harbor/src/ui/api/member.go

272 lines
7.8 KiB
Go
Raw Normal View History

2017-04-13 18:54:58 +08:00
// Copyright (c) 2017 VMware, Inc. All Rights Reserved.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
2016-02-26 18:54:14 +08:00
2016-02-01 19:59:10 +08:00
package api
import (
2016-10-27 14:16:23 +08:00
"fmt"
"net/http"
"strings"
2018-02-06 10:59:49 +08:00
"github.com/vmware/harbor/src/common"
2016-10-19 14:32:00 +08:00
"github.com/vmware/harbor/src/common/dao"
"github.com/vmware/harbor/src/common/models"
"github.com/vmware/harbor/src/common/utils/log"
"github.com/vmware/harbor/src/ui/auth"
2016-02-01 19:59:10 +08:00
)
2018-02-06 10:59:49 +08:00
// ProjectUserMemberAPI handles request to /api/projects/{}/members/{}
type ProjectUserMemberAPI struct {
2017-05-19 17:06:14 +08:00
BaseController
memberID int
currentUserID int
2016-02-01 19:59:10 +08:00
project *models.Project
}
type memberReq struct {
2016-06-01 15:17:05 +08:00
Username string `json:"username"`
UserID int `json:"user_id"`
2016-02-01 19:59:10 +08:00
Roles []int `json:"roles"`
}
2016-02-26 18:35:55 +08:00
// Prepare validates the URL and parms
2018-02-06 10:59:49 +08:00
func (pma *ProjectUserMemberAPI) Prepare() {
2017-05-19 17:06:14 +08:00
pma.BaseController.Prepare()
if !pma.SecurityCtx.IsAuthenticated() {
pma.HandleUnauthorized()
return
}
user, err := dao.GetUser(models.User{
Username: pma.SecurityCtx.GetUsername(),
})
2016-02-01 19:59:10 +08:00
if err != nil {
2017-05-19 17:06:14 +08:00
pma.HandleInternalServerError(
fmt.Sprintf("failed to get user %s: %v",
pma.SecurityCtx.GetUsername(), err))
2016-02-01 19:59:10 +08:00
return
}
2017-05-19 17:06:14 +08:00
pma.currentUserID = user.UserID
pid, err := pma.GetInt64FromPath(":pid")
if err != nil || pid <= 0 {
text := "invalid project ID: "
if err != nil {
text += err.Error()
} else {
text += fmt.Sprintf("%d", pid)
}
2017-07-10 18:17:58 +08:00
pma.HandleBadRequest(text)
return
2017-05-19 17:06:14 +08:00
}
project, err := pma.ProjectMgr.Get(pid)
2016-02-01 19:59:10 +08:00
if err != nil {
pma.ParseAndHandleError(fmt.Sprintf("failed to get project %d", pid), err)
2017-05-19 17:06:14 +08:00
return
}
if project == nil {
pma.HandleNotFound(fmt.Sprintf("project %d not found", pid))
return
2016-02-01 19:59:10 +08:00
}
2017-05-19 17:06:14 +08:00
pma.project = project
2016-02-01 19:59:10 +08:00
2017-07-12 19:17:26 +08:00
if !(pma.Ctx.Input.IsGet() && pma.SecurityCtx.HasReadPerm(pid) ||
pma.SecurityCtx.HasAllPerm(pid)) {
2017-05-19 17:06:14 +08:00
pma.HandleForbidden(pma.SecurityCtx.GetUsername())
return
2016-02-01 19:59:10 +08:00
}
2017-05-19 17:06:14 +08:00
if len(pma.GetStringFromPath(":mid")) != 0 {
mid, err := pma.GetInt64FromPath(":mid")
if err != nil || mid <= 0 {
text := "invalid member ID: "
if err != nil {
text += err.Error()
} else {
text += fmt.Sprintf("%d", mid)
}
pma.HandleBadRequest(text)
return
}
member, err := dao.GetUser(models.User{
UserID: int(mid),
})
2016-02-01 19:59:10 +08:00
if err != nil {
2017-05-19 17:06:14 +08:00
pma.HandleInternalServerError(fmt.Sprintf("failed to get user %d: %v", mid, err))
return
}
if member == nil {
pma.HandleNotFound(fmt.Sprintf("member %d not found", mid))
return
2016-02-01 19:59:10 +08:00
}
2017-05-19 17:06:14 +08:00
pma.memberID = member.UserID
2016-02-01 19:59:10 +08:00
}
}
2016-02-26 18:35:55 +08:00
// Get ...
2018-02-06 10:59:49 +08:00
func (pma *ProjectUserMemberAPI) Get() {
2016-02-26 10:15:01 +08:00
pid := pma.project.ProjectID
if pma.memberID == 0 { //member id not set return list of the members
2016-02-01 19:59:10 +08:00
username := pma.GetString("username")
2016-11-16 20:25:40 +08:00
queryUser := models.User{Username: username}
2016-02-24 18:16:16 +08:00
userList, err := dao.GetUserByProject(pid, queryUser)
2016-02-01 19:59:10 +08:00
if err != nil {
2016-03-28 08:50:09 +08:00
log.Errorf("Failed to query database for member list, error: %v", err)
pma.RenderError(http.StatusInternalServerError, "Internal Server Error")
2016-02-01 19:59:10 +08:00
return
}
pma.Data["json"] = userList
} else { //return detail of a member
2018-02-06 10:59:49 +08:00
roleList, err := listRoles(pma.memberID, pid, common.UserMember)
2016-02-01 19:59:10 +08:00
if err != nil {
2016-03-28 08:50:09 +08:00
log.Errorf("Error occurred in GetUserProjectRoles, error: %v", err)
pma.CustomAbort(http.StatusInternalServerError, "Internal error.")
2016-02-01 19:59:10 +08:00
}
2016-10-27 14:16:23 +08:00
if len(roleList) == 0 {
pma.CustomAbort(http.StatusNotFound, fmt.Sprintf("user %d is not a member of the project", pma.memberID))
}
2016-02-01 19:59:10 +08:00
//return empty role list to indicate if a user is not a member
result := make(map[string]interface{})
2016-02-26 10:15:01 +08:00
user, err := dao.GetUser(models.User{UserID: pma.memberID})
2016-02-01 19:59:10 +08:00
if err != nil {
2016-03-28 08:50:09 +08:00
log.Errorf("Error occurred in GetUser, error: %v", err)
pma.CustomAbort(http.StatusInternalServerError, "Internal error.")
2016-02-01 19:59:10 +08:00
}
2016-06-01 15:17:05 +08:00
result["username"] = user.Username
result["user_id"] = pma.memberID
2016-02-01 19:59:10 +08:00
result["roles"] = roleList
pma.Data["json"] = result
}
pma.ServeJSON()
}
2016-02-26 18:35:55 +08:00
// Post ...
2018-02-06 10:59:49 +08:00
func (pma *ProjectUserMemberAPI) Post() {
projectID := pma.project.ProjectID
2016-03-29 12:09:27 +08:00
2016-02-01 19:59:10 +08:00
var req memberReq
pma.DecodeJSONReq(&req)
username := strings.TrimSpace(req.Username)
2016-02-26 18:35:55 +08:00
userID := checkUserExists(username)
if userID <= 0 {
user, err := auth.SearchUser(username)
2017-11-24 14:53:34 +08:00
if err != nil {
log.Errorf("Failed the search user, error: %v", err)
pma.RenderError(http.StatusInternalServerError, "Failed to search user")
2017-11-24 14:53:34 +08:00
return
}
if user == nil {
log.Errorf("Current user doesn't exist: %v", username)
pma.RenderError(http.StatusNotFound, "Failed to search user: "+username)
return
}
err = auth.OnBoardUser(user)
2017-11-24 14:53:34 +08:00
if err != nil {
log.Errorf("Failed the onboard user, error: %s", err)
pma.RenderError(http.StatusInternalServerError, "Failed to onboard user")
return
}
if user.UserID <= 0 {
log.Error("Failed the onboard user, UserId <=0")
pma.RenderError(http.StatusInternalServerError, "Failed to onboard user")
2017-11-24 14:53:34 +08:00
return
}
userID = user.UserID
2017-11-24 14:53:34 +08:00
2016-02-01 19:59:10 +08:00
}
2018-02-06 10:59:49 +08:00
rolelist, err := dao.GetUserProjectRoles(userID, projectID, common.UserMember)
2016-02-01 19:59:10 +08:00
if err != nil {
2016-03-28 08:50:09 +08:00
log.Errorf("Error occurred in GetUserProjectRoles, error: %v", err)
pma.CustomAbort(http.StatusInternalServerError, "Internal error.")
2016-02-01 19:59:10 +08:00
}
if len(rolelist) > 0 {
log.Warningf("user is already added to project, user id: %d, project id: %d", userID, projectID)
pma.RenderError(http.StatusConflict, "user is ready in project")
2016-02-01 19:59:10 +08:00
return
}
2016-09-19 17:58:29 +08:00
if len(req.Roles) <= 0 || len(req.Roles) > 1 {
pma.CustomAbort(http.StatusBadRequest, "only one role is supported")
}
rid := req.Roles[0]
if !(rid == models.PROJECTADMIN ||
rid == models.DEVELOPER ||
rid == models.GUEST) {
pma.CustomAbort(http.StatusBadRequest, "invalid role")
}
2018-02-06 10:59:49 +08:00
_, err = dao.AddProjectMember(projectID, userID, rid, common.UserMember)
2016-09-19 17:58:29 +08:00
if err != nil {
log.Errorf("Failed to update DB to add project user role, project id: %d, user id: %d, role id: %d", projectID, userID, rid)
pma.RenderError(http.StatusInternalServerError, "Failed to update data in database")
return
2016-02-01 19:59:10 +08:00
}
}
2016-02-26 18:35:55 +08:00
// Put ...
2018-02-06 10:59:49 +08:00
func (pma *ProjectUserMemberAPI) Put() {
2016-02-26 10:15:01 +08:00
pid := pma.project.ProjectID
mid := pma.memberID
2016-02-01 19:59:10 +08:00
var req memberReq
pma.DecodeJSONReq(&req)
2018-02-06 10:59:49 +08:00
roleList, err := dao.GetUserProjectRoles(mid, pid, common.UserMember)
2016-02-01 19:59:10 +08:00
if len(roleList) == 0 {
2016-03-28 08:50:09 +08:00
log.Warningf("User is not in project, user id: %d, project id: %d", mid, pid)
pma.RenderError(http.StatusNotFound, "user not exist in project")
2016-02-01 19:59:10 +08:00
return
}
//TODO: delete and insert should in one transaction
//delete user project role record for the given user
2018-02-06 10:59:49 +08:00
err = dao.DeleteProjectMember(pid, mid, common.UserMember)
2016-02-01 19:59:10 +08:00
if err != nil {
2016-03-28 08:50:09 +08:00
log.Errorf("Failed to delete project roles for user, user id: %d, project id: %d, error: %v", mid, pid, err)
pma.RenderError(http.StatusInternalServerError, "Failed to update data in DB")
2016-02-01 19:59:10 +08:00
return
}
//insert roles in request
for _, rid := range req.Roles {
2018-02-06 10:59:49 +08:00
_, err = dao.AddProjectMember(pid, mid, int(rid), common.UserMember)
2016-02-01 19:59:10 +08:00
if err != nil {
2016-03-28 08:50:09 +08:00
log.Errorf("Failed to update DB to add project user role, project id: %d, user id: %d, role id: %d", pid, mid, rid)
pma.RenderError(http.StatusInternalServerError, "Failed to update data in database")
2016-02-01 19:59:10 +08:00
return
}
}
}
2016-02-26 18:35:55 +08:00
// Delete ...
2018-02-06 10:59:49 +08:00
func (pma *ProjectUserMemberAPI) Delete() {
2016-02-26 10:15:01 +08:00
pid := pma.project.ProjectID
mid := pma.memberID
2018-02-06 10:59:49 +08:00
err := dao.DeleteProjectMember(pid, mid, common.UserMember)
2016-02-01 19:59:10 +08:00
if err != nil {
2016-03-28 08:50:09 +08:00
log.Errorf("Failed to delete project roles for user, user id: %d, project id: %d, error: %v", mid, pid, err)
pma.RenderError(http.StatusInternalServerError, "Failed to update data in DB")
2016-02-01 19:59:10 +08:00
return
}
}