users.go 6.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249
  1. package admin
  2. import (
  3. "net/http"
  4. "strconv"
  5. "strings"
  6. log "unknwon.dev/clog/v2"
  7. "gogs.io/gogs/internal/conf"
  8. "gogs.io/gogs/internal/context"
  9. "gogs.io/gogs/internal/database"
  10. "gogs.io/gogs/internal/email"
  11. "gogs.io/gogs/internal/form"
  12. "gogs.io/gogs/internal/route"
  13. )
  14. const (
  15. tmplAdminUserList = "admin/user/list"
  16. tmplAdminUserNew = "admin/user/new"
  17. tmplAdminUserEdit = "admin/user/edit"
  18. )
  19. func Users(c *context.Context) {
  20. c.Data["Title"] = c.Tr("admin.users")
  21. c.Data["PageIsAdmin"] = true
  22. c.Data["PageIsAdminUsers"] = true
  23. route.RenderUserSearch(c, &route.UserSearchOptions{
  24. Type: database.UserTypeIndividual,
  25. Counter: database.Handle.Users().Count,
  26. Ranger: database.Handle.Users().List,
  27. PageSize: conf.UI.Admin.UserPagingNum,
  28. OrderBy: "id ASC",
  29. TplName: tmplAdminUserList,
  30. })
  31. }
  32. func NewUser(c *context.Context) {
  33. c.Data["Title"] = c.Tr("admin.users.new_account")
  34. c.Data["PageIsAdmin"] = true
  35. c.Data["PageIsAdminUsers"] = true
  36. c.Data["login_type"] = "0-0"
  37. sources, err := database.Handle.LoginSources().List(c.Req.Context(), database.ListLoginSourceOptions{})
  38. if err != nil {
  39. c.Error(err, "list login sources")
  40. return
  41. }
  42. c.Data["Sources"] = sources
  43. c.Data["CanSendEmail"] = conf.Email.Enabled
  44. c.Success(tmplAdminUserNew)
  45. }
  46. func NewUserPost(c *context.Context, f form.AdminCrateUser) {
  47. c.Data["Title"] = c.Tr("admin.users.new_account")
  48. c.Data["PageIsAdmin"] = true
  49. c.Data["PageIsAdminUsers"] = true
  50. sources, err := database.Handle.LoginSources().List(c.Req.Context(), database.ListLoginSourceOptions{})
  51. if err != nil {
  52. c.Error(err, "list login sources")
  53. return
  54. }
  55. c.Data["Sources"] = sources
  56. c.Data["CanSendEmail"] = conf.Email.Enabled
  57. if c.HasError() {
  58. c.HTML(http.StatusBadRequest, tmplAdminUserNew)
  59. return
  60. }
  61. createUserOpts := database.CreateUserOptions{
  62. Password: f.Password,
  63. Activated: true,
  64. }
  65. if len(f.LoginType) > 0 {
  66. fields := strings.Split(f.LoginType, "-")
  67. if len(fields) == 2 {
  68. createUserOpts.LoginSource, _ = strconv.ParseInt(fields[1], 10, 64)
  69. createUserOpts.LoginName = f.LoginName
  70. }
  71. }
  72. user, err := database.Handle.Users().Create(c.Req.Context(), f.UserName, f.Email, createUserOpts)
  73. if err != nil {
  74. switch {
  75. case database.IsErrUserAlreadyExist(err):
  76. c.Data["Err_UserName"] = true
  77. c.RenderWithErr(c.Tr("form.username_been_taken"), http.StatusUnprocessableEntity, tmplAdminUserNew, &f)
  78. case database.IsErrEmailAlreadyUsed(err):
  79. c.Data["Err_Email"] = true
  80. c.RenderWithErr(c.Tr("form.email_been_used"), http.StatusUnprocessableEntity, tmplAdminUserNew, &f)
  81. case database.IsErrNameNotAllowed(err):
  82. c.Data["Err_UserName"] = true
  83. c.RenderWithErr(c.Tr("user.form.name_not_allowed", err.(database.ErrNameNotAllowed).Value()), http.StatusBadRequest, tmplAdminUserNew, &f)
  84. default:
  85. c.Error(err, "create user")
  86. }
  87. return
  88. }
  89. log.Trace("Account %q created by admin %q", user.Name, c.User.Name)
  90. // Send email notification.
  91. if f.SendNotify && conf.Email.Enabled {
  92. email.SendRegisterNotifyMail(c.Context, database.NewMailerUser(user))
  93. }
  94. c.Flash.Success(c.Tr("admin.users.new_success", user.Name))
  95. c.Redirect(conf.Server.Subpath + "/admin/users/" + strconv.FormatInt(user.ID, 10))
  96. }
  97. func prepareUserInfo(c *context.Context) *database.User {
  98. u, err := database.Handle.Users().GetByID(c.Req.Context(), c.ParamsInt64(":userid"))
  99. if err != nil {
  100. c.Error(err, "get user by ID")
  101. return nil
  102. }
  103. c.Data["User"] = u
  104. if u.LoginSource > 0 {
  105. c.Data["LoginSource"], err = database.Handle.LoginSources().GetByID(c.Req.Context(), u.LoginSource)
  106. if err != nil {
  107. c.Error(err, "get login source by ID")
  108. return nil
  109. }
  110. } else {
  111. c.Data["LoginSource"] = &database.LoginSource{}
  112. }
  113. sources, err := database.Handle.LoginSources().List(c.Req.Context(), database.ListLoginSourceOptions{})
  114. if err != nil {
  115. c.Error(err, "list login sources")
  116. return nil
  117. }
  118. c.Data["Sources"] = sources
  119. return u
  120. }
  121. func EditUser(c *context.Context) {
  122. c.Data["Title"] = c.Tr("admin.users.edit_account")
  123. c.Data["PageIsAdmin"] = true
  124. c.Data["PageIsAdminUsers"] = true
  125. c.Data["EnableLocalPathMigration"] = conf.Repository.EnableLocalPathMigration
  126. prepareUserInfo(c)
  127. if c.Written() {
  128. return
  129. }
  130. c.Success(tmplAdminUserEdit)
  131. }
  132. func EditUserPost(c *context.Context, f form.AdminEditUser) {
  133. c.Data["Title"] = c.Tr("admin.users.edit_account")
  134. c.Data["PageIsAdmin"] = true
  135. c.Data["PageIsAdminUsers"] = true
  136. c.Data["EnableLocalPathMigration"] = conf.Repository.EnableLocalPathMigration
  137. u := prepareUserInfo(c)
  138. if c.Written() {
  139. return
  140. }
  141. if c.HasError() {
  142. c.HTML(http.StatusBadRequest, tmplAdminUserEdit)
  143. return
  144. }
  145. opts := database.UpdateUserOptions{
  146. LoginName: &f.LoginName,
  147. FullName: &f.FullName,
  148. Website: &f.Website,
  149. Location: &f.Location,
  150. MaxRepoCreation: &f.MaxRepoCreation,
  151. IsActivated: &f.Active,
  152. IsAdmin: &f.Admin,
  153. AllowGitHook: &f.AllowGitHook,
  154. AllowImportLocal: &f.AllowImportLocal,
  155. ProhibitLogin: &f.ProhibitLogin,
  156. }
  157. fields := strings.Split(f.LoginType, "-")
  158. if len(fields) == 2 {
  159. loginSource, _ := strconv.ParseInt(fields[1], 10, 64)
  160. if u.LoginSource != loginSource {
  161. opts.LoginSource = &loginSource
  162. }
  163. }
  164. if f.Password != "" {
  165. opts.Password = &f.Password
  166. }
  167. if u.Email != f.Email {
  168. opts.Email = &f.Email
  169. }
  170. err := database.Handle.Users().Update(c.Req.Context(), u.ID, opts)
  171. if err != nil {
  172. if database.IsErrEmailAlreadyUsed(err) {
  173. c.Data["Err_Email"] = true
  174. c.RenderWithErr(c.Tr("form.email_been_used"), http.StatusUnprocessableEntity, tmplAdminUserEdit, &f)
  175. } else {
  176. c.Error(err, "update user")
  177. }
  178. return
  179. }
  180. log.Trace("Account updated by admin %q: %s", c.User.Name, u.Name)
  181. c.Flash.Success(c.Tr("admin.users.update_profile_success"))
  182. c.Redirect(conf.Server.Subpath + "/admin/users/" + c.Params(":userid"))
  183. }
  184. func DeleteUser(c *context.Context) {
  185. u, err := database.Handle.Users().GetByID(c.Req.Context(), c.ParamsInt64(":userid"))
  186. if err != nil {
  187. c.Error(err, "get user by ID")
  188. return
  189. }
  190. if err = database.Handle.Users().DeleteByID(c.Req.Context(), u.ID, false); err != nil {
  191. switch {
  192. case database.IsErrUserOwnRepos(err):
  193. c.Flash.Error(c.Tr("admin.users.still_own_repo"))
  194. c.JSONSuccess(map[string]any{
  195. "redirect": conf.Server.Subpath + "/admin/users/" + c.Params(":userid"),
  196. })
  197. case database.IsErrUserHasOrgs(err):
  198. c.Flash.Error(c.Tr("admin.users.still_has_org"))
  199. c.JSONSuccess(map[string]any{
  200. "redirect": conf.Server.Subpath + "/admin/users/" + c.Params(":userid"),
  201. })
  202. default:
  203. c.Error(err, "delete user")
  204. }
  205. return
  206. }
  207. log.Trace("Account deleted by admin (%s): %s", c.User.Name, u.Name)
  208. c.Flash.Success(c.Tr("admin.users.deletion_success"))
  209. c.JSONSuccess(map[string]any{
  210. "redirect": conf.Server.Subpath + "/admin/users",
  211. })
  212. }