You can not select more than 25 topics Topics must start with a chinese character,a letter or number, can include dashes ('-') and can be up to 35 characters long.

user.go 13 kB

11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
11 years ago
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501
  1. // Copyright 2014 The Gogs Authors. All rights reserved.
  2. // Use of this source code is governed by a MIT-style
  3. // license that can be found in the LICENSE file.
  4. package models
  5. import (
  6. "crypto/sha256"
  7. "encoding/hex"
  8. "errors"
  9. "fmt"
  10. "os"
  11. "path/filepath"
  12. "strings"
  13. "time"
  14. "github.com/gogits/git"
  15. "github.com/gogits/gogs/modules/base"
  16. "github.com/gogits/gogs/modules/log"
  17. )
  18. // User types.
  19. const (
  20. UT_INDIVIDUAL = iota + 1
  21. UT_ORGANIZATION
  22. )
  23. var (
  24. ErrUserOwnRepos = errors.New("User still have ownership of repositories")
  25. ErrUserAlreadyExist = errors.New("User already exist")
  26. ErrUserNotExist = errors.New("User does not exist")
  27. ErrEmailAlreadyUsed = errors.New("E-mail already used")
  28. ErrUserNameIllegal = errors.New("User name contains illegal characters")
  29. ErrLoginSourceNotExist = errors.New("Login source does not exist")
  30. ErrLoginSourceNotActived = errors.New("Login source is not actived")
  31. ErrUnsupportedLoginType = errors.New("Login source is unknow")
  32. )
  33. // User represents the object of individual and member of organization.
  34. type User struct {
  35. Id int64
  36. LowerName string `xorm:"unique not null"`
  37. Name string `xorm:"unique not null"`
  38. FullName string
  39. Email string `xorm:"unique not null"`
  40. Passwd string `xorm:"not null"`
  41. LoginType int
  42. LoginSource int64 `xorm:"not null default 0"`
  43. LoginName string
  44. Type int
  45. NumFollowers int
  46. NumFollowings int
  47. NumStars int
  48. NumRepos int
  49. Avatar string `xorm:"varchar(2048) not null"`
  50. AvatarEmail string `xorm:"not null"`
  51. Location string
  52. Website string
  53. IsActive bool
  54. IsAdmin bool
  55. Rands string `xorm:"VARCHAR(10)"`
  56. Salt string `xorm:"VARCHAR(10)"`
  57. Created time.Time `xorm:"created"`
  58. Updated time.Time `xorm:"updated"`
  59. }
  60. // HomeLink returns the user home page link.
  61. func (user *User) HomeLink() string {
  62. return "/user/" + user.Name
  63. }
  64. // AvatarLink returns the user gravatar link.
  65. func (user *User) AvatarLink() string {
  66. if base.DisableGravatar {
  67. return "/img/avatar_default.jpg"
  68. } else if base.Service.EnableCacheAvatar {
  69. return "/avatar/" + user.Avatar
  70. }
  71. return "//1.gravatar.com/avatar/" + user.Avatar
  72. }
  73. // NewGitSig generates and returns the signature of given user.
  74. func (user *User) NewGitSig() *git.Signature {
  75. return &git.Signature{
  76. Name: user.Name,
  77. Email: user.Email,
  78. When: time.Now(),
  79. }
  80. }
  81. // EncodePasswd encodes password to safe format.
  82. func (user *User) EncodePasswd() {
  83. newPasswd := base.PBKDF2([]byte(user.Passwd), []byte(user.Salt), 10000, 50, sha256.New)
  84. user.Passwd = fmt.Sprintf("%x", newPasswd)
  85. }
  86. // Member represents user is member of organization.
  87. type Member struct {
  88. Id int64
  89. OrgId int64 `xorm:"unique(member) index"`
  90. UserId int64 `xorm:"unique(member)"`
  91. }
  92. // IsUserExist checks if given user name exist,
  93. // the user name should be noncased unique.
  94. func IsUserExist(name string) (bool, error) {
  95. if len(name) == 0 {
  96. return false, nil
  97. }
  98. return orm.Get(&User{LowerName: strings.ToLower(name)})
  99. }
  100. // IsEmailUsed returns true if the e-mail has been used.
  101. func IsEmailUsed(email string) (bool, error) {
  102. if len(email) == 0 {
  103. return false, nil
  104. }
  105. return orm.Get(&User{Email: email})
  106. }
  107. // return a user salt token
  108. func GetUserSalt() string {
  109. return base.GetRandomString(10)
  110. }
  111. // RegisterUser creates record of a new user.
  112. func RegisterUser(user *User) (*User, error) {
  113. if !IsLegalName(user.Name) {
  114. return nil, ErrUserNameIllegal
  115. }
  116. isExist, err := IsUserExist(user.Name)
  117. if err != nil {
  118. return nil, err
  119. } else if isExist {
  120. return nil, ErrUserAlreadyExist
  121. }
  122. isExist, err = IsEmailUsed(user.Email)
  123. if err != nil {
  124. return nil, err
  125. } else if isExist {
  126. return nil, ErrEmailAlreadyUsed
  127. }
  128. user.LowerName = strings.ToLower(user.Name)
  129. user.Avatar = base.EncodeMd5(user.Email)
  130. user.AvatarEmail = user.Email
  131. user.Rands = GetUserSalt()
  132. user.Salt = GetUserSalt()
  133. user.EncodePasswd()
  134. if _, err = orm.Insert(user); err != nil {
  135. return nil, err
  136. } else if err = os.MkdirAll(UserPath(user.Name), os.ModePerm); err != nil {
  137. if _, err := orm.Id(user.Id).Delete(&User{}); err != nil {
  138. return nil, errors.New(fmt.Sprintf(
  139. "both create userpath %s and delete table record faild: %v", user.Name, err))
  140. }
  141. return nil, err
  142. }
  143. if user.Id == 1 {
  144. user.IsAdmin = true
  145. user.IsActive = true
  146. _, err = orm.Id(user.Id).UseBool().Update(user)
  147. }
  148. return user, err
  149. }
  150. // GetUsers returns given number of user objects with offset.
  151. func GetUsers(num, offset int) ([]User, error) {
  152. users := make([]User, 0, num)
  153. err := orm.Limit(num, offset).Asc("id").Find(&users)
  154. return users, err
  155. }
  156. // get user by erify code
  157. func getVerifyUser(code string) (user *User) {
  158. if len(code) <= base.TimeLimitCodeLength {
  159. return nil
  160. }
  161. // use tail hex username query user
  162. hexStr := code[base.TimeLimitCodeLength:]
  163. if b, err := hex.DecodeString(hexStr); err == nil {
  164. if user, err = GetUserByName(string(b)); user != nil {
  165. return user
  166. }
  167. log.Error("user.getVerifyUser: %v", err)
  168. }
  169. return nil
  170. }
  171. // verify active code when active account
  172. func VerifyUserActiveCode(code string) (user *User) {
  173. minutes := base.Service.ActiveCodeLives
  174. if user = getVerifyUser(code); user != nil {
  175. // time limit code
  176. prefix := code[:base.TimeLimitCodeLength]
  177. data := base.ToStr(user.Id) + user.Email + user.LowerName + user.Passwd + user.Rands
  178. if base.VerifyTimeLimitCode(data, minutes, prefix) {
  179. return user
  180. }
  181. }
  182. return nil
  183. }
  184. // ChangeUserName changes all corresponding setting from old user name to new one.
  185. func ChangeUserName(user *User, newUserName string) (err error) {
  186. newUserName = strings.ToLower(newUserName)
  187. // Update accesses of user.
  188. accesses := make([]Access, 0, 10)
  189. if err = orm.Find(&accesses, &Access{UserName: user.LowerName}); err != nil {
  190. return err
  191. }
  192. sess := orm.NewSession()
  193. defer sess.Close()
  194. if err = sess.Begin(); err != nil {
  195. return err
  196. }
  197. for i := range accesses {
  198. accesses[i].UserName = newUserName
  199. if strings.HasPrefix(accesses[i].RepoName, user.LowerName+"/") {
  200. accesses[i].RepoName = strings.Replace(accesses[i].RepoName, user.LowerName, newUserName, 1)
  201. }
  202. if err = UpdateAccessWithSession(sess, &accesses[i]); err != nil {
  203. return err
  204. }
  205. }
  206. repos, err := GetRepositories(user, true)
  207. if err != nil {
  208. return err
  209. }
  210. for i := range repos {
  211. accesses = make([]Access, 0, 10)
  212. // Update accesses of user repository.
  213. if err = orm.Find(&accesses, &Access{RepoName: user.LowerName + "/" + repos[i].LowerName}); err != nil {
  214. return err
  215. }
  216. for j := range accesses {
  217. accesses[j].UserName = newUserName
  218. accesses[j].RepoName = newUserName + "/" + repos[i].LowerName
  219. if err = UpdateAccessWithSession(sess, &accesses[j]); err != nil {
  220. return err
  221. }
  222. }
  223. }
  224. // Change user directory name.
  225. if err = os.Rename(UserPath(user.LowerName), UserPath(newUserName)); err != nil {
  226. sess.Rollback()
  227. return err
  228. }
  229. return sess.Commit()
  230. }
  231. // UpdateUser updates user's information.
  232. func UpdateUser(user *User) (err error) {
  233. user.LowerName = strings.ToLower(user.Name)
  234. if len(user.Location) > 255 {
  235. user.Location = user.Location[:255]
  236. }
  237. if len(user.Website) > 255 {
  238. user.Website = user.Website[:255]
  239. }
  240. _, err = orm.Id(user.Id).AllCols().Update(user)
  241. return err
  242. }
  243. // DeleteUser completely deletes everything of the user.
  244. func DeleteUser(user *User) error {
  245. // Check ownership of repository.
  246. count, err := GetRepositoryCount(user)
  247. if err != nil {
  248. return errors.New("modesl.GetRepositories: " + err.Error())
  249. } else if count > 0 {
  250. return ErrUserOwnRepos
  251. }
  252. // TODO: check issues, other repos' commits
  253. // Delete all followers.
  254. if _, err = orm.Delete(&Follow{FollowId: user.Id}); err != nil {
  255. return err
  256. }
  257. // Delete oauth2.
  258. if _, err = orm.Delete(&Oauth2{Uid: user.Id}); err != nil {
  259. return err
  260. }
  261. // Delete all feeds.
  262. if _, err = orm.Delete(&Action{UserId: user.Id}); err != nil {
  263. return err
  264. }
  265. // Delete all watches.
  266. if _, err = orm.Delete(&Watch{UserId: user.Id}); err != nil {
  267. return err
  268. }
  269. // Delete all accesses.
  270. if _, err = orm.Delete(&Access{UserName: user.LowerName}); err != nil {
  271. return err
  272. }
  273. // Delete all SSH keys.
  274. keys := make([]*PublicKey, 0, 10)
  275. if err = orm.Find(&keys, &PublicKey{OwnerId: user.Id}); err != nil {
  276. return err
  277. }
  278. for _, key := range keys {
  279. if err = DeletePublicKey(key); err != nil {
  280. return err
  281. }
  282. }
  283. // Delete user directory.
  284. if err = os.RemoveAll(UserPath(user.Name)); err != nil {
  285. return err
  286. }
  287. _, err = orm.Delete(user)
  288. return err
  289. }
  290. // UserPath returns the path absolute path of user repositories.
  291. func UserPath(userName string) string {
  292. return filepath.Join(base.RepoRootPath, strings.ToLower(userName))
  293. }
  294. func GetUserByKeyId(keyId int64) (*User, error) {
  295. user := new(User)
  296. rawSql := "SELECT a.* FROM `user` AS a, public_key AS b WHERE a.id = b.owner_id AND b.id=?"
  297. has, err := orm.Sql(rawSql, keyId).Get(user)
  298. if err != nil {
  299. return nil, err
  300. } else if !has {
  301. err = errors.New("not exist key owner")
  302. return nil, err
  303. }
  304. return user, nil
  305. }
  306. // GetUserById returns the user object by given id if exists.
  307. func GetUserById(id int64) (*User, error) {
  308. user := new(User)
  309. has, err := orm.Id(id).Get(user)
  310. if err != nil {
  311. return nil, err
  312. }
  313. if !has {
  314. return nil, ErrUserNotExist
  315. }
  316. return user, nil
  317. }
  318. // GetUserByName returns the user object by given name if exists.
  319. func GetUserByName(name string) (*User, error) {
  320. if len(name) == 0 {
  321. return nil, ErrUserNotExist
  322. }
  323. user := &User{LowerName: strings.ToLower(name)}
  324. has, err := orm.Get(user)
  325. if err != nil {
  326. return nil, err
  327. } else if !has {
  328. return nil, ErrUserNotExist
  329. }
  330. return user, nil
  331. }
  332. // GetUserEmailsByNames returns a slice of e-mails corresponds to names.
  333. func GetUserEmailsByNames(names []string) []string {
  334. mails := make([]string, 0, len(names))
  335. for _, name := range names {
  336. u, err := GetUserByName(name)
  337. if err != nil {
  338. continue
  339. }
  340. mails = append(mails, u.Email)
  341. }
  342. return mails
  343. }
  344. // GetUserIdsByNames returns a slice of ids corresponds to names.
  345. func GetUserIdsByNames(names []string) []int64 {
  346. ids := make([]int64, 0, len(names))
  347. for _, name := range names {
  348. u, err := GetUserByName(name)
  349. if err != nil {
  350. continue
  351. }
  352. ids = append(ids, u.Id)
  353. }
  354. return ids
  355. }
  356. // GetUserByEmail returns the user object by given e-mail if exists.
  357. func GetUserByEmail(email string) (*User, error) {
  358. if len(email) == 0 {
  359. return nil, ErrUserNotExist
  360. }
  361. user := &User{Email: strings.ToLower(email)}
  362. has, err := orm.Get(user)
  363. if err != nil {
  364. return nil, err
  365. } else if !has {
  366. return nil, ErrUserNotExist
  367. }
  368. return user, nil
  369. }
  370. // SearchUserByName returns given number of users whose name contains keyword.
  371. func SearchUserByName(key string, limit int) (us []*User, err error) {
  372. // Prevent SQL inject.
  373. key = strings.TrimSpace(key)
  374. if len(key) == 0 {
  375. return us, nil
  376. }
  377. key = strings.Split(key, " ")[0]
  378. if len(key) == 0 {
  379. return us, nil
  380. }
  381. key = strings.ToLower(key)
  382. us = make([]*User, 0, limit)
  383. err = orm.Limit(limit).Where("lower_name like '%" + key + "%'").Find(&us)
  384. return us, err
  385. }
  386. // Follow is connection request for receiving user notifycation.
  387. type Follow struct {
  388. Id int64
  389. UserId int64 `xorm:"unique(follow)"`
  390. FollowId int64 `xorm:"unique(follow)"`
  391. }
  392. // FollowUser marks someone be another's follower.
  393. func FollowUser(userId int64, followId int64) (err error) {
  394. session := orm.NewSession()
  395. defer session.Close()
  396. session.Begin()
  397. if _, err = session.Insert(&Follow{UserId: userId, FollowId: followId}); err != nil {
  398. session.Rollback()
  399. return err
  400. }
  401. rawSql := "UPDATE `user` SET num_followers = num_followers + 1 WHERE id = ?"
  402. if _, err = session.Exec(rawSql, followId); err != nil {
  403. session.Rollback()
  404. return err
  405. }
  406. rawSql = "UPDATE `user` SET num_followings = num_followings + 1 WHERE id = ?"
  407. if _, err = session.Exec(rawSql, userId); err != nil {
  408. session.Rollback()
  409. return err
  410. }
  411. return session.Commit()
  412. }
  413. // UnFollowUser unmarks someone be another's follower.
  414. func UnFollowUser(userId int64, unFollowId int64) (err error) {
  415. session := orm.NewSession()
  416. defer session.Close()
  417. session.Begin()
  418. if _, err = session.Delete(&Follow{UserId: userId, FollowId: unFollowId}); err != nil {
  419. session.Rollback()
  420. return err
  421. }
  422. rawSql := "UPDATE `user` SET num_followers = num_followers - 1 WHERE id = ?"
  423. if _, err = session.Exec(rawSql, unFollowId); err != nil {
  424. session.Rollback()
  425. return err
  426. }
  427. rawSql = "UPDATE `user` SET num_followings = num_followings - 1 WHERE id = ?"
  428. if _, err = session.Exec(rawSql, userId); err != nil {
  429. session.Rollback()
  430. return err
  431. }
  432. return session.Commit()
  433. }