apollo-backend/internal/api/accounts.go

292 lines
7.1 KiB
Go
Raw Permalink Normal View History

package api
import (
"encoding/json"
2021-08-08 18:19:47 +00:00
"fmt"
"net/http"
2022-05-07 23:30:07 +00:00
"strings"
"time"
2021-08-08 18:19:47 +00:00
"github.com/gorilla/mux"
"github.com/sirupsen/logrus"
2021-08-14 17:56:03 +00:00
"github.com/christianselig/apollo-backend/internal/domain"
2022-03-12 17:50:05 +00:00
"github.com/christianselig/apollo-backend/internal/reddit"
)
type accountNotificationsRequest struct {
2022-03-12 17:50:05 +00:00
InboxNotifications bool `json:"inbox_notifications"`
WatcherNotifications bool `json:"watcher_notifications"`
GlobalMute bool `json:"global_mute"`
}
func (a *api) notificationsAccountHandler(w http.ResponseWriter, r *http.Request) {
2022-05-07 19:04:35 +00:00
ctx := r.Context()
anr := &accountNotificationsRequest{}
if err := json.NewDecoder(r.Body).Decode(anr); err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
return
}
vars := mux.Vars(r)
apns := vars["apns"]
rid := vars["redditID"]
dev, err := a.deviceRepo.GetByAPNSToken(ctx, apns)
if err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
return
}
acct, err := a.accountRepo.GetByRedditID(ctx, rid)
if err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
return
}
if err := a.deviceRepo.SetNotifiable(ctx, &dev, &acct, anr.InboxNotifications, anr.WatcherNotifications, anr.GlobalMute); err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
return
}
w.WriteHeader(http.StatusOK)
}
2022-03-12 17:50:05 +00:00
func (a *api) getNotificationsAccountHandler(w http.ResponseWriter, r *http.Request) {
2022-05-07 19:04:35 +00:00
ctx := r.Context()
2022-03-12 17:50:05 +00:00
vars := mux.Vars(r)
apns := vars["apns"]
rid := vars["redditID"]
dev, err := a.deviceRepo.GetByAPNSToken(ctx, apns)
if err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
2022-03-12 17:50:05 +00:00
return
}
acct, err := a.accountRepo.GetByRedditID(ctx, rid)
if err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
2022-03-12 17:50:05 +00:00
return
}
inbox, watchers, global, err := a.deviceRepo.GetNotifiable(ctx, &dev, &acct)
2022-03-12 17:50:05 +00:00
if err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
2022-03-12 17:50:05 +00:00
return
}
w.WriteHeader(http.StatusOK)
an := &accountNotificationsRequest{InboxNotifications: inbox, WatcherNotifications: watchers, GlobalMute: global}
2022-03-12 17:50:05 +00:00
_ = json.NewEncoder(w).Encode(an)
}
2021-08-08 18:19:47 +00:00
func (a *api) disassociateAccountHandler(w http.ResponseWriter, r *http.Request) {
2022-05-07 19:04:35 +00:00
ctx := r.Context()
2021-08-08 18:19:47 +00:00
vars := mux.Vars(r)
apns := vars["apns"]
rid := vars["redditID"]
dev, err := a.deviceRepo.GetByAPNSToken(ctx, apns)
if err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
2021-08-08 18:19:47 +00:00
return
}
acct, err := a.accountRepo.GetByRedditID(ctx, rid)
if err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
2021-08-08 18:19:47 +00:00
return
}
if err := a.accountRepo.Disassociate(ctx, &acct, &dev); err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
2021-08-08 18:19:47 +00:00
return
}
w.WriteHeader(http.StatusOK)
}
func (a *api) upsertAccountsHandler(w http.ResponseWriter, r *http.Request) {
2022-05-07 19:04:35 +00:00
ctx := r.Context()
2021-08-08 18:19:47 +00:00
vars := mux.Vars(r)
apns := vars["apns"]
dev, err := a.deviceRepo.GetByAPNSToken(ctx, apns)
if err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 422, err)
2021-08-08 18:19:47 +00:00
return
}
laccs, err := a.accountRepo.GetByAPNSToken(ctx, apns)
if err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 422, err)
2021-08-08 18:19:47 +00:00
return
}
accsMap := map[string]domain.Account{}
for _, acc := range laccs {
accsMap[acc.NormalizedUsername()] = acc
}
var raccs []domain.Account
if err := json.NewDecoder(r.Body).Decode(&raccs); err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 422, err)
2021-08-08 18:19:47 +00:00
return
}
for _, acc := range raccs {
delete(accsMap, acc.NormalizedUsername())
2022-03-12 17:50:05 +00:00
ac := a.reddit.NewAuthenticatedClient(reddit.SkipRateLimiting, acc.RefreshToken, acc.AccessToken)
tokens, err := ac.RefreshTokens(ctx)
2021-08-08 18:19:47 +00:00
if err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 422, err)
2021-08-08 18:19:47 +00:00
return
}
// Reset expiration timer
2022-03-28 21:33:01 +00:00
acc.TokenExpiresAt = time.Now().Add(tokens.Expiry)
2021-08-08 18:19:47 +00:00
acc.RefreshToken = tokens.RefreshToken
acc.AccessToken = tokens.AccessToken
2022-03-12 17:50:05 +00:00
ac = a.reddit.NewAuthenticatedClient(reddit.SkipRateLimiting, acc.RefreshToken, acc.AccessToken)
me, err := ac.Me(ctx)
2021-08-08 18:19:47 +00:00
2021-09-25 13:19:42 +00:00
if err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 422, err)
2021-09-25 13:19:42 +00:00
return
}
2021-08-08 18:19:47 +00:00
if me.NormalizedUsername() != acc.NormalizedUsername() {
2022-05-21 14:00:21 +00:00
err := fmt.Errorf("wrong user: expected %s, got %s", me.NormalizedUsername(), acc.NormalizedUsername())
a.errorResponse(w, r, 401, err)
2021-08-08 18:19:47 +00:00
return
}
2021-08-14 15:21:17 +00:00
// Set account ID from Reddit
acc.AccountID = me.ID
2021-08-08 18:19:47 +00:00
if err := a.accountRepo.CreateOrUpdate(ctx, &acc); err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 422, err)
2021-08-08 18:19:47 +00:00
return
}
2022-03-28 21:05:01 +00:00
if err := a.accountRepo.Associate(ctx, &acc, &dev); err != nil {
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 422, err)
2022-03-28 21:05:01 +00:00
return
}
2021-08-08 18:19:47 +00:00
}
for _, acc := range accsMap {
fmt.Println(acc.NormalizedUsername())
2021-09-25 13:19:42 +00:00
_ = a.accountRepo.Disassociate(ctx, &acc, &dev)
2021-08-08 18:19:47 +00:00
}
2022-05-07 23:30:07 +00:00
body := fmt.Sprintf(`{"apns_token": "%s"}`, apns)
req, err := http.NewRequestWithContext(ctx, "POST", "https://apollopushserver.xyz/api/new-server-addition", strings.NewReader(body))
2022-05-07 19:16:04 +00:00
req.Header.Set("Authorization", "Bearer 98g5j89aurqwfcsp9khlnvgd38fa15")
2022-05-07 19:16:04 +00:00
if err != nil {
a.logger.WithFields(logrus.Fields{
"apns": apns,
}).Error(err)
return
}
2021-08-08 18:19:47 +00:00
w.WriteHeader(http.StatusOK)
2022-05-07 19:16:04 +00:00
resp, _ := a.httpClient.Do(req)
if err != nil {
a.logger.WithFields(logrus.Fields{"err": err}).Error("failed to remove old client")
return
}
resp.Body.Close()
2021-08-08 18:19:47 +00:00
}
func (a *api) upsertAccountHandler(w http.ResponseWriter, r *http.Request) {
2022-05-07 19:04:35 +00:00
ctx := r.Context()
2021-08-08 18:19:47 +00:00
vars := mux.Vars(r)
2021-07-26 16:34:26 +00:00
var acct domain.Account
2021-08-08 18:19:47 +00:00
if err := json.NewDecoder(r.Body).Decode(&acct); err != nil {
a.logger.WithFields(logrus.Fields{
"err": err,
}).Info("failed to parse request json")
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 422, err)
return
}
// Here we check whether the account is supplied with a valid token.
2022-03-12 17:50:05 +00:00
ac := a.reddit.NewAuthenticatedClient(reddit.SkipRateLimiting, acct.RefreshToken, acct.AccessToken)
tokens, err := ac.RefreshTokens(ctx)
if err != nil {
a.logger.WithFields(logrus.Fields{
"err": err,
}).Info("failed to refresh token")
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 422, err)
return
}
// Reset expiration timer
2022-03-28 21:33:01 +00:00
acct.TokenExpiresAt = time.Now().Add(tokens.Expiry)
acct.RefreshToken = tokens.RefreshToken
acct.AccessToken = tokens.AccessToken
2022-03-12 17:50:05 +00:00
ac = a.reddit.NewAuthenticatedClient(reddit.SkipRateLimiting, acct.RefreshToken, acct.AccessToken)
me, err := ac.Me(ctx)
if err != nil {
a.logger.WithFields(logrus.Fields{
"err": err,
}).Info("failed to grab user details from Reddit")
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
return
}
if me.NormalizedUsername() != acct.NormalizedUsername() {
2022-05-21 14:00:21 +00:00
err := fmt.Errorf("wrong user: expected %s, got %s", me.NormalizedUsername(), acct.NormalizedUsername())
a.logger.WithFields(logrus.Fields{"err": err}).Warn("user is not who they say they are")
a.errorResponse(w, r, 401, err)
return
}
// Set account ID from Reddit
acct.AccountID = me.ID
// Associate
2021-08-08 18:19:47 +00:00
dev, err := a.deviceRepo.GetByAPNSToken(ctx, vars["apns"])
if err != nil {
a.logger.WithFields(logrus.Fields{
"err": err,
}).Info("failed fetching device from database")
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
return
}
// Upsert account
2021-07-26 16:34:26 +00:00
if err := a.accountRepo.CreateOrUpdate(ctx, &acct); err != nil {
a.logger.WithFields(logrus.Fields{
"err": err,
}).Info("failed updating account in database")
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
return
}
2021-08-08 18:19:47 +00:00
if err := a.accountRepo.Associate(ctx, &acct, &dev); err != nil {
a.logger.WithFields(logrus.Fields{
"err": err,
}).Info("failed associating account with device")
2022-05-21 14:00:21 +00:00
a.errorResponse(w, r, 500, err)
return
}
w.WriteHeader(http.StatusOK)
}