func setEmailAndFullnameFromTrustedUsername(user *tat.User) { conf := viper.GetString("trusted_usernames_emails_fullnames") tuples := strings.Split(conf, ",") user.Fullname = user.Username user.Email = user.Username + "@" + viper.GetString("default_domain") if len(conf) < 2 { return } for _, tuple := range tuples { t := strings.Split(tuple, ":") if len(t) != 3 { log.Errorf("Misconfiguration of trusted_usernames_emails tuple:%s", tuple) continue } usernameTuple := t[0] emailTuple := t[1] fullnameTuple := t[2] if usernameTuple == user.Username && emailTuple != "" && fullnameTuple != "" { user.Email = emailTuple user.Fullname = strings.Replace(fullnameTuple, "_", " ", -1) return } } }
// Create a new user, record Username, Fullname and Email // A mail is sent to ask user for validation func (u *UsersController) Create(ctx *gin.Context) { var userJSON tat.UserCreateJSON ctx.Bind(&userJSON) var userIn tat.User userIn.Username = u.computeUsername(userJSON) userIn.Fullname = strings.TrimSpace(userJSON.Fullname) userIn.Email = strings.TrimSpace(userJSON.Email) callback := strings.TrimSpace(userJSON.Callback) if len(userIn.Username) < 3 || len(userIn.Fullname) < 3 || len(userIn.Email) < 7 { err := fmt.Errorf("Invalid username (%s) or fullname (%s) or email (%s)", userIn.Username, userIn.Fullname, userIn.Email) AbortWithReturnError(ctx, http.StatusInternalServerError, err) return } if err := u.checkAllowedDomains(userJSON); err != nil { ctx.JSON(http.StatusForbidden, gin.H{"error": err.Error()}) return } user := tat.User{} foundEmail, errEmail := userDB.FindByEmail(&user, userJSON.Email) foundUsername, errUsername := userDB.FindByUsername(&user, userJSON.Username) foundFullname, errFullname := userDB.FindByFullname(&user, userJSON.Fullname) if foundEmail || foundUsername || foundFullname || errEmail != nil || errUsername != nil || errFullname != nil { e := fmt.Errorf("Please check your username, email or fullname. If you are already registered, please reset your password") AbortWithReturnError(ctx, http.StatusBadRequest, e) return } tokenVerify, err := userDB.Insert(&userIn) if err != nil { log.Errorf("Error while InsertUser %s", err) ctx.AbortWithError(http.StatusInternalServerError, err) return } go userDB.SendVerifyEmail(userIn.Username, userIn.Email, tokenVerify, callback) info := "" if viper.GetBool("username_from_email") { info = fmt.Sprintf(" Note that configuration of Tat forced your username to %s", userIn.Username) } ctx.JSON(http.StatusCreated, gin.H{"info": fmt.Sprintf("please check your mail to validate your account.%s", info)}) }
// Reset send a mail asking user to confirm reset password func (u *UsersController) Reset(ctx *gin.Context) { var userJSON userResetJSON ctx.Bind(&userJSON) var userIn tat.User userIn.Username = strings.TrimSpace(userJSON.Username) userIn.Email = strings.TrimSpace(userJSON.Email) callback := strings.TrimSpace(userJSON.Callback) if len(userIn.Username) < 3 || len(userIn.Email) < 7 { err := fmt.Errorf("Invalid username (%s) or email (%s)", userIn.Username, userIn.Email) AbortWithReturnError(ctx, http.StatusInternalServerError, err) return } tokenVerify, err := userDB.AskReset(&userIn) if err != nil { log.Errorf("Error while AskReset %s", err) ctx.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()}) return } go userDB.SendAskResetEmail(userIn.Username, userIn.Email, tokenVerify, callback) ctx.JSON(http.StatusCreated, gin.H{"info": "please check your mail to validate your account"}) }