2024-02-18 16:37:13 +01:00
|
|
|
package data
|
|
|
|
|
|
|
|
import (
|
|
|
|
"database/sql"
|
|
|
|
"fmt"
|
|
|
|
|
|
|
|
"github.com/go-sql-driver/mysql"
|
2024-02-22 18:49:51 +01:00
|
|
|
"golang.org/x/crypto/bcrypt"
|
2024-02-18 16:37:13 +01:00
|
|
|
)
|
|
|
|
|
|
|
|
type DB struct {
|
|
|
|
*sql.DB
|
|
|
|
}
|
|
|
|
|
|
|
|
func OpenDB(dbName string) (*DB, error) {
|
|
|
|
var err error
|
|
|
|
db := DB{DB: &sql.DB{}}
|
|
|
|
|
|
|
|
cfg := mysql.NewConfig()
|
|
|
|
cfg.DBName = dbName
|
|
|
|
cfg.User, cfg.Passwd, err = getCredentials()
|
|
|
|
if err != nil {
|
2024-02-22 15:23:29 +01:00
|
|
|
return nil, fmt.Errorf("error reading user credentials for DB: %v", err)
|
2024-02-18 16:37:13 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
db.DB, err = sql.Open("mysql", cfg.FormatDSN())
|
|
|
|
if err != nil {
|
2024-02-22 15:23:29 +01:00
|
|
|
return nil, fmt.Errorf("error opening DB: %v", err)
|
2024-02-18 16:37:13 +01:00
|
|
|
}
|
|
|
|
if err = db.Ping(); err != nil {
|
2024-02-22 15:23:29 +01:00
|
|
|
return nil, fmt.Errorf("error pinging DB: %v", err)
|
2024-02-18 16:37:13 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
return &db, nil
|
|
|
|
}
|
2024-02-22 18:49:51 +01:00
|
|
|
|
|
|
|
func (db *DB) AddUser(user, pass, first, last string, writer, editor, admin bool) error {
|
2024-02-22 20:12:09 +01:00
|
|
|
userString, stringLen, ok := checkUserStrings(user, first, last)
|
|
|
|
if !ok {
|
|
|
|
return fmt.Errorf("error: %v is longer than %v characters", userString, stringLen)
|
2024-02-22 18:49:51 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
if !permissionsOK(writer, editor, admin) {
|
2024-02-22 20:12:09 +01:00
|
|
|
return fmt.Errorf("error: permissions must be mutually exclusive: writer = %v, editor = %v, admin = %v",
|
2024-02-22 18:49:51 +01:00
|
|
|
writer, editor, admin)
|
|
|
|
}
|
|
|
|
|
2024-02-22 20:12:09 +01:00
|
|
|
hashedPass, err := bcrypt.GenerateFromPassword([]byte(pass), bcrypt.DefaultCost)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("error creating password hash: %v", err)
|
|
|
|
}
|
|
|
|
|
2024-02-22 18:49:51 +01:00
|
|
|
query := `
|
|
|
|
INSERT INTO users
|
|
|
|
(username, password, first_name, last_name, writer, editor, admin)
|
|
|
|
VALUES
|
|
|
|
(?, ?, ?, ?, ?, ?)
|
|
|
|
`
|
2024-02-22 20:12:09 +01:00
|
|
|
_, err = db.Exec(query, user, string(hashedPass), first, last, writer, editor, admin)
|
2024-02-22 18:49:51 +01:00
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("error inserting user into DB: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
2024-02-22 19:27:41 +01:00
|
|
|
|
|
|
|
func (db *DB) ChangePassword(id int64, oldPass, newPass string) error {
|
|
|
|
var oldHashedPass string
|
|
|
|
|
|
|
|
selectQuery := `
|
|
|
|
SELECT password FROM
|
|
|
|
users
|
|
|
|
WHERE
|
|
|
|
id = ?
|
|
|
|
`
|
|
|
|
row := db.QueryRow(selectQuery, id)
|
|
|
|
if err := row.Scan(&oldHashedPass); err != nil {
|
|
|
|
return fmt.Errorf("error reading password from DB: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
if err := bcrypt.CompareHashAndPassword([]byte(oldHashedPass), []byte(oldPass)); err != nil {
|
|
|
|
return fmt.Errorf("error checking password: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
newHashedPass, err := bcrypt.GenerateFromPassword([]byte(newPass), bcrypt.DefaultCost)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("error creating password hash: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
updateQuery := `
|
|
|
|
UPDATE users
|
|
|
|
SET password = ?
|
|
|
|
WHERE id = ?
|
|
|
|
`
|
2024-02-22 20:12:09 +01:00
|
|
|
_, err = db.Exec(updateQuery, string(newHashedPass), id)
|
2024-02-22 19:27:41 +01:00
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("error updating password in DB: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|