Prepare Build and Testing executable binary / Prepare-Build-Testing-With-Make (push) Successful in 9s
Prepare Build and Testing executable binary / Prepare-Build-Testing-With-CMake (push) Successful in 12s
Prepare Build and Testing executable binary / Prepare-Build-Testing-With-Meson (push) Successful in 11s
Prepare Build and Testing executable binary / Prepare-Build-Testing-With-Make-Without-sqlite3 (push) Successful in 9s
Prepare Build and Testing executable binary / Prepare-Build-Testing-With-CMake-Without-sqlite3 (push) Successful in 14s
Prepare Build and Testing executable binary / Prepare-Build-Testing-With-Meson-Without-sqlite3 (push) Successful in 12s
87 lines
3.1 KiB
C
87 lines
3.1 KiB
C
#include "cJSON.h"
|
|
#include "security/jwt.h"
|
|
#include "user.h"
|
|
#include "utils/utils.h"
|
|
|
|
void change_password(struct mg_connection *c, struct mg_http_message *hm) {
|
|
if (hm->body.len == 0) {
|
|
mg_http_reply(c, 400, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("must have token, old_password, new_password"));
|
|
return;
|
|
}
|
|
request_with_token *requestdata = check_body(hm);
|
|
if (requestdata->error != NULL) {
|
|
mg_http_reply(c, 403, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC(requestdata->error));
|
|
return;
|
|
}
|
|
const bool valid = jwt_verifyJWT(requestdata->token, JWT_DEFAULT_SECRET);
|
|
if (!valid) {
|
|
mg_http_reply(c, 403, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("invalid token"));
|
|
return;
|
|
}
|
|
cJSON *jsonbody = cJSON_Parse(hm->body.buf);
|
|
cJSON *old_password = cJSON_GetObjectItem(jsonbody, "old_password");
|
|
cJSON *new_password = cJSON_GetObjectItem(jsonbody, "new_password");
|
|
cJSON *userid = cJSON_GetObjectItem(jsonbody, "userid");
|
|
if ((old_password == nullptr || new_password == nullptr) &&
|
|
userid == nullptr) {
|
|
mg_http_reply(c, 400, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("must have <old_password>, <new_password>"));
|
|
return;
|
|
}
|
|
cJSON *payload = jwt_get_payload(requestdata->token);
|
|
|
|
if (!userid) {
|
|
cJSON *id = cJSON_GetObjectItem(payload, "id");
|
|
char *password = db_get_user_field_by_id(id->valueint, "password");
|
|
if (!password) {
|
|
mg_http_reply(c, 500, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("failed to update user can't get old_user_data"));
|
|
cJSON_Delete(payload);
|
|
return;
|
|
}
|
|
|
|
if (strcmp(password, old_password->valuestring)) {
|
|
mg_http_reply(c, 400, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("invalid old password"));
|
|
return;
|
|
}
|
|
if (!db_update_user_field(id->valueint, "password",
|
|
new_password->valuestring)) {
|
|
mg_http_reply(c, 500, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("failed to update user can't update database"));
|
|
cJSON_Delete(payload);
|
|
return;
|
|
}
|
|
|
|
char responsedata[64] = {0};
|
|
snprintf(responsedata, sizeof(responsedata), "{\"success\": true}");
|
|
|
|
mg_http_reply(c, 200, HTTP_HEADERS, responsedata);
|
|
cJSON_Delete(payload);
|
|
return;
|
|
}
|
|
bool is_superuser = cJSON_GetObjectItem(payload, "is_superuser")->valueint;
|
|
if (!is_superuser) {
|
|
mg_http_reply(c, 403, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("user is not superuser"));
|
|
cJSON_Delete(payload);
|
|
return;
|
|
}
|
|
if (!db_update_user_field(userid->valueint, "password",
|
|
new_password->valuestring)) {
|
|
mg_http_reply(
|
|
c, 500, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("failed to update user can't create new_user_data from root"));
|
|
cJSON_Delete(payload);
|
|
return;
|
|
}
|
|
char responsedata[64] = {0};
|
|
snprintf(responsedata, sizeof(responsedata), "{\"success\": true}");
|
|
|
|
mg_http_reply(c, 200, HTTP_HEADERS, responsedata);
|
|
cJSON_Delete(payload);
|
|
}
|