2016-04-03 17:59:27 +00:00
|
|
|
package app
|
|
|
|
|
|
|
|
import (
|
2016-04-05 20:22:13 +00:00
|
|
|
"crypto/md5"
|
2016-04-03 17:59:27 +00:00
|
|
|
"database/sql"
|
2016-04-05 20:22:13 +00:00
|
|
|
"fmt"
|
2016-04-03 17:59:27 +00:00
|
|
|
|
2016-04-19 14:07:27 +00:00
|
|
|
"git.zxq.co/ripple/rippleapi/common"
|
2016-04-03 17:59:27 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
// GetTokenFull retrieves an user ID and their token privileges knowing their API token.
|
|
|
|
func GetTokenFull(token string, db *sql.DB) (common.Token, bool) {
|
|
|
|
var uid int
|
|
|
|
var privs int
|
2016-05-15 05:20:11 +00:00
|
|
|
var priv8 bool
|
|
|
|
err := db.QueryRow("SELECT user, privileges, private FROM tokens WHERE token = ? LIMIT 1", fmt.Sprintf("%x", md5.Sum([]byte(token)))).Scan(&uid, &privs, &priv8)
|
|
|
|
if priv8 {
|
|
|
|
privs = common.PrivilegeRead | common.PrivilegeReadConfidential | common.PrivilegeWrite
|
|
|
|
}
|
2016-04-03 17:59:27 +00:00
|
|
|
switch {
|
|
|
|
case err == sql.ErrNoRows:
|
|
|
|
return common.Token{}, false
|
|
|
|
case err != nil:
|
|
|
|
panic(err)
|
|
|
|
default:
|
|
|
|
return common.Token{
|
|
|
|
Value: token,
|
|
|
|
UserID: uid,
|
|
|
|
Privileges: common.Privileges(privs),
|
|
|
|
}, true
|
|
|
|
}
|
|
|
|
}
|