auth: Moved token and user to models package, added graphql endpoint to check token
the build failed
the build failed
This commit is contained in:
@@ -0,0 +1,48 @@
|
||||
package models
|
||||
|
||||
// A Token contains the parsed results from an bearer token. Its methods are safe to use with a nil receiver, but
|
||||
// the userID should be checked.
|
||||
type Token struct {
|
||||
UserID string
|
||||
Permissions []string
|
||||
}
|
||||
|
||||
// Authenticated returns true if the token is non-nil and parsed
|
||||
func (token *Token) Authenticated() bool {
|
||||
return token != nil && token.UserID != ""
|
||||
}
|
||||
|
||||
// Permitted returns true if the token is non-nil and has the given permission or the "admin" permission
|
||||
func (token *Token) Permitted(permissions ...string) bool {
|
||||
if token == nil {
|
||||
return false
|
||||
}
|
||||
|
||||
for _, tokenPermission := range token.Permissions {
|
||||
if tokenPermission == "admin" {
|
||||
return true
|
||||
}
|
||||
|
||||
for _, permission := range permissions {
|
||||
if permission == tokenPermission {
|
||||
return true
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return false
|
||||
}
|
||||
|
||||
// PermittedUser checks the first permission if the user matches, the second otherwise. This is a common
|
||||
// pattern.
|
||||
func (token *Token) PermittedUser(userID, permissionIfUser, permissionOtherwise string) bool {
|
||||
if token == nil {
|
||||
return false
|
||||
}
|
||||
|
||||
if token.UserID == userID {
|
||||
return token.Permitted(permissionIfUser)
|
||||
}
|
||||
|
||||
return token.Permitted(permissionOtherwise)
|
||||
}
|
||||
@@ -0,0 +1,23 @@
|
||||
package models
|
||||
|
||||
// A User represents user information about a user that has logged in.
|
||||
type User struct {
|
||||
ID string `bson:"_id" json:"id"`
|
||||
Nick string `bson:"nick,omitempty" json:"nick,omitempty"`
|
||||
Permissions []string `bson:"permissions" json:"permissions"`
|
||||
}
|
||||
|
||||
// Permitted returns true if either of the permissions can be found
|
||||
//
|
||||
// `token.UserID == page.Author || token.Permitted("story.edit")`
|
||||
func (user *User) Permitted(permissions ...string) bool {
|
||||
for i := range permissions {
|
||||
for j := range user.Permissions {
|
||||
if permissions[i] == user.Permissions[j] {
|
||||
return true
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return false
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
package users
|
||||
|
||||
import (
|
||||
"git.aiterp.net/rpdata/api/internal/store"
|
||||
"github.com/globalsign/mgo"
|
||||
)
|
||||
|
||||
var collection *mgo.Collection
|
||||
|
||||
func init() {
|
||||
store.HandleInit(func(db *mgo.Database) {
|
||||
collection = db.C("core.users")
|
||||
})
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
package users
|
||||
|
||||
import (
|
||||
"git.aiterp.net/rpdata/api/models"
|
||||
"github.com/globalsign/mgo"
|
||||
)
|
||||
|
||||
// Ensure finds a user by id, or makes a new one.
|
||||
func Ensure(id string) (models.User, error) {
|
||||
user := models.User{}
|
||||
err := collection.FindId(id).One(&user)
|
||||
|
||||
if err == mgo.ErrNotFound {
|
||||
user = models.User{
|
||||
ID: id,
|
||||
Nick: "",
|
||||
Permissions: []string{
|
||||
"member",
|
||||
"log.edit",
|
||||
"post.edit",
|
||||
"post.move",
|
||||
"file.upload",
|
||||
},
|
||||
}
|
||||
|
||||
err := collection.Insert(user)
|
||||
if err != nil {
|
||||
return models.User{}, err
|
||||
}
|
||||
}
|
||||
|
||||
return user, err
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
package users
|
||||
|
||||
import (
|
||||
"git.aiterp.net/rpdata/api/models"
|
||||
)
|
||||
|
||||
// Find finds a user by id
|
||||
func Find(id string) (models.User, error) {
|
||||
user := models.User{}
|
||||
err := collection.FindId(id).One(&user)
|
||||
|
||||
return user, err
|
||||
}
|
||||
Reference in New Issue
Block a user