Prepare Build and Testing executable binary / Prepare-Build-Testing-With-Make (push) Failing after 10s
Prepare Build and Testing executable binary / Prepare-Build-Testing-With-CMake (push) Failing after 14s
Prepare Build and Testing executable binary / Prepare-Build-Testing-With-Meson (push) Failing after 12s
Prepare Build and Testing executable binary / Prepare-Build-Testing-With-Make-Without-sqlite3 (push) Failing after 9s
Prepare Build and Testing executable binary / Prepare-Build-Testing-With-CMake-Without-sqlite3 (push) Failing after 14s
Prepare Build and Testing executable binary / Prepare-Build-Testing-With-Meson-Without-sqlite3 (push) Failing after 13s
125 lines
4.5 KiB
C
125 lines
4.5 KiB
C
#include "security/jwt.h"
|
|
#include "user.h"
|
|
#include "utils/utils.h"
|
|
#include "config/config.h"
|
|
|
|
void change_user(struct mg_connection *c, struct mg_http_message *hm) {
|
|
if (hm->body.len == 0) {
|
|
mg_http_reply(c, 400, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("must have token, new_user_data"));
|
|
return;
|
|
}
|
|
request_with_token *requestdata = check_body(hm);
|
|
if (requestdata->error != NULL) {
|
|
mg_http_reply(c, 403, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC(requestdata->error));
|
|
return;
|
|
}
|
|
char *jwt_secret = cm_get_parameter_as_string(config, "jwt_secret");
|
|
bool valid = false;
|
|
if (jwt_secret) {
|
|
printf("jwt_secret is not null %s\n", jwt_secret);
|
|
valid = jwt_verifyJWT(requestdata->token, jwt_secret);
|
|
} else {
|
|
valid = jwt_verifyJWT(requestdata->token, JWT_DEFAULT_SECRET);
|
|
}
|
|
if (!valid) {
|
|
mg_http_reply(c, 403, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("invalid token"));
|
|
return;
|
|
}
|
|
cJSON *jsonbody = cJSON_Parse(hm->body.buf);
|
|
cJSON *username = cJSON_GetObjectItem(jsonbody, "username");
|
|
cJSON *email = cJSON_GetObjectItem(jsonbody, "email");
|
|
cJSON *group = cJSON_GetObjectItem(jsonbody, "group");
|
|
cJSON *is_superuser = cJSON_GetObjectItem(jsonbody, "is_superuser");
|
|
cJSON *userid = cJSON_GetObjectItem(jsonbody, "userid");
|
|
User *old_user_data = nullptr;
|
|
if (!userid) {
|
|
old_user_data = db_get_user_by_username(username->valuestring);
|
|
} else {
|
|
old_user_data = db_get_user_by_id(userid->valueint);
|
|
}
|
|
if (!old_user_data) {
|
|
mg_http_reply(c, 404, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("user not found"));
|
|
return;
|
|
}
|
|
char *password = old_user_data->password;
|
|
if (!password) {
|
|
mg_http_reply(c, 400, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("password is required"));
|
|
return;
|
|
}
|
|
if (username == nullptr || email == nullptr || is_superuser == nullptr ||
|
|
group == nullptr) {
|
|
mg_http_reply(c, 400, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("must have <username>, <email>, <group, "
|
|
"optional>, <is_superuser, optional>"));
|
|
free_user(old_user_data);
|
|
free(password);
|
|
return;
|
|
}
|
|
cJSON *payload = jwt_get_payload(requestdata->token);
|
|
int id = cJSON_GetObjectItem(payload, "id")->valueint;
|
|
const bool user_is_superuser = is_superuser->valueint ? true : false;
|
|
if (!userid) {
|
|
User *updated_user_data =
|
|
db_update_user(id, username->valuestring, email->valuestring, password,
|
|
group->valuestring, &user_is_superuser);
|
|
|
|
if (!updated_user_data) {
|
|
mg_http_reply(c, 500, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("failed to update user change user request"));
|
|
cJSON_Delete(payload);
|
|
free_user(old_user_data);
|
|
return;
|
|
}
|
|
|
|
char responsedata[2048] = {0};
|
|
snprintf(responsedata, sizeof(responsedata),
|
|
"{\"username\":\"%s\",\"email\":\"%s\",\"group\":\"%s\",\"is_"
|
|
"superuser\":%s}",
|
|
username->valuestring, email->valuestring, group->valuestring,
|
|
is_superuser->valueint ? "true" : "false");
|
|
|
|
mg_http_reply(c, 200, HTTP_HEADERS, responsedata);
|
|
free_user(updated_user_data);
|
|
free_user(old_user_data);
|
|
cJSON_Delete(payload);
|
|
return;
|
|
}
|
|
bool req_is_superuser =
|
|
cJSON_GetObjectItem(payload, "is_superuser")->valueint;
|
|
if (!req_is_superuser) {
|
|
mg_http_reply(c, 403, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"),
|
|
MG_ESC("user is not superuser"));
|
|
cJSON_Delete(payload);
|
|
free_user(old_user_data);
|
|
return;
|
|
}
|
|
User *updated_user_data = db_update_user(
|
|
userid->valueint, username->valuestring, email->valuestring, password,
|
|
group->valuestring, &user_is_superuser);
|
|
if (!updated_user_data) {
|
|
mg_http_reply(c, 500, "Content-Type: application/json\r\n", "{%m:%m}",
|
|
MG_ESC("error"),
|
|
MG_ESC("failed to update user can't change userdata"));
|
|
cJSON_Delete(payload);
|
|
free_user(old_user_data);
|
|
return;
|
|
}
|
|
|
|
char responsedata[2048] = {0};
|
|
snprintf(responsedata, sizeof(responsedata),
|
|
"{\"username\":\"%s\",\"email\":\"%s\",\"group\":\"%s\",\"is_"
|
|
"superuser\":%s}",
|
|
username->valuestring, email->valuestring, group->valuestring,
|
|
is_superuser->valueint ? "true" : "false");
|
|
|
|
mg_http_reply(c, 200, HTTP_HEADERS, responsedata);
|
|
free_user(updated_user_data);
|
|
free_user(old_user_data);
|
|
cJSON_Delete(payload);
|
|
}
|