func GetLoginToken(c *gin.Context) { remote := remote.FromContext(c) in := &tokenPayload{} err := c.Bind(in) if err != nil { c.AbortWithError(http.StatusBadRequest, err) return } login, err := remote.Auth(in.Access, in.Refresh) if err != nil { c.AbortWithError(http.StatusUnauthorized, err) return } user, err := store.GetUserLogin(c, login) if err != nil { c.AbortWithError(http.StatusNotFound, err) return } exp := time.Now().Add(time.Hour * 72).Unix() token := token.New(token.SessToken, user.Login) tokenstr, err := token.SignExpires(user.Hash, exp) if err != nil { c.AbortWithError(http.StatusInternalServerError, err) return } c.IndentedJSON(http.StatusOK, &tokenPayload{ Access: tokenstr, Expires: exp - time.Now().Unix(), }) }
func PostToken(c *gin.Context) { user := session.User(c) token := token.New(token.UserToken, user.Login) tokenstr, err := token.Sign(user.Hash) if err != nil { c.AbortWithError(http.StatusInternalServerError, err) } else { c.String(http.StatusOK, tokenstr) } }
func SetRepo() gin.HandlerFunc { return func(c *gin.Context) { var ( owner = c.Param("owner") name = c.Param("name") ) user := User(c) repo, err := store.GetRepoOwnerName(c, owner, name) if err == nil { c.Set("repo", repo) c.Next() return } // if the user is not nil, check the remote system // to see if the repository actually exists. If yes, // we can prompt the user to add. if user != nil { remote := remote.FromContext(c) repo, err = remote.Repo(user, owner, name) if err != nil { log.Errorf("Cannot find remote repository %s/%s for user %s. %s", owner, name, user.Login, err) } else { log.Debugf("Found remote repository %s/%s for user %s", owner, name, user.Login) } } data := gin.H{ "User": user, "Repo": repo, } // if we found a repository, we should display a page // to the user allowing them to activate. if repo != nil && len(repo.FullName) != 0 { // we should probably move this code to a // separate route, but for now we need to // add a CSRF token. data["Csrf"], _ = token.New( token.CsrfToken, user.Login, ).Sign(user.Hash) c.HTML(http.StatusNotFound, "repo_activate.html", data) } else { c.HTML(http.StatusNotFound, "404.html", data) } c.Abort() } }
func ShowUser(c *gin.Context) { user := session.User(c) token, _ := token.New( token.CsrfToken, user.Login, ).Sign(user.Hash) c.HTML(200, "user.html", gin.H{ "User": user, "Csrf": token, }) }
func ShowRepoEncrypt(c *gin.Context) { user := session.User(c) repo := session.Repo(c) token, _ := token.New( token.CsrfToken, user.Login, ).Sign(user.Hash) c.HTML(200, "repo_secret.html", gin.H{ "User": user, "Repo": repo, "Csrf": token, }) }
func ShowBuild(c *gin.Context) { user := session.User(c) repo := session.Repo(c) num, _ := strconv.Atoi(c.Param("number")) seq, _ := strconv.Atoi(c.Param("job")) if seq == 0 { seq = 1 } build, err := store.GetBuildNumber(c, repo, num) if err != nil { c.AbortWithError(404, err) return } jobs, err := store.GetJobList(c, build) if err != nil { c.AbortWithError(404, err) return } var job *model.Job for _, j := range jobs { if j.Number == seq { job = j break } } httputil.SetCookie(c.Writer, c.Request, "user_last", repo.FullName) var csrf string if user != nil { csrf, _ = token.New( token.CsrfToken, user.Login, ).Sign(user.Hash) } c.HTML(200, "build.html", gin.H{ "User": user, "Repo": repo, "Build": build, "Jobs": jobs, "Job": job, "Csrf": csrf, }) }
// Netrc returns a .netrc file that can be used to clone // private repositories from a remote system. func (g *Gitlab) Netrc(u *model.User, r *model.Repo) (*model.Netrc, error) { url_, err := url.Parse(g.URL) if err != nil { return nil, err } netrc := &model.Netrc{} netrc.Machine = url_.Host switch g.CloneMode { case "oauth": netrc.Login = "******" netrc.Password = u.Token case "token": t := token.New(token.HookToken, r.FullName) netrc.Login = "******" netrc.Password, err = t.Sign(r.Hash) } return netrc, err }
func GetUser(c *gin.Context) { user, err := store.GetUserLogin(c, c.Param("login")) if err != nil { c.AbortWithStatus(http.StatusNotFound) return } token := token.New(token.UserToken, user.Login) tokenstr, err := token.Sign(user.Hash) if err != nil { tokenstr = "" } userWithToken := struct { *model.User Token string `json:"token,omitempty"` }{user, tokenstr} c.IndentedJSON(http.StatusOK, userWithToken) }
func ShowUsers(c *gin.Context) { user := session.User(c) if !user.Admin { c.AbortWithStatus(http.StatusForbidden) return } users, _ := store.GetUserList(c) token, _ := token.New( token.CsrfToken, user.Login, ).Sign(user.Hash) c.HTML(200, "users.html", gin.H{ "User": user, "Users": users, "Csrf": token, }) }
func ShowRepoConf(c *gin.Context) { user := session.User(c) repo := session.Repo(c) key, _ := store.GetKey(c, repo) token, _ := token.New( token.CsrfToken, user.Login, ).Sign(user.Hash) c.HTML(200, "repo_config.html", gin.H{ "User": user, "Repo": repo, "Key": key, "Csrf": token, "Link": httputil.GetURL(c.Request), }) }
func PostUser(c *gin.Context) { in := &struct { model.User Token string `json:"oauth_token"` }{} err := c.Bind(in) if err != nil { c.String(http.StatusBadRequest, err.Error()) return } user := &model.User{} user.Login = in.Login user.Email = in.Email user.Admin = in.Admin user.Token = in.Token user.Avatar = in.Avatar user.Active = true user.Hash = crypto.Rand() err = store.CreateUser(c, user) if err != nil { c.String(http.StatusInternalServerError, err.Error()) return } token := token.New(token.UserToken, user.Login) tokenstr, err := token.Sign(user.Hash) if err != nil { tokenstr = "" } userWithToken := struct { *model.User Token string `json:"token,omitempty"` }{user, tokenstr} c.IndentedJSON(http.StatusOK, userWithToken) }
func GetRepo(c *gin.Context) { repo := session.Repo(c) user := session.User(c) if user == nil { c.IndentedJSON(http.StatusOK, repo) return } repoResp := struct { *model.Repo Token string `json:"hook_token,omitempty"` }{repo, ""} if user.Admin { t := token.New(token.HookToken, repo.FullName) sig, err := t.Sign(repo.Hash) if err != nil { log.Errorf("Error creating hook token: %s", err) } else { repoResp.Token = sig } } c.IndentedJSON(http.StatusOK, repoResp) }
func GetLogin(c *gin.Context) { remote := remote.FromContext(c) // when dealing with redirects we may need // to adjust the content type. I cannot, however, // rememver why, so need to revisit this line. c.Writer.Header().Del("Content-Type") tmpuser, open, err := remote.Login(c.Writer, c.Request) if err != nil { log.Errorf("cannot authenticate user. %s", err) c.Redirect(303, "/login?error=oauth_error") return } // this will happen when the user is redirected by // the remote provide as part of the oauth dance. if tmpuser == nil { return } // get the user from the database u, err := store.GetUserLogin(c, tmpuser.Login) if err != nil { count, err := store.CountUsers(c) if err != nil { log.Errorf("cannot register %s. %s", tmpuser.Login, err) c.Redirect(303, "/login?error=internal_error") return } // if self-registration is disabled we should // return a notAuthorized error. the only exception // is if no users exist yet in the system we'll proceed. if !open && count != 0 { log.Errorf("cannot register %s. registration closed", tmpuser.Login) c.Redirect(303, "/login?error=access_denied") return } // create the user account u = &model.User{} u.Login = tmpuser.Login u.Token = tmpuser.Token u.Secret = tmpuser.Secret u.Email = tmpuser.Email u.Avatar = tmpuser.Avatar u.Hash = crypto.Rand() // insert the user into the database if err := store.CreateUser(c, u); err != nil { log.Errorf("cannot insert %s. %s", u.Login, err) c.Redirect(303, "/login?error=internal_error") return } // if this is the first user, they // should be an admin. if count == 0 { u.Admin = true } } // update the user meta data and authorization // data and cache in the datastore. u.Token = tmpuser.Token u.Secret = tmpuser.Secret u.Email = tmpuser.Email u.Avatar = tmpuser.Avatar if err := store.UpdateUser(c, u); err != nil { log.Errorf("cannot update %s. %s", u.Login, err) c.Redirect(303, "/login?error=internal_error") return } exp := time.Now().Add(time.Hour * 72).Unix() token := token.New(token.SessToken, u.Login) tokenstr, err := token.SignExpires(u.Hash, exp) if err != nil { log.Errorf("cannot create token for %s. %s", u.Login, err) c.Redirect(303, "/login?error=internal_error") return } httputil.SetCookie(c.Writer, c.Request, "user_sess", tokenstr) redirect := httputil.GetCookie(c.Request, "user_last") if len(redirect) == 0 { redirect = "/" } c.Redirect(303, redirect) }
func PostRepo(c *gin.Context) { remote := remote.FromContext(c) user := session.User(c) owner := c.Param("owner") name := c.Param("name") paramActivate := c.Request.FormValue("activate") if user == nil { c.AbortWithStatus(403) return } r, err := remote.Repo(user, owner, name) if err != nil { c.String(404, err.Error()) return } m, err := remote.Perm(user, owner, name) if err != nil { c.String(404, err.Error()) return } if !m.Admin { c.String(403, "Administrative access is required.") return } // error if the repository already exists _, err = store.GetRepoOwnerName(c, owner, name) if err == nil { c.String(409, "Repository already exists.") return } // set the repository owner to the // currently authenticated user. r.UserID = user.ID r.AllowPush = true r.AllowPull = true r.Timeout = 60 // 1 hour default build time r.Hash = crypto.Rand() // crates the jwt token used to verify the repository t := token.New(token.HookToken, r.FullName) sig, err := t.Sign(r.Hash) if err != nil { c.String(500, err.Error()) return } // generate an RSA key and add to the repo key, err := crypto.GeneratePrivateKey() if err != nil { c.String(500, err.Error()) return } keys := new(model.Key) keys.Public = string(crypto.MarshalPublicKey(&key.PublicKey)) keys.Private = string(crypto.MarshalPrivateKey(key)) var activate bool activate, err = strconv.ParseBool(paramActivate) if err != nil { activate = true } if activate { link := fmt.Sprintf( "%s/hook?access_token=%s", httputil.GetURL(c.Request), sig, ) // activate the repository before we make any // local changes to the database. err = remote.Activate(user, r, keys, link) if err != nil { c.String(500, err.Error()) return } } // persist the repository err = store.CreateRepo(c, r) if err != nil { c.String(500, err.Error()) return } keys.RepoID = r.ID err = store.CreateKey(c, keys) if err != nil { c.String(500, err.Error()) return } c.JSON(200, r) }
func ShowNodes(c *gin.Context) { user := session.User(c) nodes, _ := store.GetNodeList(c) token, _ := token.New(token.CsrfToken, user.Login).Sign(user.Hash) c.HTML(http.StatusOK, "nodes.html", gin.H{"User": user, "Nodes": nodes, "Csrf": token}) }