auth: Moved token and user to models package, added graphql endpoint to check token
the build failed

This commit is contained in:
2018-09-16 16:57:40 +02:00
parent 07b94b3cab
commit 2ab933149e
14 changed files with 206 additions and 120 deletions
+48
View File
@@ -0,0 +1,48 @@
package models
// A Token contains the parsed results from an bearer token. Its methods are safe to use with a nil receiver, but
// the userID should be checked.
type Token struct {
UserID string
Permissions []string
}
// Authenticated returns true if the token is non-nil and parsed
func (token *Token) Authenticated() bool {
return token != nil && token.UserID != ""
}
// Permitted returns true if the token is non-nil and has the given permission or the "admin" permission
func (token *Token) Permitted(permissions ...string) bool {
if token == nil {
return false
}
for _, tokenPermission := range token.Permissions {
if tokenPermission == "admin" {
return true
}
for _, permission := range permissions {
if permission == tokenPermission {
return true
}
}
}
return false
}
// PermittedUser checks the first permission if the user matches, the second otherwise. This is a common
// pattern.
func (token *Token) PermittedUser(userID, permissionIfUser, permissionOtherwise string) bool {
if token == nil {
return false
}
if token.UserID == userID {
return token.Permitted(permissionIfUser)
}
return token.Permitted(permissionOtherwise)
}
+23
View File
@@ -0,0 +1,23 @@
package models
// A User represents user information about a user that has logged in.
type User struct {
ID string `bson:"_id" json:"id"`
Nick string `bson:"nick,omitempty" json:"nick,omitempty"`
Permissions []string `bson:"permissions" json:"permissions"`
}
// Permitted returns true if either of the permissions can be found
//
// `token.UserID == page.Author || token.Permitted("story.edit")`
func (user *User) Permitted(permissions ...string) bool {
for i := range permissions {
for j := range user.Permissions {
if permissions[i] == user.Permissions[j] {
return true
}
}
}
return false
}
+14
View File
@@ -0,0 +1,14 @@
package users
import (
"git.aiterp.net/rpdata/api/internal/store"
"github.com/globalsign/mgo"
)
var collection *mgo.Collection
func init() {
store.HandleInit(func(db *mgo.Database) {
collection = db.C("core.users")
})
}
+33
View File
@@ -0,0 +1,33 @@
package users
import (
"git.aiterp.net/rpdata/api/models"
"github.com/globalsign/mgo"
)
// Ensure finds a user by id, or makes a new one.
func Ensure(id string) (models.User, error) {
user := models.User{}
err := collection.FindId(id).One(&user)
if err == mgo.ErrNotFound {
user = models.User{
ID: id,
Nick: "",
Permissions: []string{
"member",
"log.edit",
"post.edit",
"post.move",
"file.upload",
},
}
err := collection.Insert(user)
if err != nil {
return models.User{}, err
}
}
return user, err
}
+13
View File
@@ -0,0 +1,13 @@
package users
import (
"git.aiterp.net/rpdata/api/models"
)
// Find finds a user by id
func Find(id string) (models.User, error) {
user := models.User{}
err := collection.FindId(id).One(&user)
return user, err
}