"); - nlohmann::json all_users = nlohmann::json::parse(usersfile); - usersfile.close(); - - std::string deluserid = userid; - if (json_body["userid"] != nullptr) { - deluserid = json_body["userid"]; - nlohmann::json response_user_data = nullptr; - for (auto& user : all_users) { - if (user["id"] == userid) { - response_user_data = user; - } - } - if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;} - if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;} - } - - bool found = false; - for (int i = 0; i < all_users.size(); i++) { - if (all_users[i]["id"] == deluserid) { - all_users.erase(i); - found = true; - break; - } - } - if (!found) {response.set_content("{\"status\":\"can't find this user\"}", "application/json");return;} - std::ofstream usersfilew("users.json"); - usersfilew << all_users.dump(4); - usersfilew.close(); - response.set_content("{\"status\":\"ok\"}", "application/json"); -} - -// functtion for change password for user -void change_password(const httplib::Request& request, httplib::Response& response) { - if (request.body == "") {response.set_content( - "{\"required\":\"[token,old_password,new_password] or if you superuser [token,userid,new_password]\"}", - "application/json" - );return;} - nlohmann::json json_body = nlohmann::json::parse(request.body); - - if (json_body["token"] == nullptr) {response.set_content( - "{\"required\":\"[token,old_password,new_password] or if you superuser [token,userid,new_password]\"}", - "application/json" - );return;} - if ((json_body["userid"] == nullptr) && (json_body["old_password"] == nullptr)) { - response.set_content("{\"required\":\"[token,old_password,new_password] or if you superuser [token,userid,new_password]\"}", "application/json"); - return; - } - if (json_body["new_password"] == nullptr) {response.set_content("{\"required\":\"[token] or if you superuser [token,userid]\"}", "application/json");return;} - if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;} - - std::string old_password = ""; - const std::string new_password = json_body["new_password"]; - - if (json_body["userid"] == nullptr) {old_password = json_body["old_password"];} - - auto decoded_token = jwt::decode(json_body["token"]); - std::string userid = ""; - for (auto& e : decoded_token.get_payload_json()) { - if (e.first == "userId") { - userid = e.second.to_str(); - break; - } - } - if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} - - std::ifstream usersfile("users.json"); - nlohmann::json all_users = nlohmann::json::parse(usersfile); - usersfile.close(); - - std::string changepassuserid = userid; - if (json_body["userid"] != nullptr) { - changepassuserid = json_body["userid"]; - nlohmann::json response_user_data = nullptr; - for (auto& user : all_users) { - if (user["id"] == userid) { - response_user_data = user; - } - } - if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;} - if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;} - } - - bool found = false; - if (json_body["userid"] != nullptr) { - for (int i = 0; i < all_users.size(); i++) { - if ((all_users[i]["id"] == changepassuserid)) { - all_users[i]["password"] = new_password; - found = true; - break; - } - } - } else { - for (int i = 0; i < all_users.size(); i++) { - if ((all_users[i]["id"] == changepassuserid) && (all_users[i]["password"] == old_password)) { - all_users[i]["password"] = new_password; - found = true; - break; - } - } - } - if (!found) {response.set_content("{\"status\":\"can't find this user\"}", "application/json");return;} - std::ofstream usersfilew("users.json"); - usersfilew << all_users.dump(4); - usersfilew.close(); - response.set_content("{\"status\":\"ok\"}", "application/json"); -} - -// function for access or reject authorization -void user_access(const httplib::Request& request, httplib::Response& response) { - if (request.body == "") {response.set_content("{\"required\":\"[token]\"}", "application/json");return;} - nlohmann::json json_body = nlohmann::json::parse(request.body); - - if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token]\"}", "application/json");return;} - if (!verify_auth(json_body["token"])) {response.set_content("{\"access\":\"reject\"}", "application/json");return;} - response.set_content("{\"access\":\"success\"}", "application/json"); -} diff --git a/src/users/users.hpp b/src/users/users.hpp index 532d813..1affb00 100644 --- a/src/users/users.hpp +++ b/src/users/users.hpp @@ -13,8 +13,8 @@ void get_all_users(const httplib::Request& request, httplib::Response& response) void user_access(const httplib::Request& request, httplib::Response& response); // function for add user void add_user(const httplib::Request& request, httplib::Response& response); -// function for del user -void del_user(const httplib::Request& request, httplib::Response& response); +// function for delete user +void delete_user(const httplib::Request& request, httplib::Response& response); // function for change password for user void change_password(const httplib::Request& request, httplib::Response& response);