| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | package api | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | import ( | 
					
						
							| 
									
										
										
										
											2021-10-04 21:46:09 +08:00
										 |  |  | 	"context" | 
					
						
							| 
									
										
										
										
											2020-11-19 20:34:28 +08:00
										 |  |  | 	"errors" | 
					
						
							| 
									
										
										
										
											2022-01-05 16:59:17 +08:00
										 |  |  | 	"fmt" | 
					
						
							| 
									
										
										
										
											2021-11-29 17:18:01 +08:00
										 |  |  | 	"net/http" | 
					
						
							| 
									
										
										
										
											2022-01-15 00:55:57 +08:00
										 |  |  | 	"strconv" | 
					
						
							| 
									
										
										
										
											2020-11-19 20:34:28 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-08-18 20:49:04 +08:00
										 |  |  | 	"github.com/grafana/grafana/pkg/api/dtos" | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 	"github.com/grafana/grafana/pkg/api/response" | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	"github.com/grafana/grafana/pkg/models" | 
					
						
							| 
									
										
										
										
											2022-01-05 16:59:17 +08:00
										 |  |  | 	"github.com/grafana/grafana/pkg/services/accesscontrol" | 
					
						
							| 
									
										
										
										
											2016-04-10 01:27:06 +08:00
										 |  |  | 	"github.com/grafana/grafana/pkg/setting" | 
					
						
							| 
									
										
										
										
											2015-02-19 23:09:49 +08:00
										 |  |  | 	"github.com/grafana/grafana/pkg/util" | 
					
						
							| 
									
										
										
										
											2021-11-29 17:18:01 +08:00
										 |  |  | 	"github.com/grafana/grafana/pkg/web" | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | ) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-05-18 23:28:15 +08:00
										 |  |  | // GET /api/user  (current authenticated user)
 | 
					
						
							| 
									
										
										
										
											2022-01-05 16:59:17 +08:00
										 |  |  | func (hs *HTTPServer) GetSignedInUser(c *models.ReqContext) response.Response { | 
					
						
							|  |  |  | 	return hs.getUserUserProfile(c, c.UserId) | 
					
						
							| 
									
										
										
										
											2015-05-18 23:28:15 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-01-31 13:25:55 +08:00
										 |  |  | // GET /api/users/:id
 | 
					
						
							| 
									
										
										
										
											2022-01-05 16:59:17 +08:00
										 |  |  | func (hs *HTTPServer) GetUserByID(c *models.ReqContext) response.Response { | 
					
						
							| 
									
										
										
										
											2022-01-15 00:55:57 +08:00
										 |  |  | 	id, err := strconv.ParseInt(web.Params(c.Req)[":id"], 10, 64) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		return response.Error(http.StatusBadRequest, "id is invalid", err) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 	return hs.getUserUserProfile(c, id) | 
					
						
							| 
									
										
										
										
											2015-05-18 23:28:15 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-05 16:59:17 +08:00
										 |  |  | func (hs *HTTPServer) getUserUserProfile(c *models.ReqContext, userID int64) response.Response { | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	query := models.GetUserProfileQuery{UserId: userID} | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.SQLStore.GetUserProfile(c.Req.Context(), &query); err != nil { | 
					
						
							| 
									
										
										
										
											2020-11-19 20:34:28 +08:00
										 |  |  | 		if errors.Is(err, models.ErrUserNotFound) { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 			return response.Error(404, models.ErrUserNotFound.Error(), nil) | 
					
						
							| 
									
										
										
										
											2017-01-31 13:25:55 +08:00
										 |  |  | 		} | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(500, "Failed to get user", err) | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	getAuthQuery := models.GetAuthInfoQuery{UserId: userID} | 
					
						
							| 
									
										
										
										
											2019-07-10 17:06:51 +08:00
										 |  |  | 	query.Result.AuthLabels = []string{} | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.authInfoService.GetAuthInfo(c.Req.Context(), &getAuthQuery); err == nil { | 
					
						
							| 
									
										
										
										
											2019-07-10 17:06:51 +08:00
										 |  |  | 		authLabel := GetAuthProviderLabel(getAuthQuery.Result.AuthModule) | 
					
						
							|  |  |  | 		query.Result.AuthLabels = append(query.Result.AuthLabels, authLabel) | 
					
						
							|  |  |  | 		query.Result.IsExternal = true | 
					
						
							| 
									
										
										
										
											2019-06-25 23:29:07 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-05 16:59:17 +08:00
										 |  |  | 	accessControlMetadata, errAC := hs.getGlobalUserAccessControlMetadata(c, userID) | 
					
						
							|  |  |  | 	if errAC != nil { | 
					
						
							|  |  |  | 		hs.log.Error("Failed to get access control metadata", "error", errAC) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	query.Result.AccessControl = accessControlMetadata | 
					
						
							| 
									
										
										
										
											2020-01-14 00:10:19 +08:00
										 |  |  | 	query.Result.AvatarUrl = dtos.GetGravatarUrl(query.Result.Email) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 	return response.JSON(200, query.Result) | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-05 16:59:17 +08:00
										 |  |  | func (hs *HTTPServer) getGlobalUserAccessControlMetadata(c *models.ReqContext, userID int64) (accesscontrol.Metadata, error) { | 
					
						
							|  |  |  | 	if hs.AccessControl == nil || hs.AccessControl.IsDisabled() || !c.QueryBool("accesscontrol") { | 
					
						
							|  |  |  | 		return nil, nil | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	userPermissions, err := hs.AccessControl.GetUserPermissions(c.Req.Context(), c.SignedInUser) | 
					
						
							|  |  |  | 	if err != nil || len(userPermissions) == 0 { | 
					
						
							|  |  |  | 		return nil, err | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	key := fmt.Sprintf("%d", userID) | 
					
						
							|  |  |  | 	userIDs := map[string]bool{key: true} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-06 00:24:14 +08:00
										 |  |  | 	return accesscontrol.GetResourcesMetadata(c.Req.Context(), userPermissions, "global:users", userIDs)[key], nil | 
					
						
							| 
									
										
										
										
											2022-01-05 16:59:17 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-01-31 13:25:55 +08:00
										 |  |  | // GET /api/users/lookup
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) GetUserByLoginOrEmail(c *models.ReqContext) response.Response { | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	query := models.GetUserByLoginQuery{LoginOrEmail: c.Query("loginOrEmail")} | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.SQLStore.GetUserByLogin(c.Req.Context(), &query); err != nil { | 
					
						
							| 
									
										
										
										
											2020-11-19 20:34:28 +08:00
										 |  |  | 		if errors.Is(err, models.ErrUserNotFound) { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 			return response.Error(404, models.ErrUserNotFound.Error(), nil) | 
					
						
							| 
									
										
										
										
											2017-01-31 13:25:55 +08:00
										 |  |  | 		} | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(500, "Failed to get user", err) | 
					
						
							| 
									
										
										
										
											2017-01-31 13:25:55 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 	user := query.Result | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	result := models.UserProfileDTO{ | 
					
						
							| 
									
										
										
										
											2017-06-25 20:23:03 +08:00
										 |  |  | 		Id:             user.Id, | 
					
						
							| 
									
										
										
										
											2017-01-31 13:25:55 +08:00
										 |  |  | 		Name:           user.Name, | 
					
						
							|  |  |  | 		Email:          user.Email, | 
					
						
							|  |  |  | 		Login:          user.Login, | 
					
						
							|  |  |  | 		Theme:          user.Theme, | 
					
						
							|  |  |  | 		IsGrafanaAdmin: user.IsAdmin, | 
					
						
							|  |  |  | 		OrgId:          user.OrgId, | 
					
						
							| 
									
										
										
										
											2019-10-01 03:54:09 +08:00
										 |  |  | 		UpdatedAt:      user.Updated, | 
					
						
							|  |  |  | 		CreatedAt:      user.Created, | 
					
						
							| 
									
										
										
										
											2017-01-31 13:25:55 +08:00
										 |  |  | 	} | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 	return response.JSON(200, &result) | 
					
						
							| 
									
										
										
										
											2017-01-31 13:25:55 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-05-19 01:06:19 +08:00
										 |  |  | // POST /api/user
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) UpdateSignedInUser(c *models.ReqContext) response.Response { | 
					
						
							| 
									
										
										
										
											2021-11-29 17:18:01 +08:00
										 |  |  | 	cmd := models.UpdateUserCommand{} | 
					
						
							|  |  |  | 	if err := web.Bind(c.Req, &cmd); err != nil { | 
					
						
							|  |  |  | 		return response.Error(http.StatusBadRequest, "bad request data", err) | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2016-12-15 05:19:25 +08:00
										 |  |  | 	if setting.AuthProxyEnabled { | 
					
						
							|  |  |  | 		if setting.AuthProxyHeaderProperty == "email" && cmd.Email != c.Email { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 			return response.Error(400, "Not allowed to change email when auth proxy is using email property", nil) | 
					
						
							| 
									
										
										
										
											2016-12-15 05:19:25 +08:00
										 |  |  | 		} | 
					
						
							|  |  |  | 		if setting.AuthProxyHeaderProperty == "username" && cmd.Login != c.Login { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 			return response.Error(400, "Not allowed to change username when auth proxy is using username property", nil) | 
					
						
							| 
									
										
										
										
											2016-12-15 05:19:25 +08:00
										 |  |  | 		} | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 	cmd.UserId = c.UserId | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	return hs.handleUpdateUser(c.Req.Context(), cmd) | 
					
						
							| 
									
										
										
										
											2015-05-19 01:06:19 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | // POST /api/users/:id
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) UpdateUser(c *models.ReqContext) response.Response { | 
					
						
							| 
									
										
										
										
											2021-11-29 17:18:01 +08:00
										 |  |  | 	cmd := models.UpdateUserCommand{} | 
					
						
							| 
									
										
										
										
											2022-01-15 00:55:57 +08:00
										 |  |  | 	var err error | 
					
						
							| 
									
										
										
										
											2021-11-29 17:18:01 +08:00
										 |  |  | 	if err := web.Bind(c.Req, &cmd); err != nil { | 
					
						
							|  |  |  | 		return response.Error(http.StatusBadRequest, "bad request data", err) | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2022-01-15 00:55:57 +08:00
										 |  |  | 	cmd.UserId, err = strconv.ParseInt(web.Params(c.Req)[":id"], 10, 64) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		return response.Error(http.StatusBadRequest, "id is invalid", err) | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	return hs.handleUpdateUser(c.Req.Context(), cmd) | 
					
						
							| 
									
										
										
										
											2015-05-19 01:06:19 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-09-22 22:22:19 +08:00
										 |  |  | // POST /api/users/:id/using/:orgId
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) UpdateUserActiveOrg(c *models.ReqContext) response.Response { | 
					
						
							| 
									
										
										
										
											2022-01-15 00:55:57 +08:00
										 |  |  | 	userID, err := strconv.ParseInt(web.Params(c.Req)[":id"], 10, 64) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		return response.Error(http.StatusBadRequest, "id is invalid", err) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 	orgID, err := strconv.ParseInt(web.Params(c.Req)[":orgId"], 10, 64) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		return response.Error(http.StatusBadRequest, "orgId is invalid", err) | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2016-05-26 12:51:23 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if !hs.validateUsingOrg(c.Req.Context(), userID, orgID) { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(401, "Not a valid organization", nil) | 
					
						
							| 
									
										
										
										
											2016-05-26 12:51:23 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	cmd := models.SetUsingOrgCommand{UserId: userID, OrgId: orgID} | 
					
						
							| 
									
										
										
										
											2016-05-26 12:51:23 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.SQLStore.SetUsingOrg(c.Req.Context(), &cmd); err != nil { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(500, "Failed to change active organization", err) | 
					
						
							| 
									
										
										
										
											2016-05-26 12:51:23 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 	return response.Success("Active organization changed") | 
					
						
							| 
									
										
										
										
											2016-05-26 12:51:23 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) handleUpdateUser(ctx context.Context, cmd models.UpdateUserCommand) response.Response { | 
					
						
							| 
									
										
										
										
											2015-05-19 01:06:19 +08:00
										 |  |  | 	if len(cmd.Login) == 0 { | 
					
						
							|  |  |  | 		cmd.Login = cmd.Email | 
					
						
							|  |  |  | 		if len(cmd.Login) == 0 { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 			return response.Error(400, "Validation error, need to specify either username or email", nil) | 
					
						
							| 
									
										
										
										
											2015-05-19 01:06:19 +08:00
										 |  |  | 		} | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.SQLStore.UpdateUser(ctx, &cmd); err != nil { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(500, "Failed to update user", err) | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 	return response.Success("User updated") | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-05-18 23:28:15 +08:00
										 |  |  | // GET /api/user/orgs
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) GetSignedInUserOrgList(c *models.ReqContext) response.Response { | 
					
						
							|  |  |  | 	return hs.getUserOrgList(c.Req.Context(), c.UserId) | 
					
						
							| 
									
										
										
										
											2015-05-18 23:28:15 +08:00
										 |  |  | } | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-08-08 16:26:05 +08:00
										 |  |  | // GET /api/user/teams
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) GetSignedInUserTeamList(c *models.ReqContext) response.Response { | 
					
						
							|  |  |  | 	return hs.getUserTeamList(c.Req.Context(), c.OrgId, c.UserId) | 
					
						
							| 
									
										
										
										
											2018-11-19 17:08:10 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | // GET /api/users/:id/teams
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) GetUserTeams(c *models.ReqContext) response.Response { | 
					
						
							| 
									
										
										
										
											2022-01-15 00:55:57 +08:00
										 |  |  | 	id, err := strconv.ParseInt(web.Params(c.Req)[":id"], 10, 64) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		return response.Error(http.StatusBadRequest, "id is invalid", err) | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	return hs.getUserTeamList(c.Req.Context(), c.OrgId, id) | 
					
						
							| 
									
										
										
										
											2018-11-19 17:08:10 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) getUserTeamList(ctx context.Context, orgID int64, userID int64) response.Response { | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	query := models.GetTeamsByUserQuery{OrgId: orgID, UserId: userID} | 
					
						
							| 
									
										
										
										
											2018-08-08 16:26:05 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.SQLStore.GetTeamsByUser(ctx, &query); err != nil { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(500, "Failed to get user teams", err) | 
					
						
							| 
									
										
										
										
											2018-08-08 16:26:05 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	for _, team := range query.Result { | 
					
						
							|  |  |  | 		team.AvatarUrl = dtos.GetGravatarUrlWithDefault(team.Email, team.Name) | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 	return response.JSON(200, query.Result) | 
					
						
							| 
									
										
										
										
											2018-08-08 16:26:05 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-11-19 17:08:10 +08:00
										 |  |  | // GET /api/users/:id/orgs
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) GetUserOrgList(c *models.ReqContext) response.Response { | 
					
						
							| 
									
										
										
										
											2022-01-15 00:55:57 +08:00
										 |  |  | 	id, err := strconv.ParseInt(web.Params(c.Req)[":id"], 10, 64) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		return response.Error(http.StatusBadRequest, "id is invalid", err) | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	return hs.getUserOrgList(c.Req.Context(), id) | 
					
						
							| 
									
										
										
										
											2015-05-18 23:28:15 +08:00
										 |  |  | } | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) getUserOrgList(ctx context.Context, userID int64) response.Response { | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	query := models.GetUserOrgListQuery{UserId: userID} | 
					
						
							| 
									
										
										
										
											2015-05-18 23:28:15 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.SQLStore.GetUserOrgList(ctx, &query); err != nil { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(500, "Failed to get user organizations", err) | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 	return response.JSON(200, query.Result) | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) validateUsingOrg(ctx context.Context, userID int64, orgID int64) bool { | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	query := models.GetUserOrgListQuery{UserId: userID} | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.SQLStore.GetUserOrgList(ctx, &query); err != nil { | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 		return false | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-02-24 03:07:49 +08:00
										 |  |  | 	// validate that the org id in the list
 | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 	valid := false | 
					
						
							|  |  |  | 	for _, other := range query.Result { | 
					
						
							| 
									
										
										
										
											2018-03-22 19:37:35 +08:00
										 |  |  | 		if other.OrgId == orgID { | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 			valid = true | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	return valid | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-05-20 20:59:38 +08:00
										 |  |  | // POST /api/user/using/:id
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) UserSetUsingOrg(c *models.ReqContext) response.Response { | 
					
						
							| 
									
										
										
										
											2022-01-15 00:55:57 +08:00
										 |  |  | 	orgID, err := strconv.ParseInt(web.Params(c.Req)[":id"], 10, 64) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		return response.Error(http.StatusBadRequest, "id is invalid", err) | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if !hs.validateUsingOrg(c.Req.Context(), c.UserId, orgID) { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(401, "Not a valid organization", nil) | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	cmd := models.SetUsingOrgCommand{UserId: c.UserId, OrgId: orgID} | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.SQLStore.SetUsingOrg(c.Req.Context(), &cmd); err != nil { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(500, "Failed to change active organization", err) | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 	return response.Success("Active organization changed") | 
					
						
							| 
									
										
										
										
											2015-01-20 01:01:04 +08:00
										 |  |  | } | 
					
						
							| 
									
										
										
										
											2015-02-19 23:09:49 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-04-10 01:27:06 +08:00
										 |  |  | // GET /profile/switch-org/:id
 | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | func (hs *HTTPServer) ChangeActiveOrgAndRedirectToHome(c *models.ReqContext) { | 
					
						
							| 
									
										
										
										
											2022-01-15 00:55:57 +08:00
										 |  |  | 	orgID, err := strconv.ParseInt(web.Params(c.Req)[":id"], 10, 64) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		c.JsonApiErr(http.StatusBadRequest, "id is invalid", err) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2016-04-10 01:27:06 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if !hs.validateUsingOrg(c.Req.Context(), c.UserId, orgID) { | 
					
						
							| 
									
										
										
										
											2018-10-12 17:26:42 +08:00
										 |  |  | 		hs.NotFoundHandler(c) | 
					
						
							| 
									
										
										
										
											2016-04-10 01:27:06 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	cmd := models.SetUsingOrgCommand{UserId: c.UserId, OrgId: orgID} | 
					
						
							| 
									
										
										
										
											2016-04-10 01:27:06 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.SQLStore.SetUsingOrg(c.Req.Context(), &cmd); err != nil { | 
					
						
							| 
									
										
										
										
											2018-10-12 17:26:42 +08:00
										 |  |  | 		hs.NotFoundHandler(c) | 
					
						
							| 
									
										
										
										
											2016-04-10 01:27:06 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-03-10 19:41:29 +08:00
										 |  |  | 	c.Redirect(hs.Cfg.AppSubURL + "/") | 
					
						
							| 
									
										
										
										
											2016-04-10 01:27:06 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) ChangeUserPassword(c *models.ReqContext) response.Response { | 
					
						
							| 
									
										
										
										
											2021-11-29 17:18:01 +08:00
										 |  |  | 	cmd := models.ChangeUserPasswordCommand{} | 
					
						
							|  |  |  | 	if err := web.Bind(c.Req, &cmd); err != nil { | 
					
						
							|  |  |  | 		return response.Error(http.StatusBadRequest, "bad request data", err) | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2019-05-22 20:30:03 +08:00
										 |  |  | 	if setting.LDAPEnabled || setting.AuthProxyEnabled { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(400, "Not allowed to change password when LDAP or Auth Proxy is enabled", nil) | 
					
						
							| 
									
										
										
										
											2016-12-15 05:19:25 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	userQuery := models.GetUserByIdQuery{Id: c.UserId} | 
					
						
							| 
									
										
										
										
											2015-02-19 23:09:49 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.SQLStore.GetUserById(c.Req.Context(), &userQuery); err != nil { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(500, "Could not read user from database", err) | 
					
						
							| 
									
										
										
										
											2015-02-19 23:09:49 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-10-23 16:40:12 +08:00
										 |  |  | 	passwordHashed, err := util.EncodePassword(cmd.OldPassword, userQuery.Result.Salt) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(500, "Failed to encode password", err) | 
					
						
							| 
									
										
										
										
											2019-10-23 16:40:12 +08:00
										 |  |  | 	} | 
					
						
							| 
									
										
										
										
											2015-02-19 23:09:49 +08:00
										 |  |  | 	if passwordHashed != userQuery.Result.Password { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(401, "Invalid old password", nil) | 
					
						
							| 
									
										
										
										
											2015-02-19 23:09:49 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	password := models.Password(cmd.NewPassword) | 
					
						
							| 
									
										
										
										
											2016-12-09 22:25:02 +08:00
										 |  |  | 	if password.IsWeak() { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(400, "New password is too short", nil) | 
					
						
							| 
									
										
										
										
											2015-02-19 23:09:49 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	cmd.UserId = c.UserId | 
					
						
							| 
									
										
										
										
											2019-10-23 16:40:12 +08:00
										 |  |  | 	cmd.NewPassword, err = util.EncodePassword(cmd.NewPassword, userQuery.Result.Salt) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(500, "Failed to encode password", err) | 
					
						
							| 
									
										
										
										
											2019-10-23 16:40:12 +08:00
										 |  |  | 	} | 
					
						
							| 
									
										
										
										
											2015-02-19 23:09:49 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.SQLStore.ChangeUserPassword(c.Req.Context(), &cmd); err != nil { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(500, "Failed to change user password", err) | 
					
						
							| 
									
										
										
										
											2015-02-19 23:09:49 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 	return response.Success("User password changed") | 
					
						
							| 
									
										
										
										
											2015-02-19 23:09:49 +08:00
										 |  |  | } | 
					
						
							| 
									
										
										
										
											2015-05-19 17:47:14 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-11-11 06:36:35 +08:00
										 |  |  | // redirectToChangePassword handles GET /.well-known/change-password.
 | 
					
						
							|  |  |  | func redirectToChangePassword(c *models.ReqContext) { | 
					
						
							|  |  |  | 	c.Redirect("/profile/password", 302) | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) SetHelpFlag(c *models.ReqContext) response.Response { | 
					
						
							| 
									
										
										
										
											2022-01-15 00:55:57 +08:00
										 |  |  | 	flag, err := strconv.ParseInt(web.Params(c.Req)[":id"], 10, 64) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		return response.Error(http.StatusBadRequest, "id is invalid", err) | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2016-11-09 17:41:39 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | 	bitmask := &c.HelpFlags1 | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	bitmask.AddFlag(models.HelpFlags1(flag)) | 
					
						
							| 
									
										
										
										
											2016-11-09 17:41:39 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	cmd := models.SetUserHelpFlagCommand{ | 
					
						
							| 
									
										
										
										
											2016-11-09 17:41:39 +08:00
										 |  |  | 		UserId:     c.UserId, | 
					
						
							|  |  |  | 		HelpFlags1: *bitmask, | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.SQLStore.SetUserHelpFlag(c.Req.Context(), &cmd); err != nil { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(500, "Failed to update help flag", err) | 
					
						
							| 
									
										
										
										
											2016-11-09 17:41:39 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 	return response.JSON(200, &util.DynMap{"message": "Help flag set", "helpFlags1": cmd.HelpFlags1}) | 
					
						
							| 
									
										
										
										
											2016-11-09 17:41:39 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | func (hs *HTTPServer) ClearHelpFlags(c *models.ReqContext) response.Response { | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 	cmd := models.SetUserHelpFlagCommand{ | 
					
						
							| 
									
										
										
										
											2016-11-09 17:41:39 +08:00
										 |  |  | 		UserId:     c.UserId, | 
					
						
							| 
									
										
										
										
											2020-03-04 19:57:20 +08:00
										 |  |  | 		HelpFlags1: models.HelpFlags1(0), | 
					
						
							| 
									
										
										
										
											2016-11-09 17:41:39 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-27 03:24:05 +08:00
										 |  |  | 	if err := hs.SQLStore.SetUserHelpFlag(c.Req.Context(), &cmd); err != nil { | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 		return response.Error(500, "Failed to update help flag", err) | 
					
						
							| 
									
										
										
										
											2016-11-09 17:41:39 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-01-15 21:43:20 +08:00
										 |  |  | 	return response.JSON(200, &util.DynMap{"message": "Help flag set", "helpFlags1": cmd.HelpFlags1}) | 
					
						
							| 
									
										
										
										
											2016-11-09 17:41:39 +08:00
										 |  |  | } | 
					
						
							| 
									
										
										
										
											2019-07-10 17:06:51 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | func GetAuthProviderLabel(authModule string) string { | 
					
						
							|  |  |  | 	switch authModule { | 
					
						
							|  |  |  | 	case "oauth_github": | 
					
						
							|  |  |  | 		return "GitHub" | 
					
						
							|  |  |  | 	case "oauth_google": | 
					
						
							|  |  |  | 		return "Google" | 
					
						
							| 
									
										
										
										
											2020-02-13 17:12:25 +08:00
										 |  |  | 	case "oauth_azuread": | 
					
						
							|  |  |  | 		return "AzureAD" | 
					
						
							| 
									
										
										
										
											2019-07-10 17:06:51 +08:00
										 |  |  | 	case "oauth_gitlab": | 
					
						
							|  |  |  | 		return "GitLab" | 
					
						
							|  |  |  | 	case "oauth_grafana_com", "oauth_grafananet": | 
					
						
							|  |  |  | 		return "grafana.com" | 
					
						
							| 
									
										
										
										
											2019-07-19 22:13:29 +08:00
										 |  |  | 	case "auth.saml": | 
					
						
							|  |  |  | 		return "SAML" | 
					
						
							| 
									
										
										
										
											2019-07-10 17:06:51 +08:00
										 |  |  | 	case "ldap", "": | 
					
						
							|  |  |  | 		return "LDAP" | 
					
						
							|  |  |  | 	default: | 
					
						
							|  |  |  | 		return "OAuth" | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | } |