setting.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549
  1. // Copyright 2014 The Gogs Authors. All rights reserved.
  2. // Use of this source code is governed by a MIT-style
  3. // license that can be found in the LICENSE file.
  4. package user
  5. import (
  6. "fmt"
  7. "io/ioutil"
  8. "net/url"
  9. "strings"
  10. "github.com/Unknwon/com"
  11. "github.com/Unknwon/paginater"
  12. log "gopkg.in/clog.v1"
  13. "github.com/gogits/gogs/models"
  14. "github.com/gogits/gogs/models/errors"
  15. "github.com/gogits/gogs/modules/base"
  16. "github.com/gogits/gogs/modules/context"
  17. "github.com/gogits/gogs/modules/form"
  18. "github.com/gogits/gogs/modules/mailer"
  19. "github.com/gogits/gogs/modules/setting"
  20. )
  21. const (
  22. SETTINGS_PROFILE base.TplName = "user/settings/profile"
  23. SETTINGS_AVATAR base.TplName = "user/settings/avatar"
  24. SETTINGS_PASSWORD base.TplName = "user/settings/password"
  25. SETTINGS_EMAILS base.TplName = "user/settings/email"
  26. SETTINGS_SSH_KEYS base.TplName = "user/settings/sshkeys"
  27. SETTINGS_SOCIAL base.TplName = "user/settings/social"
  28. SETTINGS_APPLICATIONS base.TplName = "user/settings/applications"
  29. SETTINGS_ORGANIZATIONS base.TplName = "user/settings/organizations"
  30. SETTINGS_REPOS base.TplName = "user/settings/repos"
  31. SETTINGS_DELETE base.TplName = "user/settings/delete"
  32. NOTIFICATION base.TplName = "user/notification"
  33. SECURITY base.TplName = "user/security"
  34. )
  35. func Settings(ctx *context.Context) {
  36. ctx.Data["Title"] = ctx.Tr("settings")
  37. ctx.Data["PageIsSettingsProfile"] = true
  38. ctx.HTML(200, SETTINGS_PROFILE)
  39. }
  40. func handleUsernameChange(ctx *context.Context, newName string) {
  41. // Non-local users are not allowed to change their username.
  42. if len(newName) == 0 || !ctx.User.IsLocal() {
  43. return
  44. }
  45. // Check if user name has been changed
  46. if ctx.User.LowerName != strings.ToLower(newName) {
  47. if err := models.ChangeUserName(ctx.User, newName); err != nil {
  48. switch {
  49. case models.IsErrUserAlreadyExist(err):
  50. ctx.Flash.Error(ctx.Tr("newName_been_taken"))
  51. ctx.Redirect(setting.AppSubUrl + "/user/settings")
  52. case models.IsErrEmailAlreadyUsed(err):
  53. ctx.Flash.Error(ctx.Tr("form.email_been_used"))
  54. ctx.Redirect(setting.AppSubUrl + "/user/settings")
  55. case models.IsErrNameReserved(err):
  56. ctx.Flash.Error(ctx.Tr("user.newName_reserved"))
  57. ctx.Redirect(setting.AppSubUrl + "/user/settings")
  58. case models.IsErrNamePatternNotAllowed(err):
  59. ctx.Flash.Error(ctx.Tr("user.newName_pattern_not_allowed"))
  60. ctx.Redirect(setting.AppSubUrl + "/user/settings")
  61. default:
  62. ctx.Handle(500, "ChangeUserName", err)
  63. }
  64. return
  65. }
  66. log.Trace("User name changed: %s -> %s", ctx.User.Name, newName)
  67. }
  68. // In case it's just a case change
  69. ctx.User.Name = newName
  70. ctx.User.LowerName = strings.ToLower(newName)
  71. }
  72. func SettingsPost(ctx *context.Context, f form.UpdateProfile) {
  73. ctx.Data["Title"] = ctx.Tr("settings")
  74. ctx.Data["PageIsSettingsProfile"] = true
  75. if ctx.HasError() {
  76. ctx.HTML(200, SETTINGS_PROFILE)
  77. return
  78. }
  79. handleUsernameChange(ctx, f.Name)
  80. if ctx.Written() {
  81. return
  82. }
  83. ctx.User.FullName = f.FullName
  84. ctx.User.Email = f.Email
  85. ctx.User.Website = f.Website
  86. ctx.User.Location = f.Location
  87. if err := models.UpdateUser(ctx.User); err != nil {
  88. ctx.Handle(500, "UpdateUser", err)
  89. return
  90. }
  91. log.Trace("User settings updated: %s", ctx.User.Name)
  92. ctx.Flash.Success(ctx.Tr("settings.update_profile_success"))
  93. ctx.Redirect(setting.AppSubUrl + "/user/settings")
  94. }
  95. // FIXME: limit size.
  96. func UpdateAvatarSetting(ctx *context.Context, f form.Avatar, ctxUser *models.User) error {
  97. ctxUser.UseCustomAvatar = f.Source == form.AVATAR_LOCAL
  98. if len(f.Gravatar) > 0 {
  99. ctxUser.Avatar = base.EncodeMD5(f.Gravatar)
  100. ctxUser.AvatarEmail = f.Gravatar
  101. }
  102. if f.Avatar != nil {
  103. fr, err := f.Avatar.Open()
  104. if err != nil {
  105. return fmt.Errorf("Avatar.Open: %v", err)
  106. }
  107. defer fr.Close()
  108. data, err := ioutil.ReadAll(fr)
  109. if err != nil {
  110. return fmt.Errorf("ioutil.ReadAll: %v", err)
  111. }
  112. if !base.IsImageFile(data) {
  113. return errors.New(ctx.Tr("settings.uploaded_avatar_not_a_image"))
  114. }
  115. if err = ctxUser.UploadAvatar(data); err != nil {
  116. return fmt.Errorf("UploadAvatar: %v", err)
  117. }
  118. } else {
  119. // No avatar is uploaded but setting has been changed to enable,
  120. // generate a random one when needed.
  121. if ctxUser.UseCustomAvatar && !com.IsFile(ctxUser.CustomAvatarPath()) {
  122. if err := ctxUser.GenerateRandomAvatar(); err != nil {
  123. log.Error(4, "GenerateRandomAvatar[%d]: %v", ctxUser.ID, err)
  124. }
  125. }
  126. }
  127. if err := models.UpdateUser(ctxUser); err != nil {
  128. return fmt.Errorf("UpdateUser: %v", err)
  129. }
  130. return nil
  131. }
  132. func SettingsAvatar(ctx *context.Context) {
  133. ctx.Data["Title"] = ctx.Tr("settings")
  134. ctx.Data["PageIsSettingsAvatar"] = true
  135. ctx.HTML(200, SETTINGS_AVATAR)
  136. }
  137. func SettingsAvatarPost(ctx *context.Context, f form.Avatar) {
  138. if err := UpdateAvatarSetting(ctx, f, ctx.User); err != nil {
  139. ctx.Flash.Error(err.Error())
  140. } else {
  141. ctx.Flash.Success(ctx.Tr("settings.update_avatar_success"))
  142. }
  143. ctx.Redirect(setting.AppSubUrl + "/user/settings/avatar")
  144. }
  145. func SettingsDeleteAvatar(ctx *context.Context) {
  146. if err := ctx.User.DeleteAvatar(); err != nil {
  147. ctx.Flash.Error(err.Error())
  148. }
  149. ctx.Redirect(setting.AppSubUrl + "/user/settings/avatar")
  150. }
  151. func SettingsPassword(ctx *context.Context) {
  152. ctx.Data["Title"] = ctx.Tr("settings")
  153. ctx.Data["PageIsSettingsPassword"] = true
  154. ctx.HTML(200, SETTINGS_PASSWORD)
  155. }
  156. func SettingsPasswordPost(ctx *context.Context, f form.ChangePassword) {
  157. ctx.Data["Title"] = ctx.Tr("settings")
  158. ctx.Data["PageIsSettingsPassword"] = true
  159. if ctx.HasError() {
  160. ctx.HTML(200, SETTINGS_PASSWORD)
  161. return
  162. }
  163. if !ctx.User.ValidatePassword(f.OldPassword) {
  164. ctx.Flash.Error(ctx.Tr("settings.password_incorrect"))
  165. } else if f.Password != f.Retype {
  166. ctx.Flash.Error(ctx.Tr("form.password_not_match"))
  167. } else {
  168. ctx.User.Passwd = f.Password
  169. var err error
  170. if ctx.User.Salt, err = models.GetUserSalt(); err != nil {
  171. ctx.Handle(500, "UpdateUser", err)
  172. return
  173. }
  174. ctx.User.EncodePasswd()
  175. if err := models.UpdateUser(ctx.User); err != nil {
  176. ctx.Handle(500, "UpdateUser", err)
  177. return
  178. }
  179. log.Trace("User password updated: %s", ctx.User.Name)
  180. ctx.Flash.Success(ctx.Tr("settings.change_password_success"))
  181. }
  182. ctx.Redirect(setting.AppSubUrl + "/user/settings/password")
  183. }
  184. func SettingsEmails(ctx *context.Context) {
  185. ctx.Data["Title"] = ctx.Tr("settings")
  186. ctx.Data["PageIsSettingsEmails"] = true
  187. emails, err := models.GetEmailAddresses(ctx.User.ID)
  188. if err != nil {
  189. ctx.Handle(500, "GetEmailAddresses", err)
  190. return
  191. }
  192. ctx.Data["Emails"] = emails
  193. ctx.HTML(200, SETTINGS_EMAILS)
  194. }
  195. func SettingsEmailPost(ctx *context.Context, f form.AddEmail) {
  196. ctx.Data["Title"] = ctx.Tr("settings")
  197. ctx.Data["PageIsSettingsEmails"] = true
  198. // Make emailaddress primary.
  199. if ctx.Query("_method") == "PRIMARY" {
  200. if err := models.MakeEmailPrimary(&models.EmailAddress{ID: ctx.QueryInt64("id")}); err != nil {
  201. ctx.Handle(500, "MakeEmailPrimary", err)
  202. return
  203. }
  204. log.Trace("Email made primary: %s", ctx.User.Name)
  205. ctx.Redirect(setting.AppSubUrl + "/user/settings/email")
  206. return
  207. }
  208. // Add Email address.
  209. emails, err := models.GetEmailAddresses(ctx.User.ID)
  210. if err != nil {
  211. ctx.Handle(500, "GetEmailAddresses", err)
  212. return
  213. }
  214. ctx.Data["Emails"] = emails
  215. if ctx.HasError() {
  216. ctx.HTML(200, SETTINGS_EMAILS)
  217. return
  218. }
  219. email := &models.EmailAddress{
  220. UID: ctx.User.ID,
  221. Email: f.Email,
  222. IsActivated: !setting.Service.RegisterEmailConfirm,
  223. }
  224. if err := models.AddEmailAddress(email); err != nil {
  225. if models.IsErrEmailAlreadyUsed(err) {
  226. ctx.RenderWithErr(ctx.Tr("form.email_been_used"), SETTINGS_EMAILS, &f)
  227. return
  228. }
  229. ctx.Handle(500, "AddEmailAddress", err)
  230. return
  231. }
  232. // Send confirmation email
  233. if setting.Service.RegisterEmailConfirm {
  234. mailer.SendActivateEmailMail(ctx.Context, models.NewMailerUser(ctx.User), email.Email)
  235. if err := ctx.Cache.Put("MailResendLimit_"+ctx.User.LowerName, ctx.User.LowerName, 180); err != nil {
  236. log.Error(4, "Set cache(MailResendLimit) fail: %v", err)
  237. }
  238. ctx.Flash.Info(ctx.Tr("settings.add_email_confirmation_sent", email.Email, setting.Service.ActiveCodeLives/60))
  239. } else {
  240. ctx.Flash.Success(ctx.Tr("settings.add_email_success"))
  241. }
  242. log.Trace("Email address added: %s", email.Email)
  243. ctx.Redirect(setting.AppSubUrl + "/user/settings/email")
  244. }
  245. func DeleteEmail(ctx *context.Context) {
  246. if err := models.DeleteEmailAddress(&models.EmailAddress{
  247. ID: ctx.QueryInt64("id"),
  248. UID: ctx.User.ID,
  249. }); err != nil {
  250. ctx.Handle(500, "DeleteEmail", err)
  251. return
  252. }
  253. log.Trace("Email address deleted: %s", ctx.User.Name)
  254. ctx.Flash.Success(ctx.Tr("settings.email_deletion_success"))
  255. ctx.JSON(200, map[string]interface{}{
  256. "redirect": setting.AppSubUrl + "/user/settings/email",
  257. })
  258. }
  259. func SettingsSSHKeys(ctx *context.Context) {
  260. ctx.Data["Title"] = ctx.Tr("settings")
  261. ctx.Data["PageIsSettingsSSHKeys"] = true
  262. keys, err := models.ListPublicKeys(ctx.User.ID)
  263. if err != nil {
  264. ctx.Handle(500, "ListPublicKeys", err)
  265. return
  266. }
  267. ctx.Data["Keys"] = keys
  268. ctx.HTML(200, SETTINGS_SSH_KEYS)
  269. }
  270. func SettingsSSHKeysPost(ctx *context.Context, f form.AddSSHKey) {
  271. ctx.Data["Title"] = ctx.Tr("settings")
  272. ctx.Data["PageIsSettingsSSHKeys"] = true
  273. keys, err := models.ListPublicKeys(ctx.User.ID)
  274. if err != nil {
  275. ctx.Handle(500, "ListPublicKeys", err)
  276. return
  277. }
  278. ctx.Data["Keys"] = keys
  279. if ctx.HasError() {
  280. ctx.HTML(200, SETTINGS_SSH_KEYS)
  281. return
  282. }
  283. content, err := models.CheckPublicKeyString(f.Content)
  284. if err != nil {
  285. if models.IsErrKeyUnableVerify(err) {
  286. ctx.Flash.Info(ctx.Tr("form.unable_verify_ssh_key"))
  287. } else {
  288. ctx.Flash.Error(ctx.Tr("form.invalid_ssh_key", err.Error()))
  289. ctx.Redirect(setting.AppSubUrl + "/user/settings/ssh")
  290. return
  291. }
  292. }
  293. if _, err = models.AddPublicKey(ctx.User.ID, f.Title, content); err != nil {
  294. ctx.Data["HasError"] = true
  295. switch {
  296. case models.IsErrKeyAlreadyExist(err):
  297. ctx.Data["Err_Content"] = true
  298. ctx.RenderWithErr(ctx.Tr("settings.ssh_key_been_used"), SETTINGS_SSH_KEYS, &f)
  299. case models.IsErrKeyNameAlreadyUsed(err):
  300. ctx.Data["Err_Title"] = true
  301. ctx.RenderWithErr(ctx.Tr("settings.ssh_key_name_used"), SETTINGS_SSH_KEYS, &f)
  302. default:
  303. ctx.Handle(500, "AddPublicKey", err)
  304. }
  305. return
  306. }
  307. ctx.Flash.Success(ctx.Tr("settings.add_key_success", f.Title))
  308. ctx.Redirect(setting.AppSubUrl + "/user/settings/ssh")
  309. }
  310. func DeleteSSHKey(ctx *context.Context) {
  311. if err := models.DeletePublicKey(ctx.User, ctx.QueryInt64("id")); err != nil {
  312. ctx.Flash.Error("DeletePublicKey: " + err.Error())
  313. } else {
  314. ctx.Flash.Success(ctx.Tr("settings.ssh_key_deletion_success"))
  315. }
  316. ctx.JSON(200, map[string]interface{}{
  317. "redirect": setting.AppSubUrl + "/user/settings/ssh",
  318. })
  319. }
  320. func SettingsApplications(ctx *context.Context) {
  321. ctx.Data["Title"] = ctx.Tr("settings")
  322. ctx.Data["PageIsSettingsApplications"] = true
  323. tokens, err := models.ListAccessTokens(ctx.User.ID)
  324. if err != nil {
  325. ctx.Handle(500, "ListAccessTokens", err)
  326. return
  327. }
  328. ctx.Data["Tokens"] = tokens
  329. ctx.HTML(200, SETTINGS_APPLICATIONS)
  330. }
  331. func SettingsApplicationsPost(ctx *context.Context, f form.NewAccessToken) {
  332. ctx.Data["Title"] = ctx.Tr("settings")
  333. ctx.Data["PageIsSettingsApplications"] = true
  334. if ctx.HasError() {
  335. tokens, err := models.ListAccessTokens(ctx.User.ID)
  336. if err != nil {
  337. ctx.Handle(500, "ListAccessTokens", err)
  338. return
  339. }
  340. ctx.Data["Tokens"] = tokens
  341. ctx.HTML(200, SETTINGS_APPLICATIONS)
  342. return
  343. }
  344. t := &models.AccessToken{
  345. UID: ctx.User.ID,
  346. Name: f.Name,
  347. }
  348. if err := models.NewAccessToken(t); err != nil {
  349. ctx.Handle(500, "NewAccessToken", err)
  350. return
  351. }
  352. ctx.Flash.Success(ctx.Tr("settings.generate_token_succees"))
  353. ctx.Flash.Info(t.Sha1)
  354. ctx.Redirect(setting.AppSubUrl + "/user/settings/applications")
  355. }
  356. func SettingsDeleteApplication(ctx *context.Context) {
  357. if err := models.DeleteAccessTokenOfUserByID(ctx.User.ID, ctx.QueryInt64("id")); err != nil {
  358. ctx.Flash.Error("DeleteAccessTokenByID: " + err.Error())
  359. } else {
  360. ctx.Flash.Success(ctx.Tr("settings.delete_token_success"))
  361. }
  362. ctx.JSON(200, map[string]interface{}{
  363. "redirect": setting.AppSubUrl + "/user/settings/applications",
  364. })
  365. }
  366. func SettingsOrganizations(ctx *context.Context) {
  367. ctx.Data["Title"] = ctx.Tr("settings")
  368. ctx.Data["PageIsSettingsOrganizations"] = true
  369. orgs, err := models.GetOrgsByUserID(ctx.User.ID, true)
  370. if err != nil {
  371. ctx.Handle(500, "GetOrgsByUserID", err)
  372. return
  373. }
  374. ctx.Data["Orgs"] = orgs
  375. ctx.HTML(200, SETTINGS_ORGANIZATIONS)
  376. }
  377. func SettingsLeaveOrganization(ctx *context.Context) {
  378. err := models.RemoveOrgUser(ctx.QueryInt64("id"), ctx.User.ID)
  379. if models.IsErrLastOrgOwner(err) {
  380. ctx.Flash.Error(ctx.Tr("form.last_org_owner"))
  381. }
  382. ctx.JSON(200, map[string]interface{}{
  383. "redirect": setting.AppSubUrl + "/user/settings/organizations",
  384. })
  385. }
  386. func SettingsRepos(ctx *context.Context) {
  387. ctx.Data["Title"] = ctx.Tr("admin.repositories")
  388. ctx.Data["PageIsSettingsRepositories"] = true
  389. keyword := ctx.Query("q")
  390. page := ctx.QueryInt("page")
  391. if page <= 0 {
  392. page = 1
  393. }
  394. repos, count, err := models.SearchRepositoryByName(&models.SearchRepoOptions{
  395. Keyword: keyword,
  396. UserID: ctx.User.ID,
  397. OrderBy: "lower_name",
  398. Page: page,
  399. PageSize: setting.UI.Admin.RepoPagingNum,
  400. })
  401. if err != nil {
  402. ctx.Handle(500, "SearchRepositoryByName", err)
  403. return
  404. }
  405. if err = models.RepositoryList(repos).LoadAttributes(); err != nil {
  406. ctx.Handle(500, "LoadAttributes", err)
  407. return
  408. }
  409. ctx.Data["Keyword"] = keyword
  410. ctx.Data["Total"] = count
  411. ctx.Data["Page"] = paginater.New(int(count), setting.UI.Admin.RepoPagingNum, page, 5)
  412. ctx.Data["Repos"] = repos
  413. ctx.HTML(200, SETTINGS_REPOS)
  414. }
  415. func SettingsDeleteRepo(ctx *context.Context) {
  416. repo, err := models.GetRepositoryByID(ctx.QueryInt64("id"))
  417. if err != nil {
  418. ctx.Handle(500, "GetRepositoryByID", err)
  419. return
  420. }
  421. // make sure the user owns the repository or is an admin before allowing them to delete it
  422. if repo.OwnerID == ctx.User.ID || ctx.User.IsAdmin {
  423. if err := models.DeleteRepository(repo.MustOwner().ID, repo.ID); err != nil {
  424. ctx.Handle(500, "DeleteRepository", err)
  425. return
  426. }
  427. log.Trace("Repository deleted: %s/%s", repo.MustOwner().Name, repo.Name)
  428. ctx.Flash.Success(ctx.Tr("repo.settings.deletion_success"))
  429. ctx.JSON(200, map[string]interface{}{
  430. "redirect": setting.AppSubUrl + "/user/settings/repos?page=" + ctx.Query("page") + "&q=" + url.QueryEscape(ctx.Query("q")),
  431. })
  432. } else {
  433. // logged in user doesn't have rights to delete this repository
  434. err := errors.New("You do not have rights to delete repository '" + repo.FullName() + "'")
  435. ctx.Handle(403, "SettingsDeleteRepo", err)
  436. }
  437. }
  438. func SettingsDelete(ctx *context.Context) {
  439. ctx.Data["Title"] = ctx.Tr("settings")
  440. ctx.Data["PageIsSettingsDelete"] = true
  441. if ctx.Req.Method == "POST" {
  442. if _, err := models.UserSignIn(ctx.User.Name, ctx.Query("password")); err != nil {
  443. if errors.IsUserNotExist(err) {
  444. ctx.RenderWithErr(ctx.Tr("form.enterred_invalid_password"), SETTINGS_DELETE, nil)
  445. } else {
  446. ctx.Handle(500, "UserSignIn", err)
  447. }
  448. return
  449. }
  450. if err := models.DeleteUser(ctx.User); err != nil {
  451. switch {
  452. case models.IsErrUserOwnRepos(err):
  453. ctx.Flash.Error(ctx.Tr("form.still_own_repo"))
  454. ctx.Redirect(setting.AppSubUrl + "/user/settings/delete")
  455. case models.IsErrUserHasOrgs(err):
  456. ctx.Flash.Error(ctx.Tr("form.still_has_org"))
  457. ctx.Redirect(setting.AppSubUrl + "/user/settings/delete")
  458. default:
  459. ctx.Handle(500, "DeleteUser", err)
  460. }
  461. } else {
  462. log.Trace("Account deleted: %s", ctx.User.Name)
  463. ctx.Redirect(setting.AppSubUrl + "/")
  464. }
  465. return
  466. }
  467. ctx.HTML(200, SETTINGS_DELETE)
  468. }