refactor and review
This commit is contained in:
+29
-16
@@ -1,15 +1,26 @@
|
||||
#include "auth.hpp"
|
||||
#include "../colors.h"
|
||||
#include "../includes.hpp"
|
||||
#include <jwt-cpp/jwt.h>
|
||||
|
||||
// function for authorization users
|
||||
void auth(const httplib::Request& request, httplib::Response& response) {
|
||||
void auth(const httplib::Request &request, httplib::Response &response) {
|
||||
std::cout << GREEN << request.path << RESET << " " << request.method << std::endl;
|
||||
response.set_header("Access-Control-Allow-Origin", "*");
|
||||
if (request.body == "") {response.set_content("{\"required\":\"[username,password]\"}", "application/json");return;}
|
||||
if (request.body.empty()) {
|
||||
response.set_content(AUTH_REQUIRED_STRING, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
nlohmann::json json_body = nlohmann::json::parse(request.body);
|
||||
|
||||
if (json_body["username"] == nullptr) {response.set_content("{\"required\":\"[username,password]\"}", "application/json");return;}
|
||||
if (json_body["password"] == nullptr) {response.set_content("{\"required\":\"[username,password]\"}", "application/json");return;}
|
||||
if (json_body["username"] == nullptr) {
|
||||
response.set_content(AUTH_REQUIRED_STRING, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (json_body["password"] == nullptr) {
|
||||
response.set_content(AUTH_REQUIRED_STRING, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
const std::string request_username = json_body["username"];
|
||||
const std::string request_password = json_body["password"];
|
||||
|
||||
@@ -17,23 +28,25 @@ void auth(const httplib::Request& request, httplib::Response& response) {
|
||||
nlohmann::json all_users = nlohmann::json::parse(usersfile);
|
||||
usersfile.close();
|
||||
|
||||
std::string userid = "";
|
||||
for (int i = 0; i < all_users.size(); i++) {
|
||||
if ((all_users[i]["username"] == request_username) && (all_users[i]["password"] == request_password)) {
|
||||
userid = all_users[i]["id"];
|
||||
std::string userid;
|
||||
for (nlohmann::basic_json<> user: all_users) {
|
||||
if ((user["username"] == request_username) && (user["password"] == request_password)) {
|
||||
userid = user["id"];
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (userid.empty()) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
|
||||
std::string token = jwt::create()
|
||||
.set_type("JWT")
|
||||
.set_issuer("auth0")
|
||||
.set_payload_claim("userId", jwt::claim(userid))
|
||||
.sign(jwt::algorithm::hs256{JWT_SECRET_KEY});
|
||||
.set_type("JWT")
|
||||
.set_issuer("auth0")
|
||||
.set_payload_claim("userId", jwt::claim(userid))
|
||||
.sign(jwt::algorithm::hs256{JWT_SECRET_KEY});
|
||||
|
||||
std::stringstream response_json;
|
||||
response_json << "{\"token\":\"" << token << "\"}";
|
||||
response.set_content(response_json.str(), "application/json");
|
||||
response_json << R"({"token":")" << token << "\"}";
|
||||
response.set_content(response_json.str(), JSON_TYPE);
|
||||
}
|
||||
|
||||
+3
-7
@@ -2,16 +2,12 @@
|
||||
#define AUTH_HPP
|
||||
|
||||
#include <httplib.h>
|
||||
#include <jwt-cpp/jwt.h>
|
||||
#include <json.hpp>
|
||||
#include <string>
|
||||
#include <fstream>
|
||||
#include "../includes.hpp"
|
||||
#include <sstream>
|
||||
|
||||
// function for authorization users
|
||||
void auth(const httplib::Request& request, httplib::Response& response);
|
||||
void auth(const httplib::Request &request, httplib::Response &response);
|
||||
|
||||
// function for verify tokens
|
||||
bool verify_auth(const std::string token);
|
||||
bool verify_auth(const std::string &token);
|
||||
|
||||
#endif // AUTH_HPP
|
||||
|
||||
@@ -1,24 +1,25 @@
|
||||
#include "auth.hpp"
|
||||
#include <jwt-cpp/jwt.h>
|
||||
#include "../includes.hpp"
|
||||
|
||||
// function for verify tokens
|
||||
bool verify_auth(const std::string token) {
|
||||
bool verify_auth(const std::string &token) {
|
||||
try {
|
||||
// parse token
|
||||
const jwt::decoded_jwt<jwt::traits::kazuho_picojson> decoded = jwt::decode(token);
|
||||
|
||||
// validate token
|
||||
const jwt::verifier<jwt::default_clock, jwt::traits::kazuho_picojson> verifier = jwt::verify()
|
||||
.allow_algorithm(jwt::algorithm::hs256{JWT_SECRET_KEY})
|
||||
.with_issuer("auth0");
|
||||
.allow_algorithm(jwt::algorithm::hs256{JWT_SECRET_KEY})
|
||||
.with_issuer("auth0");
|
||||
|
||||
verifier.verify(decoded);
|
||||
return true;
|
||||
}
|
||||
catch (const std::system_error& e) {
|
||||
} catch (const std::system_error &e) {
|
||||
std::cout << "Verification error: " << e.what() << std::endl;
|
||||
return false;
|
||||
}
|
||||
catch (...) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,9 +1,6 @@
|
||||
#include <iostream>
|
||||
#include <fstream>
|
||||
#include <httplib.h>
|
||||
#include <json.hpp>
|
||||
#include <jwt-cpp/jwt.h>
|
||||
|
||||
#include "auth/auth.hpp"
|
||||
#include "users/users.hpp"
|
||||
#include "colors.h"
|
||||
@@ -29,9 +26,9 @@ int main() {
|
||||
srv.set_mount_point("/admin", "../src/web");
|
||||
srv.set_mount_point("/js", "../src/web/js");
|
||||
srv.set_mount_point("/css", "../src/web/css");
|
||||
|
||||
std::cout << GREEN << "Starting" << RESET << " server on [ " << YELLOW \
|
||||
<< "localhost" << RESET << ":" << CYAN << "43243" << RESET << " ]" << std::endl;
|
||||
|
||||
std::cout << GREEN << "Starting" << RESET << " server on [ " << YELLOW
|
||||
<< "localhost" << RESET << ":" << CYAN << "43243" << RESET << " ]" << std::endl;
|
||||
srv.listen("localhost", 43243);
|
||||
return 0;
|
||||
}
|
||||
|
||||
+1
-1
@@ -74,4 +74,4 @@
|
||||
#define ON_ICYAN "\033[0;106m" // CYAN
|
||||
#define ON_IWHITE "\033[0;107m" // WHITE
|
||||
|
||||
#endif // C_COLORS_H
|
||||
#endif // C_COLORS_H
|
||||
|
||||
+9
-1
@@ -2,5 +2,13 @@
|
||||
#define INCLUDES_HPP
|
||||
|
||||
#define JWT_SECRET_KEY "secret"
|
||||
#define STRING403 R"({"status":"403"})"
|
||||
#define JSON_TYPE "application/json"
|
||||
#define AUTH_REQUIRED_STRING R"({"required":"[username,password]"})"
|
||||
#define ACCESS_REQUIRED_STRING R"({"required":"[token]"})"
|
||||
#define ADD_USER_REQUIRED_STRING R"({"required":"[token,username,password]","optional":"[group,is_superuser]"})"
|
||||
#define CHANGE_PASSWORD_REQUIRED_STRING R"({"required":"[token,old_password,new_password] or if you superuser [token,userid,new_password]"})"
|
||||
#define CHANGE_USER_REQUIRED_STRING R"({"required":"[token] or if you superuser [token,userid]","optional":"[username,password,is_superuser,group]"})"
|
||||
#define DELETE_USER_REQUIRED_STRING R"({"required":"[token] or if you superuser [token,userid]"})"
|
||||
|
||||
#endif // INCLUDES_HPP
|
||||
#endif // INCLUDES_HPP
|
||||
|
||||
@@ -1,10 +1,9 @@
|
||||
#include "cors.hpp"
|
||||
#include "../colors.h"
|
||||
|
||||
void set_cors_headers(const httplib::Request& request, httplib::Response& response) {
|
||||
void set_cors_headers(const httplib::Request &request, httplib::Response &response) {
|
||||
std::cout << GREEN << request.path << " " << std::endl;
|
||||
response.set_header("Access-Control-Allow-Origin", "*");
|
||||
response.set_header("Access-Control-Allow-Methods", "GET,POST,OPTIONS");
|
||||
response.set_header("Access-Control-Allow-Headers", "Authorization,X-Custom,Content-Type");
|
||||
}
|
||||
|
||||
|
||||
@@ -5,9 +5,9 @@
|
||||
|
||||
#ifdef CORS_ENABLE
|
||||
|
||||
// function to set cors headers
|
||||
void set_cors_headers(const httplib::Request& request, httplib::Response& response);
|
||||
|
||||
#endif // CORS_ENABLE
|
||||
|
||||
#endif // CORS_HPP
|
||||
|
||||
|
||||
@@ -1,14 +1,25 @@
|
||||
#include "users.hpp"
|
||||
#include "../colors.h"
|
||||
#include "../includes.hpp"
|
||||
#include "../auth/auth.hpp"
|
||||
|
||||
// function for access or reject authorization
|
||||
void user_access(const httplib::Request& request, httplib::Response& response) {
|
||||
void user_access(const httplib::Request &request, httplib::Response &response) {
|
||||
std::cout << GREEN << request.path << RESET << " " << request.method << std::endl;
|
||||
response.set_header("Access-Control-Allow-Origin", "*");
|
||||
if (request.body == "") {response.set_content("{\"required\":\"[token]\"}", "application/json");return;}
|
||||
if (request.body.empty()) {
|
||||
response.set_content(ACCESS_REQUIRED_STRING, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
nlohmann::json json_body = nlohmann::json::parse(request.body);
|
||||
|
||||
if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token]\"}", "application/json");return;}
|
||||
if (!verify_auth(json_body["token"])) {response.set_content("{\"access\":\"reject\"}", "application/json");return;}
|
||||
response.set_content("{\"access\":\"success\"}", "application/json");
|
||||
if (json_body["token"] == nullptr) {
|
||||
response.set_content(ACCESS_REQUIRED_STRING, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (!verify_auth(json_body["token"])) {
|
||||
response.set_content(R"({"access":"reject"})", JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
response.set_content(R"({"access":"success"})", JSON_TYPE);
|
||||
}
|
||||
|
||||
+52
-19
@@ -1,68 +1,101 @@
|
||||
#include "users.hpp"
|
||||
#include "../colors.h"
|
||||
#include "../includes.hpp"
|
||||
#include "../auth/auth.hpp"
|
||||
#include <jwt-cpp/jwt.h>
|
||||
|
||||
#define ALPHABET "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789"
|
||||
|
||||
// function for generate random string
|
||||
std::string get_random_string(const char *alphabet, int quantity) {
|
||||
srand(time(NULL));
|
||||
srand(time(nullptr));
|
||||
std::string str;
|
||||
for (int i = 0; i < quantity; i++) {
|
||||
str += alphabet[0 + rand() % strlen(alphabet)];
|
||||
str += alphabet[0 + std::rand() % strlen(alphabet)];
|
||||
}
|
||||
return str;
|
||||
}
|
||||
|
||||
// function for add user
|
||||
void add_user(const httplib::Request& request, httplib::Response& response) {
|
||||
void add_user(const httplib::Request &request, httplib::Response &response) {
|
||||
std::cout << GREEN << request.path << RESET << " " << request.method << std::endl;
|
||||
response.set_header("Access-Control-Allow-Origin", "*");
|
||||
if (request.body == "") {response.set_content("{\"required\":\"[token,username,password]\",\"optional\":\"[group,is_superuser]\"}", "application/json");return;}
|
||||
if (request.body.empty()) {
|
||||
response.set_content(ADD_USER_REQUIRED_STRING,
|
||||
JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
nlohmann::json json_body = nlohmann::json::parse(request.body);
|
||||
|
||||
if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token,username,password]\",\"optional\":\"[group,is_superuser]\"}", "application/json");return;}
|
||||
if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (json_body["username"] == nullptr) {response.set_content("{\"required\":\"[token,username,password]\",\"optional\":\"[group,is_superuser]\"}", "application/json");return;}
|
||||
if (json_body["password"] == nullptr) {response.set_content("{\"required\":\"[token,username,password]\",\"optional\":\"[group,is_superuser]\"}", "application/json");return;}
|
||||
if (json_body["token"] == nullptr) {
|
||||
response.set_content(ADD_USER_REQUIRED_STRING,
|
||||
JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (!verify_auth(json_body["token"])) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (json_body["username"] == nullptr) {
|
||||
response.set_content(ADD_USER_REQUIRED_STRING,
|
||||
JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (json_body["password"] == nullptr) {
|
||||
response.set_content(ADD_USER_REQUIRED_STRING,
|
||||
JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
|
||||
jwt::decoded_jwt<jwt::traits::kazuho_picojson> decoded_token = jwt::decode(json_body["token"]);
|
||||
std::string userid = "";
|
||||
for (auto& e : decoded_token.get_payload_json()) {
|
||||
std::string userid;
|
||||
for (std::pair<const std::string, picojson::value> &e: decoded_token.get_payload_json()) {
|
||||
if (e.first == "userId") {
|
||||
userid = e.second.to_str();
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (userid.empty()) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
|
||||
std::ifstream usersfile("users.json");
|
||||
nlohmann::json all_users = nlohmann::json::parse(usersfile);
|
||||
usersfile.close();
|
||||
|
||||
nlohmann::json response_user_data = nullptr;
|
||||
for (nlohmann::json& user : all_users) {
|
||||
for (nlohmann::json &user: all_users) {
|
||||
if (user["id"] == userid) {
|
||||
response_user_data = user;
|
||||
}
|
||||
}
|
||||
if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (response_user_data == nullptr) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (response_user_data["is_superuser"] != "1") {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
|
||||
const std::string username = json_body["username"];
|
||||
const std::string password = json_body["password"];
|
||||
|
||||
for (nlohmann::json user : all_users) {
|
||||
for (nlohmann::json user: all_users) {
|
||||
if ((user["username"] == username)) {
|
||||
response.set_content("{\"status\":\"user already exists\"}", "application/json");return;
|
||||
response.set_content(R"({"status":"user already exists"})", JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
std::stringstream new_user_data;
|
||||
|
||||
new_user_data << "{\"id\":\"" << get_random_string(ALPHABET, 50) << "\",\"username\":\"" << username << "\",\"password\":\"" << password << "\",\"group\":";
|
||||
new_user_data << R"({"id":")" << get_random_string(ALPHABET, 50) << R"(","username":")"
|
||||
<< username << R"(","password":")" << password << R"(","group":)";
|
||||
(json_body["group"] != nullptr) ? new_user_data << json_body["group"] : new_user_data << "\"users\"";
|
||||
new_user_data << ",\"is_superuser\":";
|
||||
(json_body["is_superuser"] != nullptr) ? new_user_data << json_body["is_superuser"] : new_user_data << "\"0\"";
|
||||
(json_body["is_superuser"] != nullptr) ? new_user_data << json_body["is_superuser"] : new_user_data << "\"0\"";
|
||||
new_user_data << "}";
|
||||
all_users.push_back(nlohmann::json::parse(new_user_data));
|
||||
|
||||
@@ -70,5 +103,5 @@ void add_user(const httplib::Request& request, httplib::Response& response) {
|
||||
usersfilew << all_users.dump(4);
|
||||
usersfilew.close();
|
||||
|
||||
response.set_content("{\"status\":\"ok\"}", "application/json");
|
||||
response.set_content(R"({"status":"ok"})", JSON_TYPE);
|
||||
}
|
||||
|
||||
@@ -1,41 +1,62 @@
|
||||
#include "users.hpp"
|
||||
#include "../colors.h"
|
||||
#include "../includes.hpp"
|
||||
#include "../auth/auth.hpp"
|
||||
#include <jwt-cpp/jwt.h>
|
||||
|
||||
// functtion for change password for user
|
||||
void change_password(const httplib::Request& request, httplib::Response& response) {
|
||||
void change_password(const httplib::Request &request, httplib::Response &response) {
|
||||
std::cout << GREEN << request.path << RESET << " " << request.method << std::endl;
|
||||
response.set_header("Access-Control-Allow-Origin", "*");
|
||||
if (request.body == "") {response.set_content(
|
||||
"{\"required\":\"[token,old_password,new_password] or if you superuser [token,userid,new_password]\"}",
|
||||
"application/json"
|
||||
);return;}
|
||||
nlohmann::json json_body = nlohmann::json::parse(request.body);
|
||||
|
||||
if (json_body["token"] == nullptr) {response.set_content(
|
||||
"{\"required\":\"[token,old_password,new_password] or if you superuser [token,userid,new_password]\"}",
|
||||
"application/json"
|
||||
);return;}
|
||||
if ((json_body["userid"] == nullptr) && (json_body["old_password"] == nullptr)) {
|
||||
response.set_content("{\"required\":\"[token,old_password,new_password] or if you superuser [token,userid,new_password]\"}", "application/json");
|
||||
if (request.body.empty()) {
|
||||
response.set_content(
|
||||
CHANGE_PASSWORD_REQUIRED_STRING,
|
||||
JSON_TYPE
|
||||
);
|
||||
return;
|
||||
}
|
||||
if (json_body["new_password"] == nullptr) {response.set_content("{\"required\":\"[token] or if you superuser [token,userid]\"}", "application/json");return;}
|
||||
if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
nlohmann::json json_body = nlohmann::json::parse(request.body);
|
||||
|
||||
std::string old_password = "";
|
||||
if (json_body["token"] == nullptr) {
|
||||
response.set_content(
|
||||
CHANGE_PASSWORD_REQUIRED_STRING,
|
||||
JSON_TYPE
|
||||
);
|
||||
return;
|
||||
}
|
||||
if ((json_body["userid"] == nullptr) && (json_body["old_password"] == nullptr)) {
|
||||
response.set_content(
|
||||
CHANGE_PASSWORD_REQUIRED_STRING,
|
||||
JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (json_body["new_password"] == nullptr) {
|
||||
response.set_content(R"({"required":"[token] or if you superuser [token,userid]"})",
|
||||
JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (!verify_auth(json_body["token"])) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
|
||||
std::string old_password;
|
||||
const std::string new_password = json_body["new_password"];
|
||||
|
||||
if (json_body["userid"] == nullptr) {old_password = json_body["old_password"];}
|
||||
if (json_body["userid"] == nullptr) { old_password = json_body["old_password"]; }
|
||||
|
||||
jwt::decoded_jwt<jwt::traits::kazuho_picojson> decoded_token = jwt::decode(json_body["token"]);
|
||||
std::string userid = "";
|
||||
for (auto& e : decoded_token.get_payload_json()) {
|
||||
std::string userid;
|
||||
for (std::pair<const std::string, picojson::value> &e: decoded_token.get_payload_json()) {
|
||||
if (e.first == "userId") {
|
||||
userid = e.second.to_str();
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (userid.empty()) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
|
||||
std::ifstream usersfile("users.json");
|
||||
nlohmann::json all_users = nlohmann::json::parse(usersfile);
|
||||
@@ -45,36 +66,45 @@ void change_password(const httplib::Request& request, httplib::Response& respons
|
||||
if (json_body["userid"] != nullptr) {
|
||||
changepassuserid = json_body["userid"];
|
||||
nlohmann::json response_user_data = nullptr;
|
||||
for (nlohmann::json& user : all_users) {
|
||||
for (nlohmann::json &user: all_users) {
|
||||
if (user["id"] == userid) {
|
||||
response_user_data = user;
|
||||
}
|
||||
}
|
||||
if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (response_user_data == nullptr) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (response_user_data["is_superuser"] != "1") {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
bool found = false;
|
||||
if (json_body["userid"] != nullptr) {
|
||||
for (int i = 0; i < all_users.size(); i++) {
|
||||
if ((all_users[i]["id"] == changepassuserid)) {
|
||||
all_users[i]["password"] = new_password;
|
||||
for (nlohmann::basic_json<> &all_user: all_users) {
|
||||
if ((all_user["id"] == changepassuserid)) {
|
||||
all_user["password"] = new_password;
|
||||
found = true;
|
||||
break;
|
||||
}
|
||||
}
|
||||
} else {
|
||||
for (int i = 0; i < all_users.size(); i++) {
|
||||
if ((all_users[i]["id"] == changepassuserid) && (all_users[i]["password"] == old_password)) {
|
||||
all_users[i]["password"] = new_password;
|
||||
for (nlohmann::basic_json<> &all_user: all_users) {
|
||||
if ((all_user["id"] == changepassuserid) && (all_user["password"] == old_password)) {
|
||||
all_user["password"] = new_password;
|
||||
found = true;
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
if (!found) {response.set_content("{\"status\":\"can't find this user\"}", "application/json");return;}
|
||||
if (!found) {
|
||||
response.set_content(R"({"status":"can't find this user"})", JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
std::ofstream usersfilew("users.json");
|
||||
usersfilew << all_users.dump(4);
|
||||
usersfilew.close();
|
||||
response.set_content("{\"status\":\"ok\"}", "application/json");
|
||||
response.set_content(R"({"status":"ok"})", JSON_TYPE);
|
||||
}
|
||||
|
||||
+55
-37
@@ -1,41 +1,51 @@
|
||||
#include "users.hpp"
|
||||
#include "../colors.h"
|
||||
#include "../includes.hpp"
|
||||
#include "../auth/auth.hpp"
|
||||
#include <jwt-cpp/jwt.h>
|
||||
|
||||
// function for change user data
|
||||
void change_user(const httplib::Request& request, httplib::Response& response) {
|
||||
void change_user(const httplib::Request &request, httplib::Response &response) {
|
||||
std::cout << GREEN << request.path << RESET << " " << request.method << std::endl;
|
||||
response.set_header("Access-Control-Allow-Origin", "*");
|
||||
if (request.body == "") {response.set_content(
|
||||
"{\"required\":\"[token] or if you superuser [token,userid]\",\"optional\":\"[username,password,is_superuser,group]\"}",
|
||||
"application/json"
|
||||
);return;}
|
||||
nlohmann::json json_body = nlohmann::json::parse(request.body);
|
||||
|
||||
if (json_body["token"] == nullptr) {response.set_content(
|
||||
"{\"required\":\"[token] or if you superuser [token,userid]\",\"optional\":\"[username,password,is_superuser,group]\"}",
|
||||
"application/json"
|
||||
);return;}
|
||||
if ((json_body["userid"] == nullptr) && (json_body["old_password"] == nullptr)) {
|
||||
response.set_content("{\"required\":\"[token] or if you superuser [token,userid]\",\"optional\":\"[username,password,is_superuser,group]\"}", "application/json");
|
||||
if (request.body.empty()) {
|
||||
response.set_content(
|
||||
CHANGE_USER_REQUIRED_STRING,
|
||||
JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
// if (json_body["new_password"] == nullptr) {response.set_content("{\"required\":\"[token] or if you superuser [token,userid]\"}", "application/json");return;}
|
||||
if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
nlohmann::json json_body = nlohmann::json::parse(request.body);
|
||||
|
||||
// std::string old_password = "";
|
||||
// const std::string new_password = json_body["new_password"];
|
||||
|
||||
// if (json_body["userid"] == nullptr) {old_password = json_body["old_password"];}
|
||||
if (json_body["token"] == nullptr) {
|
||||
response.set_content(
|
||||
CHANGE_USER_REQUIRED_STRING,
|
||||
JSON_TYPE
|
||||
);
|
||||
return;
|
||||
}
|
||||
if ((json_body["userid"] == nullptr) && (json_body["old_password"] == nullptr)) {
|
||||
response.set_content(
|
||||
CHANGE_USER_REQUIRED_STRING,
|
||||
JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (!verify_auth(json_body["token"])) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
|
||||
jwt::decoded_jwt<jwt::traits::kazuho_picojson> decoded_token = jwt::decode(json_body["token"]);
|
||||
std::string userid = "";
|
||||
for (auto& e : decoded_token.get_payload_json()) {
|
||||
std::string userid;
|
||||
for (std::pair<const std::string, picojson::value> &e: decoded_token.get_payload_json()) {
|
||||
if (e.first == "userId") {
|
||||
userid = e.second.to_str();
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (userid.empty()) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
|
||||
std::ifstream usersfile("users.json");
|
||||
nlohmann::json all_users = nlohmann::json::parse(usersfile);
|
||||
@@ -45,40 +55,48 @@ void change_user(const httplib::Request& request, httplib::Response& response) {
|
||||
if (json_body["userid"] != nullptr) {
|
||||
changeusruserid = json_body["userid"];
|
||||
nlohmann::json response_user_data = nullptr;
|
||||
for (nlohmann::json& user : all_users) {
|
||||
for (nlohmann::json &user: all_users) {
|
||||
if (user["id"] == userid) {
|
||||
response_user_data = user;
|
||||
}
|
||||
}
|
||||
if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (response_user_data == nullptr) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (response_user_data["is_superuser"] != "1") {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
bool found = false;
|
||||
if (json_body["userid"] != nullptr) {
|
||||
for (int i = 0; i < all_users.size(); i++) {
|
||||
if ((all_users[i]["id"] == changeusruserid)) {
|
||||
if (json_body["username"] != nullptr) {all_users[i]["username"] = json_body["username"];}
|
||||
if (json_body["password"] != nullptr) {all_users[i]["password"] = json_body["password"];}
|
||||
if (json_body["group"] != nullptr) {all_users[i]["group"] = json_body["group"];}
|
||||
if (json_body["is_superuser"] != nullptr) {all_users[i]["is_superuser"] = json_body["is_superuser"];}
|
||||
for (nlohmann::basic_json<> &all_user: all_users) {
|
||||
if ((all_user["id"] == changeusruserid)) {
|
||||
if (json_body["username"] != nullptr) { all_user["username"] = json_body["username"]; }
|
||||
if (json_body["password"] != nullptr) { all_user["password"] = json_body["password"]; }
|
||||
if (json_body["group"] != nullptr) { all_user["group"] = json_body["group"]; }
|
||||
if (json_body["is_superuser"] != nullptr) { all_user["is_superuser"] = json_body["is_superuser"]; }
|
||||
found = true;
|
||||
break;
|
||||
}
|
||||
}
|
||||
} else {
|
||||
for (int i = 0; i < all_users.size(); i++) {
|
||||
if ((all_users[i]["id"] == changeusruserid)) {
|
||||
if (json_body["username"] != nullptr) {all_users[i]["username"] = json_body["username"];}
|
||||
for (nlohmann::basic_json<> &all_user: all_users) {
|
||||
if ((all_user["id"] == changeusruserid)) {
|
||||
if (json_body["username"] != nullptr) { all_user["username"] = json_body["username"]; }
|
||||
found = true;
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
if (!found) {response.set_content("{\"status\":\"can't find this user\"}", "application/json");return;}
|
||||
if (!found) {
|
||||
response.set_content(R"({"status":"can't find this user"})", JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
std::ofstream usersfilew("users.json");
|
||||
usersfilew << all_users.dump(4);
|
||||
usersfilew.close();
|
||||
response.set_content("{\"status\":\"ok\"}", "application/json");
|
||||
response.set_content(R"({"status":"ok"})", JSON_TYPE);
|
||||
}
|
||||
|
||||
|
||||
+40
-12
@@ -1,25 +1,44 @@
|
||||
#include "users.hpp"
|
||||
#include "../colors.h"
|
||||
#include "../includes.hpp"
|
||||
#include "../auth/auth.hpp"
|
||||
#include <jwt-cpp/jwt.h>
|
||||
|
||||
// function for delete user
|
||||
void delete_user(const httplib::Request& request, httplib::Response& response) {
|
||||
void delete_user(const httplib::Request &request, httplib::Response &response) {
|
||||
std::cout << GREEN << request.path << RESET << " " << request.method << std::endl;
|
||||
response.set_header("Access-Control-Allow-Origin", "*");
|
||||
if (request.body == "") {response.set_content("{\"required\":\"[token] or if you superuser [token,userid]\"}", "application/json");return;}
|
||||
if (request.body.empty()) {
|
||||
response.set_content(
|
||||
DELETE_USER_REQUIRED_STRING,
|
||||
JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
nlohmann::json json_body = nlohmann::json::parse(request.body);
|
||||
|
||||
if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token] or if you superuser [token,userid]\"}", "application/json");return;}
|
||||
if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (json_body["token"] == nullptr) {
|
||||
response.set_content(
|
||||
DELETE_USER_REQUIRED_STRING,
|
||||
JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (!verify_auth(json_body["token"])) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
|
||||
jwt::decoded_jwt<jwt::traits::kazuho_picojson> decoded_token = jwt::decode(json_body["token"]);
|
||||
std::string userid = "";
|
||||
for (auto& e : decoded_token.get_payload_json()) {
|
||||
std::string userid;
|
||||
for (std::pair<const std::string, picojson::value> &e: decoded_token.get_payload_json()) {
|
||||
if (e.first == "userId") {
|
||||
userid = e.second.to_str();
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (userid.empty()) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
|
||||
std::ifstream usersfile("users.json");
|
||||
nlohmann::json all_users = nlohmann::json::parse(usersfile);
|
||||
@@ -29,13 +48,19 @@ void delete_user(const httplib::Request& request, httplib::Response& response) {
|
||||
if (json_body["userid"] != nullptr) {
|
||||
deluserid = json_body["userid"];
|
||||
nlohmann::json response_user_data = nullptr;
|
||||
for (nlohmann::json& user : all_users) {
|
||||
for (nlohmann::json &user: all_users) {
|
||||
if (user["id"] == userid) {
|
||||
response_user_data = user;
|
||||
}
|
||||
}
|
||||
if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (response_user_data == nullptr) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (response_user_data["is_superuser"] != "1") {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
bool found = false;
|
||||
@@ -46,9 +71,12 @@ void delete_user(const httplib::Request& request, httplib::Response& response) {
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (!found) {response.set_content("{\"status\":\"can't find this user\"}", "application/json");return;}
|
||||
if (!found) {
|
||||
response.set_content(R"({"status":"can't find this user"})", JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
std::ofstream usersfilew("users.json");
|
||||
usersfilew << all_users.dump(4);
|
||||
usersfilew.close();
|
||||
response.set_content("{\"status\":\"ok\"}", "application/json");
|
||||
response.set_content(R"({"status":"ok"})", JSON_TYPE);
|
||||
}
|
||||
|
||||
+32
-11
@@ -1,35 +1,56 @@
|
||||
#include "users.hpp"
|
||||
#include "../colors.h"
|
||||
#include "../includes.hpp"
|
||||
#include "../auth/auth.hpp"
|
||||
#include <jwt-cpp/jwt.h>
|
||||
|
||||
// function for get all users data without password
|
||||
void get_all_users(const httplib::Request& request, httplib::Response& response) {
|
||||
void get_all_users(const httplib::Request &request, httplib::Response &response) {
|
||||
std::cout << GREEN << request.path << RESET << " " << request.method << std::endl;
|
||||
response.set_header("Access-Control-Allow-Origin", "*");
|
||||
if (request.body == "") {response.set_content("{\"required\":\"[token]\"}", "application/json");return;}
|
||||
if (request.body.empty()) {
|
||||
response.set_content(ACCESS_REQUIRED_STRING, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
nlohmann::json json_body = nlohmann::json::parse(request.body);
|
||||
|
||||
if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token]\"}", "application/json");return;}
|
||||
if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (json_body["token"] == nullptr) {
|
||||
response.set_content(ACCESS_REQUIRED_STRING, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (!verify_auth(json_body["token"])) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
jwt::decoded_jwt<jwt::traits::kazuho_picojson> decoded_token = jwt::decode(json_body["token"]);
|
||||
std::string userid = "";
|
||||
for (auto& e : decoded_token.get_payload_json()) {
|
||||
std::string userid;
|
||||
for (std::pair<const std::string, picojson::value> &e: decoded_token.get_payload_json()) {
|
||||
if (e.first == "userId") {
|
||||
userid = e.second.to_str();
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (userid.empty()) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
std::ifstream usersfile("users.json");
|
||||
nlohmann::json all_users = nlohmann::json::parse(usersfile);
|
||||
usersfile.close();
|
||||
nlohmann::json response_user_data = nullptr;
|
||||
for (nlohmann::json& user : all_users) {
|
||||
for (nlohmann::json &user: all_users) {
|
||||
if (user["id"] == userid) {
|
||||
response_user_data = user;
|
||||
}
|
||||
user.erase("password");
|
||||
}
|
||||
if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
response.set_content(all_users.dump(), "application/json");
|
||||
if (response_user_data == nullptr) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (response_user_data["is_superuser"] != "1") {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
response.set_content(all_users.dump(), JSON_TYPE);
|
||||
}
|
||||
|
||||
+28
-10
@@ -1,35 +1,53 @@
|
||||
#include "users.hpp"
|
||||
#include "../colors.h"
|
||||
#include "../includes.hpp"
|
||||
#include "../auth/auth.hpp"
|
||||
#include <jwt-cpp/jwt.h>
|
||||
|
||||
// function for get user data without password
|
||||
void get_user(const httplib::Request& request, httplib::Response& response) {
|
||||
void get_user(const httplib::Request &request, httplib::Response &response) {
|
||||
std::cout << GREEN << request.path << RESET << " " << request.method << std::endl;
|
||||
response.set_header("Access-Control-Allow-Origin", "*");
|
||||
if (request.body == "") {response.set_content("{\"required\":\"[token]\"}", "application/json");return;}
|
||||
if (request.body.empty()) {
|
||||
response.set_content(ACCESS_REQUIRED_STRING, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
nlohmann::json json_body = nlohmann::json::parse(request.body);
|
||||
|
||||
if (json_body["token"] == nullptr) {response.set_content("{\"required\":\"[token]\"}", "application/json");return;}
|
||||
if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (json_body["token"] == nullptr) {
|
||||
response.set_content(ACCESS_REQUIRED_STRING, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
if (!verify_auth(json_body["token"])) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
jwt::decoded_jwt<jwt::traits::kazuho_picojson> decoded_token = jwt::decode(json_body["token"]);
|
||||
std::string userid = "";
|
||||
for (auto& e : decoded_token.get_payload_json()) {
|
||||
std::string userid;
|
||||
for (std::pair<const std::string, picojson::value> &e: decoded_token.get_payload_json()) {
|
||||
if (e.first == "userId") {
|
||||
userid = e.second.to_str();
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (userid.empty()) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
std::ifstream usersfile("users.json");
|
||||
nlohmann::json all_users = nlohmann::json::parse(usersfile);
|
||||
usersfile.close();
|
||||
nlohmann::json response_user_data = nullptr;
|
||||
for (nlohmann::json& user : all_users) {
|
||||
for (nlohmann::json &user: all_users) {
|
||||
if (user["id"] == userid) {
|
||||
response_user_data = user;
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
|
||||
if (response_user_data == nullptr) {
|
||||
response.set_content(STRING403, JSON_TYPE);
|
||||
return;
|
||||
}
|
||||
response_user_data.erase("password");
|
||||
response.set_content(response_user_data.dump(), "application/json");
|
||||
response.set_content(response_user_data.dump(), JSON_TYPE);
|
||||
}
|
||||
|
||||
+13
-9
@@ -2,22 +2,26 @@
|
||||
#define USERS_HPP
|
||||
|
||||
#include <httplib.h>
|
||||
#include <json.hpp>
|
||||
#include "../auth/auth.hpp"
|
||||
|
||||
// function for get user data without password
|
||||
void get_user(const httplib::Request& request, httplib::Response& response);
|
||||
void get_user(const httplib::Request &request, httplib::Response &response);
|
||||
|
||||
// function for get all users data without password
|
||||
void get_all_users(const httplib::Request& request, httplib::Response& response);
|
||||
void get_all_users(const httplib::Request &request, httplib::Response &response);
|
||||
|
||||
// function for access or reject authorization
|
||||
void user_access(const httplib::Request& request, httplib::Response& response);
|
||||
void user_access(const httplib::Request &request, httplib::Response &response);
|
||||
|
||||
// function for add user
|
||||
void add_user(const httplib::Request& request, httplib::Response& response);
|
||||
void add_user(const httplib::Request &request, httplib::Response &response);
|
||||
|
||||
// function for delete user
|
||||
void delete_user(const httplib::Request& request, httplib::Response& response);
|
||||
void delete_user(const httplib::Request &request, httplib::Response &response);
|
||||
|
||||
// function for change password for user
|
||||
void change_password(const httplib::Request& request, httplib::Response& response);
|
||||
void change_password(const httplib::Request &request, httplib::Response &response);
|
||||
|
||||
// function for change user data
|
||||
void change_user(const httplib::Request& request, httplib::Response& response);
|
||||
void change_user(const httplib::Request &request, httplib::Response &response);
|
||||
|
||||
#endif // USERS_HPP
|
||||
|
||||
Reference in New Issue
Block a user