You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

user.go 12KB

10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
10 years ago
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509
  1. // Copyright 2014 The Gogs Authors. All rights reserved.
  2. // Use of this source code is governed by a MIT-style
  3. // license that can be found in the LICENSE file.
  4. package models
  5. import (
  6. "crypto/sha256"
  7. "encoding/hex"
  8. "errors"
  9. "fmt"
  10. "os"
  11. "path/filepath"
  12. "strings"
  13. "time"
  14. "github.com/gogits/git"
  15. "github.com/gogits/gogs/modules/base"
  16. "github.com/gogits/gogs/modules/log"
  17. )
  18. // User types.
  19. const (
  20. UT_INDIVIDUAL = iota + 1
  21. UT_ORGANIZATION
  22. )
  23. var (
  24. ErrUserOwnRepos = errors.New("User still have ownership of repositories")
  25. ErrUserAlreadyExist = errors.New("User already exist")
  26. ErrUserNotExist = errors.New("User does not exist")
  27. ErrEmailAlreadyUsed = errors.New("E-mail already used")
  28. ErrUserNameIllegal = errors.New("User name contains illegal characters")
  29. ErrKeyNotExist = errors.New("Public key does not exist")
  30. )
  31. // User represents the object of individual and member of organization.
  32. type User struct {
  33. Id int64
  34. LowerName string `xorm:"unique not null"`
  35. Name string `xorm:"unique not null"`
  36. FullName string
  37. Email string `xorm:"unique not null"`
  38. Passwd string `xorm:"not null"`
  39. LoginType int
  40. LoginSource int64 `xorm:"not null default 0"`
  41. Type int
  42. NumFollowers int
  43. NumFollowings int
  44. NumStars int
  45. NumRepos int
  46. Avatar string `xorm:"varchar(2048) not null"`
  47. AvatarEmail string `xorm:"not null"`
  48. Location string
  49. Website string
  50. IsActive bool
  51. IsAdmin bool
  52. Rands string `xorm:"VARCHAR(10)"`
  53. Salt string `xorm:"VARCHAR(10)"`
  54. Created time.Time `xorm:"created"`
  55. Updated time.Time `xorm:"updated"`
  56. }
  57. // HomeLink returns the user home page link.
  58. func (user *User) HomeLink() string {
  59. return "/user/" + user.Name
  60. }
  61. // AvatarLink returns the user gravatar link.
  62. func (user *User) AvatarLink() string {
  63. if base.DisableGravatar {
  64. return "/img/avatar_default.jpg"
  65. } else if base.Service.EnableCacheAvatar {
  66. return "/avatar/" + user.Avatar
  67. }
  68. return "//1.gravatar.com/avatar/" + user.Avatar
  69. }
  70. // NewGitSig generates and returns the signature of given user.
  71. func (user *User) NewGitSig() *git.Signature {
  72. return &git.Signature{
  73. Name: user.Name,
  74. Email: user.Email,
  75. When: time.Now(),
  76. }
  77. }
  78. // EncodePasswd encodes password to safe format.
  79. func (user *User) EncodePasswd() {
  80. newPasswd := base.PBKDF2([]byte(user.Passwd), []byte(user.Salt), 10000, 50, sha256.New)
  81. user.Passwd = fmt.Sprintf("%x", newPasswd)
  82. }
  83. // Member represents user is member of organization.
  84. type Member struct {
  85. Id int64
  86. OrgId int64 `xorm:"unique(member) index"`
  87. UserId int64 `xorm:"unique(member)"`
  88. }
  89. // IsUserExist checks if given user name exist,
  90. // the user name should be noncased unique.
  91. func IsUserExist(name string) (bool, error) {
  92. if len(name) == 0 {
  93. return false, nil
  94. }
  95. return orm.Get(&User{LowerName: strings.ToLower(name)})
  96. }
  97. // IsEmailUsed returns true if the e-mail has been used.
  98. func IsEmailUsed(email string) (bool, error) {
  99. if len(email) == 0 {
  100. return false, nil
  101. }
  102. return orm.Get(&User{Email: email})
  103. }
  104. // return a user salt token
  105. func GetUserSalt() string {
  106. return base.GetRandomString(10)
  107. }
  108. // RegisterUser creates record of a new user.
  109. func RegisterUser(user *User) (*User, error) {
  110. if !IsLegalName(user.Name) {
  111. return nil, ErrUserNameIllegal
  112. }
  113. isExist, err := IsUserExist(user.Name)
  114. if err != nil {
  115. return nil, err
  116. } else if isExist {
  117. return nil, ErrUserAlreadyExist
  118. }
  119. isExist, err = IsEmailUsed(user.Email)
  120. if err != nil {
  121. return nil, err
  122. } else if isExist {
  123. return nil, ErrEmailAlreadyUsed
  124. }
  125. user.LowerName = strings.ToLower(user.Name)
  126. user.Avatar = base.EncodeMd5(user.Email)
  127. user.AvatarEmail = user.Email
  128. user.Rands = GetUserSalt()
  129. user.Salt = GetUserSalt()
  130. user.EncodePasswd()
  131. if _, err = orm.Insert(user); err != nil {
  132. return nil, err
  133. } else if err = os.MkdirAll(UserPath(user.Name), os.ModePerm); err != nil {
  134. if _, err := orm.Id(user.Id).Delete(&User{}); err != nil {
  135. return nil, errors.New(fmt.Sprintf(
  136. "both create userpath %s and delete table record faild: %v", user.Name, err))
  137. }
  138. return nil, err
  139. }
  140. if user.Id == 1 {
  141. user.IsAdmin = true
  142. user.IsActive = true
  143. _, err = orm.Id(user.Id).UseBool().Update(user)
  144. }
  145. return user, err
  146. }
  147. // GetUsers returns given number of user objects with offset.
  148. func GetUsers(num, offset int) ([]User, error) {
  149. users := make([]User, 0, num)
  150. err := orm.Limit(num, offset).Asc("id").Find(&users)
  151. return users, err
  152. }
  153. // get user by erify code
  154. func getVerifyUser(code string) (user *User) {
  155. if len(code) <= base.TimeLimitCodeLength {
  156. return nil
  157. }
  158. // use tail hex username query user
  159. hexStr := code[base.TimeLimitCodeLength:]
  160. if b, err := hex.DecodeString(hexStr); err == nil {
  161. if user, err = GetUserByName(string(b)); user != nil {
  162. return user
  163. }
  164. log.Error("user.getVerifyUser: %v", err)
  165. }
  166. return nil
  167. }
  168. // verify active code when active account
  169. func VerifyUserActiveCode(code string) (user *User) {
  170. minutes := base.Service.ActiveCodeLives
  171. if user = getVerifyUser(code); user != nil {
  172. // time limit code
  173. prefix := code[:base.TimeLimitCodeLength]
  174. data := base.ToStr(user.Id) + user.Email + user.LowerName + user.Passwd + user.Rands
  175. if base.VerifyTimeLimitCode(data, minutes, prefix) {
  176. return user
  177. }
  178. }
  179. return nil
  180. }
  181. // ChangeUserName changes all corresponding setting from old user name to new one.
  182. func ChangeUserName(user *User, newUserName string) (err error) {
  183. newUserName = strings.ToLower(newUserName)
  184. // Update accesses of user.
  185. accesses := make([]Access, 0, 10)
  186. if err = orm.Find(&accesses, &Access{UserName: user.LowerName}); err != nil {
  187. return err
  188. }
  189. sess := orm.NewSession()
  190. defer sess.Close()
  191. if err = sess.Begin(); err != nil {
  192. return err
  193. }
  194. for i := range accesses {
  195. accesses[i].UserName = newUserName
  196. if strings.HasPrefix(accesses[i].RepoName, user.LowerName+"/") {
  197. accesses[i].RepoName = strings.Replace(accesses[i].RepoName, user.LowerName, newUserName, 1)
  198. }
  199. if err = UpdateAccessWithSession(sess, &accesses[i]); err != nil {
  200. return err
  201. }
  202. }
  203. repos, err := GetRepositories(user, true)
  204. if err != nil {
  205. return err
  206. }
  207. for i := range repos {
  208. accesses = make([]Access, 0, 10)
  209. // Update accesses of user repository.
  210. if err = orm.Find(&accesses, &Access{RepoName: user.LowerName + "/" + repos[i].LowerName}); err != nil {
  211. return err
  212. }
  213. for j := range accesses {
  214. accesses[j].UserName = newUserName
  215. accesses[j].RepoName = newUserName + "/" + repos[i].LowerName
  216. if err = UpdateAccessWithSession(sess, &accesses[j]); err != nil {
  217. return err
  218. }
  219. }
  220. }
  221. // Change user directory name.
  222. if err = os.Rename(UserPath(user.LowerName), UserPath(newUserName)); err != nil {
  223. sess.Rollback()
  224. return err
  225. }
  226. return sess.Commit()
  227. }
  228. // UpdateUser updates user's information.
  229. func UpdateUser(user *User) (err error) {
  230. user.LowerName = strings.ToLower(user.Name)
  231. if len(user.Location) > 255 {
  232. user.Location = user.Location[:255]
  233. }
  234. if len(user.Website) > 255 {
  235. user.Website = user.Website[:255]
  236. }
  237. _, err = orm.Id(user.Id).AllCols().Update(user)
  238. return err
  239. }
  240. // DeleteUser completely deletes everything of the user.
  241. func DeleteUser(user *User) error {
  242. // Check ownership of repository.
  243. count, err := GetRepositoryCount(user)
  244. if err != nil {
  245. return errors.New("modesl.GetRepositories: " + err.Error())
  246. } else if count > 0 {
  247. return ErrUserOwnRepos
  248. }
  249. // TODO: check issues, other repos' commits
  250. // Delete all followers.
  251. if _, err = orm.Delete(&Follow{FollowId: user.Id}); err != nil {
  252. return err
  253. }
  254. // Delete oauth2.
  255. if _, err = orm.Delete(&Oauth2{Uid: user.Id}); err != nil {
  256. return err
  257. }
  258. // Delete all feeds.
  259. if _, err = orm.Delete(&Action{UserId: user.Id}); err != nil {
  260. return err
  261. }
  262. // Delete all watches.
  263. if _, err = orm.Delete(&Watch{UserId: user.Id}); err != nil {
  264. return err
  265. }
  266. // Delete all accesses.
  267. if _, err = orm.Delete(&Access{UserName: user.LowerName}); err != nil {
  268. return err
  269. }
  270. // Delete all SSH keys.
  271. keys := make([]PublicKey, 0, 10)
  272. if err = orm.Find(&keys, &PublicKey{OwnerId: user.Id}); err != nil {
  273. return err
  274. }
  275. for _, key := range keys {
  276. if err = DeletePublicKey(&key); err != nil {
  277. return err
  278. }
  279. }
  280. // Delete user directory.
  281. if err = os.RemoveAll(UserPath(user.Name)); err != nil {
  282. return err
  283. }
  284. _, err = orm.Delete(user)
  285. return err
  286. }
  287. // UserPath returns the path absolute path of user repositories.
  288. func UserPath(userName string) string {
  289. return filepath.Join(base.RepoRootPath, strings.ToLower(userName))
  290. }
  291. func GetUserByKeyId(keyId int64) (*User, error) {
  292. user := new(User)
  293. rawSql := "SELECT a.* FROM `user` AS a, public_key AS b WHERE a.id = b.owner_id AND b.id=?"
  294. has, err := orm.Sql(rawSql, keyId).Get(user)
  295. if err != nil {
  296. return nil, err
  297. } else if !has {
  298. err = errors.New("not exist key owner")
  299. return nil, err
  300. }
  301. return user, nil
  302. }
  303. // GetUserById returns the user object by given id if exists.
  304. func GetUserById(id int64) (*User, error) {
  305. user := new(User)
  306. has, err := orm.Id(id).Get(user)
  307. if err != nil {
  308. return nil, err
  309. }
  310. if !has {
  311. return nil, ErrUserNotExist
  312. }
  313. return user, nil
  314. }
  315. // GetUserByName returns the user object by given name if exists.
  316. func GetUserByName(name string) (*User, error) {
  317. if len(name) == 0 {
  318. return nil, ErrUserNotExist
  319. }
  320. user := &User{LowerName: strings.ToLower(name)}
  321. has, err := orm.Get(user)
  322. if err != nil {
  323. return nil, err
  324. } else if !has {
  325. return nil, ErrUserNotExist
  326. }
  327. return user, nil
  328. }
  329. // GetUserEmailsByNames returns a slice of e-mails corresponds to names.
  330. func GetUserEmailsByNames(names []string) []string {
  331. mails := make([]string, 0, len(names))
  332. for _, name := range names {
  333. u, err := GetUserByName(name)
  334. if err != nil {
  335. continue
  336. }
  337. mails = append(mails, u.Email)
  338. }
  339. return mails
  340. }
  341. // GetUserByEmail returns the user object by given e-mail if exists.
  342. func GetUserByEmail(email string) (*User, error) {
  343. if len(email) == 0 {
  344. return nil, ErrUserNotExist
  345. }
  346. user := &User{Email: strings.ToLower(email)}
  347. has, err := orm.Get(user)
  348. if err != nil {
  349. return nil, err
  350. } else if !has {
  351. return nil, ErrUserNotExist
  352. }
  353. return user, nil
  354. }
  355. // SearchUserByName returns given number of users whose name contains keyword.
  356. func SearchUserByName(key string, limit int) (us []*User, err error) {
  357. // Prevent SQL inject.
  358. key = strings.TrimSpace(key)
  359. if len(key) == 0 {
  360. return us, nil
  361. }
  362. key = strings.Split(key, " ")[0]
  363. if len(key) == 0 {
  364. return us, nil
  365. }
  366. key = strings.ToLower(key)
  367. us = make([]*User, 0, limit)
  368. err = orm.Limit(limit).Where("lower_name like '%" + key + "%'").Find(&us)
  369. return us, err
  370. }
  371. // LoginUserPlain validates user by raw user name and password.
  372. func LoginUserPlain(uname, passwd string) (*User, error) {
  373. var u *User
  374. if strings.Contains(uname, "@") {
  375. u = &User{Email: uname}
  376. } else {
  377. u = &User{LowerName: strings.ToLower(uname)}
  378. }
  379. has, err := orm.Get(u)
  380. if err != nil {
  381. return nil, err
  382. } else if !has {
  383. return nil, ErrUserNotExist
  384. }
  385. newUser := &User{Passwd: passwd, Salt: u.Salt}
  386. newUser.EncodePasswd()
  387. if u.Passwd != newUser.Passwd {
  388. return nil, ErrUserNotExist
  389. }
  390. return u, nil
  391. }
  392. // Follow is connection request for receiving user notifycation.
  393. type Follow struct {
  394. Id int64
  395. UserId int64 `xorm:"unique(follow)"`
  396. FollowId int64 `xorm:"unique(follow)"`
  397. }
  398. // FollowUser marks someone be another's follower.
  399. func FollowUser(userId int64, followId int64) (err error) {
  400. session := orm.NewSession()
  401. defer session.Close()
  402. session.Begin()
  403. if _, err = session.Insert(&Follow{UserId: userId, FollowId: followId}); err != nil {
  404. session.Rollback()
  405. return err
  406. }
  407. rawSql := "UPDATE `user` SET num_followers = num_followers + 1 WHERE id = ?"
  408. if _, err = session.Exec(rawSql, followId); err != nil {
  409. session.Rollback()
  410. return err
  411. }
  412. rawSql = "UPDATE `user` SET num_followings = num_followings + 1 WHERE id = ?"
  413. if _, err = session.Exec(rawSql, userId); err != nil {
  414. session.Rollback()
  415. return err
  416. }
  417. return session.Commit()
  418. }
  419. // UnFollowUser unmarks someone be another's follower.
  420. func UnFollowUser(userId int64, unFollowId int64) (err error) {
  421. session := orm.NewSession()
  422. defer session.Close()
  423. session.Begin()
  424. if _, err = session.Delete(&Follow{UserId: userId, FollowId: unFollowId}); err != nil {
  425. session.Rollback()
  426. return err
  427. }
  428. rawSql := "UPDATE `user` SET num_followers = num_followers - 1 WHERE id = ?"
  429. if _, err = session.Exec(rawSql, unFollowId); err != nil {
  430. session.Rollback()
  431. return err
  432. }
  433. rawSql = "UPDATE `user` SET num_followings = num_followings - 1 WHERE id = ?"
  434. if _, err = session.Exec(rawSql, userId); err != nil {
  435. session.Rollback()
  436. return err
  437. }
  438. return session.Commit()
  439. }