forked from tsai/budibase
committed by
GitHub
13 changed files with 245 additions and 93 deletions
@ -0,0 +1,58 @@ |
|||||
|
const CouchDB = require("../../../db") |
||||
|
const { getGroupParams, StaticDatabases } = require("@budibase/auth") |
||||
|
const { generateGroupID } = require("@budibase/auth") |
||||
|
|
||||
|
const GLOBAL_DB = StaticDatabases.GLOBAL.name |
||||
|
|
||||
|
exports.save = async function(ctx) { |
||||
|
const db = new CouchDB(GLOBAL_DB) |
||||
|
const groupDoc = ctx.request.body |
||||
|
|
||||
|
// Group does not exist yet
|
||||
|
if (!groupDoc._id) { |
||||
|
groupDoc._id = generateGroupID() |
||||
|
} |
||||
|
|
||||
|
try { |
||||
|
const response = await db.post(groupDoc) |
||||
|
ctx.body = { |
||||
|
_id: response.id, |
||||
|
_rev: response.rev, |
||||
|
} |
||||
|
} catch (err) { |
||||
|
ctx.throw(err.status, err) |
||||
|
} |
||||
|
} |
||||
|
|
||||
|
exports.fetch = async function(ctx) { |
||||
|
const db = new CouchDB(GLOBAL_DB) |
||||
|
const response = await db.allDocs( |
||||
|
getGroupParams(undefined, { |
||||
|
include_docs: true, |
||||
|
}) |
||||
|
) |
||||
|
const groups = response.rows.map(row => row.doc) |
||||
|
ctx.body = groups |
||||
|
} |
||||
|
|
||||
|
exports.find = async function(ctx) { |
||||
|
const db = new CouchDB(GLOBAL_DB) |
||||
|
try { |
||||
|
const record = await db.get(ctx.params.id) |
||||
|
ctx.body = record |
||||
|
} catch (err) { |
||||
|
ctx.throw(err.status, err) |
||||
|
} |
||||
|
} |
||||
|
|
||||
|
exports.destroy = async function(ctx) { |
||||
|
const db = new CouchDB(GLOBAL_DB) |
||||
|
const { id, rev } = ctx.params |
||||
|
|
||||
|
try { |
||||
|
await db.remove(id, rev) |
||||
|
ctx.body = { message: "Group deleted successfully" } |
||||
|
} catch (err) { |
||||
|
ctx.throw(err.status, err) |
||||
|
} |
||||
|
} |
||||
@ -1,90 +1,7 @@ |
|||||
const CouchDB = require("../../../db") |
const users = require("./users") |
||||
const { |
const groups = require("./groups") |
||||
hash, |
|
||||
generateUserID, |
|
||||
getUserParams, |
|
||||
StaticDatabases, |
|
||||
} = require("@budibase/auth") |
|
||||
const { UserStatus } = require("../../../constants") |
|
||||
|
|
||||
const GLOBAL_DB = StaticDatabases.GLOBAL.name |
module.exports = { |
||||
|
users, |
||||
exports.userSave = async ctx => { |
groups, |
||||
const db = new CouchDB(GLOBAL_DB) |
|
||||
const { email, password, _id } = ctx.request.body |
|
||||
const hashedPassword = password ? await hash(password) : null |
|
||||
let user = { |
|
||||
...ctx.request.body, |
|
||||
_id: generateUserID(email), |
|
||||
password: hashedPassword, |
|
||||
} |
|
||||
let dbUser |
|
||||
// in-case user existed already
|
|
||||
if (_id) { |
|
||||
dbUser = await db.get(_id) |
|
||||
} |
|
||||
// add the active status to a user if its not provided
|
|
||||
if (user.status == null) { |
|
||||
user.status = UserStatus.ACTIVE |
|
||||
} |
|
||||
try { |
|
||||
const response = await db.post({ |
|
||||
password: hashedPassword || dbUser.password, |
|
||||
...user, |
|
||||
}) |
|
||||
ctx.body = { |
|
||||
_id: response.id, |
|
||||
_rev: response.rev, |
|
||||
email, |
|
||||
} |
|
||||
} catch (err) { |
|
||||
if (err.status === 409) { |
|
||||
ctx.throw(400, "User exists already") |
|
||||
} else { |
|
||||
ctx.throw(err.status, err) |
|
||||
} |
|
||||
} |
|
||||
} |
|
||||
|
|
||||
exports.userDelete = async ctx => { |
|
||||
const db = new CouchDB(GLOBAL_DB) |
|
||||
const dbUser = await db.get(generateUserID(ctx.params.email)) |
|
||||
await db.remove(dbUser._id, dbUser._rev) |
|
||||
ctx.body = { |
|
||||
message: `User ${ctx.params.email} deleted.`, |
|
||||
} |
|
||||
} |
|
||||
|
|
||||
// called internally by app server user fetch
|
|
||||
exports.userFetch = async ctx => { |
|
||||
const db = new CouchDB(GLOBAL_DB) |
|
||||
const response = await db.allDocs( |
|
||||
getUserParams(null, { |
|
||||
include_docs: true, |
|
||||
}) |
|
||||
) |
|
||||
const users = response.rows.map(row => row.doc) |
|
||||
// user hashed password shouldn't ever be returned
|
|
||||
for (let user of users) { |
|
||||
if (user) { |
|
||||
delete user.password |
|
||||
} |
|
||||
} |
|
||||
ctx.body = users |
|
||||
} |
|
||||
|
|
||||
// called internally by app server user find
|
|
||||
exports.userFind = async ctx => { |
|
||||
const db = new CouchDB(GLOBAL_DB) |
|
||||
let user |
|
||||
try { |
|
||||
user = await db.get(generateUserID(ctx.params.email)) |
|
||||
} catch (err) { |
|
||||
// no user found, just return nothing
|
|
||||
user = {} |
|
||||
} |
|
||||
if (user) { |
|
||||
delete user.password |
|
||||
} |
|
||||
ctx.body = user |
|
||||
} |
} |
||||
|
|||||
@ -0,0 +1,90 @@ |
|||||
|
const CouchDB = require("../../../db") |
||||
|
const { |
||||
|
hash, |
||||
|
generateUserID, |
||||
|
getUserParams, |
||||
|
StaticDatabases, |
||||
|
} = require("@budibase/auth") |
||||
|
const { UserStatus } = require("../../../constants") |
||||
|
|
||||
|
const GLOBAL_DB = StaticDatabases.GLOBAL.name |
||||
|
|
||||
|
exports.userSave = async ctx => { |
||||
|
const db = new CouchDB(GLOBAL_DB) |
||||
|
const { email, password, _id } = ctx.request.body |
||||
|
const hashedPassword = password ? await hash(password) : null |
||||
|
let user = { |
||||
|
...ctx.request.body, |
||||
|
_id: generateUserID(email), |
||||
|
password: hashedPassword, |
||||
|
} |
||||
|
let dbUser |
||||
|
// in-case user existed already
|
||||
|
if (_id) { |
||||
|
dbUser = await db.get(_id) |
||||
|
} |
||||
|
// add the active status to a user if its not provided
|
||||
|
if (user.status == null) { |
||||
|
user.status = UserStatus.ACTIVE |
||||
|
} |
||||
|
try { |
||||
|
const response = await db.post({ |
||||
|
password: hashedPassword || dbUser.password, |
||||
|
...user, |
||||
|
}) |
||||
|
ctx.body = { |
||||
|
_id: response.id, |
||||
|
_rev: response.rev, |
||||
|
email, |
||||
|
} |
||||
|
} catch (err) { |
||||
|
if (err.status === 409) { |
||||
|
ctx.throw(400, "User exists already") |
||||
|
} else { |
||||
|
ctx.throw(err.status, err) |
||||
|
} |
||||
|
} |
||||
|
} |
||||
|
|
||||
|
exports.userDelete = async ctx => { |
||||
|
const db = new CouchDB(GLOBAL_DB) |
||||
|
const dbUser = await db.get(generateUserID(ctx.params.email)) |
||||
|
await db.remove(dbUser._id, dbUser._rev) |
||||
|
ctx.body = { |
||||
|
message: `User ${ctx.params.email} deleted.`, |
||||
|
} |
||||
|
} |
||||
|
|
||||
|
// called internally by app server user fetch
|
||||
|
exports.userFetch = async ctx => { |
||||
|
const db = new CouchDB(GLOBAL_DB) |
||||
|
const response = await db.allDocs( |
||||
|
getUserParams(null, { |
||||
|
include_docs: true, |
||||
|
}) |
||||
|
) |
||||
|
const users = response.rows.map(row => row.doc) |
||||
|
// user hashed password shouldn't ever be returned
|
||||
|
for (let user of users) { |
||||
|
if (user) { |
||||
|
delete user.password |
||||
|
} |
||||
|
} |
||||
|
ctx.body = users |
||||
|
} |
||||
|
|
||||
|
// called internally by app server user find
|
||||
|
exports.userFind = async ctx => { |
||||
|
const db = new CouchDB(GLOBAL_DB) |
||||
|
let user |
||||
|
try { |
||||
|
user = await db.get(generateUserID(ctx.params.email)) |
||||
|
} catch (err) { |
||||
|
// no user found, just return nothing
|
||||
|
user = {} |
||||
|
} |
||||
|
if (user) { |
||||
|
delete user.password |
||||
|
} |
||||
|
ctx.body = user |
||||
|
} |
||||
@ -0,0 +1,38 @@ |
|||||
|
const Router = require("@koa/router") |
||||
|
const controller = require("../../controllers/admin/groups") |
||||
|
const joiValidator = require("../../../middleware/joi-validator") |
||||
|
const { authenticated } = require("@budibase/auth") |
||||
|
const Joi = require("joi") |
||||
|
|
||||
|
const router = Router() |
||||
|
|
||||
|
function buildGroupSaveValidation() { |
||||
|
// prettier-ignore
|
||||
|
return joiValidator.body(Joi.object({ |
||||
|
_id: Joi.string().optional(), |
||||
|
_rev: Joi.string().optional(), |
||||
|
name: Joi.string().required(), |
||||
|
users: Joi.array().required(), |
||||
|
managers: Joi.array().required(), |
||||
|
roles: Joi.object({ |
||||
|
default: Joi.string().optional(), |
||||
|
app: Joi.object() |
||||
|
.pattern(/.*/, Joi.string()) |
||||
|
.required() |
||||
|
.unknown(true), |
||||
|
}).unknown(true).optional(), |
||||
|
}).required().unknown(true)) |
||||
|
} |
||||
|
|
||||
|
router |
||||
|
.post( |
||||
|
"/api/admin/groups", |
||||
|
buildGroupSaveValidation(), |
||||
|
authenticated, |
||||
|
controller.save |
||||
|
) |
||||
|
.delete("/api/admin/groups/:id", authenticated, controller.destroy) |
||||
|
.get("/api/admin/groups", authenticated, controller.fetch) |
||||
|
.get("/api/admin/groups/:id", authenticated, controller.find) |
||||
|
|
||||
|
module.exports = router |
||||
@ -1,5 +1,5 @@ |
|||||
const Router = require("@koa/router") |
const Router = require("@koa/router") |
||||
const controller = require("../../controllers/admin") |
const controller = require("../../controllers/admin/users") |
||||
const joiValidator = require("../../../middleware/joi-validator") |
const joiValidator = require("../../../middleware/joi-validator") |
||||
const { authenticated } = require("@budibase/auth") |
const { authenticated } = require("@budibase/auth") |
||||
const Joi = require("joi") |
const Joi = require("joi") |
||||
@ -1,5 +1,6 @@ |
|||||
const adminRoutes = require("./admin") |
const userRoutes = require("./admin/users") |
||||
|
const groupRoutes = require("./admin/groups") |
||||
const authRoutes = require("./auth") |
const authRoutes = require("./auth") |
||||
const appRoutes = require("./app") |
const appRoutes = require("./app") |
||||
|
|
||||
exports.routes = [adminRoutes, authRoutes, appRoutes] |
exports.routes = [userRoutes, groupRoutes, authRoutes, appRoutes] |
||||
|
|||||
Loading…
Reference in new issue