| 
									
										
										
										
											2015-07-17 15:51:34 +08:00
										 |  |  | package api | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | import ( | 
					
						
							| 
									
										
										
										
											2015-07-21 18:18:11 +08:00
										 |  |  | 	"fmt" | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-07-17 15:51:34 +08:00
										 |  |  | 	"github.com/grafana/grafana/pkg/api/dtos" | 
					
						
							|  |  |  | 	"github.com/grafana/grafana/pkg/bus" | 
					
						
							| 
									
										
										
										
											2015-07-20 23:46:48 +08:00
										 |  |  | 	"github.com/grafana/grafana/pkg/events" | 
					
						
							|  |  |  | 	"github.com/grafana/grafana/pkg/metrics" | 
					
						
							| 
									
										
										
										
											2015-07-17 15:51:34 +08:00
										 |  |  | 	"github.com/grafana/grafana/pkg/middleware" | 
					
						
							|  |  |  | 	m "github.com/grafana/grafana/pkg/models" | 
					
						
							| 
									
										
										
										
											2015-07-18 23:39:12 +08:00
										 |  |  | 	"github.com/grafana/grafana/pkg/setting" | 
					
						
							| 
									
										
										
										
											2015-07-17 15:51:34 +08:00
										 |  |  | 	"github.com/grafana/grafana/pkg/util" | 
					
						
							|  |  |  | ) | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | func GetPendingOrgInvites(c *middleware.Context) Response { | 
					
						
							| 
									
										
										
										
											2015-08-28 21:14:24 +08:00
										 |  |  | 	query := m.GetTempUsersQuery{OrgId: c.OrgId, Status: m.TmpUserInvitePending} | 
					
						
							| 
									
										
										
										
											2015-07-17 15:51:34 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | 	if err := bus.Dispatch(&query); err != nil { | 
					
						
							|  |  |  | 		return ApiError(500, "Failed to get invites from db", err) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-07-20 20:26:49 +08:00
										 |  |  | 	for _, invite := range query.Result { | 
					
						
							|  |  |  | 		invite.Url = setting.ToAbsUrl("invite/" + invite.Code) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-07-17 15:51:34 +08:00
										 |  |  | 	return Json(200, query.Result) | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | func AddOrgInvite(c *middleware.Context, inviteDto dtos.AddInviteForm) Response { | 
					
						
							|  |  |  | 	if !inviteDto.Role.IsValid() { | 
					
						
							|  |  |  | 		return ApiError(400, "Invalid role specified", nil) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-07-18 17:43:34 +08:00
										 |  |  | 	// first try get existing user
 | 
					
						
							| 
									
										
										
										
											2015-08-10 20:03:08 +08:00
										 |  |  | 	userQuery := m.GetUserByLoginQuery{LoginOrEmail: inviteDto.LoginOrEmail} | 
					
						
							| 
									
										
										
										
											2015-07-18 17:43:34 +08:00
										 |  |  | 	if err := bus.Dispatch(&userQuery); err != nil { | 
					
						
							|  |  |  | 		if err != m.ErrUserNotFound { | 
					
						
							|  |  |  | 			return ApiError(500, "Failed to query db for existing user check", err) | 
					
						
							|  |  |  | 		} | 
					
						
							| 
									
										
										
										
											2017-03-18 04:35:05 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | 		if setting.DisableLoginForm { | 
					
						
							|  |  |  | 			return ApiError(401, "User could not be found", nil) | 
					
						
							|  |  |  | 		} | 
					
						
							| 
									
										
										
										
											2015-07-18 17:43:34 +08:00
										 |  |  | 	} else { | 
					
						
							| 
									
										
										
										
											2015-08-11 16:35:10 +08:00
										 |  |  | 		return inviteExistingUserToOrg(c, userQuery.Result, &inviteDto) | 
					
						
							| 
									
										
										
										
											2015-07-18 17:43:34 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-07-17 15:51:34 +08:00
										 |  |  | 	cmd := m.CreateTempUserCommand{} | 
					
						
							|  |  |  | 	cmd.OrgId = c.OrgId | 
					
						
							| 
									
										
										
										
											2015-08-10 20:03:08 +08:00
										 |  |  | 	cmd.Email = inviteDto.LoginOrEmail | 
					
						
							| 
									
										
										
										
											2015-07-17 15:51:34 +08:00
										 |  |  | 	cmd.Name = inviteDto.Name | 
					
						
							| 
									
										
										
										
											2015-07-20 16:57:39 +08:00
										 |  |  | 	cmd.Status = m.TmpUserInvitePending | 
					
						
							| 
									
										
										
										
											2015-07-17 15:51:34 +08:00
										 |  |  | 	cmd.InvitedByUserId = c.UserId | 
					
						
							|  |  |  | 	cmd.Code = util.GetRandomString(30) | 
					
						
							| 
									
										
										
										
											2015-07-17 20:42:49 +08:00
										 |  |  | 	cmd.Role = inviteDto.Role | 
					
						
							| 
									
										
										
										
											2015-07-20 16:57:39 +08:00
										 |  |  | 	cmd.RemoteAddr = c.Req.RemoteAddr | 
					
						
							| 
									
										
										
										
											2015-07-17 15:51:34 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | 	if err := bus.Dispatch(&cmd); err != nil { | 
					
						
							|  |  |  | 		return ApiError(500, "Failed to save invite to database", err) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-07-18 23:39:12 +08:00
										 |  |  | 	// send invite email
 | 
					
						
							| 
									
										
										
										
											2015-08-10 20:03:08 +08:00
										 |  |  | 	if !inviteDto.SkipEmails && util.IsEmail(inviteDto.LoginOrEmail) { | 
					
						
							| 
									
										
										
										
											2015-07-18 23:39:12 +08:00
										 |  |  | 		emailCmd := m.SendEmailCommand{ | 
					
						
							| 
									
										
										
										
											2015-08-10 20:03:08 +08:00
										 |  |  | 			To:       []string{inviteDto.LoginOrEmail}, | 
					
						
							| 
									
										
										
										
											2015-07-18 23:39:12 +08:00
										 |  |  | 			Template: "new_user_invite.html", | 
					
						
							|  |  |  | 			Data: map[string]interface{}{ | 
					
						
							| 
									
										
										
										
											2015-08-11 16:35:10 +08:00
										 |  |  | 				"Name":      util.StringsFallback2(cmd.Name, cmd.Email), | 
					
						
							|  |  |  | 				"OrgName":   c.OrgName, | 
					
						
							|  |  |  | 				"Email":     c.Email, | 
					
						
							|  |  |  | 				"LinkUrl":   setting.ToAbsUrl("invite/" + cmd.Code), | 
					
						
							|  |  |  | 				"InvitedBy": util.StringsFallback3(c.Name, c.Email, c.Login), | 
					
						
							| 
									
										
										
										
											2015-07-18 23:39:12 +08:00
										 |  |  | 			}, | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 		if err := bus.Dispatch(&emailCmd); err != nil { | 
					
						
							|  |  |  | 			return ApiError(500, "Failed to send email invite", err) | 
					
						
							|  |  |  | 		} | 
					
						
							| 
									
										
										
										
											2015-08-10 20:03:08 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | 		return ApiSuccess(fmt.Sprintf("Sent invite to %s", inviteDto.LoginOrEmail)) | 
					
						
							| 
									
										
										
										
											2015-07-18 23:39:12 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-08-10 20:03:08 +08:00
										 |  |  | 	return ApiSuccess(fmt.Sprintf("Created invite for %s", inviteDto.LoginOrEmail)) | 
					
						
							| 
									
										
										
										
											2015-07-17 15:51:34 +08:00
										 |  |  | } | 
					
						
							| 
									
										
										
										
											2015-07-20 16:57:39 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-08-11 16:35:10 +08:00
										 |  |  | func inviteExistingUserToOrg(c *middleware.Context, user *m.User, inviteDto *dtos.AddInviteForm) Response { | 
					
						
							|  |  |  | 	// user exists, add org role
 | 
					
						
							|  |  |  | 	createOrgUserCmd := m.AddOrgUserCommand{OrgId: c.OrgId, UserId: user.Id, Role: inviteDto.Role} | 
					
						
							|  |  |  | 	if err := bus.Dispatch(&createOrgUserCmd); err != nil { | 
					
						
							|  |  |  | 		if err == m.ErrOrgUserAlreadyAdded { | 
					
						
							|  |  |  | 			return ApiError(412, fmt.Sprintf("User %s is already added to organization", inviteDto.LoginOrEmail), err) | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 		return ApiError(500, "Error while trying to create org user", err) | 
					
						
							|  |  |  | 	} else { | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 		if !inviteDto.SkipEmails && util.IsEmail(user.Email) { | 
					
						
							|  |  |  | 			emailCmd := m.SendEmailCommand{ | 
					
						
							|  |  |  | 				To:       []string{user.Email}, | 
					
						
							|  |  |  | 				Template: "invited_to_org.html", | 
					
						
							|  |  |  | 				Data: map[string]interface{}{ | 
					
						
							|  |  |  | 					"Name":      user.NameOrFallback(), | 
					
						
							|  |  |  | 					"OrgName":   c.OrgName, | 
					
						
							|  |  |  | 					"InvitedBy": util.StringsFallback3(c.Name, c.Email, c.Login), | 
					
						
							|  |  |  | 				}, | 
					
						
							|  |  |  | 			} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 			if err := bus.Dispatch(&emailCmd); err != nil { | 
					
						
							|  |  |  | 				return ApiError(500, "Failed to send email invited_to_org", err) | 
					
						
							|  |  |  | 			} | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 		return ApiSuccess(fmt.Sprintf("Existing Grafana user %s added to org %s", user.NameOrFallback(), c.OrgName)) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-07-20 16:57:39 +08:00
										 |  |  | func RevokeInvite(c *middleware.Context) Response { | 
					
						
							| 
									
										
										
										
											2015-08-31 00:56:53 +08:00
										 |  |  | 	if ok, rsp := updateTempUserStatus(c.Params(":code"), m.TmpUserRevoked); !ok { | 
					
						
							|  |  |  | 		return rsp | 
					
						
							| 
									
										
										
										
											2015-07-20 16:57:39 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	return ApiSuccess("Invite revoked") | 
					
						
							|  |  |  | } | 
					
						
							| 
									
										
										
										
											2015-07-20 21:52:49 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | func GetInviteInfoByCode(c *middleware.Context) Response { | 
					
						
							| 
									
										
										
										
											2015-07-20 23:46:48 +08:00
										 |  |  | 	query := m.GetTempUserByCodeQuery{Code: c.Params(":code")} | 
					
						
							| 
									
										
										
										
											2015-07-20 21:52:49 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | 	if err := bus.Dispatch(&query); err != nil { | 
					
						
							|  |  |  | 		if err == m.ErrTempUserNotFound { | 
					
						
							|  |  |  | 			return ApiError(404, "Invite not found", nil) | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 		return ApiError(500, "Failed to get invite", err) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-08-10 19:46:59 +08:00
										 |  |  | 	invite := query.Result | 
					
						
							| 
									
										
										
										
											2015-07-20 21:52:49 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-08-10 19:46:59 +08:00
										 |  |  | 	return Json(200, dtos.InviteInfo{ | 
					
						
							|  |  |  | 		Email:     invite.Email, | 
					
						
							|  |  |  | 		Name:      invite.Name, | 
					
						
							|  |  |  | 		Username:  invite.Email, | 
					
						
							|  |  |  | 		InvitedBy: util.StringsFallback3(invite.InvitedByName, invite.InvitedByLogin, invite.InvitedByEmail), | 
					
						
							|  |  |  | 	}) | 
					
						
							| 
									
										
										
										
											2015-07-20 21:52:49 +08:00
										 |  |  | } | 
					
						
							| 
									
										
										
										
											2015-07-20 23:46:48 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | func CompleteInvite(c *middleware.Context, completeInvite dtos.CompleteInviteForm) Response { | 
					
						
							|  |  |  | 	query := m.GetTempUserByCodeQuery{Code: completeInvite.InviteCode} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	if err := bus.Dispatch(&query); err != nil { | 
					
						
							|  |  |  | 		if err == m.ErrTempUserNotFound { | 
					
						
							|  |  |  | 			return ApiError(404, "Invite not found", nil) | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 		return ApiError(500, "Failed to get invite", err) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	invite := query.Result | 
					
						
							| 
									
										
										
										
											2015-07-29 15:30:23 +08:00
										 |  |  | 	if invite.Status != m.TmpUserInvitePending { | 
					
						
							|  |  |  | 		return ApiError(412, fmt.Sprintf("Invite cannot be used in status %s", invite.Status), nil) | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2015-07-20 23:46:48 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | 	cmd := m.CreateUserCommand{ | 
					
						
							| 
									
										
										
										
											2015-09-01 18:35:06 +08:00
										 |  |  | 		Email:        completeInvite.Email, | 
					
						
							|  |  |  | 		Name:         completeInvite.Name, | 
					
						
							|  |  |  | 		Login:        completeInvite.Username, | 
					
						
							|  |  |  | 		Password:     completeInvite.Password, | 
					
						
							|  |  |  | 		SkipOrgSetup: true, | 
					
						
							| 
									
										
										
										
											2015-07-20 23:46:48 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	if err := bus.Dispatch(&cmd); err != nil { | 
					
						
							|  |  |  | 		return ApiError(500, "failed to create user", err) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-08-31 00:56:53 +08:00
										 |  |  | 	user := &cmd.Result | 
					
						
							| 
									
										
										
										
											2015-07-20 23:46:48 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-08-27 19:59:58 +08:00
										 |  |  | 	bus.Publish(&events.SignUpCompleted{ | 
					
						
							| 
									
										
										
										
											2015-08-28 21:14:24 +08:00
										 |  |  | 		Name:  user.NameOrFallback(), | 
					
						
							| 
									
										
										
										
											2015-07-20 23:46:48 +08:00
										 |  |  | 		Email: user.Email, | 
					
						
							|  |  |  | 	}) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-08-31 00:56:53 +08:00
										 |  |  | 	if ok, rsp := applyUserInvite(user, invite, true); !ok { | 
					
						
							|  |  |  | 		return rsp | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	loginUserWithUser(user, c) | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	metrics.M_Api_User_SignUpCompleted.Inc(1) | 
					
						
							|  |  |  | 	metrics.M_Api_User_SignUpInvite.Inc(1) | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	return ApiSuccess("User created and logged in") | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | func updateTempUserStatus(code string, status m.TempUserStatus) (bool, Response) { | 
					
						
							|  |  |  | 	// update temp user status
 | 
					
						
							|  |  |  | 	updateTmpUserCmd := m.UpdateTempUserStatusCommand{Code: code, Status: status} | 
					
						
							|  |  |  | 	if err := bus.Dispatch(&updateTmpUserCmd); err != nil { | 
					
						
							|  |  |  | 		return false, ApiError(500, "Failed to update invite status", err) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	return true, nil | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | func applyUserInvite(user *m.User, invite *m.TempUserDTO, setActive bool) (bool, Response) { | 
					
						
							| 
									
										
										
										
											2015-08-11 16:45:03 +08:00
										 |  |  | 	// add to org
 | 
					
						
							|  |  |  | 	addOrgUserCmd := m.AddOrgUserCommand{OrgId: invite.OrgId, UserId: user.Id, Role: invite.Role} | 
					
						
							|  |  |  | 	if err := bus.Dispatch(&addOrgUserCmd); err != nil { | 
					
						
							| 
									
										
										
										
											2015-08-17 16:55:52 +08:00
										 |  |  | 		if err != m.ErrOrgUserAlreadyAdded { | 
					
						
							| 
									
										
										
										
											2015-08-31 00:56:53 +08:00
										 |  |  | 			return false, ApiError(500, "Error while trying to create org user", err) | 
					
						
							| 
									
										
										
										
											2015-08-17 16:55:52 +08:00
										 |  |  | 		} | 
					
						
							| 
									
										
										
										
											2015-08-11 16:45:03 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-07-20 23:46:48 +08:00
										 |  |  | 	// update temp user status
 | 
					
						
							| 
									
										
										
										
											2015-08-31 00:56:53 +08:00
										 |  |  | 	if ok, rsp := updateTempUserStatus(invite.Code, m.TmpUserCompleted); !ok { | 
					
						
							|  |  |  | 		return false, rsp | 
					
						
							| 
									
										
										
										
											2015-07-20 23:46:48 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-08-31 00:56:53 +08:00
										 |  |  | 	if setActive { | 
					
						
							|  |  |  | 		// set org to active
 | 
					
						
							|  |  |  | 		if err := bus.Dispatch(&m.SetUsingOrgCommand{OrgId: invite.OrgId, UserId: user.Id}); err != nil { | 
					
						
							|  |  |  | 			return false, ApiError(500, "Failed to set org as active", err) | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2015-07-20 23:46:48 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-08-31 00:56:53 +08:00
										 |  |  | 	return true, nil | 
					
						
							| 
									
										
										
										
											2015-07-20 23:46:48 +08:00
										 |  |  | } |