login.go 1.7 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667
  1. package user
  2. import (
  3. "errors"
  4. "fmt"
  5. "net/http"
  6. "github.com/porter-dev/porter/api/server/authn"
  7. "github.com/porter-dev/porter/api/server/handlers"
  8. "github.com/porter-dev/porter/api/server/shared"
  9. "github.com/porter-dev/porter/api/server/shared/apierrors"
  10. "github.com/porter-dev/porter/api/types"
  11. "golang.org/x/crypto/bcrypt"
  12. "gorm.io/gorm"
  13. )
  14. type UserLoginHandler struct {
  15. handlers.PorterHandlerReadWriter
  16. }
  17. func NewUserLoginHandler(
  18. config *shared.Config,
  19. decoderValidator shared.RequestDecoderValidator,
  20. writer shared.ResultWriter,
  21. ) *UserLoginHandler {
  22. return &UserLoginHandler{
  23. PorterHandlerReadWriter: handlers.NewDefaultPorterHandler(config, decoderValidator, writer),
  24. }
  25. }
  26. func (u *UserLoginHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
  27. request := &types.LoginUserRequest{}
  28. ok := u.DecodeAndValidate(w, r, request)
  29. if !ok {
  30. return
  31. }
  32. // check that passwords match
  33. storedUser, err := u.Repo().User().ReadUserByEmail(request.Email)
  34. // case on user not existing, send forbidden error if not exist
  35. if err != nil {
  36. if targetErr := gorm.ErrRecordNotFound; errors.Is(err, targetErr) {
  37. u.HandleAPIError(w, apierrors.NewErrForbidden(err))
  38. return
  39. } else {
  40. u.HandleAPIError(w, apierrors.NewErrInternal(err))
  41. return
  42. }
  43. }
  44. if err := bcrypt.CompareHashAndPassword([]byte(storedUser.Password), []byte(request.Password)); err != nil {
  45. reqErr := apierrors.NewErrPassThroughToClient(fmt.Errorf("incorrect password"), http.StatusUnauthorized)
  46. u.HandleAPIError(w, reqErr)
  47. return
  48. }
  49. // save the user as authenticated in the session
  50. if err := authn.SaveUserAuthenticated(w, r, u.Config(), storedUser); err != nil {
  51. u.HandleAPIError(w, apierrors.NewErrInternal(err))
  52. return
  53. }
  54. u.WriteResult(w, storedUser.ToUserType())
  55. }