Files
wallet/backend/api/GetAllUsers.go
T
wt 599142af80
Build and Test / build-and-test-backend (push) Successful in 40s
Build and Test / build-and-test-frontend (push) Successful in 36s
feat(auth): Implement database-backed user authentication and
persistence

This commit introduces a major architectural change by replacing the
previous hardcoded user and data system with a robust, database-driven
approach. It lays the foundation for persistent data storage for all
application models.

Key Changes:

- **Database Integration:** - Added `GORM` and `SQLite` for the database
layer. - The database is now initialized and migrated on application
startup. - Configuration is managed through environment variables
(`DATABASE`, `USERS_FILE`).

- **User Authentication & Management:** - The login endpoint
(`/api/token`) now authenticates users against the database. - JWT
claims are now populated with real user data (`id`, `username`,
`is_superuser`). - Implemented a system to seed the database with
initial users from a `users.json` file.

- **New User API Endpoints:** - `GET /api/users`: Retrieves a list of
all users (superuser access required). - `GET /api/users/user`: Fetches
the data for the currently authenticated user based on their JWT.

- **Data Model Overhaul:** - Refactored all data models (`User`,
`Category`, `Operation`, `Subcategory`) to include GORM tags,
relationships, and a `BaseModel` with auto-generated UUIDs for primary
keys. - Separated user-related structs into `User` (database model),
`AuthRequest` (login payload), and `UserResponse` (safe API response).

- **Middleware & Routing:** - Improved JWT error handling for clearer
client-side messages. - Added a new middleware to allow passing the JWT
in the request body for more flexible client integration.
2025-08-08 23:47:36 +07:00

57 lines
1.0 KiB
Go

package api
import (
"backend/database"
"backend/model"
"fmt"
"github.com/gofiber/fiber/v2"
"github.com/golang-jwt/jwt/v5"
)
func GetAllUsers(c *fiber.Ctx) error {
user := c.Locals("user").(*jwt.Token)
claims := user.Claims.(jwt.MapClaims)
userid := claims["id"].(string)
dbuser, e := database.GetUserById(userid)
if e != nil {
return c.Status(
fiber.StatusInternalServerError,
).JSON(
fiber.Map{
"error": e.Error(),
},
)
}
if !dbuser.IsSuperuser {
return c.Status(
fiber.StatusForbidden,
).JSON(
fiber.Map{
"error": "you are not superuser",
},
)
}
users, e := database.GetAllUsers()
if e != nil {
return fmt.Errorf("Error: %v", e)
}
var responseUsers []model.UserResponse
for i := range users {
responseUsers = append(
responseUsers,
model.UserResponse{
ID: users[i].ID,
Username: users[i].Username,
Email: users[i].Email,
Group: users[i].Group,
IsSuperuser: users[i].IsSuperuser,
},
)
}
return c.JSON(responseUsers)
}