2016-04-03 17:59:27 +00:00
|
|
|
package app
|
|
|
|
|
|
|
|
import (
|
|
|
|
"database/sql"
|
|
|
|
"io/ioutil"
|
|
|
|
|
|
|
|
"github.com/gin-gonic/gin"
|
|
|
|
"github.com/osuripple/api/common"
|
|
|
|
)
|
|
|
|
|
|
|
|
// Method wraps an API method to a HandlerFunc.
|
|
|
|
func Method(f func(md common.MethodData) common.Response, db *sql.DB, privilegesNeeded ...int) gin.HandlerFunc {
|
|
|
|
return func(c *gin.Context) {
|
2016-04-08 15:27:55 +00:00
|
|
|
initialCaretaker(c, f, db, privilegesNeeded...)
|
|
|
|
}
|
|
|
|
}
|
2016-04-03 17:59:27 +00:00
|
|
|
|
2016-04-08 15:27:55 +00:00
|
|
|
func initialCaretaker(c *gin.Context, f func(md common.MethodData) common.Response, db *sql.DB, privilegesNeeded ...int) {
|
|
|
|
data, err := ioutil.ReadAll(c.Request.Body)
|
|
|
|
if err != nil {
|
|
|
|
c.Error(err)
|
|
|
|
}
|
|
|
|
c.Request.Body.Close()
|
2016-04-03 17:59:27 +00:00
|
|
|
|
2016-04-08 15:27:55 +00:00
|
|
|
token := ""
|
|
|
|
switch {
|
|
|
|
case c.Request.Header.Get("X-Ripple-Token") != "":
|
|
|
|
token = c.Request.Header.Get("X-Ripple-Token")
|
|
|
|
case c.Query("token") != "":
|
|
|
|
token = c.Query("token")
|
|
|
|
case c.Query("k") != "":
|
|
|
|
token = c.Query("k")
|
|
|
|
}
|
2016-04-03 17:59:27 +00:00
|
|
|
|
2016-04-08 15:27:55 +00:00
|
|
|
md := common.MethodData{
|
|
|
|
DB: db,
|
|
|
|
RequestData: data,
|
|
|
|
C: c,
|
|
|
|
}
|
|
|
|
if token != "" {
|
|
|
|
tokenReal, exists := GetTokenFull(token, db)
|
|
|
|
if exists {
|
|
|
|
md.User = tokenReal
|
2016-04-03 17:59:27 +00:00
|
|
|
}
|
2016-04-08 15:27:55 +00:00
|
|
|
}
|
2016-04-03 17:59:27 +00:00
|
|
|
|
2016-04-08 15:27:55 +00:00
|
|
|
missingPrivileges := 0
|
|
|
|
for _, privilege := range privilegesNeeded {
|
|
|
|
if int(md.User.Privileges)&privilege == 0 {
|
|
|
|
missingPrivileges |= privilege
|
2016-04-03 17:59:27 +00:00
|
|
|
}
|
|
|
|
}
|
2016-04-08 15:27:55 +00:00
|
|
|
if missingPrivileges != 0 {
|
|
|
|
c.IndentedJSON(401, common.Response{
|
|
|
|
Code: 401,
|
|
|
|
Message: "You don't have the privilege(s): " + common.Privileges(missingPrivileges).String() + ".",
|
|
|
|
})
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
resp := f(md)
|
|
|
|
if resp.Code == 0 {
|
|
|
|
resp.Code = 500
|
|
|
|
}
|
|
|
|
if _, exists := c.GetQuery("pls200"); exists {
|
|
|
|
c.IndentedJSON(200, resp)
|
|
|
|
} else {
|
|
|
|
c.IndentedJSON(resp.Code, resp)
|
|
|
|
}
|
2016-04-03 17:59:27 +00:00
|
|
|
}
|