2021-01-20 22:52:25 +01:00
|
|
|
package api
|
|
|
|
|
|
|
|
import (
|
|
|
|
"encoding/json"
|
|
|
|
"io/ioutil"
|
|
|
|
"net/http"
|
|
|
|
"strings"
|
|
|
|
|
|
|
|
"github.com/gorilla/mux"
|
2021-06-11 14:24:51 +02:00
|
|
|
"github.com/mattermost/focalboard/server/services/audit"
|
2021-05-29 08:23:10 +02:00
|
|
|
"github.com/mattermost/focalboard/server/services/mlog"
|
2021-01-20 22:52:25 +01:00
|
|
|
)
|
|
|
|
|
|
|
|
type AdminSetPasswordData struct {
|
|
|
|
Password string `json:"password"`
|
|
|
|
}
|
|
|
|
|
|
|
|
func (a *API) handleAdminSetPassword(w http.ResponseWriter, r *http.Request) {
|
|
|
|
vars := mux.Vars(r)
|
|
|
|
username := vars["username"]
|
|
|
|
|
|
|
|
requestBody, err := ioutil.ReadAll(r.Body)
|
|
|
|
if err != nil {
|
2021-07-27 18:57:29 +02:00
|
|
|
a.errorResponse(w, r.URL.Path, http.StatusInternalServerError, "", err)
|
2021-01-20 22:52:25 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
var requestData AdminSetPasswordData
|
|
|
|
err = json.Unmarshal(requestBody, &requestData)
|
|
|
|
if err != nil {
|
2021-07-27 18:57:29 +02:00
|
|
|
a.errorResponse(w, r.URL.Path, http.StatusInternalServerError, "", err)
|
2021-01-20 22:52:25 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2021-06-11 14:24:51 +02:00
|
|
|
auditRec := a.makeAuditRecord(r, "adminSetPassword", audit.Fail)
|
|
|
|
defer a.audit.LogRecord(audit.LevelAuth, auditRec)
|
|
|
|
auditRec.AddMeta("username", username)
|
|
|
|
|
2021-01-20 22:52:25 +01:00
|
|
|
if !strings.Contains(requestData.Password, "") {
|
2021-07-27 18:57:29 +02:00
|
|
|
a.errorResponse(w, r.URL.Path, http.StatusBadRequest, "password is required", err)
|
2021-01-20 22:52:25 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2021-06-18 16:03:42 +02:00
|
|
|
err = a.app.UpdateUserPassword(username, requestData.Password)
|
2021-01-20 22:52:25 +01:00
|
|
|
if err != nil {
|
2021-07-27 18:57:29 +02:00
|
|
|
a.errorResponse(w, r.URL.Path, http.StatusInternalServerError, "", err)
|
2021-01-20 22:52:25 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2021-05-29 08:23:10 +02:00
|
|
|
a.logger.Debug("AdminSetPassword, username: %s", mlog.String("username", username))
|
2021-01-20 22:52:25 +01:00
|
|
|
|
2021-02-17 20:29:20 +01:00
|
|
|
jsonStringResponse(w, http.StatusOK, "{}")
|
2021-06-11 14:24:51 +02:00
|
|
|
auditRec.Success()
|
2021-01-20 22:52:25 +01:00
|
|
|
}
|