diff --git a/CMakeLists.txt b/CMakeLists.txt index f9128ee..7a7d8f7 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -19,5 +19,6 @@ add_executable( src/users/add_user.cpp src/users/get_all_users.cpp src/users/get_user.cpp + src/users/change_user.cpp ) target_link_libraries(auth_service jwt-cpp::jwt-cpp) diff --git a/src/auth_service.cpp b/src/auth_service.cpp index 6a8bf91..3ce9ec4 100644 --- a/src/auth_service.cpp +++ b/src/auth_service.cpp @@ -17,6 +17,7 @@ int main() { srv.Post("/api/users/user/password/change", change_password); srv.Post("/api/users/del", delete_user); srv.Post("/api/access", user_access); + srv.Post("/api/users/user/change", change_user); srv.set_mount_point("/admin", "../src/web"); srv.set_mount_point("/js", "../src/web/js"); diff --git a/src/users/change_user.cpp b/src/users/change_user.cpp new file mode 100644 index 0000000..0028307 --- /dev/null +++ b/src/users/change_user.cpp @@ -0,0 +1,80 @@ +#include "users.hpp" + +void change_user(const httplib::Request& request, httplib::Response& response) { + if (request.body == "") {response.set_content( + "{\"required\":\"[token] or if you superuser [token,userid]\",\"optional\":\"[username,password,is_superuser,group]\"}", + "application/json" + );return;} + nlohmann::json json_body = nlohmann::json::parse(request.body); + + if (json_body["token"] == nullptr) {response.set_content( + "{\"required\":\"[token] or if you superuser [token,userid]\",\"optional\":\"[username,password,is_superuser,group]\"}", + "application/json" + );return;} + if ((json_body["userid"] == nullptr) && (json_body["old_password"] == nullptr)) { + response.set_content("{\"required\":\"[token] or if you superuser [token,userid]\",\"optional\":\"[username,password,is_superuser,group]\"}", "application/json"); + return; + } + // if (json_body["new_password"] == nullptr) {response.set_content("{\"required\":\"[token] or if you superuser [token,userid]\"}", "application/json");return;} + if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + + // std::string old_password = ""; + // const std::string new_password = json_body["new_password"]; + + // if (json_body["userid"] == nullptr) {old_password = json_body["old_password"];} + + jwt::decoded_jwt decoded_token = jwt::decode(json_body["token"]); + std::string userid = ""; + for (auto& e : decoded_token.get_payload_json()) { + if (e.first == "userId") { + userid = e.second.to_str(); + break; + } + } + if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + + std::ifstream usersfile("users.json"); + nlohmann::json all_users = nlohmann::json::parse(usersfile); + usersfile.close(); + + std::string changeusruserid = userid; + if (json_body["userid"] != nullptr) { + changeusruserid = json_body["userid"]; + nlohmann::json response_user_data = nullptr; + for (nlohmann::json& user : all_users) { + if (user["id"] == userid) { + response_user_data = user; + } + } + if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + } + + bool found = false; + if (json_body["userid"] != nullptr) { + for (int i = 0; i < all_users.size(); i++) { + if ((all_users[i]["id"] == changeusruserid)) { + if (json_body["username"] != nullptr) {all_users[i]["username"] = json_body["username"];} + if (json_body["password"] != nullptr) {all_users[i]["password"] = json_body["password"];} + if (json_body["group"] != nullptr) {all_users[i]["group"] = json_body["group"];} + if (json_body["is_superuser"] != nullptr) {all_users[i]["is_superuser"] = json_body["is_superuser"];} + found = true; + break; + } + } + } else { + for (int i = 0; i < all_users.size(); i++) { + if ((all_users[i]["id"] == changeusruserid)) { + if (json_body["username"] != nullptr) {all_users[i]["username"] = json_body["username"];} + found = true; + break; + } + } + } + if (!found) {response.set_content("{\"status\":\"can't find this user\"}", "application/json");return;} + std::ofstream usersfilew("users.json"); + usersfilew << all_users.dump(4); + usersfilew.close(); + response.set_content("{\"status\":\"ok\"}", "application/json"); +} + diff --git a/src/users/users.hpp b/src/users/users.hpp index 1affb00..bcf386f 100644 --- a/src/users/users.hpp +++ b/src/users/users.hpp @@ -17,5 +17,7 @@ void add_user(const httplib::Request& request, httplib::Response& response); void delete_user(const httplib::Request& request, httplib::Response& response); // function for change password for user void change_password(const httplib::Request& request, httplib::Response& response); +// function for change user data +void change_user(const httplib::Request& request, httplib::Response& response); #endif // USERS_HPP diff --git a/src/web/css/userstable.css b/src/web/css/userstable.css index edee8a8..dfef100 100644 --- a/src/web/css/userstable.css +++ b/src/web/css/userstable.css @@ -27,7 +27,7 @@ th { position: relative; border-radius: 10px; padding: 10px; - width: 16%; + width: 14%; text-overflow: auto; overflow-x: auto; } diff --git a/src/web/index.html b/src/web/index.html index 3dc2e09..749bb21 100644 --- a/src/web/index.html +++ b/src/web/index.html @@ -60,6 +60,32 @@ +
+
+

Change User Data

+
+
Username
+ +
+
+
Password
+ +
+
+
Group
+ +
+
+
Is Superuser
+ +
+
+ + +
+
+
+

Are you sure?

@@ -98,6 +124,7 @@ is_superuser delete change password + change user data @@ -114,5 +141,6 @@ + \ No newline at end of file diff --git a/src/web/js/change_user.js b/src/web/js/change_user.js new file mode 100644 index 0000000..63a0b7e --- /dev/null +++ b/src/web/js/change_user.js @@ -0,0 +1,57 @@ +const changeuserform = document.querySelector('.changeuserform') +const changeuserformbody = document.querySelector('.changeuserformbody') +const changeuserformusername = document.querySelector('#changeuserformusername') +const changeuserformpassword = document.querySelector('#changeuserformpassword') +const changeuserformgroup = document.querySelector('#changeuserformgroup') +const changeuserformissuperuser = document.querySelector('#changeuserformissuperuser') +const cancelchangeuser = document.querySelector(".cancelchangeuser") + +var changedatauserid = "" +var userdata = "" + +const change_user_data = async (userid) => { + changeuserform.classList.add('active') + changedatauserid = userid + console.log(userid) + const all_users = await fetch(routes.all_users(), { + method: 'POST', + body: `{"token":"${localStorage.getItem('token')}"}` + }).then(data => data.json()).then(jsondata => jsondata).catch((error) => { + notification(`Ошибка на сервере: ${error}`, "error") + }) + userdata = all_users.find(usr => usr.id === userid) + console.log(userdata) + changeuserformusername.value = userdata.username + changeuserformgroup.value = userdata.group + console.log(changeuserformissuperuser.checked) + changeuserformissuperuser.checked = userdata.is_superuser === "1"?true:false +} + +cancelchangeuser.addEventListener('click', (e) => { + e.preventDefault() + changeuserform.classList.remove('active') +}) + +changeuserformbody.addEventListener('submit', async (e) => { + e.preventDefault() + var request = { + token: localStorage.getItem('token'), + userid: changedatauserid, + username: changeuserformusername.value, + is_superuser: changeuserformissuperuser.checked?"1":"0", + group: changeuserformgroup.value + } + if (changeuserformpassword.value !== "") {request = {...request, "password": changeuserformpassword.value}} + const status = await fetch(routes.change_user(), { + method: 'POST', + body: JSON.stringify(request) + }).then(data => data.json()).then(jsondata => jsondata).catch((error) => { + notification(`Ошибка на сервере: ${error}`, "error") + }) + console.log(status) + if (status.status === "ok") { + notification("Данные пользователя успешно изменены", "success") + changeuserform.classList.remove('active') + get_all_users() + } +}) diff --git a/src/web/js/del_user.js b/src/web/js/del_user.js index 18ac2ac..50a880b 100644 --- a/src/web/js/del_user.js +++ b/src/web/js/del_user.js @@ -13,6 +13,9 @@ userstablebody.addEventListener('click', e => { if (e.target.classList.contains('changepassword')) { change_password(e.target.id) } + if (e.target.classList.contains('changeuser')) { + change_user_data(e.target.id) + } }) confirmformcancel.addEventListener('click', () => { diff --git a/src/web/js/get_all_users.js b/src/web/js/get_all_users.js index 09d5d4a..c09f419 100644 --- a/src/web/js/get_all_users.js +++ b/src/web/js/get_all_users.js @@ -16,6 +16,7 @@ const get_all_users = async () => { ${user.is_superuser} + ` } diff --git a/src/web/js/routes.js b/src/web/js/routes.js index ac97e52..2e42d5b 100644 --- a/src/web/js/routes.js +++ b/src/web/js/routes.js @@ -8,5 +8,6 @@ const routes = { access: () => [host, prefix, 'access'].join('/'), adduser: () => [host, prefix, 'users', 'add'].join('/'), deluser: () => [host, prefix, 'users', 'del'].join('/'), - change_password_url: () => [host, prefix, 'users', 'user', 'password', 'change'].join('/') + change_password_url: () => [host, prefix, 'users', 'user', 'password', 'change'].join('/'), + change_user: () => [host, prefix, 'users', 'user', 'change'].join('/') } \ No newline at end of file