2014-01-09 06:42:05 +00:00
|
|
|
package middleware
|
|
|
|
|
|
|
|
import (
|
2014-06-02 04:14:05 +00:00
|
|
|
"encoding/json"
|
|
|
|
"fmt"
|
2014-01-09 06:42:05 +00:00
|
|
|
"net/http"
|
2014-01-09 23:18:49 +00:00
|
|
|
|
|
|
|
ctx "github.com/gorilla/context"
|
2014-01-10 03:21:54 +00:00
|
|
|
"github.com/jordan-wright/gophish/auth"
|
2014-03-25 03:31:33 +00:00
|
|
|
"github.com/jordan-wright/gophish/models"
|
2014-01-09 06:42:05 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
// GetContext wraps each request in a function which fills in the context for a given request.
|
|
|
|
// This includes setting the User and Session keys and values as necessary for use in later functions.
|
2014-01-11 04:37:42 +00:00
|
|
|
func GetContext(handler http.Handler) http.HandlerFunc {
|
2014-01-09 06:42:05 +00:00
|
|
|
// Set the context here
|
2014-01-11 04:37:42 +00:00
|
|
|
return func(w http.ResponseWriter, r *http.Request) {
|
2014-02-04 21:23:09 +00:00
|
|
|
// Parse the request form
|
|
|
|
err := r.ParseForm()
|
|
|
|
if err != nil {
|
|
|
|
http.Error(w, "Error parsing request", http.StatusInternalServerError)
|
|
|
|
}
|
2014-01-09 23:18:49 +00:00
|
|
|
// Set the context appropriately here.
|
2014-01-10 03:21:54 +00:00
|
|
|
// Set the session
|
|
|
|
session, _ := auth.Store.Get(r, "gophish")
|
2014-01-10 04:21:12 +00:00
|
|
|
// Put the session in the context so that
|
2014-01-10 03:21:54 +00:00
|
|
|
ctx.Set(r, "session", session)
|
2014-01-10 04:21:12 +00:00
|
|
|
if id, ok := session.Values["id"]; ok {
|
2014-03-25 03:31:33 +00:00
|
|
|
u, err := models.GetUser(id.(int64))
|
2014-01-10 04:21:12 +00:00
|
|
|
if err != nil {
|
|
|
|
ctx.Set(r, "user", nil)
|
2014-06-02 04:38:21 +00:00
|
|
|
} else {
|
|
|
|
ctx.Set(r, "user", u)
|
2014-01-10 04:21:12 +00:00
|
|
|
}
|
|
|
|
} else {
|
|
|
|
ctx.Set(r, "user", nil)
|
|
|
|
}
|
2014-01-09 06:42:05 +00:00
|
|
|
handler.ServeHTTP(w, r)
|
2014-01-10 03:21:54 +00:00
|
|
|
// Remove context contents
|
2014-01-09 23:18:49 +00:00
|
|
|
ctx.Clear(r)
|
2014-01-11 04:37:42 +00:00
|
|
|
}
|
2014-01-09 06:42:05 +00:00
|
|
|
}
|
|
|
|
|
2014-01-31 04:46:25 +00:00
|
|
|
func RequireAPIKey(handler http.Handler) http.HandlerFunc {
|
|
|
|
return func(w http.ResponseWriter, r *http.Request) {
|
|
|
|
r.ParseForm()
|
|
|
|
ak := r.Form.Get("api_key")
|
2014-02-11 06:14:58 +00:00
|
|
|
w.Header().Set("Access-Control-Allow-Origin", "*")
|
|
|
|
if r.Method == "OPTIONS" {
|
|
|
|
w.Header().Set("Access-Control-Allow-Methods", "POST, GET, OPTIONS")
|
|
|
|
w.Header().Set("Access-Control-Max-Age", "1000")
|
|
|
|
w.Header().Set("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept")
|
|
|
|
return
|
|
|
|
}
|
2014-01-31 04:46:25 +00:00
|
|
|
if ak == "" {
|
2014-02-11 06:14:58 +00:00
|
|
|
JSONError(w, 400, "API Key not set")
|
2014-01-31 04:46:25 +00:00
|
|
|
} else {
|
2014-03-26 04:53:51 +00:00
|
|
|
u, err := models.GetUserByAPIKey(ak)
|
2015-02-07 20:31:41 +00:00
|
|
|
if err != nil {
|
2014-02-11 06:14:58 +00:00
|
|
|
JSONError(w, 400, "Invalid API Key")
|
2014-02-04 21:23:09 +00:00
|
|
|
return
|
|
|
|
}
|
2014-03-26 04:53:51 +00:00
|
|
|
ctx.Set(r, "user_id", u.Id)
|
2014-01-31 04:46:25 +00:00
|
|
|
ctx.Set(r, "api_key", ak)
|
|
|
|
handler.ServeHTTP(w, r)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2014-01-09 06:42:05 +00:00
|
|
|
// RequireLogin is a simple middleware which checks to see if the user is currently logged in.
|
|
|
|
// If not, the function returns a 302 redirect to the login page.
|
2014-01-11 04:37:42 +00:00
|
|
|
func RequireLogin(handler http.Handler) http.HandlerFunc {
|
|
|
|
return func(w http.ResponseWriter, r *http.Request) {
|
2014-01-10 04:21:12 +00:00
|
|
|
if u := ctx.Get(r, "user"); u != nil {
|
|
|
|
handler.ServeHTTP(w, r)
|
|
|
|
} else {
|
|
|
|
http.Redirect(w, r, "/login", 302)
|
|
|
|
}
|
2014-01-11 04:37:42 +00:00
|
|
|
}
|
2014-01-09 06:42:05 +00:00
|
|
|
}
|
2014-01-31 04:46:25 +00:00
|
|
|
|
|
|
|
func JSONError(w http.ResponseWriter, c int, m string) {
|
2014-06-02 04:14:05 +00:00
|
|
|
w.WriteHeader(c)
|
|
|
|
w.Header().Set("Content-Type", "application/json")
|
|
|
|
cj, _ := json.MarshalIndent(models.Response{Success: false, Message: m}, "", " ")
|
|
|
|
fmt.Fprintf(w, "%s", cj)
|
2014-01-31 04:46:25 +00:00
|
|
|
}
|