login.go 1.8 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768
  1. package user
  2. import (
  3. "errors"
  4. "fmt"
  5. "net/http"
  6. "github.com/porter-dev/porter/api/server/authn"
  7. "github.com/porter-dev/porter/api/server/handlers"
  8. "github.com/porter-dev/porter/api/server/shared"
  9. "github.com/porter-dev/porter/api/server/shared/apierrors"
  10. "github.com/porter-dev/porter/api/server/shared/config"
  11. "github.com/porter-dev/porter/api/types"
  12. "golang.org/x/crypto/bcrypt"
  13. "gorm.io/gorm"
  14. )
  15. type UserLoginHandler struct {
  16. handlers.PorterHandlerReadWriter
  17. }
  18. func NewUserLoginHandler(
  19. config *config.Config,
  20. decoderValidator shared.RequestDecoderValidator,
  21. writer shared.ResultWriter,
  22. ) *UserLoginHandler {
  23. return &UserLoginHandler{
  24. PorterHandlerReadWriter: handlers.NewDefaultPorterHandler(config, decoderValidator, writer),
  25. }
  26. }
  27. func (u *UserLoginHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
  28. request := &types.LoginUserRequest{}
  29. ok := u.DecodeAndValidate(w, r, request)
  30. if !ok {
  31. return
  32. }
  33. // check that passwords match
  34. storedUser, err := u.Repo().User().ReadUserByEmail(request.Email)
  35. // case on user not existing, send forbidden error if not exist
  36. if err != nil {
  37. if targetErr := gorm.ErrRecordNotFound; errors.Is(err, targetErr) {
  38. u.HandleAPIError(w, r, apierrors.NewErrForbidden(err))
  39. return
  40. } else {
  41. u.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  42. return
  43. }
  44. }
  45. if err := bcrypt.CompareHashAndPassword([]byte(storedUser.Password), []byte(request.Password)); err != nil {
  46. reqErr := apierrors.NewErrPassThroughToClient(fmt.Errorf("incorrect password"), http.StatusUnauthorized)
  47. u.HandleAPIError(w, r, reqErr)
  48. return
  49. }
  50. // save the user as authenticated in the session
  51. if err := authn.SaveUserAuthenticated(w, r, u.Config(), storedUser); err != nil {
  52. u.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  53. return
  54. }
  55. u.WriteResult(w, r, storedUser.ToUserType())
  56. }