2016-12-02 07:38:54 +00:00
package main
2017-01-17 07:55:46 +00:00
//import "fmt"
2017-02-11 14:51:16 +00:00
import "sync"
2016-12-07 09:34:09 +00:00
import "strings"
2016-12-02 07:38:54 +00:00
import "strconv"
2017-01-17 07:55:46 +00:00
import "net"
2016-12-02 07:38:54 +00:00
import "net/http"
import "golang.org/x/crypto/bcrypt"
import "database/sql"
import _ "github.com/go-sql-driver/mysql"
2017-02-15 10:49:30 +00:00
var guest_user User = User { ID : 0 , Group : 6 , Perms : GuestPerms }
2016-12-02 07:38:54 +00:00
type User struct
{
ID int
Name string
2016-12-23 12:35:22 +00:00
Email string
2016-12-02 07:38:54 +00:00
Group int
2016-12-13 02:14:14 +00:00
Active bool
2016-12-07 13:46:14 +00:00
Is_Mod bool
Is_Super_Mod bool
2016-12-02 07:38:54 +00:00
Is_Admin bool
2016-12-02 08:07:56 +00:00
Is_Super_Admin bool
2016-12-04 10:44:28 +00:00
Is_Banned bool
2016-12-21 02:30:32 +00:00
Perms Perms
2016-12-02 07:38:54 +00:00
Session string
Loggedin bool
2016-12-02 15:03:31 +00:00
Avatar string
2016-12-09 13:46:29 +00:00
Message string
URLPrefix string
URLName string
2016-12-13 02:14:14 +00:00
Tag string
2017-01-12 02:55:08 +00:00
Level int
Score int
2017-01-17 07:55:46 +00:00
Last_IP string
2016-12-02 07:38:54 +00:00
}
2017-01-03 07:47:31 +00:00
type Email struct
{
UserID int
Email string
Validated bool
Primary bool
Token string
}
2017-02-11 14:51:16 +00:00
type UserStore interface {
2017-02-15 10:49:30 +00:00
Load ( id int ) error
2017-02-11 14:51:16 +00:00
Get ( id int ) ( * User , error )
GetUnsafe ( id int ) ( * User , error )
CascadeGet ( id int ) ( * User , error )
2017-02-15 10:49:30 +00:00
Set ( item * User ) error
2017-02-11 14:51:16 +00:00
Add ( item * User ) error
AddUnsafe ( item * User ) error
Remove ( id int ) error
RemoveUnsafe ( id int ) error
GetLength ( ) int
GetCapacity ( ) int
}
type StaticUserStore struct {
items map [ int ] * User
length int
capacity int
mu sync . RWMutex
}
func NewStaticUserStore ( capacity int ) * StaticUserStore {
return & StaticUserStore { items : make ( map [ int ] * User ) , capacity : capacity }
}
func ( sts * StaticUserStore ) Get ( id int ) ( * User , error ) {
sts . mu . RLock ( )
item , ok := sts . items [ id ]
sts . mu . RUnlock ( )
if ok {
return item , nil
}
return item , sql . ErrNoRows
}
func ( sts * StaticUserStore ) GetUnsafe ( id int ) ( * User , error ) {
item , ok := sts . items [ id ]
if ok {
return item , nil
}
return item , sql . ErrNoRows
}
func ( sts * StaticUserStore ) CascadeGet ( id int ) ( * User , error ) {
sts . mu . RLock ( )
user , ok := sts . items [ id ]
sts . mu . RUnlock ( )
if ok {
return user , nil
}
2017-02-15 15:29:05 +00:00
user = & User { ID : id , Loggedin : true }
2017-02-11 14:51:16 +00:00
err := get_full_user_stmt . QueryRow ( id ) . Scan ( & user . Name , & user . Group , & user . Is_Super_Admin , & user . Session , & user . Email , & user . Avatar , & user . Message , & user . URLPrefix , & user . URLName , & user . Level , & user . Score , & user . Last_IP )
2017-02-15 10:49:30 +00:00
if user . Avatar != "" {
if user . Avatar [ 0 ] == '.' {
user . Avatar = "/uploads/avatar_" + strconv . Itoa ( user . ID ) + user . Avatar
}
} else {
user . Avatar = strings . Replace ( noavatar , "{id}" , strconv . Itoa ( user . ID ) , 1 )
}
user . Tag = groups [ user . Group ] . Tag
init_user_perms ( user )
2017-02-11 14:51:16 +00:00
if err == nil {
sts . Add ( user )
}
return user , err
}
2017-02-15 10:49:30 +00:00
func ( sts * StaticUserStore ) Load ( id int ) error {
2017-02-15 15:29:05 +00:00
user := & User { ID : id , Loggedin : true }
2017-02-15 10:49:30 +00:00
err := get_full_user_stmt . QueryRow ( id ) . Scan ( & user . Name , & user . Group , & user . Is_Super_Admin , & user . Session , & user . Email , & user . Avatar , & user . Message , & user . URLPrefix , & user . URLName , & user . Level , & user . Score , & user . Last_IP )
if err != nil {
2017-02-16 06:47:55 +00:00
sts . Remove ( id )
2017-02-15 10:49:30 +00:00
return err
}
if user . Avatar != "" {
if user . Avatar [ 0 ] == '.' {
user . Avatar = "/uploads/avatar_" + strconv . Itoa ( user . ID ) + user . Avatar
}
} else {
user . Avatar = strings . Replace ( noavatar , "{id}" , strconv . Itoa ( user . ID ) , 1 )
}
user . Tag = groups [ user . Group ] . Tag
init_user_perms ( user )
sts . Set ( user )
return nil
}
func ( sts * StaticUserStore ) Set ( item * User ) error {
sts . mu . Lock ( )
2017-02-16 06:47:55 +00:00
_ , ok := sts . items [ item . ID ]
2017-02-15 10:49:30 +00:00
if ok {
sts . items [ item . ID ] = item
} else if sts . length >= sts . capacity {
sts . mu . Unlock ( )
return ErrStoreCapacityOverflow
} else {
sts . items [ item . ID ] = item
2017-02-16 06:47:55 +00:00
sts . length ++
2017-02-15 10:49:30 +00:00
}
sts . mu . Unlock ( )
return nil
}
2017-02-11 14:51:16 +00:00
func ( sts * StaticUserStore ) Add ( item * User ) error {
if sts . length >= sts . capacity {
return ErrStoreCapacityOverflow
}
sts . mu . Lock ( )
sts . items [ item . ID ] = item
sts . mu . Unlock ( )
sts . length ++
return nil
}
func ( sts * StaticUserStore ) AddUnsafe ( item * User ) error {
if sts . length >= sts . capacity {
return ErrStoreCapacityOverflow
}
sts . items [ item . ID ] = item
sts . length ++
return nil
}
func ( sts * StaticUserStore ) Remove ( id int ) error {
sts . mu . Lock ( )
delete ( sts . items , id )
sts . mu . Unlock ( )
sts . length --
return nil
}
func ( sts * StaticUserStore ) RemoveUnsafe ( id int ) error {
delete ( sts . items , id )
sts . length --
return nil
}
func ( sts * StaticUserStore ) GetLength ( ) int {
return sts . length
}
func ( sts * StaticUserStore ) SetCapacity ( capacity int ) {
sts . capacity = capacity
}
func ( sts * StaticUserStore ) GetCapacity ( ) int {
return sts . capacity
}
//type DynamicUserStore struct {
// items_expiries list.List
// items map[int]*User
//}
type SqlUserStore struct {
}
func NewSqlUserStore ( ) * SqlUserStore {
return & SqlUserStore { }
}
func ( sus * SqlUserStore ) Get ( id int ) ( * User , error ) {
2017-02-15 15:29:05 +00:00
user := User { ID : id , Loggedin : true }
2017-02-11 14:51:16 +00:00
err := get_full_user_stmt . QueryRow ( id ) . Scan ( & user . Name , & user . Group , & user . Is_Super_Admin , & user . Session , & user . Email , & user . Avatar , & user . Message , & user . URLPrefix , & user . URLName , & user . Level , & user . Score , & user . Last_IP )
2017-02-15 10:49:30 +00:00
if user . Avatar != "" {
if user . Avatar [ 0 ] == '.' {
user . Avatar = "/uploads/avatar_" + strconv . Itoa ( user . ID ) + user . Avatar
}
} else {
user . Avatar = strings . Replace ( noavatar , "{id}" , strconv . Itoa ( user . ID ) , 1 )
}
user . Tag = groups [ user . Group ] . Tag
init_user_perms ( & user )
2017-02-11 14:51:16 +00:00
return & user , err
}
func ( sus * SqlUserStore ) GetUnsafe ( id int ) ( * User , error ) {
2017-02-15 15:29:05 +00:00
user := User { ID : id , Loggedin : true }
2017-02-11 14:51:16 +00:00
err := get_full_user_stmt . QueryRow ( id ) . Scan ( & user . Name , & user . Group , & user . Is_Super_Admin , & user . Session , & user . Email , & user . Avatar , & user . Message , & user . URLPrefix , & user . URLName , & user . Level , & user . Score , & user . Last_IP )
2017-02-15 10:49:30 +00:00
if user . Avatar != "" {
if user . Avatar [ 0 ] == '.' {
user . Avatar = "/uploads/avatar_" + strconv . Itoa ( user . ID ) + user . Avatar
}
} else {
user . Avatar = strings . Replace ( noavatar , "{id}" , strconv . Itoa ( user . ID ) , 1 )
}
user . Tag = groups [ user . Group ] . Tag
init_user_perms ( & user )
2017-02-11 14:51:16 +00:00
return & user , err
}
func ( sus * SqlUserStore ) CascadeGet ( id int ) ( * User , error ) {
2017-02-15 15:29:05 +00:00
user := User { ID : id , Loggedin : true }
2017-02-11 14:51:16 +00:00
err := get_full_user_stmt . QueryRow ( id ) . Scan ( & user . Name , & user . Group , & user . Is_Super_Admin , & user . Session , & user . Email , & user . Avatar , & user . Message , & user . URLPrefix , & user . URLName , & user . Level , & user . Score , & user . Last_IP )
2017-02-15 10:49:30 +00:00
if user . Avatar != "" {
if user . Avatar [ 0 ] == '.' {
user . Avatar = "/uploads/avatar_" + strconv . Itoa ( user . ID ) + user . Avatar
}
} else {
user . Avatar = strings . Replace ( noavatar , "{id}" , strconv . Itoa ( user . ID ) , 1 )
}
user . Tag = groups [ user . Group ] . Tag
init_user_perms ( & user )
2017-02-11 14:51:16 +00:00
return & user , err
}
2017-02-15 10:49:30 +00:00
func ( sus * SqlUserStore ) Load ( id int ) error {
user := & User { ID : id }
// Simplify this into a quick check whether the user exists
err := get_full_user_stmt . QueryRow ( id ) . Scan ( & user . Name , & user . Group , & user . Is_Super_Admin , & user . Session , & user . Email , & user . Avatar , & user . Message , & user . URLPrefix , & user . URLName , & user . Level , & user . Score , & user . Last_IP )
return err
}
2017-02-11 14:51:16 +00:00
// Placeholder methods, the actual queries are done elsewhere
2017-02-15 10:49:30 +00:00
func ( sus * SqlUserStore ) Set ( item * User ) error {
return nil
}
2017-02-11 14:51:16 +00:00
func ( sus * SqlUserStore ) Add ( item * User ) error {
return nil
}
func ( sus * SqlUserStore ) AddUnsafe ( item * User ) error {
return nil
}
func ( sus * SqlUserStore ) Remove ( id int ) error {
return nil
}
func ( sus * SqlUserStore ) RemoveUnsafe ( id int ) error {
return nil
}
func ( sus * SqlUserStore ) GetCapacity ( ) int {
return 0
}
func ( sus * SqlUserStore ) GetLength ( ) int {
// Return the total number of users registered on the forums
return 0
}
2016-12-02 07:38:54 +00:00
func SetPassword ( uid int , password string ) ( error ) {
salt , err := GenerateSafeString ( saltLength )
if err != nil {
return err
}
password = password + salt
hashed_password , err := bcrypt . GenerateFromPassword ( [ ] byte ( password ) , bcrypt . DefaultCost )
if err != nil {
return err
}
_ , err = set_password_stmt . Exec ( string ( hashed_password ) , salt , uid )
if err != nil {
return err
}
return nil
}
2017-01-03 07:47:31 +00:00
func SendValidationEmail ( username string , email string , token string ) bool {
var schema string
if enable_ssl {
schema = "s"
}
subject := "Validate Your Email @ " + site_name
2017-03-16 05:06:58 +00:00
msg := "Dear " + username + ", following your registration on our forums, we ask you to validate your email, so that we can confirm that this email actually belongs to you.\n\nClick on the following link to do so. http" + schema + "://" + site_url + "/user/edit/token/" + token + "\n\nIf you haven't created an account here, then please feel free to ignore this email.\nWe're sorry for the inconvenience this may have caused."
2017-01-03 07:47:31 +00:00
return SendEmail ( email , subject , msg )
}
2017-02-05 16:36:54 +00:00
func SimpleForumSessionCheck ( w http . ResponseWriter , r * http . Request , fid int ) ( user User , success bool ) {
2017-03-14 10:57:40 +00:00
if ! forum_exists ( fid ) {
2017-02-05 16:36:54 +00:00
PreError ( "The target forum doesn't exist." , w , r )
return user , false
2016-12-16 10:37:42 +00:00
}
2017-02-05 16:36:54 +00:00
user , success = SimpleSessionCheck ( w , r )
fperms := groups [ user . Group ] . Forums [ fid ]
if fperms . Overrides && ! user . Is_Super_Admin {
user . Perms . ViewTopic = fperms . ViewTopic
2017-02-10 13:39:13 +00:00
user . Perms . LikeItem = fperms . LikeItem
2017-02-05 16:36:54 +00:00
user . Perms . CreateTopic = fperms . CreateTopic
user . Perms . EditTopic = fperms . EditTopic
user . Perms . DeleteTopic = fperms . DeleteTopic
user . Perms . CreateReply = fperms . CreateReply
user . Perms . EditReply = fperms . EditReply
user . Perms . DeleteReply = fperms . DeleteReply
user . Perms . PinTopic = fperms . PinTopic
user . Perms . CloseTopic = fperms . CloseTopic
}
return user , success
}
func ForumSessionCheck ( w http . ResponseWriter , r * http . Request , fid int ) ( user User , noticeList [ ] string , success bool ) {
2017-03-14 10:57:40 +00:00
if ! forum_exists ( fid ) {
2017-02-05 16:36:54 +00:00
NotFound ( w , r )
2016-12-16 10:37:42 +00:00
return user , noticeList , false
}
2017-02-05 16:36:54 +00:00
user , success = SimpleSessionCheck ( w , r )
fperms := groups [ user . Group ] . Forums [ fid ]
2017-02-15 10:49:30 +00:00
//fmt.Printf("%+v\n", user.Perms)
//fmt.Printf("%+v\n", fperms)
2017-02-05 16:36:54 +00:00
if fperms . Overrides && ! user . Is_Super_Admin {
user . Perms . ViewTopic = fperms . ViewTopic
2017-02-10 13:39:13 +00:00
user . Perms . LikeItem = fperms . LikeItem
2017-02-05 16:36:54 +00:00
user . Perms . CreateTopic = fperms . CreateTopic
user . Perms . EditTopic = fperms . EditTopic
user . Perms . DeleteTopic = fperms . DeleteTopic
user . Perms . CreateReply = fperms . CreateReply
user . Perms . EditReply = fperms . EditReply
user . Perms . DeleteReply = fperms . DeleteReply
user . Perms . PinTopic = fperms . PinTopic
user . Perms . CloseTopic = fperms . CloseTopic
2016-12-21 02:30:32 +00:00
}
2016-12-16 10:37:42 +00:00
if user . Is_Banned {
2017-02-05 16:36:54 +00:00
noticeList = append ( noticeList , "Your account has been suspended. Some of your permissions may have been revoked." )
2016-12-16 10:37:42 +00:00
}
2017-02-05 16:36:54 +00:00
return user , noticeList , success
}
func SessionCheck ( w http . ResponseWriter , r * http . Request ) ( user User , noticeList [ ] string , success bool ) {
user , success = SimpleSessionCheck ( w , r )
if user . Is_Banned {
noticeList = append ( noticeList , "Your account has been suspended. Some of your permissions may have been revoked." )
2017-01-17 07:55:46 +00:00
}
2017-02-05 16:36:54 +00:00
return user , noticeList , success
2016-12-16 10:37:42 +00:00
}
2017-02-11 14:51:16 +00:00
func SimpleSessionCheck ( w http . ResponseWriter , r * http . Request ) ( User , bool ) {
2016-12-02 07:38:54 +00:00
// Are there any session cookies..?
2016-12-16 10:37:42 +00:00
cookie , err := r . Cookie ( "uid" )
2016-12-02 07:38:54 +00:00
if err != nil {
2017-02-15 10:49:30 +00:00
return guest_user , true
2016-12-02 07:38:54 +00:00
}
2017-02-11 14:51:16 +00:00
uid , err := strconv . Atoi ( cookie . Value )
2016-12-02 07:38:54 +00:00
if err != nil {
2017-02-15 10:49:30 +00:00
return guest_user , true
2016-12-02 07:38:54 +00:00
}
cookie , err = r . Cookie ( "session" )
if err != nil {
2017-02-15 10:49:30 +00:00
return guest_user , true
2016-12-02 07:38:54 +00:00
}
// Is this session valid..?
2017-02-11 14:51:16 +00:00
user , err := users . CascadeGet ( uid )
2016-12-02 07:38:54 +00:00
if err == sql . ErrNoRows {
2017-02-15 10:49:30 +00:00
return guest_user , true
2016-12-02 07:38:54 +00:00
} else if err != nil {
2017-02-05 16:36:54 +00:00
InternalError ( err , w , r )
2017-02-15 10:49:30 +00:00
return guest_user , false
2017-02-11 14:51:16 +00:00
}
if user . Session == "" || cookie . Value != user . Session {
2017-02-15 10:49:30 +00:00
return guest_user , true
2016-12-08 14:11:18 +00:00
}
2016-12-21 02:30:32 +00:00
if user . Is_Super_Admin {
user . Perms = AllPerms
} else {
user . Perms = groups [ user . Group ] . Perms
}
2017-01-17 07:55:46 +00:00
host , _ , err := net . SplitHostPort ( r . RemoteAddr )
if err != nil {
2017-02-11 14:51:16 +00:00
PreError ( "Bad IP" , w , r )
return * user , false
2017-01-17 07:55:46 +00:00
}
if host != user . Last_IP {
_ , err = update_last_ip_stmt . Exec ( host , user . ID )
if err != nil {
2017-02-05 16:36:54 +00:00
InternalError ( err , w , r )
2017-02-11 14:51:16 +00:00
return * user , false
2017-01-17 07:55:46 +00:00
}
}
2017-02-11 14:51:16 +00:00
return * user , true
2017-01-12 02:55:08 +00:00
}
2017-02-10 13:39:13 +00:00
func words_to_score ( wcount int , topic bool ) ( score int ) {
if topic {
score = 2
} else {
score = 1
}
if wcount > settings [ "megapost_min_chars" ] . ( int ) {
score += 4
} else if wcount > settings [ "bigpost_min_chars" ] . ( int ) {
score += 1
}
return score
}
2017-01-12 02:55:08 +00:00
func increase_post_user_stats ( wcount int , uid int , topic bool , user User ) error {
var mod int
base_score := 1
if topic {
_ , err := increment_user_topics_stmt . Exec ( 1 , uid )
if err != nil {
return err
}
base_score = 2
}
if wcount > settings [ "megapost_min_chars" ] . ( int ) {
_ , err := increment_user_megaposts_stmt . Exec ( 1 , 1 , 1 , uid )
if err != nil {
return err
}
mod = 4
} else if wcount > settings [ "bigpost_min_chars" ] . ( int ) {
_ , err := increment_user_bigposts_stmt . Exec ( 1 , 1 , uid )
if err != nil {
return err
}
mod = 1
} else {
_ , err := increment_user_posts_stmt . Exec ( 1 , uid )
if err != nil {
return err
}
}
_ , err := increment_user_score_stmt . Exec ( base_score + mod , uid )
if err != nil {
return err
}
2017-01-12 14:01:35 +00:00
//fmt.Println(user.Score + base_score + mod)
//fmt.Println(getLevel(user.Score + base_score + mod))
2017-01-12 02:55:08 +00:00
_ , err = update_user_level_stmt . Exec ( getLevel ( user . Score + base_score + mod ) , uid )
return err
}
func decrease_post_user_stats ( wcount int , uid int , topic bool , user User ) error {
var mod int
base_score := - 1
if topic {
_ , err := increment_user_topics_stmt . Exec ( - 1 , uid )
if err != nil {
return err
}
base_score = - 2
}
if wcount > settings [ "megapost_min_chars" ] . ( int ) {
_ , err := increment_user_megaposts_stmt . Exec ( - 1 , - 1 , - 1 , uid )
if err != nil {
return err
}
mod = 4
} else if wcount > settings [ "bigpost_min_chars" ] . ( int ) {
_ , err := increment_user_bigposts_stmt . Exec ( - 1 , - 1 , uid )
if err != nil {
return err
}
mod = 1
} else {
_ , err := increment_user_posts_stmt . Exec ( - 1 , uid )
if err != nil {
return err
}
}
_ , err := increment_user_score_stmt . Exec ( base_score - mod , uid )
if err != nil {
return err
}
_ , err = update_user_level_stmt . Exec ( getLevel ( user . Score - base_score - mod ) , uid )
return err
}
2017-02-15 10:49:30 +00:00
func init_user_perms ( user * User ) {
user . Is_Admin = user . Is_Super_Admin || groups [ user . Group ] . Is_Admin
user . Is_Super_Mod = user . Is_Admin || groups [ user . Group ] . Is_Mod
user . Is_Mod = user . Is_Super_Mod
user . Is_Banned = groups [ user . Group ] . Is_Banned
if user . Is_Banned && user . Is_Super_Mod {
user . Is_Banned = false
}
2017-02-28 09:27:28 +00:00
}
func build_profile_url ( uid int ) string {
return "/user/" + strconv . Itoa ( uid )
}