Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 19 additions & 3 deletions application/controller/auth/fn.rs
Original file line number Diff line number Diff line change
Expand Up @@ -71,18 +71,18 @@ pub fn openapi_auth_user_change_password() {}

#[utoipa::path(
post,
path = "/api/auth/user/approve/{id}",
path = "/api/auth/user/update_status/{id}",
params(
("id" = i32, Path, description = "User ID")
),
responses(
(status = 200, description = "User approval status updated successfully"),
(status = 200, description = "User status updated successfully"),
(status = 400, description = "Bad request"),
(status = 500, description = "Internal server error")
)
)]
#[instrument_trace]
pub fn openapi_auth_user_approve() {}
pub fn openapi_auth_user_update_status() {}

#[utoipa::path(
get,
Expand Down Expand Up @@ -111,3 +111,19 @@ pub fn openapi_auth_user_list() {}
)]
#[instrument_trace]
pub fn openapi_auth_user_get() {}

#[utoipa::path(
post,
path = "/api/auth/user/delete/{id}",
params(
("id" = i32, Path, description = "User ID")
),
responses(
(status = 200, description = "User deleted successfully"),
(status = 400, description = "Bad request"),
(status = 403, description = "Forbidden"),
(status = 500, description = "Internal server error")
)
)]
#[instrument_trace]
pub fn openapi_auth_user_delete() {}
95 changes: 88 additions & 7 deletions application/controller/auth/impl.rs
Original file line number Diff line number Diff line change
Expand Up @@ -152,7 +152,7 @@ impl ServerHook for UserUpdateRoute {
Ok(id) => id,
Err(error) => {
let mut response: ApiResponse<String> =
ApiResponse::new(ApiResponseStatus::BusinessLogicError, error.clone());
ApiResponse::new(ApiResponseStatus::Unauthorized, error.clone());
response.set_message(&error);
ctx.get_mut_response().set_body(response.to_json_bytes());
return;
Expand Down Expand Up @@ -264,13 +264,13 @@ impl ServerHook for UserChangePasswordRoute {
}
}

impl ServerHook for UserApproveRoute {
impl ServerHook for UserUpdateStatusRoute {
#[instrument_trace]
async fn new(_ctx: &mut Context) -> Self {
Self
}

#[prologue_macros(post_method, route_param_option(ID_KEY => id_opt), request_body_json_result(request_opt: ApproveUserRequest), response_header(CONTENT_TYPE => APPLICATION_JSON))]
#[prologue_macros(post_method, route_param_option(ID_KEY => id_opt), request_body_json_result(request_opt: UpdateUserStatusRequest), response_header(CONTENT_TYPE => APPLICATION_JSON))]
#[instrument_trace]
async fn handle(self, ctx: &mut Context) {
let user_id: i32 = match id_opt {
Expand All @@ -290,7 +290,7 @@ impl ServerHook for UserApproveRoute {
return;
}
};
let request: ApproveUserRequest = match request_opt {
let request: UpdateUserStatusRequest = match request_opt {
Ok(data) => data,
Err(error) => {
let response: ApiResponse<String> =
Expand All @@ -299,7 +299,7 @@ impl ServerHook for UserApproveRoute {
return;
}
};
match AuthService::approve_user(user_id, request.get_approved()).await {
match AuthService::update_user_status(user_id, request.get_approved()).await {
Ok(user) => {
let response: ApiResponse<UserResponse> =
ApiResponse::new(ApiResponseStatus::Success, user);
Expand Down Expand Up @@ -328,7 +328,7 @@ impl ServerHook for UserListRoute {
Ok(id) => id,
Err(error) => {
let mut response: ApiResponse<String> =
ApiResponse::new(ApiResponseStatus::BusinessLogicError, error.clone());
ApiResponse::new(ApiResponseStatus::Unauthorized, error.clone());
response.set_message(&error);
ctx.get_mut_response().set_body(response.to_json_bytes());
return;
Expand Down Expand Up @@ -428,6 +428,87 @@ impl ServerHook for UserGetRoute {
}
}

impl ServerHook for UserDeleteRoute {
#[instrument_trace]
async fn new(_ctx: &mut Context) -> Self {
Self
}

#[prologue_macros(post_method, route_param_option(ID_KEY => id_opt), response_header(CONTENT_TYPE => APPLICATION_JSON))]
#[instrument_trace]
async fn handle(self, ctx: &mut Context) {
let current_user_id: i32 = match AuthService::extract_user_from_cookie(ctx) {
Ok(id) => id,
Err(error) => {
let mut response: ApiResponse<String> =
ApiResponse::new(ApiResponseStatus::Unauthorized, error.clone());
response.set_message(&error);
ctx.get_mut_response().set_body(response.to_json_bytes());
return;
}
};
let current_user: UserResponse = match AuthService::get_user(current_user_id).await {
Ok(Some(user_info)) => user_info,
Ok(None) => {
let response: ApiResponse<&str> =
ApiResponse::new(ApiResponseStatus::Unauthorized, "User not found");
ctx.get_mut_response().set_body(response.to_json_bytes());
return;
}
Err(error) => {
let mut response: ApiResponse<String> =
ApiResponse::new(ApiResponseStatus::BusinessLogicError, error.clone());
response.set_message(&error);
ctx.get_mut_response().set_body(response.to_json_bytes());
return;
}
};
let user_role: UserRole = current_user.get_role().parse().unwrap_or_default();
if !user_role.is_admin() {
let response: ApiResponse<&str> =
ApiResponse::new(ApiResponseStatus::Forbidden, "Only admin can delete users");
ctx.get_mut_response().set_body(response.to_json_bytes());
return;
}
let target_user_id: i32 = match id_opt {
Some(id_str) => match AuthService::decode_id(&id_str) {
Ok(id) => id,
Err(_) => {
let response: ApiResponse<&str> =
ApiResponse::new(ApiResponseStatus::InvalidRequest, "Invalid user ID");
ctx.get_mut_response().set_body(response.to_json_bytes());
return;
}
},
None => {
let response: ApiResponse<&str> =
ApiResponse::new(ApiResponseStatus::InvalidRequest, "User ID is required");
ctx.get_mut_response().set_body(response.to_json_bytes());
return;
}
};
if current_user_id == target_user_id {
let response: ApiResponse<&str> =
ApiResponse::new(ApiResponseStatus::Forbidden, "Cannot delete yourself");
ctx.get_mut_response().set_body(response.to_json_bytes());
return;
}
match AuthService::delete_user(target_user_id).await {
Ok(_) => {
let response: ApiResponse<&str> =
ApiResponse::new(ApiResponseStatus::Success, "User deleted successfully");
ctx.get_mut_response().set_body(response.to_json_bytes())
}
Err(error) => {
let mut response: ApiResponse<String> =
ApiResponse::new(ApiResponseStatus::BusinessLogicError, error.clone());
response.set_message(&error);
ctx.get_mut_response().set_body(response.to_json_bytes())
}
};
}
}

impl ServerHook for UserLogoutRoute {
#[instrument_trace]
async fn new(_ctx: &mut Context) -> Self {
Expand Down Expand Up @@ -475,7 +556,7 @@ impl ServerHook for UserInfoRoute {
},
Err(error) => {
let mut response: ApiResponse<String> =
ApiResponse::new(ApiResponseStatus::BusinessLogicError, error.clone());
ApiResponse::new(ApiResponseStatus::Unauthorized, error.clone());
response.set_message(&error);
ctx.get_mut_response().set_body(response.to_json_bytes());
}
Expand Down
8 changes: 6 additions & 2 deletions application/controller/auth/struct.rs
Original file line number Diff line number Diff line change
Expand Up @@ -20,9 +20,9 @@ pub struct UserUpdateRoute;
#[derive(Clone, Copy, Data, Debug, Default)]
pub struct UserChangePasswordRoute;

#[route("/api/auth/user/approve/{id}")]
#[route("/api/auth/user/update_status/{id}")]
#[derive(Clone, Copy, Data, Debug, Default)]
pub struct UserApproveRoute;
pub struct UserUpdateStatusRoute;

#[route("/api/auth/user/list")]
#[derive(Clone, Copy, Data, Debug, Default)]
Expand All @@ -32,6 +32,10 @@ pub struct UserListRoute;
#[derive(Clone, Copy, Data, Debug, Default)]
pub struct UserGetRoute;

#[route("/api/auth/user/delete/{id}")]
#[derive(Clone, Copy, Data, Debug, Default)]
pub struct UserDeleteRoute;

#[route("/api/auth/logout")]
#[derive(Clone, Copy, Data, Debug, Default)]
pub struct UserLogoutRoute;
Expand Down
Loading
Loading