diff --git a/app/controllers/api/v1/users_controller.rb b/app/controllers/api/v1/users_controller.rb index 55f5cfb22..37a41ff75 100644 --- a/app/controllers/api/v1/users_controller.rb +++ b/app/controllers/api/v1/users_controller.rb @@ -1,6 +1,78 @@ class Api::V1::UsersController < Api::V1::BaseController - def index - render_ok + before_action :load_observe_user + before_action :check_auth_for_observe_user + + def send_email_vefify_code + code = %W(0 1 2 3 4 5 6 7 8 9) + verification_code = code.sample(6).join + mail = params[:email] + code_type = params[:code_type] + + sign = Digest::MD5.hexdigest("#{OPENKEY}#{mail}") + Rails.logger.info sign + + tip_exception(501, "请求不合理") if sign != params[:smscode] + + # 60s内不能重复发送 + send_email_limit_cache_key = "send_email_60_second_limit:#{mail}" + tip_exception(-1, '请勿频繁操作') if Rails.cache.exist?(send_email_limit_cache_key) + send_email_control = LimitForbidControl::SendEmailCode.new(mail) + tip_exception(-1, '邮件发送太频繁,请稍后再试') if send_email_control.forbid? + begin + UserMailer.update_email(mail, verification_code).deliver_now + + Rails.cache.write(send_email_limit_cache_key, 1, expires_in: 1.minute) + send_email_control.increment! + rescue Exception => e + logger_error(e) + tip_exception(-2,"邮件发送失败,请稍后重试") + end + ver_params = {code_type: code_type, code: verification_code, email: mail} + data = VerificationCode.new(ver_params) + if data.save! + render_ok + else + tip_exception(-1, "创建数据失败") + end + end + + def check_password + password = params[:password] + return render_error("8~16位密码,支持字母数字和符号") unless password =~ CustomRegexp::PASSWORD + return render_error("密码错误") unless @observe_user.check_password?(password) + render_ok + end + + def check_email + mail = strip(params[:email]) + return render_error("邮件格式有误") unless mail =~ CustomRegexp::EMAIL + + exist_owner = Owner.find_by(mail: mail) + return render_error('邮箱已被使用') if exist_owner + render_ok + end + + def check_email_verify_code + code = strip(params[:code]) + mail = strip(params[:email]) + code_type = params[:code_type] + + return render_error("邮件格式有误") unless mail =~ CustomRegexp::EMAIL + + verifi_code = VerificationCode.where(email: mail, code: code, code_type: code_type).last + + return render_error("验证码不正确") if verifi_code&.code != code + return render_error("验证码已失效") if !verifi_code&.effective? + render_ok + end + + def update_email + @result_object = Api::V1::Users::UpdateEmailService.call(@observe_user, params, current_user.gitea_token) + if @result_object + return render_ok + else + return render_error('更改邮箱失败!') + end end end \ No newline at end of file diff --git a/app/controllers/application_controller.rb b/app/controllers/application_controller.rb index 8dacc7bb9..5714c520b 100644 --- a/app/controllers/application_controller.rb +++ b/app/controllers/application_controller.rb @@ -709,9 +709,15 @@ class ApplicationController < ActionController::Base # @project = nil if !@project.is_public? # render_forbidden and return else - logger.info "###########:project not found" - @project = nil - render_not_found and return + if @project.present? + logger.info "###########: has project and but can't read project" + @project = nil + render_forbidden and return + else + logger.info "###########:project not found" + @project = nil + render_not_found and return + end end @project end diff --git a/app/controllers/attachments_controller.rb b/app/controllers/attachments_controller.rb index 22af22831..1f5d5f459 100644 --- a/app/controllers/attachments_controller.rb +++ b/app/controllers/attachments_controller.rb @@ -31,11 +31,11 @@ class AttachmentsController < ApplicationController def get_file normal_status(-1, "参数缺失") if params[:download_url].blank? - url = URI.encode(params[:download_url].to_s.gsub("http:", "https:")) + url = base_url.starts_with?("https:") ? URI.encode(params[:download_url].to_s.gsub("http:", "https:")) : URI.encode(params[:download_url].to_s) if url.starts_with?(base_url) domain = GiteaService.gitea_config[:domain] api_url = GiteaService.gitea_config[:base_url] - url = url.split(base_url)[1].gsub("api", "repos").gsub('?filepath=', '/').gsub('&', '?') + url = ("/repos"+url.split(base_url + "/api")[1]).gsub('?filepath=', '/').gsub('&', '?') request_url = [domain, api_url, url, "?ref=#{params[:ref]}&access_token=#{current_user&.gitea_token}"].join response = Faraday.get(request_url) filename = url.to_s.split("/").pop() diff --git a/app/controllers/concerns/api/user_helper.rb b/app/controllers/concerns/api/user_helper.rb index e6156ea56..4c7b713fc 100644 --- a/app/controllers/concerns/api/user_helper.rb +++ b/app/controllers/concerns/api/user_helper.rb @@ -16,4 +16,13 @@ module Api::UserHelper end @observe_user end + + # 是否具有查看用户或编辑用户的权限 + def check_auth_for_observe_user + return render_forbidden unless current_user.admin? || @observe_user.id == current_user.id + end + + def strip(str) + str.to_s.strip.presence + end end \ No newline at end of file diff --git a/app/docs/slate/source/includes/_users.md b/app/docs/slate/source/includes/_users.md index 318c7930a..e16a52033 100644 --- a/app/docs/slate/source/includes/_users.md +++ b/app/docs/slate/source/includes/_users.md @@ -2304,4 +2304,189 @@ await octokit.request('GET /api/users/:login/applied_projects/:id/refuse.json') "created_at": "2021-06-09 16:41", "time_ago": "7分钟前" } +``` + + +## 用户发送邮件验证码 +用户发送邮件验证码 + +> 示例: + +```shell +curl -X GET http://localhost:3000/api/v1/yystopf/send_email_vefify_code.json +``` + +```javascript +await octokit.request('GET /api/v1/:login/send_email_vefify_code.json') +``` + +### HTTP 请求 +`GET /api/v1/:login/send_email_vefify_code.json` + +### 请求字段说明: +参数 | 类型 | 字段说明 +--------- | ----------- | ----------- +|login |string |用户标识 | +|code_type |int |10: 更新邮箱| +|email |string |邮箱| +|smscode |string |邮箱md5加密值| + +### 返回字段说明: + +> 返回的JSON示例: + +```json +{ + "status": 0, + "message": "success" +} +``` + + +## 用户验证邮件验证码 +用户验证邮件验证码 + +> 示例: + +```shell +curl -X POST http://localhost:3000/api/v1/yystopf/check_email_verify_code.json +``` + +```javascript +await octokit.request('POST /api/v1/:login/check_email_verify_code.json') +``` + +### HTTP 请求 +`POST /api/v1/:login/check_email_verify_code.json` + +### 请求字段说明: +参数 | 类型 | 字段说明 +--------- | ----------- | ----------- +|login |string |用户标识 | +|code_type |int |10: 更新邮箱| +|email |string |邮箱| +|code |string |邮箱验证码| + +### 返回字段说明: + +> 返回的JSON示例: + +```json +{ + "status": 0, + "message": "success" +} +``` + + +## 用户验证密码 +用户验证密码,检查是否和用户密码一致 + +> 示例: + +```shell +curl -X POST http://localhost:3000/api/v1/yystopf/check_password.json +``` + +```javascript +await octokit.request('POST /api/v1/:login/check_password.json') +``` + +### HTTP 请求 +`POST /api/v1/:login/check_password.json` + +### 请求字段说明: +参数 | 类型 | 字段说明 +--------- | ----------- | ----------- +|login |string |用户标识 | +|password |string |用户密码| + +### 返回字段说明: + +> 返回的JSON示例: + +```json +{ + "status": 0, + "message": "success" +} +``` + + +## 用户验证邮箱 +用户验证邮箱是否符合规范以及是否已被使用 + +> 示例: + +```shell +curl -X POST http://localhost:3000/api/v1/yystopf/check_email.json +``` + +```javascript +await octokit.request('POST /api/v1/:login/check_email.json') +``` + +### HTTP 请求 +`POST /api/v1/:login/check_email.json` + +### 请求字段说明: +参数 | 类型 | 字段说明 +--------- | ----------- | ----------- +|login |string |用户标识 | +|email |string |邮箱地址| + +### 返回字段说明: + +> 返回的JSON示例: + +```json +{ + "status": 0, + "message": "success" +} +``` + + +## 用户更改邮箱 +用户更改一个新的邮箱 + +> 示例: + +```shell +curl -X PATCH http://localhost:3000/api/v1/yystopf/update_email.json +``` + +```javascript +await octokit.request('PATCH /api/v1/:login/update_email.json') +``` + +### HTTP 请求 +`PATCH /api/v1/:login/update_email.json` + +### 请求字段说明: +参数 | 类型 | 字段说明 +--------- | ----------- | ----------- +|login |string |用户标识 | +|password |string |用户密码| +|email |string |邮箱地址| +|code |string |邮箱验证码| + + +> 请求的JSON示例: + +```json +{ + "password": "Aa19960425.", + "code": "657134", + "email": "yystopf@163.com" +} +``` + +> 返回的JSON示例: + +```json +{ + "status": 0, + "message": "success" +} ``` \ No newline at end of file diff --git a/app/mailers/user_mailer.rb b/app/mailers/user_mailer.rb index acd34fbbd..21ed5b0d5 100644 --- a/app/mailers/user_mailer.rb +++ b/app/mailers/user_mailer.rb @@ -8,4 +8,8 @@ class UserMailer < ApplicationMailer mail(to: mail, subject: 'Gitink | 注册验证码') end + def update_email(mail, code) + @code = code + mail(to: mail, subject: 'Gitink | 更改邮箱验证码') + end end diff --git a/app/models/message_template.rb b/app/models/message_template.rb index bc6c5a714..d9ba3eb76 100644 --- a/app/models/message_template.rb +++ b/app/models/message_template.rb @@ -13,7 +13,7 @@ # class MessageTemplate < ApplicationRecord - self.inheritance_column = nil + # self.inheritance_column = nil PLATFORM = 'GitLink' def self.build_init_data diff --git a/app/models/team.rb b/app/models/team.rb index b831cd069..eacb96a0d 100644 --- a/app/models/team.rb +++ b/app/models/team.rb @@ -70,4 +70,15 @@ class Team < ApplicationRecord end end + + def to_gitea_hash + { + can_create_org_repo: self.can_create_org_project, + description: self.description || "", + includes_all_repositories: self.includes_all_project, + name: self.name, + permission: self.authorize, + units: self.team_units.pluck(:unit_type).map{|i| "repo.#{i}"} + } + end end diff --git a/app/services/api/v1/users/update_email_service.rb b/app/services/api/v1/users/update_email_service.rb new file mode 100644 index 000000000..e11dd2f61 --- /dev/null +++ b/app/services/api/v1/users/update_email_service.rb @@ -0,0 +1,68 @@ +class Api::V1::Users::UpdateEmailService < ApplicationService + include ActiveModel::Model + + attr_reader :user, :token, :password, :mail, :old_mail, :code, :verify_code + attr_accessor :gitea_data + + validates :password, :code, presence: true + validates :mail, presence: true, format: { with: CustomRegexp::EMAIL } + + def initialize(user, params, token =nil) + @user = user + @token = token + @password = params[:password] + @mail = params[:email] + @old_mail = user.mail + @code = params[:code] + @verify_code = VerificationCode.where(email: @mail, code: @code, code_type: 10).last + end + + def call + raise Error, errors.full_messages.join(",") unless valid? + raise Error, "密码不正确." unless @user.check_password?(@password) + raise Error, "验证码不正确." if @verify_code&.code != @code + raise Error, "验证码已失效." if !@verify_code&.effective? + + # begin + ActiveRecord::Base.transaction do + change_user_email + excute_data_to_gitea + excute_change_email_from_gitea + end + + return gitea_data + + # rescue + # raise Error, "服务器错误,请联系系统管理员!" + # end + end + + private + def request_params + { + access_token: token + } + end + + def request_body + { + email: @mail, + login_name: @user.login, + source_id: 0 + } + end + + def change_user_email + @user.update_attributes!({mail: @mail}) + end + + def excute_data_to_gitea + Rails.logger.info request_body + @gitea_data = $gitea_client.patch_admin_users_by_username(@user.login, {body: request_body.to_json}) + end + + def excute_change_email_from_gitea + $gitea_client.delete_user_emails({body: {emails: [@old_mail]}.to_json, query: request_params}) + $gitea_client.post_user_emails({body: {emails: [@mail]}.to_json, query: request_params}) + end +end \ No newline at end of file diff --git a/app/views/admins/users/shared/_user_list.html.erb b/app/views/admins/users/shared/_user_list.html.erb index ae4657b5e..16cd403de 100644 --- a/app/views/admins/users/shared/_user_list.html.erb +++ b/app/views/admins/users/shared/_user_list.html.erb @@ -2,7 +2,7 @@ 序号 - 真实姓名 + 昵称 邮件地址 手机号码 角色 diff --git a/app/views/user_mailer/update_email.html.erb b/app/views/user_mailer/update_email.html.erb new file mode 100644 index 000000000..c93366e4a --- /dev/null +++ b/app/views/user_mailer/update_email.html.erb @@ -0,0 +1,61 @@ + + + + GitLink-验证码发送 + + + + + +
+
+
+ + <%= image_tag("logo.png", alt: "确实开源", width: '100', :style => "float:left; margin-top: 8px;") %> + +
+
+
+

+ 您好! +

+

+ 你正在进行GitLink邮箱更改操作,如非本人操作,请忽略。 +

+
+
+

<%= @code %>

+
+ + 此邮件为系统所发,请勿直接回复。
+ 要解决问题或了解您的帐户详情,您可以访问 帮助中心。 +
+
+

+ 如果您并未发过此请求,则可能是因为其他用户在注册时误输了您的邮件地址,而使您收到了这封邮件,那么您可以放心的忽略此邮件,无需进一步采取任何操作。 +

+
+
+ www.gitlink.org.cn +
+
+
+ + diff --git a/config/initializers/gitea_client.rb b/config/initializers/gitea_client.rb index 92706ffd8..c909cebf4 100644 --- a/config/initializers/gitea_client.rb +++ b/config/initializers/gitea_client.rb @@ -6,6 +6,6 @@ gitea_config = config[:gitea].symbolize_keys! $gitea_client = Gitea::Api::Client.new({ domain: gitea_config[:domain], base_url: gitea_config[:base_url], - username: gitea_config[:username], - password: gitea_config[:password] + username: gitea_config[:access_key_id], + password: gitea_config[:access_key_secret] }) \ No newline at end of file diff --git a/config/routes/api.rb b/config/routes/api.rb index d5f82ff7b..ab098b1dc 100644 --- a/config/routes/api.rb +++ b/config/routes/api.rb @@ -2,7 +2,15 @@ defaults format: :json do namespace :api do namespace :v1 do scope ':owner' do - resource :users, path: '/', only: [:show, :update, :edit, :destroy] + resource :users, path: '/', only: [:show, :update, :edit, :destroy] do + collection do + get :send_email_vefify_code + post :check_password + post :check_email + post :check_email_verify_code + patch :update_email + end + end scope module: :users do resources :projects, only: [:index] end diff --git a/lib/tasks/sync_data_to_gitea.rake b/lib/tasks/sync_data_to_gitea.rake index 85df9c69a..8b8dd0ab0 100644 --- a/lib/tasks/sync_data_to_gitea.rake +++ b/lib/tasks/sync_data_to_gitea.rake @@ -4,6 +4,35 @@ desc "初始化数据同步到gitea平台" # 再同步项目及项目成员 namespace :sync_data_to_gitea do + desc "同步组织数据" + # 同步组织成员,并仅保留最高权限 + task organizations: :environment do + Organization.includes(:organization_users, teams: [:team_users, :team_projects]).find_each do |org| + ActiveRecord::Base.transaction do + org.teams.each do |team| + if team.gtid.blank? + gteam = $gitea_client.post_orgs_teams_by_org(org.login, {body: team.to_gitea_hash.to_json}) rescue nil + team.update_attributes!({gtid: gteam["id"]}) unless gteam.nil? + end + team.team_users.each do |teamuser| + userlogin = teamuser&.user&.login + next if ($gitea_client.get_teams_members_by_id_username(team.gtid, userlogin) rescue nil) + tu_result = $gitea_client.put_teams_members_by_id_username(team.gtid, userlogin) rescue nil + raise ActiveRecord::Rollback if tu_result.nil? + end + team.team_projects.each do |teamp| + tp_result = $gitea_client.put_teams_repos_by_id_org_repo(team.gtid, org.login, teamp&.project.identifier) rescue nil + raise ActiveRecord::Rollback if tp_result.nil? + end + end + org.organization_users.each do |user| + next if ($gitea_client.get_orgs_members_by_org_username(org.login, user.login) rescue nil) + user.destroy! + end + end + end + end + desc "同步用户" task users: :environment do users = User.where.not(mail: [nil, ""], type: 'Anonymous').or(User.where.not(login: [nil, ""])).distinct diff --git a/public/docs/api.html b/public/docs/api.html index b41272321..3b0558cd4 100644 --- a/public/docs/api.html +++ b/public/docs/api.html @@ -423,6 +423,21 @@
  • 用户拒绝申请
  • +
  • + 用户发送邮件验证码 +
  • +
  • + 用户验证邮件验证码 +
  • +
  • + 用户验证密码 +
  • +
  • + 用户验证邮箱 +
  • +
  • + 用户更改邮箱 +
  • @@ -4708,6 +4723,230 @@ Success — a happy kitten is an authenticated kitten! "created_at": "2021-06-09 16:41", "time_ago": "7分钟前" } +

    用户发送邮件验证码

    +

    用户发送邮件验证码

    + +
    +

    示例:

    +
    +
    curl -X GET http://localhost:3000/api/v1/yystopf/send_email_vefify_code.json
    +
    await octokit.request('GET /api/v1/:login/send_email_vefify_code.json')
    +

    HTTP 请求

    +

    GET /api/v1/:login/send_email_vefify_code.json

    +

    请求字段说明:

    + + + + + + + + + + + + + + + + + + + + + + + + + + + +
    参数类型字段说明
    loginstring用户标识
    code_typeint10: 更新邮箱
    emailstring邮箱
    smscodestring邮箱md5加密值
    +

    返回字段说明:

    +
    +

    返回的JSON示例:

    +
    +
    {
    +    "status": 0,
    +    "message": "success"
    +}
    +

    用户验证邮件验证码

    +

    用户验证邮件验证码

    + +
    +

    示例:

    +
    +
    curl -X POST http://localhost:3000/api/v1/yystopf/check_email_verify_code.json
    +
    await octokit.request('POST /api/v1/:login/check_email_verify_code.json')
    +

    HTTP 请求

    +

    POST /api/v1/:login/check_email_verify_code.json

    +

    请求字段说明:

    + + + + + + + + + + + + + + + + + + + + + + + + + + + +
    参数类型字段说明
    loginstring用户标识
    code_typeint10: 更新邮箱
    emailstring邮箱
    codestring邮箱验证码
    +

    返回字段说明:

    +
    +

    返回的JSON示例:

    +
    +
    {
    +    "status": 0,
    +    "message": "success"
    +}
    +

    用户验证密码

    +

    用户验证密码,检查是否和用户密码一致

    + +
    +

    示例:

    +
    +
    curl -X POST http://localhost:3000/api/v1/yystopf/check_password.json
    +
    await octokit.request('POST /api/v1/:login/check_password.json')
    +

    HTTP 请求

    +

    POST /api/v1/:login/check_password.json

    +

    请求字段说明:

    + + + + + + + + + + + + + + + + + +
    参数类型字段说明
    loginstring用户标识
    passwordstring用户密码
    +

    返回字段说明:

    +
    +

    返回的JSON示例:

    +
    +
    {
    +    "status": 0,
    +    "message": "success"
    +}
    +

    用户验证邮箱

    +

    用户验证邮箱是否符合规范以及是否已被使用

    + +
    +

    示例:

    +
    +
    curl -X POST http://localhost:3000/api/v1/yystopf/check_email.json
    +
    await octokit.request('POST /api/v1/:login/check_email.json')
    +

    HTTP 请求

    +

    POST /api/v1/:login/check_email.json

    +

    请求字段说明:

    + + + + + + + + + + + + + + + + + +
    参数类型字段说明
    loginstring用户标识
    emailstring邮箱地址
    +

    返回字段说明:

    +
    +

    返回的JSON示例:

    +
    +
    {
    +    "status": 0,
    +    "message": "success"
    +}
    +

    用户更改邮箱

    +

    用户更改一个新的邮箱

    + +
    +

    示例:

    +
    +
    curl -X PATCH http://localhost:3000/api/v1/yystopf/update_email.json
    +
    await octokit.request('PATCH /api/v1/:login/update_email.json')
    +

    HTTP 请求

    +

    PATCH /api/v1/:login/update_email.json

    +

    请求字段说明:

    + + + + + + + + + + + + + + + + + + + + + + + + + + + +
    参数类型字段说明
    loginstring用户标识
    passwordstring用户密码
    emailstring邮箱地址
    codestring邮箱验证码
    + +
    +

    请求的JSON示例:

    +
    +
    {
    +    "password": "Aa19960425.",
    +    "code": "657134",
    +    "email": "yystopf@163.com"
    +}
    +
    +
    +

    返回的JSON示例:

    +
    +
    {
    +    "status": 0,
    +    "message": "success"
    +}
     

    Projects

    获取项目邀请链接(项目管理员)

    当前登录(管理员)用户获取项目邀请链接的接口(第一次请求会默认生成role类型为developer和is_apply为true的链接)