user.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540
  1. package main
  2. /*
  3. User Management System
  4. Entry points for handler user functions
  5. */
  6. import (
  7. "encoding/base64"
  8. "encoding/json"
  9. "fmt"
  10. "image"
  11. "image/gif"
  12. "image/jpeg"
  13. "image/png"
  14. "net/http"
  15. "strconv"
  16. "strings"
  17. uuid "github.com/satori/go.uuid"
  18. auth "imuslab.com/arozos/mod/auth"
  19. module "imuslab.com/arozos/mod/modules"
  20. prout "imuslab.com/arozos/mod/prouter"
  21. user "imuslab.com/arozos/mod/user"
  22. "imuslab.com/arozos/mod/utils"
  23. )
  24. func UserSystemInit() {
  25. //Create a new User Handler
  26. uh, err := user.NewUserHandler(sysdb, authAgent, permissionHandler, baseStoragePool, &shareEntryTable)
  27. if err != nil {
  28. panic(err)
  29. }
  30. userHandler = uh
  31. /*
  32. router := prout.NewModuleRouter(prout.RouterOption{
  33. ModuleName: "System Settings",
  34. AdminOnly: false,
  35. UserHandler: userHandler,
  36. DeniedHandler: func(w http.ResponseWriter, r *http.Request) {
  37. utils.SendErrorResponse(w, "Permission Denied")
  38. },
  39. })
  40. */
  41. //Create Endpoint Listeners
  42. http.HandleFunc("/system/users/list", user_handleList)
  43. //Everyone logged in should have permission to view their profile and change their password
  44. http.HandleFunc("/system/users/userinfo", func(w http.ResponseWriter, r *http.Request) {
  45. authAgent.HandleCheckAuth(w, r, user_handleUserInfo)
  46. })
  47. //Interface info should be able to view by everyone logged in
  48. http.HandleFunc("/system/users/interfaceinfo", func(w http.ResponseWriter, r *http.Request) {
  49. authAgent.HandleCheckAuth(w, r, user_getInterfaceInfo)
  50. })
  51. //API for loading other users thumbnail as image file
  52. http.HandleFunc("/system/users/profilepic", func(w http.ResponseWriter, r *http.Request) {
  53. authAgent.HandleCheckAuth(w, r, user_getProfilePic)
  54. })
  55. //Register setting interface for module configuration
  56. registerSetting(settingModule{
  57. Name: "My Account",
  58. Desc: "Manage your account and password",
  59. IconPath: "SystemAO/users/img/small_icon.png",
  60. Group: "Users",
  61. StartDir: "SystemAO/users/account.html",
  62. RequireAdmin: false,
  63. })
  64. registerSetting(settingModule{
  65. Name: "User List",
  66. Desc: "A list of users registered on this system",
  67. IconPath: "SystemAO/users/img/small_icon.png",
  68. Group: "Users",
  69. StartDir: "SystemAO/users/userList.html",
  70. RequireAdmin: true,
  71. })
  72. //Register auth management events that requires user handler
  73. adminRouter := prout.NewModuleRouter(prout.RouterOption{
  74. ModuleName: "System Settings",
  75. AdminOnly: true,
  76. UserHandler: userHandler,
  77. DeniedHandler: func(w http.ResponseWriter, r *http.Request) {
  78. utils.SendErrorResponse(w, "Permission Denied")
  79. },
  80. })
  81. //Handle Authentication Unregister Handler
  82. adminRouter.HandleFunc("/system/auth/unregister", authAgent.HandleUnregister)
  83. adminRouter.HandleFunc("/system/users/editUser", user_handleUserEdit)
  84. adminRouter.HandleFunc("/system/users/removeUser", user_handleUserRemove)
  85. }
  86. // Remove a user from the system
  87. func user_handleUserRemove(w http.ResponseWriter, r *http.Request) {
  88. // Check if multiple usernames are provided (new format)
  89. usernamesJSON, err := utils.PostPara(r, "usernames")
  90. var usernames []string
  91. if err == nil && usernamesJSON != "" {
  92. // New format: multiple usernames as JSON array
  93. err = json.Unmarshal([]byte(usernamesJSON), &usernames)
  94. if err != nil {
  95. utils.SendErrorResponse(w, "Invalid usernames format")
  96. return
  97. }
  98. } else {
  99. // Old format: single username (for backward compatibility)
  100. username, err := utils.PostPara(r, "username")
  101. if err != nil {
  102. utils.SendErrorResponse(w, "Username not defined")
  103. return
  104. }
  105. usernames = []string{username}
  106. }
  107. if len(usernames) == 0 {
  108. utils.SendErrorResponse(w, "No usernames provided")
  109. return
  110. }
  111. currentUserinfo, err := userHandler.GetUserInfoFromRequest(w, r)
  112. if err != nil {
  113. //This user has not logged in
  114. utils.SendErrorResponse(w, "User not logged in")
  115. return
  116. }
  117. // Process each user for removal
  118. var errors []string
  119. var successCount int
  120. for _, username := range usernames {
  121. // Check if user exists
  122. if !authAgent.UserExists(username) {
  123. errors = append(errors, username+": User not exists")
  124. continue
  125. }
  126. // Get user info
  127. userinfo, err := userHandler.GetUserInfoFromUsername(username)
  128. if err != nil {
  129. errors = append(errors, username+": "+err.Error())
  130. continue
  131. }
  132. // Check if user is trying to remove themselves
  133. if currentUserinfo.Username == userinfo.Username {
  134. errors = append(errors, username+": You can't remove yourself")
  135. continue
  136. }
  137. // Remove the user
  138. userinfo.RemoveUser()
  139. // Clean up FileSystem preferences
  140. system_fs_removeUserPreferences(username)
  141. successCount++
  142. }
  143. // Send response
  144. if len(errors) > 0 {
  145. if successCount == 0 {
  146. // All removals failed
  147. utils.SendErrorResponse(w, strings.Join(errors, "; "))
  148. } else {
  149. // Partial success
  150. response := map[string]interface{}{
  151. "success": successCount,
  152. "errors": errors,
  153. "message": fmt.Sprintf("%d user(s) removed successfully, %d failed", successCount, len(errors)),
  154. }
  155. js, _ := json.Marshal(response)
  156. utils.SendJSONResponse(w, string(js))
  157. }
  158. } else {
  159. // All successful
  160. utils.SendOK(w)
  161. }
  162. }
  163. func user_handleUserEdit(w http.ResponseWriter, r *http.Request) {
  164. userinfo, err := userHandler.GetUserInfoFromRequest(w, r)
  165. if err != nil {
  166. //This user has not logged in
  167. utils.SendErrorResponse(w, "User not logged in")
  168. return
  169. }
  170. if userinfo.IsAdmin() == false {
  171. //Require admin access
  172. utils.SendErrorResponse(w, "Permission Denied")
  173. return
  174. }
  175. opr, _ := utils.PostPara(r, "opr")
  176. username, _ := utils.PostPara(r, "username")
  177. if !authAgent.UserExists(username) {
  178. utils.SendErrorResponse(w, "User not exists")
  179. return
  180. }
  181. if opr == "" {
  182. //List this user information
  183. type returnValue struct {
  184. Username string
  185. Icondata string
  186. Usergroup []string
  187. Quota int64
  188. }
  189. iconData := getUserIcon(username)
  190. userGroup, err := permissionHandler.GetUsersPermissionGroup(username)
  191. if err != nil {
  192. utils.SendErrorResponse(w, "Unable to get user group")
  193. return
  194. }
  195. //Parse the user permission groupts
  196. userGroupNames := []string{}
  197. for _, gp := range userGroup {
  198. userGroupNames = append(userGroupNames, gp.Name)
  199. }
  200. //Get the user's storaeg quota
  201. userinfo, _ := userHandler.GetUserInfoFromUsername(username)
  202. jsonString, _ := json.Marshal(returnValue{
  203. Username: username,
  204. Icondata: iconData,
  205. Usergroup: userGroupNames,
  206. Quota: userinfo.StorageQuota.GetUserStorageQuota(),
  207. })
  208. utils.SendJSONResponse(w, string(jsonString))
  209. } else if opr == "updateUserGroup" {
  210. //Update the target user's group
  211. newgroup, err := utils.PostPara(r, "newgroup")
  212. if err != nil {
  213. systemWideLogger.PrintAndLog("User", err.Error(), err)
  214. utils.SendErrorResponse(w, "New Group not defined")
  215. return
  216. }
  217. newQuota, err := utils.PostPara(r, "quota")
  218. if err != nil {
  219. systemWideLogger.PrintAndLog("User", err.Error(), err)
  220. utils.SendErrorResponse(w, "Quota not defined")
  221. return
  222. }
  223. quotaInt, err := strconv.Atoi(newQuota)
  224. if err != nil {
  225. systemWideLogger.PrintAndLog("User", err.Error(), err)
  226. utils.SendErrorResponse(w, "Invalid Quota Value")
  227. return
  228. }
  229. newGroupKeys := []string{}
  230. err = json.Unmarshal([]byte(newgroup), &newGroupKeys)
  231. if err != nil {
  232. systemWideLogger.PrintAndLog("User", err.Error(), err)
  233. utils.SendErrorResponse(w, "Unable to parse new groups")
  234. return
  235. }
  236. if len(newGroupKeys) == 0 {
  237. utils.SendErrorResponse(w, "User must be in at least one user permission group")
  238. return
  239. }
  240. //Check if each group exists
  241. for _, thisgp := range newGroupKeys {
  242. if !permissionHandler.GroupExists(thisgp) {
  243. utils.SendErrorResponse(w, "Group not exists, given: "+thisgp)
  244. return
  245. }
  246. }
  247. //OK to proceed
  248. userinfo, err := userHandler.GetUserInfoFromUsername(username)
  249. if err != nil {
  250. utils.SendErrorResponse(w, err.Error())
  251. return
  252. }
  253. //Check if the current user is the only one admin in the administrator group and he is leaving the group
  254. allAdministratorGroupUsers, err := userHandler.GetUsersInPermissionGroup("administrator")
  255. if err == nil {
  256. //Skip checking if error
  257. if len(allAdministratorGroupUsers) == 1 && userinfo.UserIsInOneOfTheGroupOf([]string{"administrator"}) && !utils.StringInArray(newGroupKeys, "administrator") {
  258. //Current administrator group only contain 1 user
  259. //This user is in the administrator group
  260. //The user want to unset himself from administrator group
  261. //Reject the operation as this will cause system lockdown
  262. utils.SendErrorResponse(w, "You are the only administrator. You cannot remove yourself from the administrator group.")
  263. return
  264. }
  265. }
  266. //Get the permission groups by their ids
  267. newPermissioGroups := userHandler.GetPermissionHandler().GetPermissionGroupByNameList(newGroupKeys)
  268. //Set the user's permission to these groups
  269. userinfo.SetUserPermissionGroup(newPermissioGroups)
  270. if err != nil {
  271. utils.SendErrorResponse(w, err.Error())
  272. return
  273. }
  274. //Write to quota handler
  275. userinfo.StorageQuota.SetUserStorageQuota(int64(quotaInt))
  276. utils.SendOK(w)
  277. } else if opr == "resetPassword" {
  278. //Reset password for this user
  279. //Generate a random password for this user
  280. tmppassword := uuid.NewV4().String()
  281. hashedPassword := auth.Hash(tmppassword)
  282. err := sysdb.Write("auth", "passhash/"+username, hashedPassword)
  283. if err != nil {
  284. utils.SendErrorResponse(w, err.Error())
  285. return
  286. }
  287. //Finish. Send back the reseted password
  288. utils.SendJSONResponse(w, "\""+tmppassword+"\"")
  289. } else {
  290. utils.SendErrorResponse(w, "Not supported opr")
  291. return
  292. }
  293. }
  294. // Get the user interface info for the user to launch into
  295. func user_getInterfaceInfo(w http.ResponseWriter, r *http.Request) {
  296. userinfo, err := userHandler.GetUserInfoFromRequest(w, r)
  297. if err != nil {
  298. //User not logged in
  299. utils.SendErrorResponse(w, "User not logged in")
  300. return
  301. }
  302. interfacingModules := userinfo.GetInterfaceModules()
  303. interfaceModuleInfos := []module.ModuleInfo{}
  304. for _, im := range interfacingModules {
  305. interfaceModuleInfos = append(interfaceModuleInfos, *moduleHandler.GetModuleInfoByID(im))
  306. }
  307. jsonString, _ := json.Marshal(interfaceModuleInfos)
  308. utils.SendJSONResponse(w, string(jsonString))
  309. }
  310. // return the user profile picture as image file
  311. func user_getProfilePic(w http.ResponseWriter, r *http.Request) {
  312. thisUsername, err := authAgent.GetUserName(w, r)
  313. if err != nil {
  314. utils.SendErrorResponse(w, "User not logged in")
  315. return
  316. }
  317. targetUsername, err := utils.GetPara(r, "user")
  318. if err != nil {
  319. targetUsername = thisUsername
  320. }
  321. base64Image := getUserIcon(targetUsername)
  322. if base64Image == "" && utils.FileExists("./web/img/system/close.png") {
  323. //There are no profile image for this user
  324. http.ServeFile(w, r, "./web/img/system/close.png")
  325. return
  326. }
  327. // Remove the data:image/...;base64, part if it exists
  328. if commaIndex := strings.Index(base64Image, ","); commaIndex != -1 {
  329. base64Image = base64Image[commaIndex+1:]
  330. }
  331. imgBytes, err := base64.StdEncoding.DecodeString(base64Image)
  332. if err != nil {
  333. http.Error(w, "Failed to decode base64 string", http.StatusInternalServerError)
  334. return
  335. }
  336. img, format, err := image.Decode(strings.NewReader(string(imgBytes)))
  337. if err != nil {
  338. http.Error(w, "Failed to decode image", http.StatusInternalServerError)
  339. return
  340. }
  341. switch format {
  342. case "jpeg":
  343. w.Header().Set("Content-Type", "image/jpeg")
  344. err = jpeg.Encode(w, img, nil)
  345. case "png":
  346. w.Header().Set("Content-Type", "image/png")
  347. err = png.Encode(w, img)
  348. case "gif":
  349. w.Header().Set("Content-Type", "image/gif")
  350. err = gif.Encode(w, img, nil)
  351. default:
  352. http.Error(w, "Unsupported image format", http.StatusInternalServerError)
  353. return
  354. }
  355. if err != nil {
  356. utils.SendErrorResponse(w, err.Error())
  357. }
  358. }
  359. func user_handleUserInfo(w http.ResponseWriter, r *http.Request) {
  360. username, err := authAgent.GetUserName(w, r)
  361. if err != nil {
  362. utils.SendErrorResponse(w, "User not logged in")
  363. return
  364. }
  365. opr, _ := utils.PostPara(r, "opr")
  366. if opr == "" {
  367. //Listing mode
  368. iconData := getUserIcon(username)
  369. userGroup, err := permissionHandler.GetUsersPermissionGroup(username)
  370. if err != nil {
  371. utils.SendErrorResponse(w, "Unable to get user group")
  372. return
  373. }
  374. userGroupNames := []string{}
  375. for _, group := range userGroup {
  376. userGroupNames = append(userGroupNames, group.Name)
  377. }
  378. type returnValue struct {
  379. Username string
  380. Icondata string
  381. Usergroup []string
  382. }
  383. jsonString, _ := json.Marshal(returnValue{
  384. Username: username,
  385. Icondata: iconData,
  386. Usergroup: userGroupNames,
  387. })
  388. utils.SendJSONResponse(w, string(jsonString))
  389. return
  390. } else if opr == "changepw" {
  391. oldpw, _ := utils.PostPara(r, "oldpw")
  392. newpw, _ := utils.PostPara(r, "newpw")
  393. if oldpw == "" || newpw == "" {
  394. utils.SendErrorResponse(w, "Password cannot be empty")
  395. return
  396. }
  397. //valid the old password
  398. hashedPassword := auth.Hash(oldpw)
  399. var passwordInDB string
  400. err = sysdb.Read("auth", "passhash/"+username, &passwordInDB)
  401. if hashedPassword != passwordInDB {
  402. //Old password entry invalid.
  403. utils.SendErrorResponse(w, "Invalid old password.")
  404. return
  405. }
  406. //Logout users from all switchable accounts
  407. authAgent.SwitchableAccountManager.ExpireUserFromAllSwitchableAccountPool(username)
  408. //OK! Change user password
  409. newHashedPassword := auth.Hash(newpw)
  410. sysdb.Write("auth", "passhash/"+username, newHashedPassword)
  411. utils.SendOK(w)
  412. } else if opr == "changeprofilepic" {
  413. picdata, _ := utils.PostPara(r, "picdata")
  414. if picdata != "" {
  415. setUserIcon(username, picdata)
  416. utils.SendOK(w)
  417. } else {
  418. utils.SendErrorResponse(w, "Empty image data received.")
  419. return
  420. }
  421. } else {
  422. utils.SendErrorResponse(w, "Not supported opr")
  423. return
  424. }
  425. }
  426. func user_handleList(w http.ResponseWriter, r *http.Request) {
  427. userinfo, err := userHandler.GetUserInfoFromRequest(w, r)
  428. if err != nil {
  429. //This user has not logged in
  430. utils.SendErrorResponse(w, "User not logged in")
  431. return
  432. }
  433. noicon, _ := utils.GetBool(r, "noicon")
  434. if authAgent.CheckAuth(r) {
  435. entries, _ := sysdb.ListTable("auth")
  436. var results [][]interface{}
  437. for _, keypairs := range entries {
  438. if strings.Contains(string(keypairs[0]), "group/") {
  439. username := strings.Split(string(keypairs[0]), "/")[1]
  440. group := []string{}
  441. //Get user icon if it exists in the database
  442. userIcon := ""
  443. if !noicon {
  444. userIcon = getUserIcon(username)
  445. }
  446. json.Unmarshal(keypairs[1], &group)
  447. var thisUserInfo []interface{}
  448. thisUserInfo = append(thisUserInfo, username)
  449. thisUserInfo = append(thisUserInfo, group)
  450. thisUserInfo = append(thisUserInfo, userIcon)
  451. thisUserInfo = append(thisUserInfo, username == userinfo.Username)
  452. results = append(results, thisUserInfo)
  453. }
  454. }
  455. jsonString, _ := json.Marshal(results)
  456. utils.SendJSONResponse(w, string(jsonString))
  457. } else {
  458. utils.SendErrorResponse(w, "Permission Denied")
  459. }
  460. }
  461. func getUserIcon(username string) string {
  462. var userIconpath []byte
  463. sysdb.Read("auth", "profilepic/"+username, &userIconpath)
  464. return string(userIconpath)
  465. }
  466. func setUserIcon(username string, base64data string) {
  467. sysdb.Write("auth", "profilepic/"+username, []byte(base64data))
  468. return
  469. }