added get_user and get_all_users

This commit is contained in:
wt
2024-05-22 16:44:53 +07:00
parent afbd7ed4d2
commit fa573aa734
6 changed files with 133 additions and 16 deletions
+29 -8
View File
@@ -1,11 +1,12 @@
#include "auth.hpp"
// function for authorization users
void auth(const httplib::Request& request, httplib::Response& response) {
if (request.body == "") {response.set_content("{\"needed\":\"[uername,password]\"}", "application/json");return;}
if (request.body == "") {response.set_content("{\"needed\":\"[username,password]\"}", "application/json");return;}
nlohmann::json json_body = nlohmann::json::parse(request.body);
if (json_body["username"] == nullptr) {response.set_content("{\"needed\":\"[uername,password]\"}", "application/json");return;}
if (json_body["password"] == nullptr) {response.set_content("{\"needed\":\"[uername,password]\"}", "application/json");return;}
if (json_body["username"] == nullptr) {response.set_content("{\"needed\":\"[username,password]\"}", "application/json");return;}
if (json_body["password"] == nullptr) {response.set_content("{\"needed\":\"[username,password]\"}", "application/json");return;}
const std::string request_username = json_body["username"];
const std::string request_password = json_body["password"];
@@ -13,19 +14,20 @@ void auth(const httplib::Request& request, httplib::Response& response) {
nlohmann::json all_users = nlohmann::json::parse(usersfile);
usersfile.close();
int userid = -1;
std::string userid = "";
for (int i = 0; i < all_users.size(); i++) {
if ((all_users[i]["username"] == request_username) && (all_users[i]["password"] == request_password)) {
userid = all_users[i]["id"];
break;
}
}
if (userid == -1) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
auto token = jwt::create()
.set_type("JWT")
// .set_issuer("auth0")
.set_payload_claim("userId", jwt::claim(std::to_string(userid)))
.set_issuer("auth0")
.set_payload_claim("userId", jwt::claim(userid))
.sign(jwt::algorithm::hs256{JWT_SECRET_KEY});
std::stringstream response_json;
@@ -33,6 +35,25 @@ void auth(const httplib::Request& request, httplib::Response& response) {
response.set_content(response_json.str(), "application/json");
}
// function for verify tokens
bool verify_auth(const std::string token) {
return true;
try {
// parse token
const auto decoded = jwt::decode(token);
// validate token
const auto verifier = jwt::verify()
.allow_algorithm(jwt::algorithm::hs256{JWT_SECRET_KEY})
.with_issuer("auth0");
verifier.verify(decoded);
return true;
}
catch (const std::system_error& e) {
std::cout << "Verification error: " << e.what() << std::endl;
return false;
}
catch (...) {
return false;
}
}
+2
View File
@@ -9,7 +9,9 @@
#include "../includes.hpp"
#include <sstream>
// function for authorization users
void auth(const httplib::Request& request, httplib::Response& response);
// function for verify tokens
bool verify_auth(const std::string token);
#endif // AUTH_HPP
+8 -7
View File
@@ -5,18 +5,19 @@
#include <jwt-cpp/jwt.h>
#include "auth/auth.hpp"
#include "users/users.hpp"
int main() {
httplib::Server srv;
srv.Post("/api/token", auth);
srv.Get("/api/users", [](const httplib::Request& request, httplib::Response& response) {
std::ifstream usersfile("users.json");
nlohmann::json usersdata = nlohmann::json::parse(usersfile);
usersfile.close();
response.set_content(usersdata.dump(), "application/json");
});
srv.Post("/api/user", get_user);
srv.Post("/api/users/all", get_all_users);
// srv.Post("/api/adduser", add_user);
// srv.Post("/api/changepassword", change_password);
// srv.Post("/api/deluser", del_user);
// srv.Post("/api/deluserassuperuser", del_user_as_superuser);
srv.Post("/api/access", user_access);
srv.listen("localhost", 43243);
return 0;
+6 -1
View File
@@ -1 +1,6 @@
#define JWT_SECRET_KEY "secret"
#ifndef INCLUDES_HPP
#define INCLUDES_HPP
#define JWT_SECRET_KEY "secret"
#endif // INCLUDES_HPP
+73
View File
@@ -0,0 +1,73 @@
#include "users.hpp"
// function for get user data without password
void get_user(const httplib::Request& request, httplib::Response& response) {
if (request.body == "") {response.set_content("{\"needed\":\"[token]\"}", "application/json");return;}
nlohmann::json json_body = nlohmann::json::parse(request.body);
if (json_body["token"] == nullptr) {response.set_content("{\"needed\":\"[token]\"}", "application/json");return;}
if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
auto decoded_token = jwt::decode(json_body["token"]);
std::string userid = "";
for (auto& e : decoded_token.get_payload_json()) {
if (e.first == "userId") {
userid = e.second.to_str();
break;
}
}
if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
std::ifstream usersfile("users.json");
nlohmann::json all_users = nlohmann::json::parse(usersfile);
usersfile.close();
nlohmann::json response_user_data = nullptr;
for (auto& user : all_users) {
if (user["id"] == userid) {
response_user_data = user;
break;
}
}
if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
response_user_data.erase("password");
response.set_content(response_user_data.dump(), "application/json");
}
// function for get all users data without password
void get_all_users(const httplib::Request& request, httplib::Response& response) {
if (request.body == "") {response.set_content("{\"needed\":\"[token]\"}", "application/json");return;}
nlohmann::json json_body = nlohmann::json::parse(request.body);
if (json_body["token"] == nullptr) {response.set_content("{\"needed\":\"[token]\"}", "application/json");return;}
if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
auto decoded_token = jwt::decode(json_body["token"]);
std::string userid = "";
for (auto& e : decoded_token.get_payload_json()) {
if (e.first == "userId") {
userid = e.second.to_str();
break;
}
}
if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
std::ifstream usersfile("users.json");
nlohmann::json all_users = nlohmann::json::parse(usersfile);
usersfile.close();
nlohmann::json response_user_data = nullptr;
for (auto& user : all_users) {
if (user["id"] == userid) {
response_user_data = user;
}
user.erase("password");
}
if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;}
if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;}
response.set_content(all_users.dump(), "application/json");
}
// function for access or reject authorization
void user_access(const httplib::Request& request, httplib::Response& response) {
if (request.body == "") {response.set_content("{\"needed\":\"[token]\"}", "application/json");return;}
nlohmann::json json_body = nlohmann::json::parse(request.body);
if (json_body["token"] == nullptr) {response.set_content("{\"needed\":\"[token]\"}", "application/json");return;}
if (!verify_auth(json_body["token"])) {response.set_content("{\"access\":\"reject\"}", "application/json");return;}
response.set_content("{\"access\":\"success\"}", "application/json");
}
+15
View File
@@ -0,0 +1,15 @@
#ifndef USERS_HPP
#define USERS_HPP
#include <httplib.h>
#include <json.hpp>
#include "../auth/auth.hpp"
// function for get user data without password
void get_user(const httplib::Request& request, httplib::Response& response);
// function for get all users data without password
void get_all_users(const httplib::Request& request, httplib::Response& response);
// function for access or reject authorization
void user_access(const httplib::Request& request, httplib::Response& response);
#endif // USERS_HPP